Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Distributed Energy Resource Cybersecurity Framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

The Distributed Energy Resource Cybersecurity Framework

For facilities with distributed energy resources (DERs), cybersecurity must be considered holistically, across system architectures and down to individual components. It's hard to know where to start. That's why the National Renewable Energy Laboratory (NREL) has developed an assessment tool for organizations with DERs to understand and improve their cybersecurity. With support from the U.S. Department of Energy's Federal Energy Management Program, the Distributed Energy Resource Cybersecurity Framework (DER-CF) provides a holistic evaluation of a facility's DER cybersecurity and makes customized recommendations that follow widely recognized best practices for cybersecurity. The DER-CF is available at no cost as an interactive web tool (dercf.nrel.gov).

cybersecurity↗

Distributed Energy Resource Cybersecurity Framework and Cyber Range Integration

Distributed energy resource (DER) systems feature complex, data-driven communications networks that require careful system coordination and constant vigilance to ensure that grid assets are secure. Because DERs are an important component of the decarbonization strategy, agencies need to secure energy data that could implicate issues of national security if compromised. To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's (NREL's) Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions that are used to generate a site-specific report and recommendations. This paper outlines a plan to integrate the DER-CF with another key asset-NREL's cyber range-to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF for federal facility energy managers and planners. This integration will result in a visualization environment to interpret and interact with compliance data. Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners.

24 POWER TRANSMISSION AND DISTRIBUTION↗

International Cybersecurity: Capabilities and Overview [Slides]

Innovations in clean energy technology are beginning to transform electric grids around the world. It is more important than ever to understand and improve the resiliency and security of the grid against natural and human disruptions as our energy systems become more distributed, intelligent, and interconnected. Through its advanced cybersecurity technical assistance portfolio, experts at the National Renewable Energy Laboratory (NREL) work with international governments to support secure and resilient deployment of renewable energy assets and address grid interconnection challenges. Cybersecurity technical assistance is tailored to the needs of our international partners.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Assessment for a Behind-the-Meter Solar PV System: A Use Case for the DER-CF

The world's energy production is shifting toward lower-cost, cleaner, more efficient, and sustainable sources. The increasing numbers of distributed energy resources (DERs) are allowing for the rapid transformation of electric grids toward achieving the goal of energy decarbonization. Along with cleaner and more efficient energy, however, we must also aim for a secure energy future. Solar photovoltaic (PV) systems are an important part of this transition. This paper discusses a cybersecurity risk assessment for behind-the-meter DERs using a solar PV system as a use case of the Distributed Energy Resource Cybersecurity Framework (DER-CF) developed by the National Renewable Energy Laboratory. This poster presents a conference paper on the risk assessment processes and summarizes the DER-CF's use case recommendations to strengthen the cybersecurity posture of the electric grid.

cybersecurity↗

Applying the Risk Management Framework: The Distributed Energy Resource Risk Manager

As part of a multiyear effort, the National Renewable Energy Laboratory (NREL) has dedicated resources to understand and identify cybersecurity weaknesses in distributed energy resources (DERs) by performing assessments. Due to a lack of standardization and rapidly increasing adoption of DERs, there is a critical need to address cybersecurity needs for DER systems in an interactive way. Furthermore, federal agencies, which are required to obtain an authority to operate, are challenged by the complexities of including their DERs. To help meet this need, in early 2020, NREL released the Distributed Energy Resources Cybersecurity Framework (DERCF) and accompanying Web application. This process is supported by the Risk Management Framework (RMF) developed by the National Institute of Standards and Technology. This project, referred to as the DERCF RMF application, expands on the existing DERCF work to include methods that support walking a user through the seven RMF steps. The tool will be available for download at no cost from [link ]. The purpose of this paper is to describe the steps the DERCF team at NREL took to understand Steps 1-5 of the RMF process. Additionally, this document will identify future work on the first five steps as well as a plan for Steps 6 and 7.

24 POWER TRANSMISSION AND DISTRIBUTION↗

DER Cybersecurity R&D

The National Renewable Energy Laboratory (NREL) conducted more than 30 assessments for utilities across the United States with a cybersecurity assessment tool based on the U.S. Department of Energy (DOE) Cybersecurity Capability Maturity Model (C2M2) and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) and focused on business process. With funding from the DOE Office of Renewable Energy and Energy Efficiency Federal Energy Management Program, NREL modified the current cyber governance assessment tool to include an assessment process specifically for distributed energy resources (DERs). The Distributed Energy Resources Cybersecurity Framework (DER-CF) was developed to help federal agencies mitigate gaps in their cybersecurity posture for distributed energy systems.

