ciso.diy

Critical infrastructure — one baseline, every regulator

Power, pipelines, water, rail and nuclear answer to different regulators that converge on the same twenty control families. CIP-003-9’s vendor remote-access duties for low-impact assets have been enforceable since 1 April 2026, TSA pipeline reporting runs on twelve hours, and CIP-015 internal network monitoring phases in through 2028 and 2030. Build once to the strictest formulation, then present each regulator its own view.

Key dates

9 dated obligations. Rows marked verify are not final in their source. See the whole calendar.

In force SD Pipeline-2021-01G in force — 12-hour CISA reporting, annual assessment plan, 100% coverage in three years
In force CIP-003-9 — vendor electronic remote-access controls for low-impact assets become enforceable
In force Mid-size systems — risk and resilience assessment due
In force CIP-012-2 — communications between control centres, including availability
Pending Mid-size systems — emergency response plan due
Pending SD Pipeline-2021-01G expires — reissue or the permanent rule
Pending CIP-015 internal network security monitoring — compliance for control centres verify
Pending CIP-003-11 becomes enforceable verify
Pending CIP-015 internal network security monitoring — compliance for remaining medium-impact assets with ERC verify

What practitioners need to know

Lifted verbatim from the kits below, each attributed to the product that says it.

  • CISA estimates roughly 300,000 covered entities across the 16 sectors, and most do not think of themselves as critical infrastructure — water utilities, clinics, food and agriculture, regional transport, mid-size manufacturers and their MSPs.

    — CIRCIA 72/24 Reporting Readiness Pack
  • The hard part is not the report. It is knowing whether you owe one at 2 a.m. while the incident is still running — a two-gate covered-entity test, then four prongs and the exclusions.

    — CIRCIA 72/24 Reporting Readiness Pack
  • 72 hours for a substantial incident, 24 hours for a ransom payment, with a report pre-fill so Section A is complete before anything happens.

    — CIRCIA 72/24 Reporting Readiness Pack
  • Built on the NPRM and honest about it: everything still open is marked “verify final” rather than presented as settled, and the updated edition is free when the final rule publishes.

    — CIRCIA 72/24 Reporting Readiness Pack
  • The regimes converge on the same twenty control families — mapped across NERC CIP, the TSA directives, EPA/AWIA and state rules, NIS2, IEC 62443, CSF 2.0 and the CISA CPGs, with the strictest formulation named in each row. Build once, present each regulator its own view.

    — Critical Infrastructure Regime Kit
  • CIP-003-9 vendor remote-access duties for low-impact assets have been enforceable since 1 April 2026 — reaching the municipal utilities and solar arrays that used to sit behind a VPN and outside the conversation.

    — Critical Infrastructure Regime Kit
  • TSA pipeline reporting is 12 hours under SD-01G, in force to 15 January 2027, with a three-year 100% assessment plan while the permanent rule is still pending.

    — Critical Infrastructure Regime Kit
  • Every clock computes from one determination time, starting at CIP-008’s one hour — which applies to attempted compromises too, and is why the IR plan has to define "determination" before you need it.

    — Critical Infrastructure Regime Kit
  • The assessment planner carries the cadences that actually catch entities — fifteen months, thirty-five days, fifteen days, thirty-six months, TSA’s annual plan, AWIA’s five years — as one calendar with an evidence-location index.

    — Critical Infrastructure Regime Kit
  • Safety first, and that is not a disclaimer. In IT you contain by isolating; in OT, isolating the wrong thing takes the operator’s view of a running process away. Every task carries a safety gate.

    — OT Security Program Kit for the Plant

Kits that cover it

3 products, cheapest first.

Bundles

2 bundles cover this alongside adjacent work — always below the sum of the parts.

Other regimes: EU AI Act · HIPAA · DORA & NIS2 · PCI DSS · Third-party risk · Post-quantum

Working to a date? The compliance calendar. Not legal advice.