A major power failure can disrupt far more than electricity. The 2003 Northeast blackout affected many people across parts of the United States and Canada. It showed how quickly grid problems can interrupt homes and essential services.
NERC CIP compliance helps applicable electricity organisations protect the systems behind reliable power delivery. Regulatory scrutiny also remains active. In 2025, the ERO Enterprise reduced its backlog of unresolved enforcement matters by nearly 50% through faster case processing. The result points to more efficient oversight rather than lower cyber risk.
Security threats continue to change. Organisations must keep their safeguards effective and remain ready to prove compliance. This guide explains what the standards cover and how you can meet their requirements.
Key Takeaways
- NERC registration alone does not decide your complete CIP responsibility. The role performed and the systems involved shape the final scope.
- BES Cyber Systems needs the correct impact rating before you can determine which safeguards apply.
- Compliance depends on proof from daily operations. Written policies cannot show that a required task actually happened.
- Changes to facilities and technology can make an earlier applicability decision outdated.
- Third-party access still requires oversight because the registered entity keeps responsibility for applicable obligations.
- Organisations affected by NERC CIP 015 should assess monitoring gaps well before its October 2028 effective date.
What Is NERC CIP Compliance?
NERC CIP compliance means meeting the Critical Infrastructure Protection Reliability Standards that apply to your organisation and its Bulk Electric System responsibilities.
NERC develops these mandatory standards through the Electric Reliability Organization framework. FERC approves and enforces them within the United States. Regional Entities support compliance monitoring through audits and other review activities.
NERC CIP is not a voluntary certification. Security products may support compliance but cannot replace the required controls or evidence. The standards define what you must do.
Who Must Comply With NERC CIP?
NERC CIP may apply to organisations registered for functions connected to the reliable operation of the North American Bulk Electric System. NERC registration covers users, owners, and operators that perform specified reliability functions.
Functions commonly linked to CIP obligations include:
- Balancing Authority
- Generator Owner
- Generator Operator
- Reliability Coordinator
- Transmission Owner
- Transmission Operator
- Certain Distribution Providers
Operating a utility or renewable energy facility does not mean every NERC CIP standard applies. Your obligations depend on your registered function and the applicability wording of each standard.
Vendors, cloud providers, consultants, and equipment manufacturers do not automatically become registered entities because they support a utility. The registered organisation may remain accountable for outsourced compliance work.
In the United States, approved standards become mandatory under FERC oversight. Canadian authorities apply relevant requirements through their own provincial processes.
How Is NERC CIP Applicability Determined?
Registration alone does not define your full NERC CIP scope. You must connect each registered function to the facilities and reliability duties under your control. You must then identify the related BES Cyber Systems and review the applicability statement in each CIP standard.
1. Confirm Registration, Function, and Jurisdiction
Check the following:
- Confirm the legal entity listed in the NERC Compliance Registry.
- Record every registered function performed by that entity.
- Identify who owns or operates each relevant facility.
- Review agreements where control or duties are shared.
- Note any responsibilities delegated to another organisation.
- Confirm the Regional Entity responsible for oversight.
- Determine whether United States or Canadian rules apply.
- Link each scope decision to a registered function.
2. Identify Applicable Bulk Electric System Facilities
Apply the current NERC Bulk Electric System definition to each facility. Do not rely on voltage alone because the definition also contains specific inclusions and exclusions.
Review:
- Generation capacity
- Transmission configuration
- Interconnection arrangements
- Control centre responsibility
- Facility ownership
- Operating responsibility
- Approved exclusions
Document why each facility was included or excluded from scope. Review the decision whenever a facility is commissioned, retired, repurposed, transferred, or affected by operational changes.
3. Identify the BES Cyber Systems Supporting Those Functions
Identify the Cyber Assets that support each applicable reliability function. Group related assets into BES Cyber Systems based on the task they perform together. NERC uses this grouping to organise the application of CIP requirements.
Review shared systems as well as recovery services and remote access tools. Include vendor-managed or cloud-hosted systems when they support an in-scope function.
Compare operational and technical records to reduce the chance of missing relevant systems from the NERC CIP compliance scope.
4. Review Each Standard’s Applicability
Not every NERC CIP standard applies to every entity or system. Check each applicability statement against the registered function, facility, BES Cyber System, impact category, connectivity, and control centre role.
