Person
Person

Aug 11, 2026

Energy Infrastructure Resilience Policy Checklist

Capacity Building

In This Article

Evaluate energy resilience policy against clear ownership, funded projects, asset inventories, 72‑hour backups, and regular reviews.

Energy Infrastructure Resilience Policy Checklist

Weather drives about 80% of major U.S. power outages, and weather-linked outages have doubled in the last two decades. If I am checking an energy resilience policy, I should look for one simple thing first: is it assigned, funded, tested, and updated?

Here’s the short version of what matters most:

  • Clear ownership: I need named roles, backup contacts, and plain escalation rules.

  • Current risk review: I should use FEMA, NOAA, and USGS data, not old assumptions.

  • Asset and load tracking: I need an inventory of generation, wires, fuel, control systems, and critical sites like hospitals and water plants.

  • Emergency rules that work on the ground: That includes 72-hour backup power, fuel supply plans, mutual aid, and post-event reviews within 60–90 days.

  • Cross-sector checks: I should map how power loss hits water, telecom, health care, fuel, and transportation.

  • Money tied to risk: Resilience projects need stated funding sources, spending rules, and project tests such as avoided outage value and equity review.

  • Score and update cycle: The policy should be scored, tracked, and reviewed every 3–5 years, with early updates after major outages or new hazard data.

At a glance, a ready policy should answer these questions:

Check

What I look for

Ownership

Named lead, alternates, and legal authority

Risk

Current hazard data and future climate timeframes

Assets

GIS-based inventory with criticality tiers

Response

Backup power, fuel, mutual aid, restoration priorities

Dependencies

Links to water, telecom, health care, and transport

Funding

Budget line, eligible sources, and project screens

Oversight

Annual metrics, thresholds, and corrective action triggers

Updates

Set review cycle plus event-based revisions

If those pieces are missing, the policy may exist on paper but fail under stress. I would use this checklist as a plain scorecard to spot gaps, assign owners, and set deadlines fast.

Energy Infrastructure Resilience Policy Checklist: 8 Core Elements

Energy Infrastructure Resilience Policy Checklist: 8 Core Elements

1. Governance, Scope, and Accountability Checks

Policy scope and resilience objectives

Start by spelling out exactly what the policy covers: which assets, which hazards, and which places.

The scope statement should name covered systems by class - electric transmission and distribution, gas infrastructure, liquid fuels, and digital/control systems. It should also identify the critical customer loads those systems support, such as hospitals, emergency operations centers, and water and wastewater plants. From there, connect each asset class to its owner or operator, note which assets count as critical under state, federal, or local rules, and define the geographic reach of the policy - statewide, multi-county, tribal lands, or a single metro area. If assets cross jurisdiction lines, say how responsibility is assigned.

The policy also needs a hazard list tied to current risk data and local exposure, not a generic menu. FEMA's National Risk Index tracks 18 major hazard types and includes social vulnerability and community resilience data.[6] One useful reference point comes from DOE's Texas Energy Sector Risk Profile, which found that numeric resilience targets - not broad language - are needed to reflect actual exposure frequency.[4]

That matters because terms like resilient or prepared can sound fine on paper and still mean almost nothing in practice. A workable policy sets measurable targets for continuity, backup power, restoration, and equity.

Once the scope is set, responsibility for each asset class and hazard should be assigned in writing.

Named roles and reporting lines

After scope comes accountability. This is where many policies get fuzzy, and that fuzziness tends to show up at the worst possible moment.

Name specific roles, not just agencies. Saying "the state energy office" is in charge leaves room for confusion during a reorganization, leadership turnover, or a vacancy. A stronger policy names roles such as State Energy Assurance Director, Utility Emergency Operations Center Director, Local Emergency Manager, and Public Health Emergency Preparedness Coordinator. Each role should have a named alternate and clear succession language.

The policy should also identify one lead coordinating entity, usually the state energy office or the state emergency management agency. Just as important, it should cite the statute, executive order, ordinance, or commission order that gives that entity authority to set standards, require resilience filings, and enforce compliance.

Reporting lines need the same level of detail. Energy decisions hit hardest during planning, response, and rebuilding, so escalation authority should be plain on the page.

Phase

Primary Accountability

Key Mechanism

Preparedness & Planning

State Energy Office / PUC

Resilience plan filings, capital plan approvals

Emergency Response

State Emergency Management Agency / state EOC

Escalation protocols, ESF-12 activation, MOUs

Recovery & Rebuilding

Governor's Office / state resilience office

Interagency agreements, rebuilding decisions

A written escalation protocol should define the exact trigger for each step. For example, if more than 100,000 customers lose power for over 24 hours, or if any critical facility loses power for more than 4 hours, the issue should move from utility to regulator to state EOC. MOUs between utilities and public health agencies, emergency management, transportation departments, and planning departments should set communication formats, data-sharing schedules, and secure channels. Those agreements should be reviewed every 3 to 5 years and tested through exercises.[3]

Those roles should not sit off to the side. They need to line up with the emergency, hazard mitigation, and capital planning systems already in place.

Alignment with other plans and partners

Energy resilience policy works better when it matches the plans governments already use.

The policy's risk priorities, roles, and mitigation actions should align with the state or local hazard mitigation plan (HMP). Energy sector mitigation projects - like substation elevation, line undergrounding, and fuel terminal relocation - should be listed in the HMP so they can qualify for FEMA mitigation funding. Activation thresholds and public communication chains in the energy policy should also match the Emergency Operations Plan, especially under Emergency Support Function #12 (Energy).[2][5]

The same test applies to climate action plans and capital improvement plans. Distributed solar-plus-storage microgrids, for example, can support both resilience and decarbonization goals - but only when both plans identify them and pay for them together. A simple check helps here: look for the policy's resilience investments in the capital improvement plan. If they are missing, treat them as potentially unfunded.

2. Asset Risk Review and Emergency Planning Checks

Critical asset and service inventory

A policy without a maintained asset inventory can't set risk or restoration priorities in any serious way. The inventory should cover generation, transmission, distribution, fuel, control, telecom, and IT assets. That includes power plants, distributed energy resources, substations, lines, pipelines, compressor stations, terminals, tanks, and control centers.

