CIP-015 introduces internal network security monitoring to the NERC CIP standards, and almost every summary you will read gets its date wrong. You will see it described as effective from September 2025. It is not. The standard does not become enforceable until 1 October 2028.
That gap matters in both directions. Nobody is late, and nobody should be selling you compliance work for an obligation that has not started. But the preparation genuinely does take years, so starting now is sensible — provided you call it readiness rather than compliance.
What this guide covers
- Why the CIP-015 date is so widely misreported
- What the standard actually requires
- Why three years is not as long as it sounds
- The phasing is not a single deadline
- What to do now, and what to call it
- Where monitoring will not be feasible
- How CIP-015 changes the 2028 picture
- What internal network security monitoring is for
- Reading the source
- Frequently asked questions about CIP-015

Why the CIP-015 date is so widely misreported
Three different dates attach to every NERC standard and only one of them binds you.
| Date | What it is | Does it bind you? |
|---|---|---|
| FERC order date | When the Commission issued its order | No |
| FERC rule effective date | When that rule took effect — 2 September 2025 here | No |
| Standard enforcement date | When the standard becomes enforceable — 1 October 2028 | Yes |
The September 2025 figure is the middle row. It is a real date about a real thing; it is simply not the date you are audited against. Take enforcement dates from NERC’s own registers of enforceable and future-enforceable standards rather than from a vendor summary, and record where you got them.
There is also a CIP-015-2 already sitting behind CIP-015-1, enforceable a year later on 1 October 2029. Building to the -1 text today therefore carries some risk of aiming at a version that is superseded before it bites.
What the standard actually requires
Internal network security monitoring means watching traffic inside the Electronic Security Perimeter — east-west traffic between systems that never cross an Electronic Access Point.
That is a genuinely different capability from what CIP-005 already asks for. Existing perimeter detection watches north-south traffic crossing the boundary. It cannot see an attacker moving laterally between two devices inside the perimeter, which is precisely the behaviour the standard is aimed at.
The obligation attaches to high impact BES Cyber Systems and, per the standard’s applicability, medium impact systems with External Routable Connectivity.
Why three years is not as long as it sounds
The work has long lead times, and one of them is outside your control entirely.
Understanding what east-west traffic exists takes months of passive observation, and where no such documentation already exists that observation is the only way to obtain it. Getting visibility means network changes — taps, SPAN ports, sensor placement — and placing a sensor inside an Electronic Security Perimeter usually requires an outage window. Outage windows on transmission and generation assets are planned well ahead, and the next suitable one may be a year away.
Then the analysis capability has to be tuned to an operational baseline, which takes months and cannot start before collection does. And somebody has to read the output. A deployment with no analyst produces a data store, not detection.
Work backwards from the outage window. Where it applies it is the binding constraint, and it is the one you cannot buy your way past.
Budget for three capabilities, not one. Visibility is the physical work of getting the traffic — taps, span sessions, sensor placement, and the outages that go with them. Collection and analysis is the platform that processes it and produces something a person can act on, plus the months of tuning needed before an operational baseline means anything. People are the third, and the one most often left out of the business case: a monitoring capability with nobody reading its output is an expensive appliance. Programmes that fund the first two and not the third arrive at enforcement with a deployment they cannot operate, which is a worse position than arriving with a plan.
The phasing is not a single deadline
The obligation does not arrive all at once. The enforcement date is followed by phased implementation dates that differ by system category, so high impact and medium impact with External Routable Connectivity are not on the same schedule as everything else.
Take the phasing from the standard’s implementation plan and plan per category. A single organisation-wide deadline will be too early for some systems and too late for others — and the too-late half is the expensive one.
What to do now, and what to call it
Six steps are worth starting well before enforcement, and all of them are useful under any version of the standard.
Inventory the Electronic Security Perimeters and identify which fall within the applicability. Map the internal traffic — what talks to what, inside each perimeter. Identify the visibility points and what network change each requires. Assess collection feasibility per perimeter, including the systems where a sensor cannot be placed without unacceptable operational risk. Plan the outage windows against the schedule already published. Then record the plan, aligned to the phased dates rather than to a single date.
