Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Implementation And Compliance topic
No spam. Unsubscribe anytime.
Utilities, manufacturers and NERC debate implementation: risk‑based, shareable validation preferred over prescriptive audits
Summary
Panelists at the FERC‑NERC workshop urged a risk‑based, plan‑and‑execute approach to validating vendor information, favoring shared tools and third‑party attestations for high‑criticality items while warning against prescriptive validation that would overburden smaller utilities and limit competition.
Get email alerts on the Implementation And Compliance topic
No spam. Unsubscribe anytime.
Panelists in Roundtable 2 focused on operationalizing vendor assessments and the compliance consequences of different validation approaches.
Panelists representing small municipals and large investor‑owned utilities described contrasting constraints: small utilities flagged manpower and procurement leverage limits, while large utilities warned of scale and complexity. Landon Raider (Nashville Electric Service) said small utilities ‘‘can’t push anybody around’’ in procurement and must balance cost, while Lance Spross (large T&D utility) stressed deep vendor relationships as a key mitigation.
Howard Guo (NERC) urged treating the SIP/CIP suite collectively and recommended that entities focus on evaluating vendor risk as part of their entity‑level risk assessment instead of imposing uniform, prescriptive audit requirements. He also noted legal sensitivities: compiling or endorsing a list that effectively ranks vendors could raise antitrust concerns.
Panelists discussed shared industry resources: trade‑group templates (NATF, EEI) and emerging vendor libraries (UTC/industry pilots) that collect vendor questionnaires, certifications and attestations. Several speakers recommended that standards reference such tools as optional guidance rather than mandate a single instrument. Darlington "Dart" Fee (Entergy) and others emphasized plan‑based compliance—have a plan, follow it, and measure execution.
Speakers also addressed certifications and government programs. Panelists said certifications like ISO 27001 or FedRAMP can be useful inputs but do not fully cover all supply‑chain concerns and should not be mandated as the sole proof of security. Multiple panelists cautioned that certifications and tools age and require updating; locking them into an enforceable standard risks obsolescence and procurement delays.
Emerging technology was highlighted as an opportunity and a caution: vendors and analytics firms are using AI and big data to surface supplier risk and automate triage, but panelists urged careful validation before wide operational use.
The second roundtable closed with shared themes: validate by risk, favor shareability and industry collaboration, rely on defense‑in‑depth rather than a single verification mechanism, and continue FERC/NERC coordination in rule development and guidance.