Critical loads should sit in that same inventory. Hospitals, emergency operations centers, fire and police stations, water and wastewater plants, shelters, and major telecommunications hubs all need to be mapped to the exact feeders, circuits, and assets that serve them. FEMA is clear on this point: build a pre-incident inventory of critical infrastructure and use it to set restoration priorities before a disaster hits, not in the middle of one.[7]

For each asset, the record should include GIS coordinates, design standards, age, condition, redundancy status, and a criticality tier based on failure impact. The policy should require updates every 2–3 years, along with event-triggered updates after major system changes, retirements, or major upgrades.[8][10] The inventory should also connect to asset management systems so maintenance history, outage records, and risk scores appear in one place. That same record should drive hazard scenarios, restoration order, and backup power priorities.

Climate and multi-hazard risk requirements

Risk review can't rely only on what happened in the past. Policy should require forward-looking assessments using NOAA's Climate at a Glance, FEMA's Disaster Declarations Summary, and USGS hazard maps.[18] Planning horizons should be set at 2030 and 2050, and at 2100 for long-lived or coastal assets.[17]

The policy should also require compound-risk scenarios. Think heat plus drought plus wildfire, or hurricane plus flood. Research on interdependency shows that tighter power-water coupling increases cascade risk, which is why high-load, highly connected nodes should be protected first.[16][1][19] Scenario-based stress tests should show where current design standards fail under plausible future conditions. Those results should then shape restoration priorities and emergency activation triggers.

Assessment Factor

Definition

Policy Requirement Check

Exposure

Asset location in a hazard-prone area

Use FEMA/NOAA geospatial maps

Sensitivity

Degree of damage from a given hazard

Evaluate asset age and material durability

Adaptive Capacity

Ability to recover or adapt

Check for backup power and emergency plan coverage

Preparedness, Response, and Recovery Rules

Each response rule should tie back to the Tier 1 assets and critical loads listed above. Emergency plans need to be hazard-specific and concrete. A plan that names roles but skips activation triggers, or talks about restoration priorities without tying them to actual feeders and circuits, tends to fall apart when conditions get rough.

Policies should require 72-hour backup power at critical facilities, multi-site fuel storage, fuel rotation, emergency purchase procedures, periodic load tests, fuel-quality checks, and refueling contracts.[9][14]

They should also require participation in EEI mutual assistance programs or RMAGs, along with deployable crew and equipment lists and shared training and safety standards. That way, incoming crews can plug into the local incident command structure without confusion or delay.[11][12][13]

Requirement

State Energy Office

Utilities / Operators

Local Emergency Management

Asset inventory maintenance

Set standards and update cycle

Maintain and report

Identify critical loads

Climate risk assessment

Require and review filings

Conduct per asset class

Input on community vulnerabilities

Emergency plan filing

Approve and audit

Develop hazard-specific plans

Integrate with local EOPs

Backup power compliance

Set minimums (e.g., 72-hour rule)

Install, test, and document

Verify at critical facilities

Mutual aid participation

Require and track agreements

Execute and maintain RMAGs

Coordinate logistics and staging

Post-event review

Set deadline (60–90 days)

Submit after-action report with corrective actions

Contribute field observations

Post-event reviews should be due within 60–90 days and should lead to specific corrective actions.[15] Those findings should feed straight into updated emergency plans, asset management strategies, and capital investment decisions, with a named owner for each follow-up item.

Energy Resilience: What is it? How do we value it? @infraday

3. Interdependency, Funding, and Performance Oversight Checks

Sections 1 and 2 set the chain of authority and clarify which assets matter most. This section asks a tougher question: does the policy deal with system links, money, and follow-through?

Interdependency and cascading risk review

Power failures don't stay in one lane. When energy goes down, water systems, hospitals, fuel supply, telecom networks, and transportation can go with it. A sound policy should map those links in both directions, using the critical asset inventory and named roles from earlier sections.

Policy should require a formal interdependency map that shows upstream and downstream ties across energy, water, transportation, communications, healthcare, and fuel supply. That map should use GIS overlays to show where energy assets sit in relation to floodplains, wildfire risk zones, and socially vulnerable communities. It should also include a cascade failure register: a documented list of high-risk scenarios, such as a 48-hour regional outage that disrupts water, healthcare, and communications, ranked by severity and likelihood.

That work can't sit on a shelf. Policy should require a cross-sector dependency review group, annual updates to the register, and biennial tabletop or functional exercises built around multi-day outages, fuel limits, and communications loss. Lessons learned and corrective actions from those exercises should be written down, assigned to named owners, and tracked until they're done.[22][19]

Use the interdependency map to rank which assets, services, and communities need priority protection and restoration. That's where the policy moves from theory to triage.

Funding rules and investment criteria

The dependency register should guide funding toward the highest-risk nodes first. If everything is labeled urgent, nothing is.

Resilience funding often comes from a mix of federal, state, utility, bond, and reserve sources. Policy should name the eligible funding sources, spell out which project types qualify, set a minimum annual resilience budget, and line up multi-year funding with asset lifecycles and climate projections.

For major investments, require climate-adjusted cost-benefit analysis, avoided-outage estimates, and an equity impact review showing whether reliability gaps in vulnerable communities are shrinking.[20][21]

Funding Source

Typical Use

Key Requirement

DOE GRIP / Grid Resilience Utility and Industry Grants

Grid hardening, microgrids, control systems

100% non-federal cost match

FEMA BRIC

Pre-disaster mitigation, critical facility resilience

Climate-adjusted CBA; equity documentation

Municipal Bonds / Green Bonds

Large capital projects

Debt service capacity; project eligibility

Utility Rate Recovery

Prudent resilience upgrades approved by PUC

Affordability screen; ratepayer impact analysis

State Resilience Reserve Funds

Emergency repairs, rapid deployment

Access and drawdown rules

Reporting metrics and oversight triggers

Reporting should tie back to the same critical assets, communities, and restoration priorities already identified. Otherwise, the numbers may look neat while missing the point.

Policy should require annual reporting on SAIDI, SAIFI, CAIDI, critical-facility restoration times, resilience spending, and corrective actions.[23][24][25] Ownership for reporting should be plain: utilities collect and submit the data, and the state energy office or public utility commission validates it and publishes the annual report.

