Critical infrastructure — one baseline, every regulator
Power, pipelines, water, rail and nuclear answer to different regulators that converge on the same twenty control families. CIP-003-9’s vendor remote-access duties for low-impact assets have been enforceable since 1 April 2026, TSA pipeline reporting runs on twelve hours, and CIP-015 internal network monitoring phases in through 2028 and 2030. Build once to the strictest formulation, then present each regulator its own view.
Key dates
9 dated obligations. Rows marked verify are not final in their source. See the whole calendar.
What practitioners need to know
Lifted verbatim from the kits below, each attributed to the product that says it.
-
CISA estimates roughly 300,000 covered entities across the 16 sectors, and most do not think of themselves as critical infrastructure — water utilities, clinics, food and agriculture, regional transport, mid-size manufacturers and their MSPs.
— CIRCIA 72/24 Reporting Readiness Pack -
The hard part is not the report. It is knowing whether you owe one at 2 a.m. while the incident is still running — a two-gate covered-entity test, then four prongs and the exclusions.
— CIRCIA 72/24 Reporting Readiness Pack -
72 hours for a substantial incident, 24 hours for a ransom payment, with a report pre-fill so Section A is complete before anything happens.
— CIRCIA 72/24 Reporting Readiness Pack -
Built on the NPRM and honest about it: everything still open is marked “verify final” rather than presented as settled, and the updated edition is free when the final rule publishes.
— CIRCIA 72/24 Reporting Readiness Pack -
The regimes converge on the same twenty control families — mapped across NERC CIP, the TSA directives, EPA/AWIA and state rules, NIS2, IEC 62443, CSF 2.0 and the CISA CPGs, with the strictest formulation named in each row. Build once, present each regulator its own view.
— Critical Infrastructure Regime Kit -
CIP-003-9 vendor remote-access duties for low-impact assets have been enforceable since 1 April 2026 — reaching the municipal utilities and solar arrays that used to sit behind a VPN and outside the conversation.
— Critical Infrastructure Regime Kit -
TSA pipeline reporting is 12 hours under SD-01G, in force to 15 January 2027, with a three-year 100% assessment plan while the permanent rule is still pending.
— Critical Infrastructure Regime Kit -
Every clock computes from one determination time, starting at CIP-008’s one hour — which applies to attempted compromises too, and is why the IR plan has to define "determination" before you need it.
— Critical Infrastructure Regime Kit -
The assessment planner carries the cadences that actually catch entities — fifteen months, thirty-five days, fifteen days, thirty-six months, TSA’s annual plan, AWIA’s five years — as one calendar with an evidence-location index.
— Critical Infrastructure Regime Kit -
Safety first, and that is not a disclaimer. In IT you contain by isolating; in OT, isolating the wrong thing takes the operator’s view of a running process away. Every task carries a safety gate.
— OT Security Program Kit for the Plant
Kits that cover it
3 products, cheapest first.
CIRCIA 72/24 Reporting Readiness Pack
Know in ten minutes whether CIRCIA covers you, decide in one call whether an incident is reportable, and have the report drafted inside the first day — the two-gate covered-entity worksheet, the four-prong decision tree, the 72/24 clock runbook, and a report pre-fill with a JSON Schema twin for your SOAR. Built on the NPRM, with a free update when the final rule publishes.
Critical Infrastructure Regime Kit
One baseline, every regulator. Power, pipelines, water, rail and nuclear — which regimes bind each asset, what changed in 2026 and what lands by 2030, twenty control families mapped across all of them, and the incident clocks that run in hours.
OT Security Program Kit for the Plant
Segment the plant, fence vendor remote access, survive the outage. For the plant with a flat network, a vendor VPN, SCADA on an ageing hypervisor and a safety PLC on the same VLAN — the IEC 62443 zones-and-conduits programme, sequenced for a plant that cannot stop.
Bundles
2 bundles cover this alongside adjacent work — always below the sum of the parts.
Utility Board Package
The regime calendar an operator is judged against, and the twelve questions a director should be asking about it. What management owes the regulator, and what the board records having asked. 15% off buying separately.
Critical Infrastructure Complete
The plant, the regulators above it, the federal reporting duty, the drill and the board layer — five products covering an operator end to end, from the vendor VPN that should already be off to the evidence log a director keeps. 25% off buying separately.
Other regimes: EU AI Act · HIPAA · DORA & NIS2 · PCI DSS · Third-party risk · Post-quantum
Working to a date? The compliance calendar. Not legal advice.