You built the spectrum, radio network, and core across your service territory. OneLayer closes the device visibility gap that remains, so what NERC CIP demands becomes something you can show.
Supported FAN cores
The Challenge
Utilities that build and operate a private Field Area Network gain dedicated spectrum, deterministic performance for protection and automation traffic, and full control over a network regulators expect them to secure. But the core authenticates by SIM, not device. Whether you're bringing your first substations online or already at AMI scale, the gap between what's authenticated and what's actually connected is exactly what a NERC CIP audit will ask about.
Your core confirms the subscription is valid. It has no record of what device sits behind that SIM, whether it was swapped in the field, or whether it belongs on the network.
CIP-015 compliance dates run through 2028 to 2030, but east-west visibility across a field network spanning hundreds of substations takes years to build. Waiting for the deadline leaves no runway.
Figuring out which device sits behind a given modem today means calling vendors and resellers and tracking it in a spreadsheet, a process that can take weeks per case. That doesn't scale to the tens of thousands of devices a grid modernization rollout requires.
The Solution
How OneLayer Fits: A Device Identity
Layer for the Network You Already
Built
OneLayer Bridge connects to your FAN core's northbound management interface, across Ericsson, Nokia, Druid, Athonet, GE Vernova, and Cisco alike, and binds every SIM authentication to a verified device fingerprint. Read-only, agentless, no changes to the running network. Whether your team needs fast onboarding as the footprint grows or audit-ready evidence at full scale, OneLayer gives the operational picture the core was never built to provide on its own.
Onboard
Automated SIM provisioning and activation at fleet scale, triggered from your ITSM or CMDB instead of manual per-device work. Every device gets the same security policy from day one, with bulk enroll, activate, edit, and deactivate from a single interface, built for compliance rather than retrofitted after deployment.
Observe
Automatic fingerprinting classifies make, model, vendor, and protocol, not just a MAC address, extending discovery to assets behind field and cellular routers that other tools miss. Cellular threats like IMEI spoofing, SIM swaps, and SIM farms surface alongside policy violations like an unpermitted manufacturer or a geofence breach, exported straight to your SOC.
Protect
OneLayer feeds the device identity your NGFW needs for per-device access control and identity-based segmentation, with dynamic labels that update automatically as behavior changes, no manual tagging. A flagged device gets blocked at the firewall instead of just logged, closing the loop CIP-015 will expect.
What Our Customers Are Saying
“Our partnership with OneLayer allows us to scale and secure all of the devices on our network so we can effectively and efficiently expand network utilization. OneLayer's Bridge platform gives us control of connected assets on our LTE network and provides essential tools to better manage and secure our network as usage expands.”
TRUSTED BY
No. OneLayer extends your existing Zero Trust architecture to cover your field area network, which most ZTNA tools were never designed to reach. Your current stack (NAC, MDM, ISE, SIEM) continues to operate as is. OneLayer integrates with it, surfacing cellular connection events and policy decisions into the same workflows your security team already uses.
OneLayer uses signature-based fingerprinting for devices that can’t support certificates. A device identity is built from stable, device-specific attributes: IMEI, radio behavior, connection patterns, and other observable characteristics, extending discovery to devices behind field routers your core doesn’t show. That signature becomes the identity assertion at connection time. Certificate-based validation is used for managed endpoints that support it.
Your core confirms the SIM is valid, not what device sits behind it, and that is the exact gap CIP-015’s internal network security monitoring requirement is built around. OneLayer adds the device-level layer your core was never built to provide: verified identity, make, model, and vendor for every device, plus the connection history and policy violations you need as audit evidence, from your first substations through full AMI scale.
No. OneLayer connects to your FAN core’s existing northbound management interface, across Ericsson, Nokia, Druid, Athonet, GE Vernova, and Cisco alike, without requiring changes to your SIMs, field devices, or network hardware. It’s read-only and agentless, so your live network keeps running exactly as it does today.