There also needs to be a trigger for action, not just another PDF. Require a mandatory corrective action plan when outage performance misses thresholds for two straight years or when critical facilities keep missing restoration targets. Equity triggers should be part of that framework too. If outage gaps persist, policy should shift funding to those areas, not just log the problem. The point is to track whether the policy is changing outcomes, not merely counting outages.

4. Policy Update Cycle and Final Readiness Summary

Scheduled and event-triggered policy updates

Once reporting and oversight triggers are in place, the policy needs a set review cycle. Review the resilience policy every 3–5 years and test emergency and energy security plans every year, with revisions approved at least every 3 years.[26][30]

Don’t wait for the calendar if conditions shift. Launch an out-of-cycle update after a major outage, new hazard data, evolving climate resilience needs, regulatory changes, a major system reconfiguration, or serious audit or exercise findings.[26][27] Put one person in charge of watching for those triggers and starting the review within 6 months.[26][27]

Lessons learned should feed straight back into the policy. That means updating thresholds, funding priorities, and operating rules, then tracking each corrective action by owner and deadline.[26][27]

How to score findings and set next steps

After the update schedule is set, score the current policy against each checklist item. Use a simple scale:

  • 2 = in place and tested

  • 1 = partially defined

  • 0 = missing or undocumented

Subtotals by category - governance, asset and hazard review, emergency planning, interdependencies, funding, reporting, and updates - make it easy to see where the policy is solid and where gaps remain.[28]

From there, sort actions across three factors: urgency, based on hazard exposure and outage probability; regulatory exposure, based on compliance duties and funding rules; and service impact on critical facilities and vulnerable customers. The table below turns that into a clear action path.

Priority Tier

Criteria

Next Step

Tier 1 – Critical

High impact, high exposure, and missing or partial readiness

Address immediately and assign an owner

Tier 2 – High

Moderate impact or exposure with partial readiness

Build into the near-term work plan

Tier 3 – Low

Low impact, low exposure, and mostly complete

Track and revisit in the next review cycle

Each Tier 1 item should include a named owner, a deadline, and a resource estimate before the checklist cycle closes.

Conclusion: Core elements of a resilient energy policy

Use the scorecard to produce the final readiness summary. A policy is ready when it covers governance, asset and hazard review, emergency planning, cross-sector coordination, funding, reporting, and update mechanisms.[26][28][29] Summarize the top gaps, owners, deadlines, and resource needs.

FAQs

Who should own the policy?

Policy ownership needs a clear governance structure. Without it, plans drift and lose steam. Put one person in charge - a dedicated leader or climate champion - and back them with a cross-department team that includes operations, finance, and facilities.

Executive leadership should set the mandate and provide the budget. Board-level oversight helps keep people accountable and keeps the work on track. An external advisory panel can bring technical expertise and help keep the policy strong and well connected across the organization.

How often should the policy be updated?

Use a dual-track approach: do a full review and update every 2 to 5 years, with annual reviews to check progress, refresh metrics, and stay in step with budgeting and day-to-day operations.

Make targeted updates right after climate-related disruptions or major organizational changes.

What makes a resilience project worth funding?

A resilience project deserves funding when its expected value is higher than its cost to put in place. The clearest way to sort projects is with a benefit-cost ratio that reflects the full picture: lower hazard risk, stronger assets, and added gains such as social, economic, or environmental returns.

The strongest proposals don’t stop at the project itself. They show what happens if nothing gets done by using regional loss data to quantify the cost of inaction. They also line up with federal funding criteria, bring in local matching funds, and connect the project to broader infrastructure or economic development plans.

That’s what makes a project more competitive. It’s not just about solving one problem. It’s about showing, in plain terms, why the investment pays off and how it fits into a bigger plan.

Related Blog Posts

FAQ

01

What does it really mean to “redefine profit”?

02

What makes Council Fire different?

03

Who does Council Fire work with?

04

What does working with Council Fire actually look like?

05

How does Council Fire help organizations turn big goals into action?

06

How does Council Fire define and measure success?

Person
Person

Aug 11, 2026

Energy Infrastructure Resilience Policy Checklist

Capacity Building

In This Article

Evaluate energy resilience policy against clear ownership, funded projects, asset inventories, 72‑hour backups, and regular reviews.

Energy Infrastructure Resilience Policy Checklist

Weather drives about 80% of major U.S. power outages, and weather-linked outages have doubled in the last two decades. If I am checking an energy resilience policy, I should look for one simple thing first: is it assigned, funded, tested, and updated?

Here’s the short version of what matters most:

  • Clear ownership: I need named roles, backup contacts, and plain escalation rules.

  • Current risk review: I should use FEMA, NOAA, and USGS data, not old assumptions.

  • Asset and load tracking: I need an inventory of generation, wires, fuel, control systems, and critical sites like hospitals and water plants.

  • Emergency rules that work on the ground: That includes 72-hour backup power, fuel supply plans, mutual aid, and post-event reviews within 60–90 days.

  • Cross-sector checks: I should map how power loss hits water, telecom, health care, fuel, and transportation.

  • Money tied to risk: Resilience projects need stated funding sources, spending rules, and project tests such as avoided outage value and equity review.

  • Score and update cycle: The policy should be scored, tracked, and reviewed every 3–5 years, with early updates after major outages or new hazard data.

At a glance, a ready policy should answer these questions:

Check

What I look for

Ownership

Named lead, alternates, and legal authority

Risk

Current hazard data and future climate timeframes

Assets

GIS-based inventory with criticality tiers

Response

Backup power, fuel, mutual aid, restoration priorities

Dependencies

Links to water, telecom, health care, and transport

Funding

Budget line, eligible sources, and project screens

Oversight

Annual metrics, thresholds, and corrective action triggers

Updates

Set review cycle plus event-based revisions

If those pieces are missing, the policy may exist on paper but fail under stress. I would use this checklist as a plain scorecard to spot gaps, assign owners, and set deadlines fast.

