Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “distributed energy resources cybersecurity framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Distributed Energy Resources Cybersecurity Framework & Risk Manager

Distributed Energy Resource Cybersecurity Framework (DER-CF) provides a holistic assessment for evaluating the cybersecurity posture of DER systems - filling an important gap that expands upon existing cybersecurity frameworks for more modern energy systems. The DER-CF is available as a written framework and an interactive Web tool. Distributed Energy Resource Risk Manager (DER-RM) process adheres closely to NIST's seven risk management steps: prepare, categorize, select, implement, assess, monitor, and authorize. This added feature is independent of the DER-CF's existing self-assessment and allows managers to focus on the RMF process.

cybersecurity↗

The Distributed Energy Resource Cybersecurity Framework

For facilities with distributed energy resources (DERs), cybersecurity must be considered holistically, across system architectures and down to individual components. It's hard to know where to start. That's why the National Renewable Energy Laboratory (NREL) has developed an assessment tool for organizations with DERs to understand and improve their cybersecurity. With support from the U.S. Department of Energy's Federal Energy Management Program, the Distributed Energy Resource Cybersecurity Framework (DER-CF) provides a holistic evaluation of a facility's DER cybersecurity and makes customized recommendations that follow widely recognized best practices for cybersecurity. The DER-CF is available at no cost as an interactive web tool (dercf.nrel.gov).

cybersecurity↗

Distributed Energy Resource Cybersecurity Framework and Cyber Range Integration

Distributed energy resource (DER) systems feature complex, data-driven communications networks that require careful system coordination and constant vigilance to ensure that grid assets are secure. Because DERs are an important component of the decarbonization strategy, agencies need to secure energy data that could implicate issues of national security if compromised. To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's (NREL's) Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions that are used to generate a site-specific report and recommendations. This paper outlines a plan to integrate the DER-CF with another key asset-NREL's cyber range-to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF for federal facility energy managers and planners. This integration will result in a visualization environment to interpret and interact with compliance data. Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners.

24 POWER TRANSMISSION AND DISTRIBUTION↗

International Cybersecurity: Capabilities and Overview [Slides]

Innovations in clean energy technology are beginning to transform electric grids around the world. It is more important than ever to understand and improve the resiliency and security of the grid against natural and human disruptions as our energy systems become more distributed, intelligent, and interconnected. Through its advanced cybersecurity technical assistance portfolio, experts at the National Renewable Energy Laboratory (NREL) work with international governments to support secure and resilient deployment of renewable energy assets and address grid interconnection challenges. Cybersecurity technical assistance is tailored to the needs of our international partners.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity Assessment for a Behind-the-Meter Solar PV System: A Use Case for the DER-CF

The world's energy production is shifting toward lower-cost, cleaner, more efficient, and sustainable sources. The increasing numbers of distributed energy resources (DERs) are allowing for the rapid transformation of electric grids toward achieving the goal of energy decarbonization. Along with cleaner and more efficient energy, however, we must also aim for a secure energy future. Solar photovoltaic (PV) systems are an important part of this transition. This paper discusses a cybersecurity risk assessment for behind-the-meter DERs using a solar PV system as a use case of the Distributed Energy Resource Cybersecurity Framework (DER-CF) developed by the National Renewable Energy Laboratory. This poster presents a conference paper on the risk assessment processes and summarizes the DER-CF's use case recommendations to strengthen the cybersecurity posture of the electric grid.

cybersecurity↗

Cybersecurity Assessment Tools for Distributed Energy Resources

This growing number of smart devices that support DERs can increase the number of access points outside a utility’s administrative domain, which can increase the potential for cyberattack. With the integration of DERs at federal sites, the cybersecurity vulnerabilities of DER systems must be understood and addressed. This presentation covers two NREL tools available. The Distributed Energy Resource Cybersecurity Framework (DER-CF) is a web-based holistic tool for evaluating cybersecurity posture including governance, physical security and technical management. The Distributed Energy Resource Risk Manager (DER-RM) extends the DER-CF by applying it to the NIST risk management framework process. It will be downloadable application that runs locally and documents all the major requirements for achieving Authority to Operate the DER.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Applying the Risk Management Framework: The Distributed Energy Resource Risk Manager

