Critical Infrastructure Regime Kit
One baseline, every regulator. Power, pipelines, water, rail and nuclear — which regimes bind each asset, what changed in 2026 and what lands by 2030, twenty control families mapped across all of them, and the incident clocks that run in hours.
What this actually gives you
- The regimes converge on the same twenty control families — mapped across NERC CIP, the TSA directives, EPA/AWIA and state rules, NIS2, IEC 62443, CSF 2.0 and the CISA CPGs, with the strictest formulation named in each row. Build once, present each regulator its own view.
- CIP-003-9 vendor remote-access duties for low-impact assets have been enforceable since 1 April 2026 — reaching the municipal utilities and solar arrays that used to sit behind a VPN and outside the conversation.
- TSA pipeline reporting is 12 hours under SD-01G, in force to 15 January 2027, with a three-year 100% assessment plan while the permanent rule is still pending.
- Every clock computes from one determination time, starting at CIP-008’s one hour — which applies to attempted compromises too, and is why the IR plan has to define "determination" before you need it.
- The assessment planner carries the cadences that actually catch entities — fifteen months, thirty-five days, fifteen days, thirty-six months, TSA’s annual plan, AWIA’s five years — as one calendar with an evidence-location index.
One baseline, every regulator. The regimes that reach critical infrastructure converge on the same twenty control families, and file 05 maps them across NERC CIP, the TSA directives, EPA and AWIA and the state water rules, NIS2, IEC 62443, CSF 2.0 and the CISA cross-sector performance goals — naming the strictest formulation in each row. CIP-005's defined perimeter. CIP-004's 24-hour revocation. CIP-007's 35-day patch clock. CIP-015's 90-day retention. TSA's requirement that OT remain operable if IT is down. Build once to the strictest, then present each regulator its own view.
The 2026–2030 calendar is dense, dated, and mostly already running. CIP-003-9's vendor remote-access duties for low-impact assets have been enforceable since 1 April 2026 — that reaches the municipal utilities and solar arrays that used to sit behind a VPN and outside the conversation. CIP-012-2 since 1 July 2026. The virtualization package was approved in March. CIP-015 internal network monitoring phases in to September 2028 for control centres and 2030 for the rest, with CIP-015-2 extending it to the access-control systems that hold the keys. CIP-003-11 lands in 2029.
TSA's SD Pipeline-2021-01G runs 16 January 2026 to 15 January 2027 with a 12-hour reporting clock and a three-year 100% assessment plan, while the permanent-rule NPRM is still pending. AWIA's mid-size water tier hit its risk assessment on 30 June 2026 and its emergency response plan on 31 December, with New York and New Jersey layering state rules on top.
Every clock computed from one determination time. File 06 starts at CIP-008's one hour — which applies to attempted compromises as well as actual ones, and is exactly why your incident response plan has to define what "determination" means before you need it — and runs out through CIRCIA, TSA, EPA, NIS2 and the SEC from that single input.
The regime layer above the plant. This is the compliance half of a pair. The OT Security Program Kit is the plant — inventory, zones and conduits, the remote-access broker, patch and EOL, the safety-first playbook. Every row in this kit points at the OT-01 file that produces the evidence for it. Buy this one if you are in compliance or regulatory affairs; buy that one if you run the plant; most operators need both, and the Critical Infrastructure Complete bundle is the pair with the drill and the federal reporting pack.
What you get
01 Sector & Regime Selector (XLSX) — which regimes bind each asset, by sector and characteristics.
02 NERC CIP 2026 Crosswalk (XLSX) — the standards with their 2026-to-2030 effective and compliance dates, including CIP-015 and the virtualization package.
03 TSA Pipeline Directive Crosswalk (XLSX) — the SD-01G and 02F requirement set, the 12-hour clock, the annual cybersecurity assessment plan and the three-year coverage requirement.
04 Water & Wastewater Regime Sheet (XLSX) — AWIA tiers with their risk assessment and emergency response plan dates, EPA expectations, and the state rules layered above them.
05 Unified Control Baseline (XLSX) — the twenty families across every regime, with the strictest formulation named in each row.
06 Multi-Regime Incident Clock (XLSX) — every deadline from one determination time, starting at one hour.
07 Assessment Programme Planner (XLSX) — the cadences that actually catch entities: fifteen months, thirty-five days, fifteen days, thirty-six months, TSA's annual plan and AWIA's five years, as one calendar with an evidence-location index.
08 Executive Brief (PPTX) — the position, the exposure and the decisions.
09 Practitioner Guide (PDF) — the regimes, what changed, the baseline, the clocks, the assessment programme, running it, failure patterns and an FAQ.
ci01.json — regimes, control families, dates and clock rules.
Safety first. This kit sits above a live process. Nothing in it should be applied to a plant without plant engineering in the room, and where a compliance deadline and a safe operating state disagree, the safe state wins and the deviation gets documented.
Pairs with the CIRCIA 72/24 Reporting Readiness Pack for the federal reporting duty, the Executive Tabletop Kit whose scenario 6 is the drill, and the Director's Cyber Oversight Kit for the board layer above all of it.
Every date is marked for verification against FERC, NERC, TSA and EPA sources — including a known discrepancy between trackers on the CIP-015 compliance date (2 September versus 1 October 2028), which the files flag rather than silently resolve. A practitioner's toolset, not legal advice.
Also available in 2 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
Utility Board Package
The regime calendar an operator is judged against, and the twelve questions a director should be asking about it. What management owes the regulator, and what the board records having asked. 15% off buying separately.
Critical Infrastructure Complete
The plant, the regulators above it, the federal reporting duty, the drill and the board layer — five products covering an operator end to end, from the vendor VPN that should already be off to the evidence log a director keeps. 25% off buying separately.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee