SB1501 requires the Arizona Corporation Commission to conduct a grid security review at least once every two years, or as part of its integrated resource planning process or biennial transmission assessment. The commission must adopt an order setting the review schedule and may revise that order as needed. The bill is aimed at investor-owned public service corporations and requires them to study and evaluate technologies and practices that can protect the electric grid from physical attacks, cyberattacks, and electromagnetic pulse events.
Under the bill, utilities must also evaluate new information technology systems, update their cybersecurity and grid protection protocols, and submit those protocols to the commission for review. The commission must then verify that each utility has active cybersecurity and grid protection protocols, determine whether the submitted protocols are adequate or need changes, and make recommendations to address deficiencies while considering implementation time and cost. The bill also declares that the review materials, protocols, deficiencies, and related information are not open to public inspection.
Impact
SB1501 adds a new section to Title 40 governing the power plant and transmission line siting framework, expanding the Arizona Corporation Commission’s oversight of utility grid security and cybersecurity. It creates recurring review obligations for investor-owned utilities, requires submission of security protocols to the commission, and authorizes the commission to assess adequacy and recommend corrective measures. The bill also exempts the review-related materials from public inspection, limiting public access to sensitive grid-security information.
Sentiment
The bill appears to have received generally favorable but not unanimous support, advancing through both chambers with majority votes. Committee and floor votes show meaningful support for the concept of grid hardening and cybersecurity oversight, while the narrower margins in some stages suggest some legislators had reservations. The legislative findings emphasize reliability, cost reduction, and preparedness for electromagnetic pulse threats, indicating the bill was framed as a public-safety and infrastructure-resilience measure.
Contention
The main points of contention likely centered on the scope of commission oversight, the burden on investor-owned utilities, and the confidentiality provision that shields the review materials from public inspection. Some lawmakers may have been concerned about the costs and operational impacts of requiring utilities to update protocols and undergo recurring reviews, while others likely supported the bill’s emphasis on protecting the electric grid from cyber and physical threats. The inclusion of electromagnetic pulse preparedness may also have been a more debated aspect because it broadens the bill beyond conventional cybersecurity planning.