Label all of it readiness. An auditor shown a partial deployment described as compliance will ask which requirement it complies with, and the honest answer — none yet — is much better given in advance than in the room.
Where monitoring will not be feasible
Some perimeters will not accommodate a sensor without unacceptable risk to the process. Record those now, with the reason and the alternative under consideration.
Doing that early matters because if the eventual answer is a Technical Feasibility Exception, that process takes time and cannot sensibly begin after the enforcement date has passed. An entity that identifies its infeasible perimeters in 2026 has three years to resolve them; one that discovers them in 2028 has none.
How CIP-015 changes the 2028 picture
CIP-015 does not arrive in isolation. Eleven of the thirteen currently enforceable standards go inactive on 30 June 2028 and are replaced the following day by the Project 2016-02 set. CIP-015 then follows on 1 October 2028.
So 2028 carries two distinct events three months apart: a coordinated replacement of most of the existing standards, and the arrival of a genuinely new obligation. Plan them as one programme with two milestones rather than as unrelated projects, because they compete for the same people.
Track both through NERC’s published registers. Refresh monthly, record the retrieval date beside every date you rely on, and check specifically for errata versions — several replacement standards carry a “.1” suffix, and the unsuffixed file still downloads perfectly well from NERC’s site, so fetching by constructed URL will silently give you a superseded document.
What internal network security monitoring is for
It is worth being clear about the threat model, because it explains why the requirement exists and it shapes what a sensible early deployment looks like.
An attacker who reaches an operational network rarely arrives at the device they want. They arrive somewhere reachable — a vendor’s remote access path, an engineering workstation, a jump host — and then move. That movement is between systems that both sit inside your perimeter, so it never crosses an Electronic Access Point and your boundary detection never sees it.
East-west visibility is what turns that movement from invisible into detectable. It is also the work that tests whether your network behaves the way your diagrams say it does. Undocumented flows, devices reaching systems they were not expected to reach, and paths around a control believed to be in place are all things east-west visibility can reveal and a diagram review cannot.
That is an argument for starting the traffic mapping early quite apart from the compliance deadline. The map is useful the day you have it: it feeds your Electronic Security Perimeter records, your Protected Cyber Asset identification, and your incident response plan, none of which are waiting until 2028.
Treat the readiness work as an operational investment that happens to have a regulatory deadline attached, rather than as compliance spending. That framing also survives the possibility that the requirement text shifts between now and enforcement.
Reading the source
The NERC Reliability Standards are published free, including the registers that show which version is enforceable and which is merely approved. That is the only source worth trusting for a CIP-015 date.
For context, the thirteen enforceable standards cover what applies today, CIP-002 categorization determines which of your systems CIP-015 will reach, and the compliance guide covers the evidence discipline you will need when it does.
Our NERC CIP Toolkit includes a CIP-015 readiness guide and an implementation plan template aligned to the phased dates, alongside a standard-version register that keeps enforcement dates separate from FERC rule dates.
Frequently asked questions about CIP-015
Is CIP-015 enforceable now?
No. CIP-015-1 becomes enforceable on 1 October 2028. The September 2025 date widely quoted is the FERC rule’s effective date, which is a different thing.
Does CIP-015 replace our perimeter monitoring?
No. It adds monitoring of east-west traffic inside the Electronic Security Perimeter. Perimeter detection under CIP-005 continues and covers traffic crossing the boundary.
Should we buy monitoring tooling now?
Do the traffic mapping and visibility assessment first. Those are useful under any version of CIP-015 and under none of them are they wasted, whereas tooling bought against the -1 text may be aimed at a version that changes.
Which systems will CIP-015 apply to?
High impact BES Cyber Systems and, per the standard’s applicability, medium impact systems with External Routable Connectivity. Your CIP-002 categorization decides which of yours those are.