Administered by

  • HOME
  • CONTACT US
  • ABOUT THIS SITE
  • DISCLAIMER
  • Supported by
  • Australian Renewable Energy Agency (ARENA)
English (UK)
GB English (UK)
US English (US)
  • EXPLORE KNOWLEDGE BASE

  • CERI Knowledge Base

    • About the CERI knowledge base

      • Introduction to Australia’s electricity markets

        • Australian consumer insights

          • CER technical and interoperability standards

            • Connecting a customer to an electricity network

              • Connecting a generator to a distribution network

                • Utility interconnection (CSIP-AUS)

                  • Dynamic network export and generation control schemes

                    • Network load control schemes

                      • Network tariffs and network support services

                        • Participating in the National Electricity Market

                          • Participating in a frequency control market

                            • Participating in the RERT

                              • Participating in the Wholesale Electricity Market (Western Australia)

                                • Participating in the I-NTEM (NT)

                                  • Cyber security and data privacy arrangements

                                    • Consumer protection frameworks

                                    National Energy PKI (NEPKI) and CSIP-AUS

                                    Last Updated on 4 August 2026

                                    SUGGEST AN EDIT

                                    LIKE THIS PAGE?

                                    Table of Contents

                                    Key points ACCC authorisation and limitations Likely arrangements for CSIP-AUS client providers Organisational and Technical Controls Hybrid and Tiered Compliance Approach Core Compliance and Operational Obligations Emergency Backstop and Regulatory Context Industry Engagement and Continuous Improvement Related articles

                                    NEPKI is a not-for-profit entity which procures and operates a national PKI service for CSIP-AUS clients and servers. This national approach replaces fragmented, utility-specific PKI solutions, and intends to reduce complexity and cost for manufacturers and consumers. It secures current use-cases including emergency backstop requirements, mandated in several jurisdictions, that allow utilities (e.g., DNSPs and Synergy) to remotely curtail CER exports during contingency events, as well as offer flexible export limits.

                                    Using a single PKI provider is intended to streamline OEM PKI security compliance. It works alongside national CER testing and certification, which uses certificates to verify and validate system functionality. From 2026, NEPKI will manage certificate issuance through a root CA and Manufacturer Issuing Certificate Authorities (MICAs), overseen by a Policy Management Authority (PMA) within NEPKI. Becoming a MICA allows an OEM to issue digital certificates to their own CER.

                                    The Utility Interconnection (CSIP-AUS) section of this knowledge base summarises the CSIP-AUS communications protocol including its cybersecurity requirements. It references the national effort led by the ENA in establishing a central PKI for CSIP-AUS under a new entity called NEPKI, which is expanded on here.

                                    Key points

                                    • NEPKI provides a national certificate service for CSIP-AUS clients and servers. It is intended to replace fragmented utility-specific PKI arrangements.
                                    • The ACCC authorisation currently limits NEPKI to CSIP-AUS communications.
                                    • Participating organisations must validate their identity and securely manage certificates.
                                    • CSIP-AUS products and servers must complete applicable testing and certification.
                                    • Cybersecurity requirements are proposed to scale according to the total CER capacity managed by each provider.

                                    ACCC authorisation and limitations

                                    ENA was required to obtain ACCC authorisation given potential competition risks associated with the operation of NEPKI as a cooperative and monopoly service.

                                    ENA’s application to the ACCC sought authorisation for a national PKI service to support secure communications for CER broadly, including solar, batteries, and EVs. CSIP-AUS was identified as the initial protocol and the proposal contemplated expansion to other protocols and use-cases in the future.

                                    The final ACCC authorisation for NEPKI however is limited to PKI services for managing communications using CSIP-AUS. This mitigates risks of NEPKI expanding into unrelated use cases (e.g., electric vehicle roaming) without oversight. NEPKI cannot extend beyond the CSIP-AUS use-case without further regulatory review and approval.

                                    Likely arrangements for CSIP-AUS client providers

                                    Recent collaboration among DNSPs in NSW, ACT, and SA, and Synergy (as of November 2025) has led to the development of a Common Cyber Security Requirements document, responding to industry calls for clear, consistent expectations for CSIP-AUS client providers.

