Next Tier Compliance

NERC CIP + O&P compliance advisory

Confidence before the audit.

Practical compliance support for electric-sector organizations, data center owners, and project teams—from emerging IBR obligations to early CLO and CLOP readiness.

Audit-readyEvidence organized around what reviewers need.
Operator-mindedControls designed to work in real operations.
Forward-lookingDeadlines and emerging standards tracked in one regulatory radar.
01 / Services

Three practices. One defensible compliance program.

Next Tier helps registered entities and emerging computational-load stakeholders translate requirements into controls, ownership, and evidence that stand up to review.

Cybersecurity

NERC CIP Compliance

Program assessments and control support across governance, asset categorization, access, configuration change, incident response, recovery, and evidence.

Explore CIP services
Reliability operations

Operations & Planning Compliance

Applicability, readiness, and evidence support for O&P obligations, with dedicated focus on the new IBR performance standards.

Explore O&P services
Computational loads

Data Center CLO Readiness

Early-stage scoping and program planning for data center owners, operators, and project managers preparing for the proposed CLO and CLOP framework.

Explore CLO readiness
01

Readiness assessments

Structured reviews that identify control and evidence gaps, clarify priorities, and turn findings into an actionable remediation plan.

02

Evidence preparation

Requirement-to-evidence mapping, sampling support, document review, and audit-room preparation.

03

Program development

Practical policies, procedures, controls, calendars, and ownership models built for repeatable execution.

04

Remediation support

Root-cause review, corrective-action planning, implementation tracking, and durable evidence of completion.

Service / NERC CIP

Cyber controls that work beyond the binder.

Next Tier connects policy language to the systems, teams, approvals, and records that make a CIP program operational.

Discuss a CIP engagement
Program foundation

Applicability, scoping, and governance

Review registered functions, BES Cyber System categorization, ownership, delegation, and the links between policies, procedures, and technical controls.

Control operation

Access, change, vulnerability, and asset controls

Test whether control activities are performed consistently, supported by usable records, and aligned across compliance, operations, IT, and security teams.

Response

Incident response and recovery readiness

Examine plan quality, role clarity, exercises, recovery evidence, and lessons-learned workflows before they are tested by an incident or audit.

Assurance

Audit preparation and mock reviews

Build evidence indexes, test narratives, rehearse interviews, and trace sampled records from requirement through implementation.

Service / O&P

Reliability obligations translated into operating practice.

Support spans applicability, program design, control testing, and event-ready evidence for Operations & Planning standards.

See the IBR focus
Applicability

Registered-function and facility mapping

Map obligations to Generator Owner, Generator Operator, Transmission Owner, and other applicable responsibilities, with documented scoping decisions.

Program design

Requirement-to-control alignment

Translate Reliability Standard language into procedures, responsible roles, recurring tasks, source systems, and retained evidence.

Performance

IBR monitoring, ride-through, and event response

Coordinate engineering, operations, compliance, OEM, and plant-level responsibilities across PRC-028, PRC-029, and PRC-030 readiness.

Testing

Self-certification and audit readiness

Validate evidence quality, test execution against documented controls, and prepare clear narratives for reviewers.

Service / CLO readiness

Prepare the site, the team, and the evidence path.

Next Tier helps data center owners, computational load operators, and project managers organize early readiness work while NERC’s CLO and CLOP framework is still developing.

Discuss CLO readiness
Applicability

Facility and role scoping

Document site configuration, connected load, voltage, ownership, operating responsibilities, and interconnection relationships against the latest proposed CLO and CLOP definitions.

Project delivery

Requirements built into the project plan

Give project and program managers a practical workstream for studies, model data, communications, protection coordination, disturbance monitoring, owners, and decision gates.

Interfaces

Utility and reliability-entity coordination

Clarify the information, studies, technical contacts, and operating communications that may be needed across the data center, serving utility, Transmission Planner, and operating entities.

Readiness record

Gap register and defensible documentation

Create a living inventory of assumptions, open decisions, source records, and remediation actions so the program can adapt as draft requirements change.

