Checked against primary sources 2026-08-24
The networked breaker rule arrived in 2023, not 2026
A breaker whose rating can be raised from somewhere else is a breaker whose protection can be removed from somewhere else, and the code has said so since the 2023 edition.
On this page
What the section covers
A circuit breaker whose trip setting can be adjusted remotely gets to be treated as rated at its adjusted setting only when access to that adjustment is controlled at both ends (NEC 240.6(D)).
Adjustable-trip breakers are not new. What changed is that a lot of them now sit on a network, so the setting that decides how much current the circuit is protected at can be moved by somebody who is not standing in front of the panel.
The code treats that as an overcurrent protection question, because it is one. If the adjustment is reachable and unguarded, the rating you designed to is not the rating the installation actually has.
The two conditions
Local restricted access comes first, and it uses the methods already in 240.6(C): behind a sealable cover over the adjusting means, behind a bolted equipment door, behind a locked door available only to qualified personnel, or password protected with the password held by qualified personnel.
Remote access is the second half. It is satisfied by a local nonnetworked interface, or by a networked interface that meets one of two tests.
- The breaker and the software used to adjust it have been identified as having been evaluated for cybersecurity.
- A cybersecurity risk assessment of the network has been completed, with documentation and certification available to those authorized to inspect, operate and maintain the system.
That second option is the one with teeth on a live job, because it produces a document somebody has to be able to hand over.
Which edition this is actually in
The 2023 edition. 240.6(D) is one of a small group of sections that brought cybersecurity language into NFPA 70 in that cycle, alongside 110.3(A)(8) on examining network-connected equipment and 708.7 in the critical operations power systems article.
And nothing happened to it in the 2026 cycle. NFPA published first and second draft reports for every code-making panel, and panel 10, which owns Article 240, made no revision to 240.6 or any part of it. If your tab points at 240.6 it still lands in the right place, and the text under it reads the same as it did in your last book.
That matters mainly because the section keeps being described as a 2026 arrival, including once on this site. It is worth knowing which of the things you are being told are new actually are.
The standards it points at, and where they sit
ISA 62443, UL 2900 and NEMA CY70001 appear in informational notes attached to the section, not in its enforceable text. The code treats an informational note as explanatory material rather than as a requirement (NEC 90.5(C)).
So an inspector cannot cite you for failing to follow ISA 62443. What is enforceable is the sentence in 240.6(D) itself: the evaluation, or the completed risk assessment with its documentation. The named standards tell you what a defensible answer looks like.
None of those are electrical standards, which is the genuinely interesting part. The code reached outside its own discipline because the failure mode it is worried about is not electrical either.
What it changes on a job
The answer to "can we put this breaker on the building network" used to be an IT decision made after the electrical design was finished.
It now has a code section attached to it, and the documentation route means somebody has to be able to produce a risk assessment when asked. On an industrial or institutional job with networked protection, that is a deliverable, and deciding who owns it late is expensive.
The practical read for a working electrician: if the adjustment is only reachable from a local, nonnetworked interface, you are in familiar territory and 240.6(C) is the whole job. The moment it is on a network, somebody has to hold a document.
What this page cites
- NEC 240.6(D) Remotely accessible adjustable-trip circuit breakers. Added in the 2023 edition, confirmed by the ICC 2023 NEC changes list at item 119 and by Eaton, which names 110.3(A), 240.6(D), 708.7 and 708.8(A) as the 2023 cybersecurity additions. NFPA panel 10 made no first or second revision to 240.6 in the A2025 cycle that produced the 2026 edition. source
- NEC 240.6(C) The four local restricted access methods the remote-access rule builds on.
- NEC 90.5(C) Explanatory material. Informational notes are explanatory and are not enforceable as requirements of the code, which is where the ISA, UL and NEMA references in 240.6(D) sit.
- NEC 110.3(A) The other place the 2023 edition put cybersecurity language, on examination of equipment. source