cybersecurity valuation↗

Distributed Energy Resource Visual Emulator: Phase 1

To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions, which are used to generate a site-specific report and recommendations. This paper outlines a technical approach to integrate the DER-CF with another key asset—NREL's Advanced Research on Integrated Energy Systems (ARIES) Cyber Range—to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF. The result is a new tool called the Distributed Energy Resource Visual Emulator (DER-VE). Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners. Phase 0 of the integration project was concluded in 2021. Phase 1, completed in 2022, has two components: The first is developing a working visualization of system compliance using the DER-CF, and the second is planning the design of a server application that takes input data from the DER-CF and creates a personal emulated environment of the user's system or a selected reference architect. Major components that were addressed in this phase are the DER-CF output, compliance visualization, data model, and compliance server design.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CARILEC Resilient Energy Community CoP for Cybersecurity Workshop Series: Cybersecurity Assessment Tools [Slides]

For the last several years and in collaboration with CARILEC, USAID and NREL have been working to support cyber resilience at power sector utilities in Latin America and the Caribbean. Direct technical assistance with regional utilities has been a key component of USAID-NREL Partnership activities, and technical assistance has typically included a foundational cybersecurity assessment using NREL's Distributed Energy Resource Cybersecurity Framework (DER-CF) tool. The DER-CF allows organizations to benchmark and evaluate their cybersecurity posture across the areas of Governance, Technical Management, and Physical Security. To complement the activities of the newly created CAREC IT/OT and Cybersecurity Team, this webinar on cybersecurity assessment tools includes an overview of the DER-CF tool and a discussion with regional stakeholders and NREL experts on the DER-CF assessment process and other resources for cybersecurity assessments.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Hydropower Cybersecurity Value-at-Risk Framework

Hydropower remains one of the strongest forms of renewable energy generation methods. It is crucial to address the increasing risks associated with the rapid digitization. The push towards decarbonization also factors in the need to ensure security and resilience for grid-connected renewable energy resources. This report summarizes the U.S. Department of Energy's Water Power Technologies Office's effort to develop a cybersecurity valuation methodology that assists hydropower stakeholders in assessing risks associated with plan operations and gathers valuation guidance through a web-based application. The Hydropower Cybersecurity Value-at-Risk Framework delivers a platform for industry members to perform self-assessments and make informed decisions on their cybersecurity investments.

13 HYDRO ENERGY↗

Cybersecurity for Energy Systems: Foundational Concepts for Bangladesh Electric Utilities [Slides]

This slide deck was developed for a training for the Northern Electricity Supply Company (NESCO) in Rajshahi, Bangladesh. The topics include: understanding the cybersecurity landscape in power utilities, fundamentals of cybersecurity for power utilities, regulatory compliance and standards, and best practices and strategies. The concepts in this slide deck are relevant for electric utilities throughout Bangladesh.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The Distributed Energy Resource Risk Manager

Organizations need a comprehensive approach to managing security and privacy risks, especially for energy resources that are becoming increasingly distributed. A tool by the National Renewable Energy Laboratory (NREL) makes it possible to manage these risks and maintain the highest standards of cybersecurity. To simplify risk management for facilities and distributed energy resources, NREL has created the Distributed Energy Resource Risk Manager, an automated, user-friendly tool that helps navigate and implement one of the most widely trusted frameworks for information security, the National Institute of Standards and Technology Risk Management Framework.

compliance↗

Cybersecurity Workforce Training for SMR Integration into Distribution Grids: A Competency Framework and Containerized Hands-On Lab for the SMR/DER/Microgrid Boundary

Small modular reactors (SMRs) and microreactors are entering the U.S. distribution grid as synchronous generation on feeders designed for loads and inverter-based distributed energy resources (DERs). No existing cybersecurity training program addresses this intersection of nuclear operations, DER management, and operational technology security. As subcontractor to Iowa State University on the CyDERMS Center, Argonne analyzed the relevant standards and training landscape, translated the resulting gaps into a twelve-objective competency framework across distribution-operator and graduate-analyst role tracks, and built a containerized training lab using a ∼400-bus composite grid model behind a realistically simulated Modbus TCP SCADA stack. The analysis isolates the balance-of-plant / energy-management-system (BOP/EMS) boundary as the critical jurisdictional seam where, as of March 2026, neither NRC nor NERC CIP cleanly claims cybersecurity responsibility for distribution-connected SMRs. The framework maps each objective across NIST CSF 2.0, ISA/IEC 62443, NIST NICE Task–Knowledge–Skill statements, and NRC RG 5.71 awareness-and-training controls. The training lab implements operator-recognition assessment scenarios spanning grid-side disturbances and telemetry-layer anomalies.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Cybersecurity Standards for Distributed Energy Resources: Gaps and Harmonization Strategy

This report examines cybersecurity standards for Distributed Energy Resources (DERs) in light of their rapid growth and increasing integration into energy systems. It identifies critical gaps in existing frameworks, including inadequate coverage of DER-specific challenges, complexities in implementing comprehensive standards, integration issues with legacy systems, adoption hurdles for newer standards, and a lack of harmonization across regulatory landscapes. The analysis highlights vulnerabilities such as data integrity risks, unauthorized device control, and denial-of-service attacks across various DER technologies like solar PV, wind turbines, energy storage systems, and hydrogen fuel cells. The report proposes a harmonization strategy to address these deficiencies by developing unified cybersecurity requirements, certification programs, and training resources while fostering collaboration among stakeholders such as government agencies, industry groups, DER operators, manufacturers, and research institutions. A phased roadmap is outlined to refine and implement these measures through pilot testing and widespread adoption. Ultimately, the report underscores the urgent need for coordinated efforts to enhance DER cybersecurity and ensure the reliable operation of future energy systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Aggregation and Grid Security Workshop Report

