Supply Chain Considerations

By Gabriela Barragan
CIP Cyber and Physical Analyst

The ERO Enterprise has identified supply chain as a risk element within the 2026 Compliance Monitoring and Enforcement Program (CMEP) Implementation Plan (IP), largely due to the ongoing reliability concerns involving malicious software insertion. CIP-010-4 R1, Part 1.6 requires Responsible Entities to implement software verification controls, including identity verification software sources and the integrity of software obtained prior to implementing any baseline change associated with operating systems, firmware, commercially available software, open-source software, and security patches.

While Responsible Entities should implement operational safeguards tailored to their environment, industry best practices for CIP-010-4 R1, Part 1.6 include:

  • Maintain a formal record of every completed software integrity check.
    • This includes documenting the file name, calculated hash value, comparison source, and final validation outcome.
    • This can be attached to the corresponding change to provide history of the baseline change.
  • Ensure the personnel downloading the software is not the same authorized individual who signs off on the final Part 1.6 verification check. Separating these tasks reduces the risk of a single point of failure during deployment.

For more information and further guidance on implementing best practices related to supply chain, Texas RE encourages Responsible Entities to consult the Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations.