Search NASA⌕ Search

SEARCH · Search NASA

Results for “NERC”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Securing Grid Communications Infrastructure: Addressing Gaps Beyond NERC CIP Facility Perimeters

The North American electric grid relies on a complex communications infrastructure that extends beyond facility perimeters traditionally covered by NERC Critical Infrastructure Protection (CIP) standards. While CIP requirements have significantly strengthened cybersecurity within Electronic Security Perimeters, many operational communications—such as those between control centers, substations, and third-party networks—fall outside current regulatory scope. As grid modernization introduces new technologies and connectivity models, these external pathways present evolving security challenges. This brief explores the nature of these challenges, including emerging attack vectors and supply chain considerations, and highlights how ongoing grid transformation increases exposure to sophisticated threats. It outlines practical strategies and policy options to complement existing standards, such as expanding secure communications practices, enhancing supply chain transparency, and fostering collaboration among federal, state, and industry stakeholders. Near-term actions like encryption, authentication, and contractual safeguards can help reduce risk while longer-term frameworks are developed to ensure resilient and secure grid operations.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

CIE Update for NERC RSTC (March 2024)

This brief presentation provides a brief overview of Cyber-Informed Engineering (CIE), explains public resources available for CIE application, and reviews current efforts to expand CIE knowledge and use. To be presented to the NERC Reliability and Security Technical Committee at their annual in-person meetings in San Diego, CA.

42 ENGINEERING↗

GridCoPilot for Thermal Events: An LLM-Based Platform for Power Grid Reliability Analysis

Large Language Models show promise for translating natural language into database queries, but deploying such systems in safety-critical domains requires high reliability. We present an application of GridCoPilot to thermal event analysis (heatwaves and coldwaves) that affect power grid reliability. Our approach uses a LangChain SQL Agent to translate natural language queries into auditable SQL statements, with deterministic visualization routines that parse the structured query results. We introduce structural framing as a design principle, we integrate a NERC-region-level event library with county-level meteorology and decompose the combined data into three relational tables (event metadata, county-level event details, and a county-to-NERC subregion mapping), using prompt-guided joins to direct the model toward correct multi-table queries. For two core analytical patterns (identifying worst events by region and by region-year), the system achieved 100% SQL accuracy across all 16 NERC subregions and both event types (64 queries total). These results validate the approach for target use cases, though performance on diverse natural language formulations requires further investigation. We discuss design trade-offs, failure modes including JSON output truncation, and pathways for extending this approach to other hazard domains.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cyber-Informed Engineering Overview: Joint NERC/INL/E-ISAC Webinar

In July, NERC, the Electricity Information Sharing and Analysis Center (E-ISAC), and Idaho National Laboratory (INL) will host a joint informational webinar to highlight areas focused on integrating cyber and physical security with conventional engineering practices (security integration). NERC's work on these topics represents one of the first focused applications of Cyber-Informed Engineering (CIE). INL is leading the development of philosophy and practices to identify and mitigate the inherent risks of digital technology by including cybersecurity as a core element of engineering risk management. This presentation will provide an overview of CIE, a discussion of how NERC's work represents one of the first new discipline-specific applications of CIE, and an update on significant milestones and resources from the CIE program.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Grid Reliability Statistics [SWR-25-45]

This codebase houses a suite of statistical and descriptive analyses of NERC GADS data of interest to grid modelers and planners. This repository is envisioned to house a collection of statistical and descriptive summaries of NERC GADS data, particularly summaries that on their own might be insufficient to warrant publication. In addition, it is intended to disseminate results rather than to enable reproduction as GADS is non-public.