Record each decision in a simple matrix with the requirement, applicable system, reason, approver, and review date.
Keep current and future versions separate. NERC lists standards that are already enforceable alongside versions scheduled for later enforcement.
What Are BES Cyber Systems and Impact Categories?
BES Cyber Assets and BES Cyber Systems
A BES Cyber Asset is a programmable electronic device whose loss or misuse could affect reliable Bulk Electric System operation within the timeframe defined by NERC. Related assets may be grouped into a BES Cyber System when they work together to support the same reliability function.
Start with the operational task and its possible effect on grid reliability. Do not begin with an existing IT inventory.
Before finalising the asset list, approve a clear categorisation method that records:
- Reliability function
- Related facility and registered function
- System dependencies
- Inclusion or exclusion reason
- Approver
- Review date
- Events that trigger reassessment
Supporting and Associated Cyber Assets
Supporting systems may include electronic and physical access controls, Protected Cyber Assets, recovery tools, authentication services, monitoring platforms, time synchronisation systems, and remote access pathways.
These assets may fall within scope because they protect access or support the operation and recovery of BES Cyber Systems, even when they do not directly control a power system process.
Transient Cyber Assets and Removable Media
Maintenance laptops and vendor equipment can expose protected systems to malware or unapproved software. Removable media may also carry unsafe files.
Your procedures should cover authorisation and scanning. They should also define connection rules and individual responsibility. Keep records that show how each device or media item was handled. NERC addresses these controls under CIP 010.
High, Medium, and Low Impact BES Cyber Systems
CIP 002 categorises BES Cyber Systems according to the potential effect their loss or misuse could have on reliable Bulk Electric System operation. Systems that do not meet the high or medium criteria are treated as low impact.
| Impact Category | General Context | Compliance Effect | Common Scope Risk |
| High impact | Critical control centre functions with significant reliability consequences | Most prescriptive requirements | Missing shared or supporting systems |
| Medium impact | Specified generation, transmission, control centre, and connected systems | Broad personnel, technical, physical, and evidence controls | Incorrect facility or connectivity analysis |
| Low impact | Systems that do not meet high or medium impact criteria | Defined security plans and selected protection controls | Treating low impact systems as unregulated |
Current NERC CIP Standards and Their Status
| Standard | Main Purpose | Primary Evidence | Current or Transition Note |
CIP 002 |
Identify and categorise BES Cyber Systems | Methodology, facility analysis, asset lists, impact records, approvals | Establishes the scope for the remaining standards |
CIP 003 |
Set security governance and low impact plans | Policies, delegated authority, security plans, review records | Track enforceable and future versions separately |
CIP 004 |
Manage personnel risk and access | Training records, personnel assessments, approvals, revocation records | Applies to relevant employees, contractors, and vendor personnel |
CIP 005 |
Protect electronic access and remote connections | Network diagrams, access point lists, firewall rules, remote access logs | Review every external routable pathway |
CIP 006 |
Protect physical access to BES Cyber Systems | Physical security plans, badge records, visitor logs, alarm tests | Access should remain tied to an approved business need |
CIP 007 |
Manage system security | Port records, patch reviews, malware controls, accounts, security logs | Operational technology patch decisions require documented evaluation |
CIP 008 |
Prepare for cyber incidents and reporting | Response plans, exercises, notification decisions, review records | Future versions should be tracked without treating them as current duties |
CIP 009 |
Support recovery of BES Cyber Systems | Recovery plans, backups, restoration tests, exercise results | Evidence should show successful restoration rather than backup completion alone |
CIP 010 |
Control configuration changes and vulnerabilities | Baselines, change records, integrity checks, assessment results | Reviews should cover the complete applicable system population |
CIP 011 |
Protect BES Cyber System Information | Classification rules, access controls, transfer records, disposal records | Include third party and cloud repositories where applicable |
CIP 012 |
Protect communications between control centres | Communication paths, cryptographic controls, key records, exceptions | CIP 012 2 became effective in the United States on July 1, 2026 |
CIP 013 |
Manage supply chain cyber risk | Supplier reviews, contract records, access records, notifications | Controls should address the full supplier relationship |
CIP 014 |
Protect critical transmission facilities from physical threats | Risk assessments, third party verification, threat reviews, security plans | Reassessment may be needed after material facility changes |
CIP 015 |
Establish internal network security monitoring | Coverage maps, sensor design, monitoring use cases, alert records, retention settings | CIP 015 1 is approved but does not become effective until October 1, 2028 |
These standards work together rather than as separate compliance tasks. CIP 002 establishes the systems in scope. The remaining requirements apply governance and protection measures to that defined environment. Response and recovery duties complete the control cycle. Newer requirements extend coverage to communications and internal network activity.
