[UPDATE September 3, 2026] The comment period has closed and feedback has been incorporated into a revised proposed procurement contract addendum. Consensus has been reached up through section 3.2 romanette vi. A meeting is scheduled for September 14 to complete the review and publish a recommendation for the consensus procurement contract addendum by September 15 where it will be subject to a 30 day member review before the Executive Committee votes on the status of the proposal, https://naesb.org/pdf4/weq_bps_css091426w2.docx
Careful consideration was given to existing laws and regulations setting cybersecurity practice expectations on manufacturers to provide timely vulnerability reporting and attestation of Secure by Design best practices, i.e. EU CRA and FDA Final Guidance to medical device manufacturers, in order to leverage existing common practices that manufacturers already need to comply with and avoid extraneous, burdensome work.
[UPDATE August 27. 2026] The proposed NAESB Procurement Contract Language, scheduled for a vote on September 3, is well aligned with Executive Order 14420. FOCI information is provided in the "Company Information" item found in the Vendor Response File (VRF) identified in Exhibit A. Details of a Vendor Response File are provided in this article: https://www.energycentral.com/intelligent-utility/post/advice-for-software-vendors-to-prepare-for-omb-m-22-18-requirements-and-zi1Y7M8FADm8mma
The NAESB cybersecurity committee met earlier today to review and revise the proposed Cybersecurity Terms and Conditions Procurement Contract Addendum document aimed at improving product cybersecurity trust and transparency for critical infrastructure operators that require more timely visibility into product cyber risks and assurances that product vendors are building secure products following effective "Secure By Design" and "Secure by Demand" best practices identified by NIST and CISA.
https://www.naesb.org/pdf4/weq_bps_css081826reqcom_a1.docx
NAESB is an ANSI Standards Development Organization (SDO) responsible for developing business practice standards for the North American Natural Gas and Electric Industries that frequently become FERC regulations.
Efforts to harmonize this procurement language with existing cybersecurity regulations affecting product manufacturers, i.e. EU CRA and US EO 14028, were considered throughout the initiative in order to avoid introducing variation from existing regulatory expectations already applicable to product manufacturers.
This public review of the proposed procurement contract language is open for comment until September 1. All responses received will be reviewed by the subcommittee during its next scheduled meeting taking place on Thursday, September 3, 2026 from 2:30 pm to 4:00 pm Central and inform the process going forward.
Please submit comments to the NAESB office ([email protected]). All interested parties, regardless of membership status within NAESB, are eligible to submit informal comments for consideration.
Microsoft CoPilot provides an easy to read summary of expectations based on this procurement contract language: https://copilot.microsoft.com/shares/mR1v3fniaeekQpxo3xR9y
Microsoft CoPilot example SAGScore and explanation: https://copilot.microsoft.com/shares/JBfS7tEs7Cv3HadndUZfq