Murphy, Sinnott [National Renewable Energy Laborat↗

Supply Chain Cybersecurity Recommendations for Solar Photovoltaics

Solar photovoltaic (PV) cybersecurity is a growing field of research. As deployments of solar PV has increased, cyber risk has also increased. However, utility solar PV installations are not required to comply with North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) unless they meet a minimum generation threshold of 75 Megawatts (MW). Individual residential scale solar PV deployments will not meet that generation threshold and are therefore excluded from NERC CIP requirements. With most solar installations below 75MW, solar PV has been deployed with minimal oversight and highly variable cybersecurity maturity. The resources that make up the digital supply chain can include software, code, data, as well as other digital components. However as clean energy technology advances, cybersecurity threats and vulnerabilities continue to evolve and grow in sophistication. Solar PV faces a unique challenge in which it can be deployed in residential buildings and purchased by a consumer directly. This makes the supply chain of PV a unique challenge, where responsible parties for cybersecurity vary widely depending on the type of solar PV being deployed. Supply chain cybersecurity for solar PV represents a critical area for ensuring safe operations as the U.S. moves towards a clean energy future.

14 SOLAR ENERGY↗

Bat Smart Curtailment: Efficacy and Operational Testing

Curtailment, or blanket curtailment, is a leading method to mitigate the impacts to bats from operating wind turbines. Although this strategy results in considerable decreases in bat fatalities, it also results in decreased energy production. In 2019, Natural Power was awarded funding by the Department of Energy to assess the readiness of the informed smart curtailment technology, EchoSense (formerly referred to as Detection and Active Response Curtailment, [DARC]). The research undertaken by this project expands the understanding of alternative methods, known as smart curtailment, to maintain a reduction in bat fatalities while simultaneously recovering lost energy associated with blanket curtailment. The overall project was composed of three major tasks; Task 1 was focused on cybersecurity compliance of the EchoSense system in accordance with the North American Electric Reliability Corporation Critical Infrastructure Protection (“NERC CIP”) standards, Task 2 assessed the mechanical loads exerted on turbines when operating under a smart curtailment regime, and Task 3 assessed the efficacy of the EchoSense system at an operational wind farm. Regarding Task 1, an external review by the National Renewable Energy Laboratory determined that the EchoSense system did not create any new cybersecurity weaknesses and was compliant with the NERC CIP standards. As a result of this process, Natural Power developed some best practices (10.1) for wind- wildlife technology developers. In conjunction with the National Renewable Energy Laboratory, the results (10.2) of the loads testing demonstrated that the periodic curtailment and release of turbines by the EchoSense system did not have any detrimental impact on the mechanical components of a wind turbine (Task 2). During the late summer to fall of 2020 and 2021, Natural Power demonstrated that the use of the EchoSense smart curtailment system resulted in no significant difference in bat fatalities compared to blanket curtailment with cut-in speeds at 6.9 m/s (2020) and 5.0 m/s (2021) while resulting in a significant difference in decreased lost energy (Task 3). This translates to an average of 41% (2020) and 56% (2021) reduction in per turbine energy loss compared to blanket curtailment. The reduction in energy loss that would have been achieved by EchoSense curtailment compared to blanket curtailment, if applied across all 69 turbines, is roughly equivalent to having an additional turbine on site. These results are notable for finding a balance between the environmental impact of wind energy and the economic feasibility in energy production associated with mitigating that impact. https://www.naturalpower.com/us/expertise/service/engineering-operations/echosense

17 WIND ENERGY↗

Space Weather, Geomagnetic Disturbances and Impact on the High-Voltage Transmission Systems

Geomagnetically induced currents (GIC) affecting the performance of high-voltage power transmission systems are one of the most significant hazards space weather poses on the operability of critical US infrastructure. The severity of the threat was emphasized, for example, in two recent reports: the National Research Council (NRC) report "Severe Space Weather Events--Understanding Societal and Economic Impacts: A Workshop Report" and the North American Electric Reliability Corporation (NERC) report "HighImpact, Low-Frequency Event Risk to the North American Bulk Power System." The NRC and NERC reports demonstrated the important national security dimension of space weather and GIC and called for comprehensive actions to forecast and mitigate the hazard. In this paper we will give a brief overview of space weather storms and accompanying geomagnetic storm events that lead to GIC. We will also review the fundamental principles of how GIC can impact the power transmission systems. Space weather has been a subject of great scientific advances that have changed the wonder of the past to a quantitative field of physics with true predictive power of today. NASA's Solar Shield system aimed at forecasting of GIC in the North American high-voltage power transmission system can be considered as one of the ultimate fruits of those advances. We will review the fundamental principles of the Solar Shield system and provide our view of the way forward in the science of GIC.