02 / IBR focus

Prepare the operating model—not just the filing.

The three standards create an interconnected readiness problem: capture useful disturbance data, establish ride-through performance, and turn unexpected behavior into analysis and mitigation.

PRC-028-1

Disturbance monitoring & reporting

Build the data foundation needed to analyze IBR behavior during Bulk Electric System disturbances.

Readiness work
Equipment and data-source inventory, SER/FR/DDR capability review, time synchronization, data retention, request workflows, and evidence mapping.
Key coordination
Generator Owner, Transmission Owner, engineering, operations, plant controls, and monitoring-system owners.
Read the NERC standard ↗
PRC-029-1

Frequency & voltage ride-through

Align facility design, settings, studies, and operating evidence with plant-level ride-through performance expectations.

Readiness work
Protection and control-setting review, equipment-limitation records, study traceability, disturbance evidence, and change-management integration.
Key coordination
Plant engineering, OEMs, protection teams, Transmission Owners, compliance owners, and model custodians.
Read NERC’s technical rationale ↗
PRC-030-1

Unexpected IBR event mitigation

Create a repeatable path from event identification through technical analysis, corrective action, and completion evidence.

Readiness work
Event-detection procedures, data intake, root-cause and fleet-susceptibility analysis, corrective-action governance, and implementation tracking.
Key coordination
Generator Owners, Reliability Coordinators, Balancing Authorities, Transmission Operators, OEMs, and plant operators.
Read NERC’s filed standard package ↗

Applicability, approved versions, and effective dates vary by entity, facility, and jurisdiction. Engagements begin by confirming the controlling requirements and current implementation schedule.

03 / Who we support

The right compliance lens for your operating model.

Work is shaped around the entity, facilities, functions, and teams that carry the obligation—not a generic template.

GO / GOP

Generator owners & operators

Applicability, registration, program buildout, evidence, and audit readiness for BES and qualifying non-BES resources.

IBR

Developers & asset owners

Coordinate engineering, OEM, modeling, plant controls, and compliance work across the project lifecycle.

PUBLIC POWER

Municipal & cooperative utilities

Practical CIP and O&P controls that fit lean teams and real control-room operations.

RELIABILITY

Transmission & planning teams

Clear requirement-to-control mapping, model and evidence workflows, and cross-functional ownership.

DATA CENTERS

Data center owners & project managers

Bring emerging compliance considerations into site development, interconnection, design, commissioning, and operating-readiness plans.

CLO / CLOP

Computational Load Owners & Operators

Early applicability, role mapping, utility coordination, and readiness work for NERC’s proposed CLO and CLOP framework.

LEAN TEAMS

Organizations needing added capacity

Focused advisory support for assessments, remediation, documentation, training, and audit preparation.

04 / Regulatory radar

Track the next obligation before it becomes the next fire drill.

Next Tier monitors effective dates, phase-ins, and developing standards across IBRs, dynamic models, and computational loads—then translates them into decisions, owners, and evidence.

Reviewed 29 Sep 2026

This is a dated regulatory snapshot, not a substitute for entity-specific legal or Regional Entity guidance. Draft standards and anticipated milestones can change before approval.

Current standards & deadlines

The dates below separate enforceable obligations from proposed work so teams can prioritize without treating a draft as a requirement.

Category 2 GO/GOP registration effective IN EFFECT

Non-BES IBRs meeting the aggregate 20 MVA and common-point 60 kV test entered the new registration population.

PRC-029-1 and PRC-030-1 APPROVED

BES IBR ride-through design obligations and unexpected-event analysis requirements begin. Qualifying non-BES IBR dates follow on 1 January 2027.

Computational-load filing deadline PROPOSAL

FERC directed NERC to file standards, definitions, and registry criteria. This is a filing milestone—not an approval or compliance date.

Category 2 PRC-029/030 milestone APPROVED

Design compliance under PRC-029-1 R1–R3 and PRC-030-1 applicability begin for qualifying non-BES IBRs.

MOD-026-2 R1/R7 + PRC-028-1 R8 APPROVED

Model-data process requirements mature under MOD-026-2; PRC-028-1 R8 reaches qualifying non-BES IBRs.