Energy Infrastructure Resilience Policy Checklist: 8 Core Elements

Energy Infrastructure Resilience Policy Checklist: 8 Core Elements

1. Governance, Scope, and Accountability Checks

Policy scope and resilience objectives

Start by spelling out exactly what the policy covers: which assets, which hazards, and which places.

The scope statement should name covered systems by class - electric transmission and distribution, gas infrastructure, liquid fuels, and digital/control systems. It should also identify the critical customer loads those systems support, such as hospitals, emergency operations centers, and water and wastewater plants. From there, connect each asset class to its owner or operator, note which assets count as critical under state, federal, or local rules, and define the geographic reach of the policy - statewide, multi-county, tribal lands, or a single metro area. If assets cross jurisdiction lines, say how responsibility is assigned.

The policy also needs a hazard list tied to current risk data and local exposure, not a generic menu. FEMA's National Risk Index tracks 18 major hazard types and includes social vulnerability and community resilience data.[6] One useful reference point comes from DOE's Texas Energy Sector Risk Profile, which found that numeric resilience targets - not broad language - are needed to reflect actual exposure frequency.[4]

That matters because terms like resilient or prepared can sound fine on paper and still mean almost nothing in practice. A workable policy sets measurable targets for continuity, backup power, restoration, and equity.

Once the scope is set, responsibility for each asset class and hazard should be assigned in writing.

Named roles and reporting lines

After scope comes accountability. This is where many policies get fuzzy, and that fuzziness tends to show up at the worst possible moment.

Name specific roles, not just agencies. Saying "the state energy office" is in charge leaves room for confusion during a reorganization, leadership turnover, or a vacancy. A stronger policy names roles such as State Energy Assurance Director, Utility Emergency Operations Center Director, Local Emergency Manager, and Public Health Emergency Preparedness Coordinator. Each role should have a named alternate and clear succession language.

The policy should also identify one lead coordinating entity, usually the state energy office or the state emergency management agency. Just as important, it should cite the statute, executive order, ordinance, or commission order that gives that entity authority to set standards, require resilience filings, and enforce compliance.

Reporting lines need the same level of detail. Energy decisions hit hardest during planning, response, and rebuilding, so escalation authority should be plain on the page.

Phase

Primary Accountability

Key Mechanism

Preparedness & Planning

State Energy Office / PUC

Resilience plan filings, capital plan approvals

Emergency Response

State Emergency Management Agency / state EOC

Escalation protocols, ESF-12 activation, MOUs

Recovery & Rebuilding

Governor's Office / state resilience office

Interagency agreements, rebuilding decisions

A written escalation protocol should define the exact trigger for each step. For example, if more than 100,000 customers lose power for over 24 hours, or if any critical facility loses power for more than 4 hours, the issue should move from utility to regulator to state EOC. MOUs between utilities and public health agencies, emergency management, transportation departments, and planning departments should set communication formats, data-sharing schedules, and secure channels. Those agreements should be reviewed every 3 to 5 years and tested through exercises.[3]

Those roles should not sit off to the side. They need to line up with the emergency, hazard mitigation, and capital planning systems already in place.

Alignment with other plans and partners

Energy resilience policy works better when it matches the plans governments already use.

The policy's risk priorities, roles, and mitigation actions should align with the state or local hazard mitigation plan (HMP). Energy sector mitigation projects - like substation elevation, line undergrounding, and fuel terminal relocation - should be listed in the HMP so they can qualify for FEMA mitigation funding. Activation thresholds and public communication chains in the energy policy should also match the Emergency Operations Plan, especially under Emergency Support Function #12 (Energy).[2][5]

The same test applies to climate action plans and capital improvement plans. Distributed solar-plus-storage microgrids, for example, can support both resilience and decarbonization goals - but only when both plans identify them and pay for them together. A simple check helps here: look for the policy's resilience investments in the capital improvement plan. If they are missing, treat them as potentially unfunded.

2. Asset Risk Review and Emergency Planning Checks

Critical asset and service inventory

A policy without a maintained asset inventory can't set risk or restoration priorities in any serious way. The inventory should cover generation, transmission, distribution, fuel, control, telecom, and IT assets. That includes power plants, distributed energy resources, substations, lines, pipelines, compressor stations, terminals, tanks, and control centers.

Critical loads should sit in that same inventory. Hospitals, emergency operations centers, fire and police stations, water and wastewater plants, shelters, and major telecommunications hubs all need to be mapped to the exact feeders, circuits, and assets that serve them. FEMA is clear on this point: build a pre-incident inventory of critical infrastructure and use it to set restoration priorities before a disaster hits, not in the middle of one.[7]

For each asset, the record should include GIS coordinates, design standards, age, condition, redundancy status, and a criticality tier based on failure impact. The policy should require updates every 2–3 years, along with event-triggered updates after major system changes, retirements, or major upgrades.[8][10] The inventory should also connect to asset management systems so maintenance history, outage records, and risk scores appear in one place. That same record should drive hazard scenarios, restoration order, and backup power priorities.

Climate and multi-hazard risk requirements

Risk review can't rely only on what happened in the past. Policy should require forward-looking assessments using NOAA's Climate at a Glance, FEMA's Disaster Declarations Summary, and USGS hazard maps.[18] Planning horizons should be set at 2030 and 2050, and at 2100 for long-lived or coastal assets.[17]

The policy should also require compound-risk scenarios. Think heat plus drought plus wildfire, or hurricane plus flood. Research on interdependency shows that tighter power-water coupling increases cascade risk, which is why high-load, highly connected nodes should be protected first.[16][1][19] Scenario-based stress tests should show where current design standards fail under plausible future conditions. Those results should then shape restoration priorities and emergency activation triggers.

Assessment Factor

Definition

Policy Requirement Check

Exposure

Asset location in a hazard-prone area

Use FEMA/NOAA geospatial maps

Sensitivity

Degree of damage from a given hazard

Evaluate asset age and material durability

Adaptive Capacity

Ability to recover or adapt

Check for backup power and emergency plan coverage

Preparedness, Response, and Recovery Rules

Each response rule should tie back to the Tier 1 assets and critical loads listed above. Emergency plans need to be hazard-specific and concrete. A plan that names roles but skips activation triggers, or talks about restoration priorities without tying them to actual feeders and circuits, tends to fall apart when conditions get rough.

