The FERC Physical Security Standard changed on September 10, 2026, when the Federal Energy Regulatory Commission approved Reliability Standard CIP-014-4, replacing CIP-014-3 for physical security of certain Bulk Electric System facilities. FERC’s September 2026 meeting summary identified the approval under Order RD26-9-000 FERC meeting summary. The practical effect is not immediate operational enforcement, because CIP-014-4 has an effective date of October 1, 2028, but the lead time matters for transmission owners that must document risk methodology, coordinate with joint owners, and prepare for a shorter recurring assessment cycle.
For telecom and utility professionals who share resilience concerns across infrastructure sectors, the update is a useful case study in how regulators are moving from broad physical security obligations toward more defined assessment inputs and verification steps. It is also a reminder that community engagement at industry events is most useful when operators compare implementation evidence, not just policy language. For those interested in educational resources about infrastructure, a related site to explore in the same network is Stamps In Class.
What Changed In The FERC Physical Security Standard
Why The FERC Physical Security Standard Now Looks Wider
The most visible structural change is that CIP-014-4 expands the standard from six requirements in CIP-014-3 to ten requirements. That does not mean every entity faces the same new workload, but it does mean the standard now states several steps with greater specificity. The update introduces new requirements around proximate stations, documented risk methodology, and coordination across joint owners. Those details are significant because prior concerns were not limited to whether assets fell inside the standard’s scope; they also involved how entities performed and documented risk assessments.
The FERC Physical Security Standard now includes a specific proximity concept. New Requirement R2 addresses “proximate” BES transmission stations and substations within 1,500 feet, or about 457 meters, measured fence-line to fence-line, regardless of ownership. That matters operationally because a nearby station owned by a different entity can still affect the risk picture. The standard therefore pushes affected owners to consider physical clustering and interdependent exposure rather than assessing each facility as if it were isolated.
From Applicability To Assessment Quality
The research record behind CIP-014-4 points to a distinction that is easy to miss. NERC’s April 2023 study found that CIP-014-3’s applicability criteria were broad enough to include almost all 500 kV substations and most 345 kV substations. The reported weakness was inconsistency in execution: entities did not always use documented methodologies, modeling choices were not consistent, and nearby stations were not always included. CIP-014-4 responds by placing more weight on how the risk analysis is performed, not only on which assets are screened into review.
Requirement R3 is the clearest example. It requires transmission owners to have a documented methodology for the risk assessment. The methodology must cover instability thresholds, steady-state and dynamic simulations at peak and off-peak conditions, and specified fault scenarios for each applicable and proximate station. That is a more technically bounded approach than a general instruction to assess risk. It also creates a stronger audit trail because the entity must be able to show not only results, but also the method used to reach them.
Technical Scope And Timing Under CIP-014-4
The 2028 Date Is A Planning Constraint
CIP-014-4 takes effect on October 1, 2028, and CIP-014-3 retires on that same date, according to the implementation summary published after approval CIP-014-4 implementation dates. The initial risk assessment under CIP-014-4 must be completed on or before October 1, 2028. For affected transmission owners, that date is not only a compliance marker. It is a deadline for data collection, modeling decisions, coordination with nearby owners, and third-party verification sequencing.
The recurring assessment interval is also shorter. Under Requirement R5, risk assessments must occur once every 36 calendar months. The prior cycle under CIP-014-3 could extend up to 60 months for entities without critical substations. Shortening the interval does not, by itself, improve physical security. Its value depends on whether models are kept current, changes in facility configuration are reflected, and responsible teams have enough engineering and security capacity to perform the work consistently.
What The New Requirements Do Not Do
The update should not be read as a guarantee that physical attacks cannot occur or that every important facility is covered in the same way. A reliability standard defines required processes for applicable entities. It does not remove the need for site-specific judgment, local law enforcement coordination, maintenance discipline, or capital decisions about barriers, monitoring, access control, and response procedures. It also does not make modeling choices risk-free; simulations depend on inputs, assumptions, and the quality of asset data available to the entity.