PRC-029-1 R4 documentation APPROVED

The implementation window for documented hardware-limitations submissions closes for applicable IBRs.

PRC-028-1 50% milestone APPROVED

For covered legacy BES IBR fleets, at least half of applicable MVA must meet R1–R7 under the approved phase-in.

MOD-026-2 R2–R6 APPROVED

Core dynamic-model verification and validation requirements reach their implementation-plan milestone.

PRC-028-1 full phase-in APPROVED

R1–R7 reach the 100% milestone for covered legacy BES fleets and qualifying non-BES IBRs.

Computational-load watch

Project 2026-02 passed its first industry ballots in September 2026. These Draft 1 standards are not yet approved or enforceable.

CLO-001-1 · DRAFT

Interconnection, studies & modeling

Proposes facility requirements, reliability-impact studies, modeling data, verification, and planning-case reporting.

CLO-002-1 · DRAFT

Operational data & communications

Proposes planning and real-time information exchange plus defined communications among load owners/operators and reliability entities.

CLO-003-1 · DRAFT

Protection & disturbance monitoring

Proposes protection coordination and disturbance-monitoring requirements for qualifying computational-load sites.

Applicability decision paths

Use these as scoping prompts. Final applicability depends on facility configuration, registration, definitions, and the controlling implementation plan.

1 · BES facility?

Do you own or operate a generating BES facility? If yes, the current framework points to Category 1 GO/GOP.

2 · If non-BES, test both thresholds

Aggregate nameplate capacity of at least 20 MVA, delivered through a system designed primarily for that capacity to a common point at 60 kV or above.

3 · Confirm the result

Both non-BES tests point to Category 2. If neither path fits, Order 901 GO/GOP registration is not triggered by this test alone.

Category 2 registration became effective 15 May 2026. Registration does not itself complete the associated PRC and MOD obligations.

05 / Field guides

Practical readiness guides for the standards taking shape now.

Three focused guides turn the regulatory language into scoping questions, workstreams, evidence needs, and near-term actions for owners and project teams.

PRC-029-1

Ride-Through Readiness for IBR Owners

A field guide to applicability, engineering coordination, settings, documentation, and the path to an auditable ride-through program.

Read the guide
PROJECT 2026-02

CLO Readiness for Data Center Owners

A practical preparation plan for data center owners, operators, and PMs while the proposed CLO and CLOP framework develops.

Read the guide
PRC-028-1

Disturbance Monitoring for IBR Owners

A field guide to monitoring capability, data quality, event retrieval, request response, and defensible evidence.

Read the guide
Field guide / PRC-029-1

Ride-Through Readiness for IBR Owners

A practical path from applicability and facility design through settings, limitations, change control, and evidence.

Audience: IBR owners, operators & project teamsReviewed: 29 Sep 2026
Start with the controlling implementation plan.

PRC-029-1 readiness depends on facility category, commercial-operation timing, and jurisdiction. Confirm applicability and effective dates before turning this guide into a project schedule.

01 / What the standard changes

Ride-through becomes a coordinated facility obligation.

PRC-029-1 is intended to keep applicable inverter-based resources connected through defined frequency and voltage excursions, subject to the standard’s permitted exceptions and documented equipment limitations. The compliance challenge is not a single relay setting. It is the chain linking facility design, protection, controls, OEM capabilities, studies, operating practice, and retained evidence.

That chain often crosses owners: plant engineering may understand the design basis, an OEM may control inverter logic, a protection group may own relay settings, operations may manage outages and changes, and compliance may hold the evidence. A defensible program makes those interfaces explicit.

02 / Readiness workstreams

Build one traceable line from requirement to plant behavior.

Applicability & facility inventory

Document registration category, facilities and units in scope, commercial-operation dates, equipment vintages, common points of connection, and the implementation dates that apply to each population.

Design-basis review

Map the ride-through expectations to inverter controls, plant controller logic, collector-system protection, main transformers, auxiliary systems, and other equipment that can initiate disconnection.