As part of a multiyear effort, the National Renewable Energy Laboratory (NREL) has dedicated resources to understand and identify cybersecurity weaknesses in distributed energy resources (DERs) by performing assessments. Due to a lack of standardization and rapidly increasing adoption of DERs, there is a critical need to address cybersecurity needs for DER systems in an interactive way. Furthermore, federal agencies, which are required to obtain an authority to operate, are challenged by the complexities of including their DERs. To help meet this need, in early 2020, NREL released the Distributed Energy Resources Cybersecurity Framework (DERCF) and accompanying Web application. This process is supported by the Risk Management Framework (RMF) developed by the National Institute of Standards and Technology. This project, referred to as the DERCF RMF application, expands on the existing DERCF work to include methods that support walking a user through the seven RMF steps. The tool will be available for download at no cost from [link ]. The purpose of this paper is to describe the steps the DERCF team at NREL took to understand Steps 1-5 of the RMF process. Additionally, this document will identify future work on the first five steps as well as a plan for Steps 6 and 7.

24 POWER TRANSMISSION AND DISTRIBUTION↗

DER Cybersecurity R&D

The National Renewable Energy Laboratory (NREL) conducted more than 30 assessments for utilities across the United States with a cybersecurity assessment tool based on the U.S. Department of Energy (DOE) Cybersecurity Capability Maturity Model (C2M2) and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) and focused on business process. With funding from the DOE Office of Renewable Energy and Energy Efficiency Federal Energy Management Program, NREL modified the current cyber governance assessment tool to include an assessment process specifically for distributed energy resources (DERs). The Distributed Energy Resources Cybersecurity Framework (DER-CF) was developed to help federal agencies mitigate gaps in their cybersecurity posture for distributed energy systems.

cybersecurity valuation↗

Distributed Energy Resource Visual Emulator: Phase 1

To help federal energy managers assess, monitor, and manage cybersecurity while achieving decarbonization, the National Renewable Energy Laboratory's Distributed Energy Resource Cybersecurity Framework (DER-CF) offers a comprehensive, web-based assessment tool focusing on cyber governance or policies, technical management, and physical security. The DER-CF currently presents users with a series of pertinent cybersecurity questions, which are used to generate a site-specific report and recommendations. This paper outlines a technical approach to integrate the DER-CF with another key asset—NREL's Advanced Research on Integrated Energy Systems (ARIES) Cyber Range—to visualize cybersecurity resilience and compliance and to enhance the usability and accessibility of the DER-CF. The result is a new tool called the Distributed Energy Resource Visual Emulator (DER-VE). Its development will include regular conversations with stakeholders to assess the effectiveness of these efforts, refine the visualization capability, and ensure its value to our partners. Phase 0 of the integration project was concluded in 2021. Phase 1, completed in 2022, has two components: The first is developing a working visualization of system compliance using the DER-CF, and the second is planning the design of a server application that takes input data from the DER-CF and creates a personal emulated environment of the user's system or a selected reference architect. Major components that were addressed in this phase are the DER-CF output, compliance visualization, data model, and compliance server design.