Policies should require 72-hour backup power at critical facilities, multi-site fuel storage, fuel rotation, emergency purchase procedures, periodic load tests, fuel-quality checks, and refueling contracts.[9][14]

They should also require participation in EEI mutual assistance programs or RMAGs, along with deployable crew and equipment lists and shared training and safety standards. That way, incoming crews can plug into the local incident command structure without confusion or delay.[11][12][13]

Requirement

State Energy Office

Utilities / Operators

Local Emergency Management

Asset inventory maintenance

Set standards and update cycle

Maintain and report

Identify critical loads

Climate risk assessment

Require and review filings

Conduct per asset class

Input on community vulnerabilities

Emergency plan filing

Approve and audit

Develop hazard-specific plans

Integrate with local EOPs

Backup power compliance

Set minimums (e.g., 72-hour rule)

Install, test, and document

Verify at critical facilities

Mutual aid participation

Require and track agreements

Execute and maintain RMAGs

Coordinate logistics and staging

Post-event review

Set deadline (60–90 days)

Submit after-action report with corrective actions

Contribute field observations

Post-event reviews should be due within 60–90 days and should lead to specific corrective actions.[15] Those findings should feed straight into updated emergency plans, asset management strategies, and capital investment decisions, with a named owner for each follow-up item.

Energy Resilience: What is it? How do we value it? @infraday

3. Interdependency, Funding, and Performance Oversight Checks

Sections 1 and 2 set the chain of authority and clarify which assets matter most. This section asks a tougher question: does the policy deal with system links, money, and follow-through?

Interdependency and cascading risk review

Power failures don't stay in one lane. When energy goes down, water systems, hospitals, fuel supply, telecom networks, and transportation can go with it. A sound policy should map those links in both directions, using the critical asset inventory and named roles from earlier sections.

Policy should require a formal interdependency map that shows upstream and downstream ties across energy, water, transportation, communications, healthcare, and fuel supply. That map should use GIS overlays to show where energy assets sit in relation to floodplains, wildfire risk zones, and socially vulnerable communities. It should also include a cascade failure register: a documented list of high-risk scenarios, such as a 48-hour regional outage that disrupts water, healthcare, and communications, ranked by severity and likelihood.

That work can't sit on a shelf. Policy should require a cross-sector dependency review group, annual updates to the register, and biennial tabletop or functional exercises built around multi-day outages, fuel limits, and communications loss. Lessons learned and corrective actions from those exercises should be written down, assigned to named owners, and tracked until they're done.[22][19]

Use the interdependency map to rank which assets, services, and communities need priority protection and restoration. That's where the policy moves from theory to triage.

Funding rules and investment criteria

The dependency register should guide funding toward the highest-risk nodes first. If everything is labeled urgent, nothing is.

Resilience funding often comes from a mix of federal, state, utility, bond, and reserve sources. Policy should name the eligible funding sources, spell out which project types qualify, set a minimum annual resilience budget, and line up multi-year funding with asset lifecycles and climate projections.

For major investments, require climate-adjusted cost-benefit analysis, avoided-outage estimates, and an equity impact review showing whether reliability gaps in vulnerable communities are shrinking.[20][21]

Funding Source

Typical Use

Key Requirement

DOE GRIP / Grid Resilience Utility and Industry Grants

Grid hardening, microgrids, control systems

100% non-federal cost match

FEMA BRIC

Pre-disaster mitigation, critical facility resilience

Climate-adjusted CBA; equity documentation

Municipal Bonds / Green Bonds

Large capital projects

Debt service capacity; project eligibility

Utility Rate Recovery

Prudent resilience upgrades approved by PUC

Affordability screen; ratepayer impact analysis

State Resilience Reserve Funds

Emergency repairs, rapid deployment

Access and drawdown rules

Reporting metrics and oversight triggers

Reporting should tie back to the same critical assets, communities, and restoration priorities already identified. Otherwise, the numbers may look neat while missing the point.

Policy should require annual reporting on SAIDI, SAIFI, CAIDI, critical-facility restoration times, resilience spending, and corrective actions.[23][24][25] Ownership for reporting should be plain: utilities collect and submit the data, and the state energy office or public utility commission validates it and publishes the annual report.

There also needs to be a trigger for action, not just another PDF. Require a mandatory corrective action plan when outage performance misses thresholds for two straight years or when critical facilities keep missing restoration targets. Equity triggers should be part of that framework too. If outage gaps persist, policy should shift funding to those areas, not just log the problem. The point is to track whether the policy is changing outcomes, not merely counting outages.

4. Policy Update Cycle and Final Readiness Summary

Scheduled and event-triggered policy updates

Once reporting and oversight triggers are in place, the policy needs a set review cycle. Review the resilience policy every 3–5 years and test emergency and energy security plans every year, with revisions approved at least every 3 years.[26][30]

Don’t wait for the calendar if conditions shift. Launch an out-of-cycle update after a major outage, new hazard data, evolving climate resilience needs, regulatory changes, a major system reconfiguration, or serious audit or exercise findings.[26][27] Put one person in charge of watching for those triggers and starting the review within 6 months.[26][27]

Lessons learned should feed straight back into the policy. That means updating thresholds, funding priorities, and operating rules, then tracking each corrective action by owner and deadline.[26][27]

How to score findings and set next steps

After the update schedule is set, score the current policy against each checklist item. Use a simple scale:

  • 2 = in place and tested

  • 1 = partially defined

  • 0 = missing or undocumented

Subtotals by category - governance, asset and hazard review, emergency planning, interdependencies, funding, reporting, and updates - make it easy to see where the policy is solid and where gaps remain.[28]

From there, sort actions across three factors: urgency, based on hazard exposure and outage probability; regulatory exposure, based on compliance duties and funding rules; and service impact on critical facilities and vulnerable customers. The table below turns that into a clear action path.

Priority Tier

Criteria

Next Step

Tier 1 – Critical

High impact, high exposure, and missing or partial readiness

Address immediately and assign an owner

Tier 2 – High

Moderate impact or exposure with partial readiness

Build into the near-term work plan

Tier 3 – Low

Low impact, low exposure, and mostly complete

Track and revisit in the next review cycle

Each Tier 1 item should include a named owner, a deadline, and a resource estimate before the checklist cycle closes.

Conclusion: Core elements of a resilient energy policy

Use the scorecard to produce the final readiness summary. A policy is ready when it covers governance, asset and hazard review, emergency planning, cross-sector coordination, funding, reporting, and update mechanisms.[26][28][29] Summarize the top gaps, owners, deadlines, and resource needs.

FAQs

Who should own the policy?

Policy ownership needs a clear governance structure. Without it, plans drift and lose steam. Put one person in charge - a dedicated leader or climate champion - and back them with a cross-department team that includes operations, finance, and facilities.

Executive leadership should set the mandate and provide the budget. Board-level oversight helps keep people accountable and keeps the work on track. An external advisory panel can bring technical expertise and help keep the policy strong and well connected across the organization.

How often should the policy be updated?

Use a dual-track approach: do a full review and update every 2 to 5 years, with annual reviews to check progress, refresh metrics, and stay in step with budgeting and day-to-day operations.

Make targeted updates right after climate-related disruptions or major organizational changes.

What makes a resilience project worth funding?

A resilience project deserves funding when its expected value is higher than its cost to put in place. The clearest way to sort projects is with a benefit-cost ratio that reflects the full picture: lower hazard risk, stronger assets, and added gains such as social, economic, or environmental returns.

The strongest proposals don’t stop at the project itself. They show what happens if nothing gets done by using regional loss data to quantify the cost of inaction. They also line up with federal funding criteria, bring in local matching funds, and connect the project to broader infrastructure or economic development plans.

That’s what makes a project more competitive. It’s not just about solving one problem. It’s about showing, in plain terms, why the investment pays off and how it fits into a bigger plan.

Related Blog Posts

FAQ

01

What does it really mean to “redefine profit”?

02

What makes Council Fire different?

03

Who does Council Fire work with?

04

What does working with Council Fire actually look like?

05

How does Council Fire help organizations turn big goals into action?

06

How does Council Fire define and measure success?

Person
Person

Aug 11, 2026

Energy Infrastructure Resilience Policy Checklist

Capacity Building

In This Article

Evaluate energy resilience policy against clear ownership, funded projects, asset inventories, 72‑hour backups, and regular reviews.

Energy Infrastructure Resilience Policy Checklist

Weather drives about 80% of major U.S. power outages, and weather-linked outages have doubled in the last two decades. If I am checking an energy resilience policy, I should look for one simple thing first: is it assigned, funded, tested, and updated?

Here’s the short version of what matters most:

  • Clear ownership: I need named roles, backup contacts, and plain escalation rules.

  • Current risk review: I should use FEMA, NOAA, and USGS data, not old assumptions.

  • Asset and load tracking: I need an inventory of generation, wires, fuel, control systems, and critical sites like hospitals and water plants.

  • Emergency rules that work on the ground: That includes 72-hour backup power, fuel supply plans, mutual aid, and post-event reviews within 60–90 days.

  • Cross-sector checks: I should map how power loss hits water, telecom, health care, fuel, and transportation.

  • Money tied to risk: Resilience projects need stated funding sources, spending rules, and project tests such as avoided outage value and equity review.

  • Score and update cycle: The policy should be scored, tracked, and reviewed every 3–5 years, with early updates after major outages or new hazard data.

At a glance, a ready policy should answer these questions:

Check

What I look for

Ownership

Named lead, alternates, and legal authority

Risk

Current hazard data and future climate timeframes

Assets

GIS-based inventory with criticality tiers

Response

Backup power, fuel, mutual aid, restoration priorities

Dependencies

Links to water, telecom, health care, and transport

Funding

Budget line, eligible sources, and project screens

Oversight

Annual metrics, thresholds, and corrective action triggers

Updates

Set review cycle plus event-based revisions

If those pieces are missing, the policy may exist on paper but fail under stress. I would use this checklist as a plain scorecard to spot gaps, assign owners, and set deadlines fast.

Energy Infrastructure Resilience Policy Checklist: 8 Core Elements

Energy Infrastructure Resilience Policy Checklist: 8 Core Elements

1. Governance, Scope, and Accountability Checks

Policy scope and resilience objectives

Start by spelling out exactly what the policy covers: which assets, which hazards, and which places.

The scope statement should name covered systems by class - electric transmission and distribution, gas infrastructure, liquid fuels, and digital/control systems. It should also identify the critical customer loads those systems support, such as hospitals, emergency operations centers, and water and wastewater plants. From there, connect each asset class to its owner or operator, note which assets count as critical under state, federal, or local rules, and define the geographic reach of the policy - statewide, multi-county, tribal lands, or a single metro area. If assets cross jurisdiction lines, say how responsibility is assigned.

The policy also needs a hazard list tied to current risk data and local exposure, not a generic menu. FEMA's National Risk Index tracks 18 major hazard types and includes social vulnerability and community resilience data.[6] One useful reference point comes from DOE's Texas Energy Sector Risk Profile, which found that numeric resilience targets - not broad language - are needed to reflect actual exposure frequency.[4]

That matters because terms like resilient or prepared can sound fine on paper and still mean almost nothing in practice. A workable policy sets measurable targets for continuity, backup power, restoration, and equity.

Once the scope is set, responsibility for each asset class and hazard should be assigned in writing.

Named roles and reporting lines

After scope comes accountability. This is where many policies get fuzzy, and that fuzziness tends to show up at the worst possible moment.

Name specific roles, not just agencies. Saying "the state energy office" is in charge leaves room for confusion during a reorganization, leadership turnover, or a vacancy. A stronger policy names roles such as State Energy Assurance Director, Utility Emergency Operations Center Director, Local Emergency Manager, and Public Health Emergency Preparedness Coordinator. Each role should have a named alternate and clear succession language.

The policy should also identify one lead coordinating entity, usually the state energy office or the state emergency management agency. Just as important, it should cite the statute, executive order, ordinance, or commission order that gives that entity authority to set standards, require resilience filings, and enforce compliance.

Reporting lines need the same level of detail. Energy decisions hit hardest during planning, response, and rebuilding, so escalation authority should be plain on the page.

