CISA's ANCHOR-CI just replaced 20 years of critical infrastructure policy. Here's what it means for your NERC, NIST, and FERC compliance program.
For 20 years, critical infrastructure operators had one legal mechanism to sit down with the federal government and hash out cyber risk: the Critical Infrastructure Partnership Advisory Council, or CIPAC. When DHS shut it down last year, energy, water, and manufacturing operators lost their seat at the table — and Congress and industry groups objected almost immediately.
On July 1, CISA answered back. A new Federal Register notice established ANCHOR-CI (Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure), a replacement framework that will govern how the public and private sectors coordinate on cybersecurity for at least the next two years. If your organization touches a regulated sector — energy, water and wastewater, oil and gas, healthcare, or manufacturing — this isn't background noise. It's a structural change to how compliance expectations get set, and it's worth understanding before your next audit cycle.
Why CIPAC's collapse mattered more than it looked
CIPAC wasn't glamorous, but it did one thing well: it gave 16 sector-coordinating councils legal cover (a FACA exemption) to meet privately with federal counterparts, pick members on expertise rather than balanced representation, and move faster than public advisory rules normally allow. When it disappeared, those councils lost the mechanism entirely. Programs like the Joint Cyber Defense Collaborative filled some of the gap, but nothing replaced the standing forums where industry and government worked out how threat intelligence, incident response expectations, and compliance guidance actually got shaped.
Four councils, one bigger shift: threats don't respect sector lines anymore
ANCHOR-CI keeps the FACA exemption but restructures around a real problem: a vulnerability in a cloud platform or industrial software vendor can hit hospitals, pipelines, and utilities at the same time, and the old sector-by-sector model wasn't built for that. The new framework creates four council types:
Critical Infrastructure Sector Councils — the old SCCs, but the CISA director now directly approves or removes members.
Cross-Sector Councils — the ones to watch, tackling threats that span multiple sectors at once (AI risk, drone threats, foreign supply chain dependence).
Critical Infrastructure Industry Councils — built for issues like Volt Typhoon that don't map neatly to one sector, pulling together OEMs, software vendors, and asset owners.
Regional Coordinating Councils — aimed at state and local risk, from Cascadia earthquake prep to hurricane resilience.
What it means for your NERC, NIST, and FERC obligations
Here's the part that lands on compliance teams directly: councils like these are where informal guidance, sector expectations, and eventually formal rulemaking take shape. Operators already navigating NERC CIP standards, NIST frameworks, and FERC reporting requirements should expect ANCHOR-CI's cross-sector and industry councils to influence how those obligations evolve — particularly around OT/ICS reporting, incident disclosure timelines, and supply chain risk documentation. Waiting for the final rule before adjusting your program is a losing strategy; the operators with a seat at these tables (or a partner tracking them closely) get the runway to adapt early.
Three questions your GRC program should be asking right now
Does our compliance roadmap assume the old CIPAC/SCC structure still applies? If so, it's already out of date.
Do we have visibility into which Cross-Sector or Industry Council conversations touch our risk profile — AI threats, OT/ICS, supply chain — before requirements get formalized?
Can we demonstrate audit-ready evidence today if NERC, NIST, or FERC expectations shift faster than our internal review cycle?
If any of those gave you pause, you're not alone — and you're not without options.
How InfoSight keeps regulated operators ahead of the shift
InfoSight has spent more than 25 years inside the compliance requirements this kind of policy change touches — NERC CIP, NIST, and FERC — for energy, water, oil and gas, healthcare, and manufacturing operators. Our
GRC and risk management team tracks exactly this kind of regulatory movement so our clients aren't reacting to a final rule; they're already positioned for it. Whether that means a compliance gap assessment, updated risk documentation, or a straight answer on what ANCHOR-CI means for your sector, that's the conversation we have every day.
Regulatory frameworks like this don't slow down, and neither should your compliance strategy. Subscribe to InfoSight's monthly newsletter for a plain-English read on what's changing in critical infrastructure cybersecurity policy — and what it actually means for your compliance calendar.
Source: https://cyberscoop.com/cisa-anchor-ci-critical-infrastructure-framework-op-ed/