Settings coordination

Compare protection and control settings across devices and owners. Record the approved basis, review authority, implementation record, and how field values are verified.

Equipment limitations

Identify claimed hardware limitations early. Assemble engineering support, OEM documentation, affected equipment, operating implications, and the submission path required by the standard.

Change management

Bring firmware, model, controller, relay, transformer, and protection changes into a single impact-review process so ride-through capability is reassessed before implementation.

Event feedback

Connect disturbance review to corrective action. Unexpected trips, momentary cessation, or control interactions should feed settings review, model validation, and fleet-wide lessons learned.

03 / Evidence file

What a reviewer should be able to follow.

  • A dated applicability memorandum and facility inventory tied to the registration record.
  • Approved one-lines, protection philosophies, design criteria, studies, OEM information, and setting files for the in-scope configuration.
  • A requirement-to-evidence map showing where each obligation is performed, who owns it, and which record proves completion.
  • Records of settings review, approval, field implementation, independent checks, and later changes.
  • Engineering support for any documented hardware limitation, with affected units and required follow-up clearly identified.
  • Event records and corrective actions that show how actual facility behavior is evaluated against the design basis.
04 / A 90-day start

Sequence the work before the deadline drives it.

DAYS 1–30

Confirm applicability, freeze the in-scope facility list, name accountable owners, collect current drawings and settings, and log missing source records.

DAYS 31–60

Perform the coordinated engineering review, test the equipment-limitations position, map evidence, and identify settings or process gaps by risk.

DAYS 61–90

Approve remediation plans, complete high-priority changes, exercise the change-control and event-review workflows, and assemble a reviewer-ready evidence index.

05 / Sources

Controlling materials to keep in the project file.

Next step

How Next Tier Compliance Can Help

Next Tier can confirm applicability, lead the cross-functional readiness assessment, build the requirement-to-evidence map, facilitate settings and equipment-limitations reviews, and turn the results into an owned remediation plan.

Discuss PRC-029-1 readiness
Field guide / CLO readiness

CLO Readiness for Data Center Owners

A stage-gated preparation plan for owners, operators, and project managers facing the proposed computational-load standards.

Audience: data center owners, operators & PMsReviewed: 29 Sep 2026
The CLO framework is still proposed.

Project 2026-02 Draft 1 passed initial industry ballots in September 2026, but the standards, definitions, thresholds, and registry criteria are not yet approved or enforceable. Prepare adaptable foundations—do not label a draft obligation as final.

01 / Why act now

Major reliability interfaces are decided before operations begin.

Site topology, utility interconnection, protection schemes, load-control behavior, communications, models, monitoring equipment, and project records are expensive to retrofit after commissioning. Early readiness work lets a data center preserve the information and decision trail likely to matter without treating the draft as settled law.

Current Draft 1 uses a 50 MW total-connected-load threshold and electrical equipment connected at 100 kV or above in its proposed computational-load framework. Those details can change. The right first step is a documented threshold watch and facility dossier, not an unsupported registration conclusion.

02 / The readiness dossier

Assemble the facts before the definitions settle.

Facility configuration

Maintain current one-lines, service voltage, total connected load, phased energization dates, utility feeds, on-site generation, storage, transfer schemes, and backup-power arrangements.

Owner and operator roles

Document who owns the load, who directs real-time operation, who controls switching and load-management systems, and which responsibilities sit with vendors or managed-service providers.

Interconnection record

Keep study requests, assumptions, models, utility comments, protection requirements, operating limits, and accepted changes tied to the as-built facility.

Load behavior

Characterize normal ramps, block changes, transfer events, power-supply behavior, protection actions, demand response, and controls that could produce rapid or simultaneous load changes.

Monitoring and time

Identify available disturbance, sequence-of-events, frequency, voltage, and power data; document time synchronization, retention, access, export formats, and responsible system owners.

Communications

Map planning and real-time contacts across the site, serving utility, Transmission Planner, Balancing Authority, Transmission Operator, and Reliability Coordinator as applicable.

03 / PM stage gates

Put readiness decisions into the project plan.

SITE SELECTION

Capture prospective service voltage, connected-load buildout, utility configuration, ownership model, and the current draft-threshold assessment.

INTERCONNECTION

Assign model, study, protection, communications, and data-delivery owners; establish a controlled assumptions and responses log.

DESIGN

Confirm monitoring points, time synchronization, record retention, controls visibility, secure data access, and the evidence each discipline must hand over.

COMMISSIONING

Verify as-built records, test data capture and retrieval, validate contact paths, and close gaps between study assumptions and installed equipment.

OPERATIONS

Maintain the facility dossier, govern changes, rehearse disturbance-data response, monitor the standards project, and update the applicability position at defined triggers.

04 / Questions for leadership

Readiness is an ownership problem before it is a filing problem.

  • Can the organization state who would own CLO and CLOP responsibilities if the current framework were approved?
  • Can the team reproduce the facility configuration and connected-load position used in its applicability assessment?
  • Are utility study assumptions traceable to the final design and as-built equipment?
  • Can operators retrieve useful, time-aligned event data without a vendor-led emergency project?
  • Does a formal trigger require reassessment after material load, topology, control, protection, or ownership changes?
  • Is one accountable leader tracking Project 2026-02 and translating ballot changes into project impacts?
05 / Source

Follow the standards project—not summaries alone.

Next step

How Next Tier Compliance Can Help

Next Tier can build the initial CLO/CLOP applicability file, facilitate owner-operator role mapping, add compliance gates to the project schedule, review the data and communications architecture, and maintain a change log as the draft standards evolve.

Discuss CLO readiness
Field guide / PRC-028-1

Disturbance Monitoring for IBR Owners

A field guide to monitoring coverage, data quality, event retrieval, reporting workflows, and evidence that can withstand review.

Audience: IBR owners, operators & monitoring teamsReviewed: 29 Sep 2026
Monitoring readiness is more than installing a recorder.

The usable compliance product is a complete chain: scoped facilities, capable devices, known data paths, synchronized records, trained responders, controlled retention, and evidence that the process works.

01 / Build the monitoring chain

Start at the event and work backward to the evidence.

PRC-028-1 establishes disturbance-monitoring and reporting obligations for applicable IBR facilities. A readiness review should ask whether the organization can identify an event, retrieve the required sequence-of-events, fault-recording, and dynamic-disturbance information, validate its quality, preserve it, and deliver it through a controlled workflow.

Every link matters. A technically capable device can still fail the program if channels are misnamed, clocks are not aligned, files are inaccessible, settings drift, ownership is unclear, or a request waits in the wrong queue.

02 / Six control areas

Test capability as a system, not as an asset list.

Applicability & coverage

Map each in-scope facility to required monitoring functions, installed devices, monitored quantities, trigger sources, communication paths, and the implementation milestone that applies.

Configuration baseline

Control device settings, enabled channels, labels, scaling, trigger logic, record length, sampling configuration, firmware, and the approved basis for each value.

Time synchronization

Document time sources, distribution, health monitoring, tolerances, alarms, outage response, and how timestamp quality is checked before records are released.

Data retrieval

Define automated and manual paths from field devices to historians or repositories, including access, file formats, naming, secure transfer, and fallback steps.

Quality assurance

Verify completeness, channel mapping, units, scaling, trigger performance, timestamp alignment, and readability through periodic tests and selected event reviews.

Retention & response

Set preservation rules, request intake, due-date tracking, technical review, approval, transmittal, and proof of delivery with named owners and backups.

03 / Event-response workflow

Make the first real request feel routine.

INTAKE

Log the requester, event window, facilities, requested data, format, due date, and accountable response lead.

RETRIEVE

Collect source files through the controlled path, preserve originals, document retrieval gaps, and escalate missing records immediately.

VALIDATE

Check timestamps, channels, units, scaling, trigger alignment, completeness, and whether the record actually covers the requested interval.

RELEASE

Apply technical and compliance review, transmit through the approved channel, and retain the package, approval, delivery evidence, and any explanation.

LEARN

Track defects and corrective actions. Use each request or event to improve monitoring coverage, configuration control, training, and fleet consistency.