Phase

Primary Accountability

Key Mechanism

Preparedness & Planning

State Energy Office / PUC

Resilience plan filings, capital plan approvals

Emergency Response

State Emergency Management Agency / state EOC

Escalation protocols, ESF-12 activation, MOUs

Recovery & Rebuilding

Governor's Office / state resilience office

Interagency agreements, rebuilding decisions

A written escalation protocol should define the exact trigger for each step. For example, if more than 100,000 customers lose power for over 24 hours, or if any critical facility loses power for more than 4 hours, the issue should move from utility to regulator to state EOC. MOUs between utilities and public health agencies, emergency management, transportation departments, and planning departments should set communication formats, data-sharing schedules, and secure channels. Those agreements should be reviewed every 3 to 5 years and tested through exercises.[3]

Those roles should not sit off to the side. They need to line up with the emergency, hazard mitigation, and capital planning systems already in place.

Alignment with other plans and partners

Energy resilience policy works better when it matches the plans governments already use.

The policy's risk priorities, roles, and mitigation actions should align with the state or local hazard mitigation plan (HMP). Energy sector mitigation projects - like substation elevation, line undergrounding, and fuel terminal relocation - should be listed in the HMP so they can qualify for FEMA mitigation funding. Activation thresholds and public communication chains in the energy policy should also match the Emergency Operations Plan, especially under Emergency Support Function #12 (Energy).[2][5]

The same test applies to climate action plans and capital improvement plans. Distributed solar-plus-storage microgrids, for example, can support both resilience and decarbonization goals - but only when both plans identify them and pay for them together. A simple check helps here: look for the policy's resilience investments in the capital improvement plan. If they are missing, treat them as potentially unfunded.

2. Asset Risk Review and Emergency Planning Checks

Critical asset and service inventory

A policy without a maintained asset inventory can't set risk or restoration priorities in any serious way. The inventory should cover generation, transmission, distribution, fuel, control, telecom, and IT assets. That includes power plants, distributed energy resources, substations, lines, pipelines, compressor stations, terminals, tanks, and control centers.

Critical loads should sit in that same inventory. Hospitals, emergency operations centers, fire and police stations, water and wastewater plants, shelters, and major telecommunications hubs all need to be mapped to the exact feeders, circuits, and assets that serve them. FEMA is clear on this point: build a pre-incident inventory of critical infrastructure and use it to set restoration priorities before a disaster hits, not in the middle of one.[7]

For each asset, the record should include GIS coordinates, design standards, age, condition, redundancy status, and a criticality tier based on failure impact. The policy should require updates every 2–3 years, along with event-triggered updates after major system changes, retirements, or major upgrades.[8][10] The inventory should also connect to asset management systems so maintenance history, outage records, and risk scores appear in one place. That same record should drive hazard scenarios, restoration order, and backup power priorities.

Climate and multi-hazard risk requirements

Risk review can't rely only on what happened in the past. Policy should require forward-looking assessments using NOAA's Climate at a Glance, FEMA's Disaster Declarations Summary, and USGS hazard maps.[18] Planning horizons should be set at 2030 and 2050, and at 2100 for long-lived or coastal assets.[17]

The policy should also require compound-risk scenarios. Think heat plus drought plus wildfire, or hurricane plus flood. Research on interdependency shows that tighter power-water coupling increases cascade risk, which is why high-load, highly connected nodes should be protected first.[16][1][19] Scenario-based stress tests should show where current design standards fail under plausible future conditions. Those results should then shape restoration priorities and emergency activation triggers.

Assessment Factor

Definition

Policy Requirement Check

Exposure

Asset location in a hazard-prone area

Use FEMA/NOAA geospatial maps

Sensitivity

Degree of damage from a given hazard

Evaluate asset age and material durability

Adaptive Capacity

Ability to recover or adapt

Check for backup power and emergency plan coverage

Preparedness, Response, and Recovery Rules

Each response rule should tie back to the Tier 1 assets and critical loads listed above. Emergency plans need to be hazard-specific and concrete. A plan that names roles but skips activation triggers, or talks about restoration priorities without tying them to actual feeders and circuits, tends to fall apart when conditions get rough.

Policies should require 72-hour backup power at critical facilities, multi-site fuel storage, fuel rotation, emergency purchase procedures, periodic load tests, fuel-quality checks, and refueling contracts.[9][14]

They should also require participation in EEI mutual assistance programs or RMAGs, along with deployable crew and equipment lists and shared training and safety standards. That way, incoming crews can plug into the local incident command structure without confusion or delay.[11][12][13]

Requirement

State Energy Office

Utilities / Operators

Local Emergency Management

Asset inventory maintenance

Set standards and update cycle

Maintain and report

Identify critical loads

Climate risk assessment

Require and review filings

Conduct per asset class

Input on community vulnerabilities

Emergency plan filing

Approve and audit

Develop hazard-specific plans

Integrate with local EOPs

Backup power compliance

Set minimums (e.g., 72-hour rule)

Install, test, and document

Verify at critical facilities

Mutual aid participation

Require and track agreements

Execute and maintain RMAGs

Coordinate logistics and staging

Post-event review

Set deadline (60–90 days)

Submit after-action report with corrective actions

Contribute field observations

Post-event reviews should be due within 60–90 days and should lead to specific corrective actions.[15] Those findings should feed straight into updated emergency plans, asset management strategies, and capital investment decisions, with a named owner for each follow-up item.

Energy Resilience: What is it? How do we value it? @infraday

3. Interdependency, Funding, and Performance Oversight Checks

Sections 1 and 2 set the chain of authority and clarify which assets matter most. This section asks a tougher question: does the policy deal with system links, money, and follow-through?

Interdependency and cascading risk review

Power failures don't stay in one lane. When energy goes down, water systems, hospitals, fuel supply, telecom networks, and transportation can go with it. A sound policy should map those links in both directions, using the critical asset inventory and named roles from earlier sections.