How to Build a NERC CIP Compliance Programme

1. Create an Applicability Matrix
Turn your approved scope decisions into one applicability matrix. For each requirement, record the responsible function, facility, BES Cyber System, impact category, jurisdiction, decision rationale, approver, and review date.
Base every entry on the applicability wording in the relevant standard. Do not assume all CIP requirements apply across the organisation in the same way. Record unclear interpretations separately and seek formal guidance before final approval. NERC provides supporting resources, but the approved Reliability Standard remains the controlling source.
2. Build and Reconcile the Asset Inventory
Create one inventory using engineering drawings, discovery results, configuration databases, firewall records, identity platforms, procurement files, cloud inventories, and vendor records. Include shared services plus recovery systems and remote access infrastructure.
Do not remove unmatched assets without checking why the records differ.
Review the inventory after major changes such as:
- New generation or acquisitions
- Platform or topology changes
- Cloud migrations
- Vendor replacement
- Facility retirement
A reliable inventory supports the critical infrastructure protection standards by helping you detect unauthorised changes and maintain an accurate view of applicable systems. CIP 010 specifically addresses configuration change management and vulnerability assessment for BES Cyber Systems.
3. Categorise Systems and Obtain Formal Approval
Once the categorisation work is complete, send the results to operations, engineering, compliance, and cybersecurity for review. Record any challenge or revision made during this process.
Retain the final decision with its supporting rationale and approval date. The CIP Senior Manager should formally approve the identified and categorised BES Cyber Systems.
4. Map Requirements to Controls and Owners
Use a traceability model that follows this sequence:
Standard → Requirement → Procedure → Owner → System of record → Evidence → Reviewer → Exception → Corrective action
Assign a named role to every control instead of listing only a department. Keep the person who performs the task separate from the person who reviews it.
Use a RACI matrix when several teams share responsibility. This is useful for asset categorisation, vendor access, incident response, and BCSI handling.
The final mapping may involve HR, engineering, physical security, procurement, legal, compliance, IT, OT security, and vendor management. NERC audit worksheets expect entities to explain how each requirement is met and link that explanation to supporting evidence.
5. Create Procedures That Match Actual Operations
Write procedures around the way each task is performed. Define the trigger and applicable population. State the frequency and responsible person. Include the required input plus the expected result. Record where evidence is stored and how exceptions are escalated.
Test whether staff can follow the procedure during routine work as well as outages or emergencies. It should also remain usable when the usual control owner is absent.
Revise the document when systems or responsibilities change. Supplier replacements and network updates may also require a review. An old approval does not make an outdated procedure reliable.
6. Implement and Validate Controls
Align technical settings with approved procedures. Test each control across relevant systems and realistic operating conditions.
Check how identity tools interact with network controls and logging platforms. Vendor access and physical security processes should also work as intended. Record any limitation found during testing along with the measure used to address it.
7. Establish Evidence Collection
Decide how each control will generate evidence before it goes live. Use trusted systems of record instead of rebuilding documents when an audit begins.
Set rules for naming and storage. Assign ownership and retention periods. Add approval and quality checks where required.
Automation can reduce manual work, but the output still needs review. Confirm that timestamps are accurate and all applicable assets and users are covered. Any later change to the evidence should remain traceable.
8. Test Operating Effectiveness
Test controls across the full applicable population and review period. Select samples from different sites, systems, users, vendors, and dates. Reperform selected tasks and compare the results with independent records. NERC audit worksheets recognise sampling when reviewing every item is not practical.
Investigate conflicts such as:
- Terminated users with active access
- Retired systems left in firewall rules
- Vendor sessions without approved work orders
- Recovery exercises with no proof of restoration
Assign each finding a risk rating and owner. Set a due date and define what is required for closure.
9. Manage Exceptions and Potential Noncompliance
Create one process for missed deadlines, failed controls, incomplete evidence, unavailable systems, and procedural deviations.