Pullkkinen, A.↗

DER Digital Supply Chain Gap Analysis

Solar photovoltaic (PV) cybersecurity is a growing field of research. As deployments of solar PV have increased, cyber risk has also increased. Utility solar PV installations, however, are not required to comply with the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) plan unless they meet a minimum generation threshold of 75 MW. Individual residential-scale solar PV deployments will not meet that generation threshold and are therefore excluded from the NERC CIP requirements. With most solar installations less than 75 MW, solar PV has been deployed with minimal oversight and highly variable cybersecurity maturity. The resources that comprise the digital supply chain can include software, code, data, and other digital components. But as clean energy technologies advance, cybersecurity threats and vulnerabilities continue to evolve and grow in sophistication. Supply chain cybersecurity represents a critical area for ensuring safe operations as the U.S. moves toward a clean energy future.

cybersecurity↗

Data Centers and Digital Assurance Workshop 3 – Mitigations for Digital Assurance Risks

The third session of the TADA (Technical Assistance for Digital Assurance) Data Centers Cohort, held on November 18, 2025, focused on developing mitigation strategies for digital assurance risks identified in previous workshops. Hosted by Idaho National Laboratory (INL) and ScottMadden, the session emphasized the application of Cyber-Informed Engineering (CIE) to data center infrastructure, particularly at the utility–data center interface. Participants revisited and ranked key digital assurance risks, including architecture and interface weaknesses, governance gaps, and AI-enabled threats. The workshop introduced the 12 principles of CIE, advocating for consequence-focused design, engineered controls, and secure information architecture to proactively reduce cyber-physical vulnerabilities. These principles were applied to critical data center systems such as power distribution, UPS, cooling, SCADA/BMS, and grid-forming batteries. The session also addressed governance challenges at the interconnection boundary, highlighting the need for clear roles in telemetry sharing, firmware management, and trip settings. Special attention was given to emerging risks from behind-the-meter (BTM) generation, including reverse-power flow and the integration of small modular reactors (SMRs), which shift data centers from large loads to complex generation nodes. Participants explored how interconnection agreements can serve as enforceable instruments for digital assurance, and reviewed gaps in current standards such as NERC CIP, IEC 62443, and IEEE 1547. The workshop concluded with pathways to standardization, including model agreement language, state-level programs, and expanded NERC guidance. INL also presented tools and frameworks for secure procurement and supplier risk management, reinforcing the need for integrated engineering and policy solutions to secure the evolving data center–grid ecosystem. Session 3 of 3.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Cradle-to-Gate Life Cycle Analysis Baseline for United States Coal Mining and Delivery

The goal of this study is to highlight the environmental impacts from upstream coal production to its delivery at a power plant. This study is meant to characterize different coal basins, coal types, and mine types used to produce electric power in the North American Electric Reliability Corporation (NERC) regions in the United States using a functional unit of 1 kg of coal. The boundary of this study includes underground or surface extraction, water use at the mine, ventilation, coal handling, coal cleaning, mine tailing disposal, and transportation via conveyer belt, truck, ocean vessel, barge, and train. See the following URLs for accompanying documents: NETL Coal Baseline Model - Transportation Inventories: https://www.netl.doe.gov/energy-analysis/details?id=27ea1ba4-6ea9-4ee5-8b32-d7fce7f4e1e0. NETL Coal Baseline Model - Basin Inventories: https://www.netl.doe.gov/energy-analysis/details?id=0f290eed-5e4b-4b5f-bec0-36b0ea89c6e5. NETL Coal Baseline Model - Excel file: https://www.netl.doe.gov/energy-analysis/details?id=0dc18730-4214-4878-8a0f-d1941c45123c. NETL Coal Baseline Model - Open LCA model: https://www.netl.doe.gov/energy-analysis/details?id=0c0dde04-0d3c-4c7f-bd33-2745e061b8e0.