                                    Organisational and Technical Controls

                                    The Common Cyber Security Requirements document divides obligations into:

                                    • Organisational Requirements: Drawing on AESCSF and IEC 62443-2-1, these cover cybersecurity programme management, asset management, incident management, risk management, supply chain dependencies, threat and vulnerability management, and workforce management.
                                    • Control System Requirements: Based on IEC 62443-3-3, these include network segmentation, access control, patch and vulnerability management, encryption, monitoring and logging, and incident response. These controls apply across the CER ecosystem, including CER, and any gateway devices, proxy server or aggregation platform.

                                    Hybrid and Tiered Compliance Approach

                                    The draft requirements adopt a hybrid model, blending maturity-based practices from the AESCSF with specific technical controls from international standards such as IEC 62443.

                                    A tiered structure is proposed, scaling requirements according to the provider’s total CER capacity under management in Australia:

                                    1. Tier 0: Less than 50 MW
                                    2. Tier 1: 50-500 MW
                                    3. Tier 2: Greater than 500 MW

                                    Providers are expected to meet baseline requirements within 12 months of reaching a new threshold or when new versions of the requirements are released. This ensures proportionality and supports both small-scale innovators and large fleet operators.

                                    Core Compliance and Operational Obligations

                                    Entities operating CSIP-AUS utility servers (utilities typically operate servers and CER manufacturers operate clients) become PKI-consuming entities and are subject to the following core obligations:

                                    • Onboarding and Validation: PKI-consuming entities must validate their identity with NEPKI as part of an onboarding process. Successful validation enables them to receive certificates.
                                    • PKI Integration: Prior to CSIP-AUS operation, servers and devices must have a valid PKI certificate installed. Entities generally complete certificate installation during or immediately prior to commissioning. Servers and devices must securely store and manage certificates.
                                    • Testing and Certification: All servers and devices must complete CSIP-AUS testing and certification, administered by the ANU. This process includes validating correct PKI behaviour using certificates issued by ANU for simulation and interoperability testing.
                                    • Cost Considerations: Under NEPKI’s operating principles, operational costs of NEPKI are recovered from parties that consume CSIP-AUS server certificates (initially, DNSPs and Synergy) and are recovered from electricity customers.
                                    • Governance Compliance: Participation requires adherence to Policy Management Authority (PMA) directions and governance standards, including providing technical data on CER assets and complying with security protocols for certificate lifecycle management.

                                    More information on the processes and requirements can be found at:

                                    • https://www.csipaus.org/certification (for product certification)
                                    • https://www.nepki.com.au (for information about NEPKI including scheme participation requirements)

                                    Emergency Backstop and Regulatory Context

                                    A critical regulatory backdrop for CSIP-AUS client providers is the requirement to support emergency backstop mechanisms. These enable utilities (such as DNSPs and Synergy) to remotely curtail CER exports during minimum system load conditions, ensuring grid stability and security. The critical nature of the emergency backstop mechanism, and the expected large volume of CSIP-AUS connected devices reinforce the need for robust, interoperable, and secure device communications and mature organisational cybersecurity capability.

                                    Industry Engagement and Continuous Improvement

                                    The framework emphasises ongoing industry engagement, inviting OEMs and platform providers to participate in the development and refinement of requirements. Providers are encouraged to stay informed about evolving standards, participate in consultations, and ensure timely compliance with new or updated obligations. This can be done by registering for updates via csipaus.org/contact. Organisations can also nominate to join DERIAPITWG – the working group leading future CSIP-AUS development.

                                    Related articles

                                    • Utility Interconnection (CSIP-AUS)
                                    • Australian energy sector cyber security framework
                                    • CER Cybersecurity Roadmap
                                    • Security of Critical Infrastructure (SOCI) Act
                                    energy infrastructure national energy accc service protocol security cybersecurity interconnection compliance and operation emergency backstop improvement development

                                    Copyright 2026 – CERI.

                                    Knowledge Base Software powered by Helpjuice

                                    Expand