Classify each issue correctly:
- Operational exception
- Security risk acceptance
- Technical Feasibility Exception
- Potential noncompliance
- Confirmed violation
A Technical Feasibility Exception follows a formal NERC process and cannot be treated as a general waiver.
Escalate suspected noncompliance through approved legal and compliance channels. Preserve the original records instead of recreating evidence after the issue is found. Close corrective actions only after an independent reviewer confirms that the problem has been resolved.
What Evidence Do NERC CIP Auditors Expect?
Audit teams look for records that connect the applicable requirement to the activity or system under review. NERC’s Evidence Request Tool first gathers programme information and applicable populations. Auditors may then request implementation evidence for selected samples.
The following examples show practical differences between limited records and more complete evidence. They are not official NERC evidence ratings.
| Evidence Type | Limited Evidence | Better Supported Evidence |
| Screenshot | Undated image with no asset details | Timestamped image linked to the system and approved ticket |
| Access review | Basic username list | Reconciled population showing ownership, business need, approval, exceptions, and revocation |
| Patch record | Vendor notice saved in a folder | Applicability review followed by testing, approval, installation, or a documented exception |
| Vulnerability assessment | Scan report with unclear coverage | Approved scope with exclusions, findings, remediation, and closure records |
| Training record | Employee attendance list | Complete employee, contractor, and vendor population with completion records |
| Recovery test | Successful backup result | Restoration test showing timing, dependencies, findings, and recovery outcome |
Common weaknesses include undated screenshots and spreadsheets with no clear source. Tickets without approval may also raise questions. The same applies to logs that cannot be connected to a specific asset. Records created only when an audit begins may not show how the control operated during the review period.
How NERC CIP Audits Work
The ERO Enterprise uses several methods to assess compliance with Reliability Standards. These include audits and spot checks. It may also use self-certifications, compliance investigations, self-reports, complaints, and periodic data submissions. Regional Entities conduct much of this work within their assigned areas.
A typical audit may involve:
- Confirming registration and applicable requirements
- Requesting policies plus inventories and operational records
- Selecting samples for closer review
- Interviewing control owners
- Testing selected activities
- Requesting further records where questions remain
- Sharing preliminary findings
- Reviewing the entity’s response
- Closing the review or referring concerns for enforcement
Where a standard allows an entity-defined process, auditors may check whether the organisation followed its own approved procedure.
Preparation should use the current CMEP Implementation Plan along with relevant Regional Entity guidance and audit worksheets. Existing operational records should support the review. Creating evidence after the fact may not show that a control worked during the required period.
NERC CIP Supply Chain Risk Management
CIP 013 requires applicable entities to assess and address cyber risks linked to vendors and supplied products or services. The current enforceable version is CIP 013 2. CIP 013 3 is scheduled for future enforcement.
Before Procurement
Check whether the product or service supports a BES Cyber System or enables remote access. Review software integrity and update methods. Consider data handling plus vulnerability disclosure, and future product support.
Contract Requirements
Define expectations for incident notices and security updates. Address vendor access approval and removal. Contracts may also cover personnel changes and corrective action. Include data disposal and subcontractor responsibilities where relevant to the risk.
Ongoing Vendor Monitoring
Review vendor accounts and remote sessions. Track security advisories as well as material product or service changes. Verify update integrity before deployment. Supplier incidents should enter the organisation’s incident response process.
Vendor Offboarding
Remove vendor accounts and access credentials when the service ends. Delete obsolete firewall rules and VPN profiles. Recover issued equipment where applicable. Update inventories after confirming that stored data has been returned or securely disposed of.
Preparing for CIP 015 Internal Network Security Monitoring
Perimeter controls mainly watch traffic crossing an Electronic Security Perimeter. They may not reveal harmful activity that continues inside the trusted network.
NERC CIP 015 introduces internal monitoring to improve the detection of anomalous or unauthorised network activity. It can help identify lateral movement and credential misuse. It may also expose unexpected protocols or command and control traffic. Unusual communication between assets can reveal compromised hosts or unauthorised connections.
CIP 015 1 is approved but remains subject to future enforcement.