Policy should require a formal interdependency map that shows upstream and downstream ties across energy, water, transportation, communications, healthcare, and fuel supply. That map should use GIS overlays to show where energy assets sit in relation to floodplains, wildfire risk zones, and socially vulnerable communities. It should also include a cascade failure register: a documented list of high-risk scenarios, such as a 48-hour regional outage that disrupts water, healthcare, and communications, ranked by severity and likelihood.

That work can't sit on a shelf. Policy should require a cross-sector dependency review group, annual updates to the register, and biennial tabletop or functional exercises built around multi-day outages, fuel limits, and communications loss. Lessons learned and corrective actions from those exercises should be written down, assigned to named owners, and tracked until they're done.[22][19]

Use the interdependency map to rank which assets, services, and communities need priority protection and restoration. That's where the policy moves from theory to triage.

Funding rules and investment criteria

The dependency register should guide funding toward the highest-risk nodes first. If everything is labeled urgent, nothing is.

Resilience funding often comes from a mix of federal, state, utility, bond, and reserve sources. Policy should name the eligible funding sources, spell out which project types qualify, set a minimum annual resilience budget, and line up multi-year funding with asset lifecycles and climate projections.

For major investments, require climate-adjusted cost-benefit analysis, avoided-outage estimates, and an equity impact review showing whether reliability gaps in vulnerable communities are shrinking.[20][21]

Funding Source

Typical Use

Key Requirement

DOE GRIP / Grid Resilience Utility and Industry Grants

Grid hardening, microgrids, control systems

100% non-federal cost match

FEMA BRIC

Pre-disaster mitigation, critical facility resilience

Climate-adjusted CBA; equity documentation

Municipal Bonds / Green Bonds

Large capital projects

Debt service capacity; project eligibility

Utility Rate Recovery

Prudent resilience upgrades approved by PUC

Affordability screen; ratepayer impact analysis

State Resilience Reserve Funds

Emergency repairs, rapid deployment

Access and drawdown rules

Reporting metrics and oversight triggers

Reporting should tie back to the same critical assets, communities, and restoration priorities already identified. Otherwise, the numbers may look neat while missing the point.

Policy should require annual reporting on SAIDI, SAIFI, CAIDI, critical-facility restoration times, resilience spending, and corrective actions.[23][24][25] Ownership for reporting should be plain: utilities collect and submit the data, and the state energy office or public utility commission validates it and publishes the annual report.

There also needs to be a trigger for action, not just another PDF. Require a mandatory corrective action plan when outage performance misses thresholds for two straight years or when critical facilities keep missing restoration targets. Equity triggers should be part of that framework too. If outage gaps persist, policy should shift funding to those areas, not just log the problem. The point is to track whether the policy is changing outcomes, not merely counting outages.

4. Policy Update Cycle and Final Readiness Summary

Scheduled and event-triggered policy updates

Once reporting and oversight triggers are in place, the policy needs a set review cycle. Review the resilience policy every 3–5 years and test emergency and energy security plans every year, with revisions approved at least every 3 years.[26][30]

Don’t wait for the calendar if conditions shift. Launch an out-of-cycle update after a major outage, new hazard data, evolving climate resilience needs, regulatory changes, a major system reconfiguration, or serious audit or exercise findings.[26][27] Put one person in charge of watching for those triggers and starting the review within 6 months.[26][27]

Lessons learned should feed straight back into the policy. That means updating thresholds, funding priorities, and operating rules, then tracking each corrective action by owner and deadline.[26][27]

How to score findings and set next steps

After the update schedule is set, score the current policy against each checklist item. Use a simple scale:

  • 2 = in place and tested

  • 1 = partially defined

  • 0 = missing or undocumented

Subtotals by category - governance, asset and hazard review, emergency planning, interdependencies, funding, reporting, and updates - make it easy to see where the policy is solid and where gaps remain.[28]

From there, sort actions across three factors: urgency, based on hazard exposure and outage probability; regulatory exposure, based on compliance duties and funding rules; and service impact on critical facilities and vulnerable customers. The table below turns that into a clear action path.

Priority Tier

Criteria

Next Step

Tier 1 – Critical

High impact, high exposure, and missing or partial readiness

Address immediately and assign an owner

Tier 2 – High

Moderate impact or exposure with partial readiness

Build into the near-term work plan

Tier 3 – Low

Low impact, low exposure, and mostly complete

Track and revisit in the next review cycle

Each Tier 1 item should include a named owner, a deadline, and a resource estimate before the checklist cycle closes.

Conclusion: Core elements of a resilient energy policy

Use the scorecard to produce the final readiness summary. A policy is ready when it covers governance, asset and hazard review, emergency planning, cross-sector coordination, funding, reporting, and update mechanisms.[26][28][29] Summarize the top gaps, owners, deadlines, and resource needs.

FAQs

Who should own the policy?

Policy ownership needs a clear governance structure. Without it, plans drift and lose steam. Put one person in charge - a dedicated leader or climate champion - and back them with a cross-department team that includes operations, finance, and facilities.

Executive leadership should set the mandate and provide the budget. Board-level oversight helps keep people accountable and keeps the work on track. An external advisory panel can bring technical expertise and help keep the policy strong and well connected across the organization.

How often should the policy be updated?

Use a dual-track approach: do a full review and update every 2 to 5 years, with annual reviews to check progress, refresh metrics, and stay in step with budgeting and day-to-day operations.

Make targeted updates right after climate-related disruptions or major organizational changes.

What makes a resilience project worth funding?

A resilience project deserves funding when its expected value is higher than its cost to put in place. The clearest way to sort projects is with a benefit-cost ratio that reflects the full picture: lower hazard risk, stronger assets, and added gains such as social, economic, or environmental returns.

The strongest proposals don’t stop at the project itself. They show what happens if nothing gets done by using regional loss data to quantify the cost of inaction. They also line up with federal funding criteria, bring in local matching funds, and connect the project to broader infrastructure or economic development plans.

That’s what makes a project more competitive. It’s not just about solving one problem. It’s about showing, in plain terms, why the investment pays off and how it fits into a bigger plan.

Related Blog Posts

FAQ

What does it really mean to “redefine profit”?

What makes Council Fire different?

Who does Council Fire work with?

What does working with Council Fire actually look like?

How does Council Fire help organizations turn big goals into action?

How does Council Fire define and measure success?