01 COAL, LIGNITE, AND PEAT↗

Idaho National Laboratory Energy Cybersecurity Programs Update

This brief presentation provides a status update on three Idaho National Laboratory energy cybersecurity programs of particular interest to NERC Reliability and Security Technical Committee annual in-person Security Groups summit. Public information on the following three programs is included: Cybersecurity for Operational Technology Environments (CyOTE™) program Cyber-Informed Engineering (CIE) Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, and associated high-level information on the Energy Software Bill of Materials POC, Executive Order 14017, and the Energy Cyber Sense Act

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity for System Operators

SERC's System Operator Conference is an annual education and sustainment training for electric power system operators across the southeastern United States. In recognition of the growing importance of cybersecurity for energy systems, a block of instruction on cybersecurity concepts was included for this year's conferences. This presentation provides an overview of the need for and general approach used in the DOE CESER-sponsored Cybersecurity for the Operational Technology Environment (CyOTE) program, tailored for electric power system operators. NERC's updated Cyber Intrusion Guide for System Operators is reviewed, explaining how it is an operationalization of some of CyOTE's principles and approach.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Grid Communications: Digital Assurance and Supply Chain Challenges and Emerging Regulation Session Two

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem. This is Session 2 of 3 (Full Version).

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Grid Communications: Cybersecurity and Supply Chain Challenges and Emerging Regulation Session Three

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem. This is Session 3 of 3 (Full Version).

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Grid Communications Supply Chain & Emerging Regulation Challenges Session 1

The TADA Grid Communications Workshops are designed to strengthen cybersecurity and digital assurance across the energy sector by focusing on secure deployment and management of grid communications technologies. These workshops bring together state energy offices, utilities, and technology suppliers to explore the intersection of communications infrastructure, supply chain risks, and emerging regulatory requirements. Participants will apply Cyber-Informed Engineering (CIE) principles to reduce risks in communications systems, engage with INL’s procurement guidance, and explore future tools. Through scenario-based exercises and peer exchange, attendees will develop risk-based security strategies and actionable compliance roadmaps tailored to their grid communications projects. The workshops also help participants navigate evolving regulatory frameworks such as FEOC rules in the OBBB, NERC CIP-013, and NDAA 2024, while identifying compliance gaps in mixed-technology environments. A key outcome is the formation of a practitioner network with ongoing access to INL expertise and resources, fostering long-term resilience in the digital energy ecosystem.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

What Technical Choices Matter to Characterize Heat Wave and Cold Snap Events in Support of Bulk Power Grid Reliability Studies?

Extreme weather events, such as Heat Waves (HW) and Cold Snaps (CS), pose significant risks to the power grid. The United States (U.S.) Federal Energy Regulatory Commission Order No. 896 mandates regional coordination standards that account for extreme thermal events. However, the lack of a universal definition for extreme thermal events may lead to inconsistent compliance efforts among neighboring entities, undermining the reliability of the transmission system. This study directly addresses this challenge by systematically evaluating how varying technical choices in defining HW and CS fundamentally impact the characterization and ranking of extreme events for power grid reliability studies. We used 12 event definitions and multiple temperature spatial aggregation approaches to construct historical (1980–2024) regional extreme thermal event libraries across North American Electric Reliability Corporation (NERC) subregions in the conterminous U.S. We examined the sensitivity of event characteristics (e.g., duration, frequency, intensity, and spatial coverage) to different definitions. While some definitions produced similar libraries and top event rankings, definitions based on moving-window-averaged temperatures yielded markedly different characteristics. Spatial aggregation methods had minimal impact on heat wave or cold snap intensity, frequency and duration but significantly influenced spatial coverage. The top events identified across different aggregation methods were consistent, but their ranking order varied. These findings offer critical insights for characterizing and selecting extreme thermal events and for supporting local and cross-regional coordination as required by reliability standards.

Wan, Heng [Pacific Northwest National Laboratory (↗