Assess Existing Visibility
Identify the high-impact environments and medium-impact systems with External Routable Connectivity that fall within CIP 015 scope. Map critical systems and internal network segments. Include communication flows and remote access paths. Review encrypted traffic as well as proprietary protocols.
Compare this map with existing sensor coverage. Record any blind spots and explain whether current monitoring can detect anomalous activity across the relevant network.
Design the Monitoring Architecture
Choose collection methods that provide useful internal visibility without affecting operational systems. Passive monitoring may suit sensitive environments where active collection could create disruption.
Review:
- Network taps or SPAN ports
- Sensor placement and failover
- Time synchronisation
- Legacy and encrypted traffic
- Data retention and availability
Add enough asset context to connect network activity with the affected system. Test the design again after network changes or platform upgrades because earlier sensor coverage may no longer capture the required traffic.
Build Detection and Response Processes
Monitoring only adds value when alerts lead to a clear response. Develop use cases around realistic internal threats. Give each alert a severity level and a named owner.
Set rules for escalation and incident response. Review false positives so noisy detections can be adjusted without hiding genuine threats. Keep records of the alert review and the action taken. Coverage should also be checked after major system or network changes.
CIP 015 Transition Roadmap
Start by confirming which systems are affected and when the requirement takes effect. Compare current monitoring capabilities with the future standard to identify gaps.
Then:
- Assign owners for architecture and detection
- Design or procure the required capability
- Test it in a representative environment
- Check operational safety and monitoring coverage
- Update procedures and staff training
- Complete an internal readiness review
Keep implementation records throughout the transition. CIP 015 uses phased compliance dates, so timelines may differ between control centres and other applicable medium-impact environments.
NERC CIP Penalties and Enforcement
Violations may result in penalties and corrective action. They can also lead to closer regulatory review.
FERC may impose up to US$1 million per violation for each day it continues. This is the maximum penalty rather than the standard outcome. Enforcement decisions may consider:
- Risk to grid reliability
- Severity and duration
- Repeat violations
- Self reporting
- Cooperation
- Internal controls
- Remediation quality
Missing evidence may create a compliance issue when an organisation cannot prove that a required activity occurred. Suspected noncompliance should be escalated through approved legal and compliance channels.
How Qualysec Can Support NERC CIP Cybersecurity Efforts
Penetration testing cannot certify NERC CIP compliance or replace a regulatory assessment. Qualysec can support your wider security programme by testing approved systems for exploitable weaknesses.
Its manual and automated approach can assess external networks, web applications, APIs, cloud environments, and connected devices. External network penetration testing may cover internet-facing services and remote access gateways.
Operational technology testing requires strict scope controls to avoid disruption or safety concerns. Qualysec provides severity-based findings with reproduction steps and remediation guidance. Consultation and retesting can support corrective action after testing.
Conclusion
Effective NERC CIP compliance begins with an accurate scope. Your organisation must understand which facilities and systems are covered before applying the relevant requirements.
That scope cannot remain static. Changes to assets and operations may affect earlier decisions. Upcoming standard versions must also be tracked separately from requirements already in force.
A dependable programme relies on cooperation across technical and business teams. Regular reassessment helps ensure that your compliance approach continues to reflect the systems and responsibilities that exist today.
Discuss the approved systems and operational limits with Qualysec before planning an assessment. Talk with experts!
FAQs
1. What is the NERC CIP regulation?
NERC CIP is a set of cybersecurity and physical security standards for applicable Bulk Electric System entities. It covers system categorisation, access, incident response, recovery, and supply chain risk.
2. What are the NERC CIP criteria?
Applicability depends on the registered function, relevant facilities, BES Cyber Systems, impact category, and the wording of each standard.
3. Is NERC CIP mandatory?
Yes. FERC-approved standards are mandatory for applicable Bulk Electric System users, owners, and operators in the United States.
4. How do you comply with NERC CIP standards?
Identify the systems within scope. Determine which requirements apply. Assign owners, implement controls, retain evidence, and test whether those controls continue to work.
5. Who is responsible for NERC CIP compliance?
The registered entity remains responsible. Work may involve compliance, engineering, operations, cybersecurity, physical security, HR, procurement, and legal teams.
6. What are common NERC CIP violations?
Frequently reported issues include weak configuration change management, delayed access revocation, missed patch evaluations, poor system access controls, visitor control failures, and incomplete low-impact security plans.