04 / Readiness test

Run one tabletop and one technical drill.

  • Select an in-scope facility and a realistic event window without warning the response team in advance.
  • Issue a mock request through the normal intake channel and track acknowledgments, owners, and elapsed steps.
  • Retrieve source files, preserve originals, and validate channels, units, scaling, and time alignment.
  • Assemble the release package with an evidence index, approvals, transmittal record, and explanation of any gap.
  • Record process and technical defects separately, assign corrective actions, and retest material failures.
05 / Sources

Keep the standard and implementation plan together.

Next step

How Next Tier Compliance Can Help

Next Tier can scope the fleet, map monitoring coverage, assess device and data-path controls, facilitate a request-response drill, and build the evidence index and remediation plan needed for sustained PRC-028-1 readiness.

Discuss PRC-028-1 readiness
06 / Approach

From requirements to work that holds up.

A disciplined engagement keeps the focus on decisions, evidence, and sustainable execution—not paperwork for its own sake.

STEP 01

Establish the scope

Define the objective, relevant standards, stakeholders, and the evidence needed to evaluate current state.

STEP 02

Find the gaps

Review controls and records, distinguish documentation issues from execution issues, and prioritize by risk.

STEP 03

Build the path forward

Translate findings into clear owners, practical next actions, and a defensible record of improvement.

07 / Working principles

Compliance should strengthen operations.

The best program is not simply documented. It is understood by the people who own it, supported by the right evidence, and repeatable under pressure.

  • Plain-language guidance for technical and business teams
  • Recommendations tied to operational reality
  • Clear ownership and next steps
OPERATIONAL
CONFIDENCE
07 / Client perspectives

Trusted in high-stakes compliance work.

What utility and energy-sector leaders say about working with our team. Client identities are withheld to respect confidentiality.

01

“Your team was instrumental in helping us navigate becoming a NERC-certified entity. From there, our relationship expanded into strengthening our compliance program, leadership training, and individual coaching. You've become an integral part of the process, and we highly recommend your services. You won't be disappointed.”

President and CEO · Electric Cooperative
02

“Your experience with electric distribution, transmission, and generation assets—and how those assets achieve maximum compliance with federal, regional, and state entities—is unrivaled. Helping us through our Transmission Operator (TOP) Certification process with hundreds of information requests, a systematic approach to training, and audit-proven document development made all the difference.”

Director of Grid Control & Compliance · Municipal Utility
03

“Your deep background and leadership in NERC compliance enable you to create structured programs that bring real, sustainable value to clients. Your ability to simplify regulatory complexity and equip energy sector organizations with critical knowledge helps teams navigate complex landscapes with complete confidence.”

CEO · Energy Technology Company
04

“Preparing for a NERC audit always feels high-stakes, but having your guidance transformed our approach. You didn't just hand us a template; you worked side-by-side with our operations and engineering teams to ensure our evidence packages were bulletproof. We cleared our audit with zero findings—an outcome we couldn't have achieved without your expertise.”

Director of Compliance · Generation Facility
05

“Your engineering background combined with a deep, practical understanding of NERC Operations and Planning standards is a rare find. You spoke our language, understood the realities of control room operations, and helped us build a sustainable compliance framework that doesn't get in the way of running a reliable grid.”

Manager of System Operations · Municipal Utility
08 / About

Independent guidance for high-consequence compliance work.

Next Tier Compliance is a focused NERC compliance consultancy serving electric-sector organizations that need experienced support without unnecessary complexity.

The work is built around a simple standard: advice must be technically grounded, operationally usable, and supported by evidence that another reviewer can follow.

Focused expertiseNERC CIP and Operations & Planning compliance.
Current priorityIBR readiness for PRC-028, PRC-029, and PRC-030.
Engagement styleDirect, collaborative, and built around the work your teams actually perform.
09 / Contact

Start with the compliance issue in front of you.

Share the situation, the outcome you need, and any time constraints. Your inquiry goes directly to Steven White for a focused discussion of fit and next steps.

Consultation inquiries