Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Deras topic
No spam. Unsubscribe anytime.
PSC cybersecurity office proposes COMAR changes and strengthened DERA licensing; utilities, stakeholders urge staged approach
Summary
Maryland PSC cybersecurity staff recommended a COMAR regulation adopting DOE baselines and strengthened DERA licensing that would require cybersecurity risk‑management plans at application; utilities urged caution about enforcement roles and auditors, while stakeholders backed baseline adoption and prioritized a risk‑based, phased approach.
Get email alerts on the Cybersecurity Deras topic
No spam. Unsubscribe anytime.
The Maryland Public Service Commission’s Office of Cybersecurity proposed adopting by reference narrow DOE/NIST baselines for distribution system and DER cybersecurity and strengthening the DERA licensing process to require a cybersecurity risk management plan at application. "We requested and recommended that [DERA licensing] be revised, to strengthen cybersecurity attestations at the time of licensing," said Ben Abramovitz, director of cybersecurity for the PSC.
The office’s draft COMAR language would incorporate evolving national baselines to avoid a patchwork approach and would require license applicants to demonstrate risk assessment methods, asset criticality determinations, and strategies for protecting internet‑connected DERs. Staff also flagged a gap in ongoing enforcement authority: because third‑party aggregators are not classified as regulated utilities, the PSC may have limited audit authority outside the licensing window and asked for clarity on compliance verification and whether statute changes are needed to enable ongoing audits.
Why this matters: Aggregated DERs and VPPs increase digital attack surface on the distribution system. Stakeholders agreed cyber baselines are important but differed on enforcement: joint utilities and some advocates said initial enforcement via utilities should be limited because utilities lack resources to be primary compliance enforcers; cybersecurity staff said government oversight or statutory clarity is likely required for durable enforcement.
Stakeholder responses: Joint utilities and industry groups supported adopting baseline standards by reference, but asked for more stakeholder work on enforcement and audit mechanics. Several panelists urged a risk‑based, phased approach that prioritizes larger resources. Staff proposed additional training and an academic joint study (University of Maryland Baltimore County) to help develop standards and compliance frameworks.
Next steps: The cybersecurity office requested more time to coordinate with stakeholders to define scope (thresholds for covered assets, ongoing compliance checks, and the compliance/enforcement mechanism). Commissioners asked staff to identify whether statutory changes are required and to propose a workable compliance model that balances government oversight, utility responsibilities, and industry capabilities.

