Legal & Tax Updates [Back to list]
DOE Establishes Cybersecurity and Cyber Resilience Framework for the Energy Sector
The Department of Energy (DOE) has issued Department Circular No. DC2025-01-0001, which promulgates the adoption of the policy “Institutionalizing the Energy Sector Cybersecurity and Cyber Resilience Framework” across the energy sector. DOE recognizes that the increasing reliance on digital technologies in the energy sector necessitates robust cybersecurity measures to safeguard Information Technology (IT) and Operational Technology (OT) infrastructure The Circular applies broadly to energy industry stakeholders and participants, including entities involved in energy resources, power generation, transmission and distribution, the oil and gas industry, and the utilization sector designated as Critical Information Infrastructure (CII). Aligned with the guiding principles of the National Cybersecurity Plan (NCSP) 2023–2028, the Circular establishes a government-wide framework to strengthen the protection and resilience of the energy sector’s cyber infrastructure.
To oversee implementation, the Circular establishes key oversight, coordination, and advisory bodies. The Oversight Committee on Energy Cybersecurity and Cyber Resilience (OC-ESCCR) is responsible for monitoring the implementation of the policy’s plans and programs. The Technical Working Group on the Identification of Critical Information Infrastructure (TWG-IDCII) uses a risk-based approach to identify and recommend entities for designation as CIIs. At the operational level, the Energy Sector Computer Emergency Response Team (ES-CERT-PH) oversees individual emergency response teams. Energy companies designated as CIIs are required to establish their own Organizational CERT-PH to promptly respond to and mitigate cybersecurity incidents.
Covered entities must comply with rigorous assessment and auditing requirements, including the submission of Cybersecurity Assessment Framework (CAF) results and the Cyber Resilience Scorecard (CRS). The CAF provides a standards-based framework for assessing the cybersecurity posture of information technology (IT) and operational technology (OT) systems and identifying current and desired risk management states. The CRS complements the CAF by assessing organizational cyber resilience and its alignment with cybersecurity outcomes. For compliance purposes, both the CAF and CRS must be validated by an external auditor and approved by the Department of Information and Communications Technology (DICT), serving as the mandatory Audit Report required under the NCSP.
Section 5 of the Circular further requires periodic technical and operational reporting. Regulated CIIs must submit annually on or before the 30th of April the CAF results and the CRS. Additionally, they must submit Vulnerability Assessment and Penetration Testing (VAPT) Reports for identified Critical Information Technology Assets, including Internet of Things (IoT) devices, to the DICT. They must also submit quarterly reports detailing cyber issues handled, closed, and remediated. These requirements must be supported by the development and implementation of an overarching Cybersecurity and Cyber Resilience Program.
Finally, compliance under the Circular remains subject to the Data Privacy Act of 2012 (DPA), confidentiality and intellectual property rules, and applicable cybercrime laws. While cybersecurity incident reports are generally treated as classified information, incidents that may compromise the confidentiality, secrecy, or integrity of personal information must be disclosed to the National Privacy Commission (NPC). Under the DPA, the OC-ESCCR and ES-CERT-PH must notify affected data subjects within 72 hours of a potential exposure to enable prompt risk mitigation.