24 POWER TRANSMISSION AND DISTRIBUTION↗

CARILEC Resilient Energy Community CoP for Cybersecurity Workshop Series: Cybersecurity Assessment Tools [Slides]

For the last several years and in collaboration with CARILEC, USAID and NREL have been working to support cyber resilience at power sector utilities in Latin America and the Caribbean. Direct technical assistance with regional utilities has been a key component of USAID-NREL Partnership activities, and technical assistance has typically included a foundational cybersecurity assessment using NREL's Distributed Energy Resource Cybersecurity Framework (DER-CF) tool. The DER-CF allows organizations to benchmark and evaluate their cybersecurity posture across the areas of Governance, Technical Management, and Physical Security. To complement the activities of the newly created CAREC IT/OT and Cybersecurity Team, this webinar on cybersecurity assessment tools includes an overview of the DER-CF tool and a discussion with regional stakeholders and NREL experts on the DER-CF assessment process and other resources for cybersecurity assessments.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Guide to the Distributed Energy Resource Risk Management Framework

The emergence of distributed energy resources (DERs) has transformed the electric power sector and will likely have even more profound impacts on the future evolution of the United States energy sector as it modernizes and becomes more reliant upon complex informatics programming and systems to ensure that our power grid remains safe from malicious interference. To mitigate risks associated with the increased and diversified use of DERs, the Distributed Energy Resource Cybersecurity Framework (DER-CF) was developed in 2019. The National Renewable Energy Laboratory extended the scope of the DER-CF to include the RMF. To address the challenges faced by federal energy managers and energy system stakeholders in applying the RMF to DER systems, the Distributed Energy Resource Risk Manager (DER-RM) is a six-step process to proactively manage cybersecurity risk in a methodical manner. The DER-RM is independent of the DER-CF's existing assessment, allowing users to focus specifically on the RMF steps. The tools are targeted to different processes - DER-CF enables organizations to perform self-assessments to improve their cybersecurity posture, while DER-RM assists organizations in achieving compliance with specific requirements. This document provides an overview of the DER-RM. The RMF process outlined in this report serves as a guide to diagnose information and operational system threats, gather required materials to comply with industry standards, and document plans for achieving Authority to Operate. Using the DER-RM, federal agencies and other organizations can easily and intuitively follow the RMF process, manage the risks to their grid-edge infrastructure through the integration of their on-site DERs, and comply with appropriate requirements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Hydropower Cybersecurity Value-at-Risk Framework

Hydropower remains one of the strongest forms of renewable energy generation methods. It is crucial to address the increasing risks associated with the rapid digitization. The push towards decarbonization also factors in the need to ensure security and resilience for grid-connected renewable energy resources. This report summarizes the U.S. Department of Energy's Water Power Technologies Office's effort to develop a cybersecurity valuation methodology that assists hydropower stakeholders in assessing risks associated with plan operations and gathers valuation guidance through a web-based application. The Hydropower Cybersecurity Value-at-Risk Framework delivers a platform for industry members to perform self-assessments and make informed decisions on their cybersecurity investments.

13 HYDRO ENERGY↗

Cybersecurity for Energy Systems: Foundational Concepts for Bangladesh Electric Utilities [Slides]

This slide deck was developed for a training for the Northern Electricity Supply Company (NESCO) in Rajshahi, Bangladesh. The topics include: understanding the cybersecurity landscape in power utilities, fundamentals of cybersecurity for power utilities, regulatory compliance and standards, and best practices and strategies. The concepts in this slide deck are relevant for electric utilities throughout Bangladesh.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cybersecurity for Fast Charging EV Infrastructure

The integration of electric vehicles (EVs) into electric grid operations can potentially leave the grid vulnerable to cyberattacks from both legacy and new equipment and protocols, including extreme fast-charging infrastructure. This paper introduces a co-simulation platform to perform cyber vulnerability analysis of EV charging infrastructure and its dependencies on communications and control systems. Grid impact scenarios through linkages to power system simulation tools such as OpenDSS and vehicle infrastructure-specific attack paths are discussed. An adaptive platform that assists with predicting and solving evolving cybersecurity challenges is demonstrated with a cyber-energy emulation that accelerates the analysis of cyberattacks and system behavior.