The Aggregation and Grid Security Workshop - held on June 17-18, 2025, National Laboratory of the Rockies (NLR) in Golden, Colorado - brought together approximately 40 external stakeholders from the energy sector, including VPP owner/operators, aggregators, OEMs, utilities, testing & certification labs, trade associations, and cybersecurity vendors. Led by key facilitators, the workshop focused on addressing cybersecurity challenges and enhancing grid resilience for aggregated Distributed Energy Resources (DERs) and Virtual Power Plants (VPPs). The workshop was catalyzed by recognition that traditional, rearward-looking regulatory frameworks are insufficient to keep pace with technological change. There is a "missing understanding" of risk, an "absent security basis" for managing it, and an "untenable responsibility" due to unclear ownership and requirements. The workshop aimed to shift the mindset from reacting to past crises to proactively preparing for emerging threats, fostering forward resilience through risk simulation and collaborative action. This report summarizes the outcomes of the workshop, marking it a significant step toward a secure, reliable and affordable energy future.

14 SOLAR ENERGY↗

Secure and Resilient Operations Using Open-Source Distributed Systems Platform (OpenDSP)

The goal of this project is to identify and address cybersecurity gaps by developing a multi-layer multi-channel cyber-physical defense and survival mechanism for operating distribution networks with high penetration of solar / inverter-based resource (IBR) / distributed energy resource (DER). The proposed security enhancements are built upon the distributed framework and solution architecture for both information technology (IT) and operational technology (OT) systems. The technical solutions consist of two composite functionalities and six layers: proactive defense (vulnerability assessment, communication protection, and attack detection, as layers 1-3), and adaptive self-healing (attack-resilient control, adaptive recovery, and resilient survival, as layers 4-6). These layers, built on and extended from DHS CISA Cyber Framework, establish an integrated and robust cybersecurity framework for operating large-scale distribution networks.

14 SOLAR ENERGY↗

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING↗

Threat Hunt Guide for BESS Environments

The rapid digitalization of the electric grid - driven by the integration of inverter-based resources (IBRs), battery energy storage systems (BESS), and advanced grid control platforms - has significantly enhanced grid efficiency, visibility, and flexibility. However, this evolution also introduces new cybersecurity risks, particularly through supply chain dependencies and operational blind spots at the grid edge. To address these challenges, Idaho National Laboratory (INL), through the Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) Rapid Risk initiative, conducted a series of rapid risk assessment engagements with energy organizations across the United States. Drawing on lessons learned from these engagements, INL developed the following threat hunting guide for asset owners and operators (AOOs) to enhance their cybersecurity visibility within BESS and IBR systems. The guide demonstrates how to use passive network monitoring to baseline device behavior, detect adversarial activity, and investigate anomalies without disrupting operations. By implementing these practices, energy sector stakeholders can improve coordination between cybersecurity and operations teams and strengthen the resilience of distributed energy resources (DERs) within the modern power grid. Prior to implementing any network monitoring, packet capture, or threat hunting activity described in this guide, AOOs are strongly advised to review applicable governance frameworks, legal requirements, and organizational policies. This guide is intended for informational and educational purposes only. It does not replace compliance with any federal, state, or local cybersecurity mandates or industry standards. Implementation of described configurations, technologies, or analytic workflows is performed at the discretion and responsibility of the asset owner and operator.

25 - ENERGY STORAGE↗

Cyber-Informed Engineering (CIE) Guide for States

The Cyber-Informed Engineering (CIE) Guide for States provides state energy offices, public utility commissions, and partner organizations with a structured framework for integrating cyber-resilient engineering practices into energy planning, grantmaking, interconnection processes, and workforce development. As grid digitalization and the adoption of distributed energy resources accelerate, states face expanding cyber-physical risks that traditional cybersecurity measures alone cannot fully address. CIE offers a proactive, consequence-focused engineering methodology that emphasizes eliminating or mitigating high-impact failure modes through design, physical controls, and operational safeguards. The guide outlines the 12 core CIE principles, demonstrates their application through state-focused use cases—including grant evaluation rubrics, interconnection reviews, allow-list development, and training programs—and provides practical tools such as scoring frameworks, impact assessment methods, and implementation checklists. It also highlights pathways for state–utility collaboration and opportunities for technical assistance from national laboratories. By adopting CIE, states can enhance grid reliability, reduce lifecycle costs, strengthen supply-chain assurance, and foster a security-aware engineering culture that aligns with broader resilience and modernization goals. November 2025

29 ENERGY PLANNING, POLICY, AND ECONOMY↗