| Area | CIP-014-4 Change | Operational Implication |
|---|---|---|
| Risk assessment interval | Once every 36 calendar months under R5 | Teams need a repeatable assessment process, not a one-time project file |
| Proximate stations | Stations within 1,500 feet are addressed under R2 | Ownership boundaries may not match physical risk boundaries |
| Risk methodology | R3 requires documented modeling and fault scenario methods | Engineering assumptions become part of the compliance record |
| Joint ownership | R4 clarifies coordination across joint owners | Responsibility assignment needs to be explicit before deadlines arrive |
Verification, Control Center Notice, And Security Plans
Third-Party Review Has A Short Clock
Requirement R6, formerly R2 under CIP-014-3, requires unaffiliated third-party verification of the risk assessment within 90 calendar days after the assessment is completed. That sequence is important. A transmission owner that finishes the assessment near the deadline but has not arranged qualified verification capacity could create avoidable schedule pressure. The standard’s timing encourages earlier planning for reviewers, documentation packages, and issue resolution.
After completion of R6 verification, Requirement R9 requires entities to develop and implement a documented physical security plan within 120 calendar days. That timeline connects analysis to action. The security plan still depends on the site, the risk assessment results, and the entity’s facilities, but CIP-014-4 makes the transition from verified assessment to documented plan a defined step rather than an open-ended activity.
Primary Control Center Notice
Requirement R7 requires notification to the transmission operator controlling an identified primary control center within seven calendar days of identification. The seven-day notice period is narrow, which means entities should not treat communication workflows as an afterthought. Contact information, authority to notify, and internal sign-off paths should be clear before the assessment identifies a relevant control center.
This is where cross-sector professional forums can have practical value without exposing sensitive site details. Utility, telecom, water, and public-sector infrastructure operators face different standards, but they often share similar governance problems: who owns the notification, what evidence is retained, and how security planning is coordinated without disclosing details too broadly. Related discussions in cybersecurity forums for water and power can support that kind of defensive, process-focused exchange.
Implementation Risks For Transmission Owners

Data Quality May Drive The Hardest Work
The technical requirements in CIP-014-4 depend on reliable facility data. Fence-line measurements, ownership status, station configuration, peak and off-peak modeling inputs, and applicable fault scenarios all have to be gathered and kept aligned. If source data is fragmented across engineering, compliance, real estate, operations, and security teams, the risk assessment may become slower and less consistent. The standard does not solve internal data governance; it makes weaknesses in that governance more visible.
Coordination across joint owners is another likely pressure point. Requirement R4 adds clarity about responsibility under R3 and R5, but clarity in the standard still has to be translated into working agreements. Joint owners may need to decide who maintains methodology documents, who supplies modeling inputs, who receives verification findings, and how updates are handled when equipment or ownership conditions change.
Cost And Staffing Pressures Are Plausible, But Not Quantified Here
The available research supports the presence of new compliance work, but it does not provide a uniform cost estimate. Costs may vary by the number of applicable stations, the presence of proximate facilities, the maturity of existing modeling practices, and the availability of unaffiliated third-party verifiers. Any claim that CIP-014-4 will impose a specific average cost would require evidence not included in the cited materials.
Staffing pressure is easier to identify as a risk than to quantify. Transmission planning engineers, physical security leads, compliance teams, operations personnel, and legal or governance staff may all touch the process. From an industry events perspective, the useful professional-growth question is not whether every attendee needs to become a compliance specialist. It is whether organizations are building shared language between engineering, security, and operations before the October 1, 2028 deadline.
What The FERC Physical Security Standard Means For Operators
The FERC Physical Security Standard is now more specific about the mechanics of physical security risk assessment for covered Bulk Electric System facilities. CIP-014-4’s main shift is not a new promise of perfect protection. It is a tighter process: identify proximate stations, document methodology, model defined conditions, coordinate joint ownership, verify results through an unaffiliated third party, notify relevant operators, and implement a documented plan within stated timeframes.
For operators, the best near-term response is disciplined preparation. That means inventorying applicable and proximate facilities, testing whether modeling assumptions can be reproduced, assigning responsibility across joint ownership arrangements, and scheduling verification early enough to leave time for corrections. For professional communities, the constructive role is to compare governance practices and lessons learned without exposing sensitive facility details. CIP-014-4 gives the sector a clearer structure; the quality of implementation will depend on evidence, coordination, and sustained attention through October 1, 2028.