ADVANCED PROPULSION SYSTEMS,POWER TRANSMISSION AND↗

The Distributed Energy Resource Risk Manager

Organizations need a comprehensive approach to managing security and privacy risks, especially for energy resources that are becoming increasingly distributed. A tool by the National Renewable Energy Laboratory (NREL) makes it possible to manage these risks and maintain the highest standards of cybersecurity. To simplify risk management for facilities and distributed energy resources, NREL has created the Distributed Energy Resource Risk Manager, an automated, user-friendly tool that helps navigate and implement one of the most widely trusted frameworks for information security, the National Institute of Standards and Technology Risk Management Framework.

compliance↗

Cybersecurity Workforce Training for SMR Integration into Distribution Grids: A Competency Framework and Containerized Hands-On Lab for the SMR/DER/Microgrid Boundary

Small modular reactors (SMRs) and microreactors are entering the U.S. distribution grid as synchronous generation on feeders designed for loads and inverter-based distributed energy resources (DERs). No existing cybersecurity training program addresses this intersection of nuclear operations, DER management, and operational technology security. As subcontractor to Iowa State University on the CyDERMS Center, Argonne analyzed the relevant standards and training landscape, translated the resulting gaps into a twelve-objective competency framework across distribution-operator and graduate-analyst role tracks, and built a containerized training lab using a ∼400-bus composite grid model behind a realistically simulated Modbus TCP SCADA stack. The analysis isolates the balance-of-plant / energy-management-system (BOP/EMS) boundary as the critical jurisdictional seam where, as of March 2026, neither NRC nor NERC CIP cleanly claims cybersecurity responsibility for distribution-connected SMRs. The framework maps each objective across NIST CSF 2.0, ISA/IEC 62443, NIST NICE Task–Knowledge–Skill statements, and NRC RG 5.71 awareness-and-training controls. The training lab implements operator-recognition assessment scenarios spanning grid-side disturbances and telemetry-layer anomalies.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Resilience Framework for Electric Energy Delivery Systems (R.1)

The intent of this document is to provide a Resilience Framework for electrical energy delivery systems which can be applied to Distributed Wind. However, the framework is not limited by application to any resource or system. This framework represents the defined steps to a cyclical process similar in mechanism to both cybersecurity and risk frameworks, while providing a common set of language and process for all stakeholders involved. The need for this Resilience Framework was established in a previous document, “Distributed Wind Resilience Metrics for Electric Energy Delivery Systems.” One important characteristic we see in resilience is the unique needs and perspectives of different systems, geographies, resources, stakeholders, perceived risks, and consequences, which we term the distinctiveness property. This distinctiveness property drives the requirement to have a resilience framework or methodology that can be implemented by different types of organizations and systems. The process or methodology should be cyclic. Recognizing that a system’s resilience is based on finite resources and time, it must continually evolve through this framework’s risk management and capital investment steps at an appropriate pace for its distinctiveness property.

17 WIND ENERGY↗

Cybersecurity Standards for Distributed Energy Resources: Gaps and Harmonization Strategy

This report examines cybersecurity standards for Distributed Energy Resources (DERs) in light of their rapid growth and increasing integration into energy systems. It identifies critical gaps in existing frameworks, including inadequate coverage of DER-specific challenges, complexities in implementing comprehensive standards, integration issues with legacy systems, adoption hurdles for newer standards, and a lack of harmonization across regulatory landscapes. The analysis highlights vulnerabilities such as data integrity risks, unauthorized device control, and denial-of-service attacks across various DER technologies like solar PV, wind turbines, energy storage systems, and hydrogen fuel cells. The report proposes a harmonization strategy to address these deficiencies by developing unified cybersecurity requirements, certification programs, and training resources while fostering collaboration among stakeholders such as government agencies, industry groups, DER operators, manufacturers, and research institutions. A phased roadmap is outlined to refine and implement these measures through pilot testing and widespread adoption. Ultimately, the report underscores the urgent need for coordinated efforts to enhance DER cybersecurity and ensure the reliable operation of future energy systems.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