NERC CIP — the North American Electric Reliability Corporation's Critical Infrastructure Protection standards — is the mandatory cybersecurity framework for organizations that own or operate elements of the bulk electric system (BES) in North America. Non-compliance can result in fines of up to $1 million per violation per day. This guide explains what NERC CIP requires, who it applies to, and how to build a practical compliance program.
Who Must Comply with NERC CIP?
NERC CIP applies to "registered entities" — organizations that own or operate facilities that are part of the bulk electric system. This includes transmission owners and operators, generation owners and operators, distribution providers for certain facilities, and reliability coordinators. If your organization is registered with NERC or a regional reliability organization (such as WECC, SERC, RFC, or MRO), NERC CIP applies to you.
Critical assets are categorized as High, Medium, or Low impact based on their effect on the reliable operation of the bulk electric system. Higher-impact assets face more stringent requirements.
The Core NERC CIP Standards
CIP-002: BES Cyber System Categorization
The foundation of all NERC CIP work. Requires registered entities to identify and categorize all BES Cyber Systems as High, Medium, or Low impact. Everything else flows from this categorization — get it wrong and your entire compliance program is built on a faulty foundation.
CIP-003: Security Management Controls
Requires documented cybersecurity policies covering all NERC CIP requirements. Senior leadership must review and approve policies annually. CIP-003-8 added specific requirements for Low impact BES Cyber Systems, including electronic access controls and physical security.
CIP-004: Personnel and Training
Mandates personnel risk assessment (background checks) for anyone with authorized electronic or unescorted physical access to High and Medium impact BES Cyber Systems. Annual cybersecurity awareness training is required for all personnel, with role-specific training for those with operational access.
CIP-005: Electronic Security Perimeters
Requires defined Electronic Security Perimeters (ESPs) around High and Medium impact BES Cyber Systems. All electronic access points to the ESP must be identified and protected. Interactive Remote Access (IRA) — vendor or operator remote access to BES Cyber Systems — requires multi-factor authentication and encrypted communications.
CIP-006: Physical Security
Physical Security Plans must define physical security perimeters protecting High and Medium impact BES Cyber Systems. Access must be controlled, monitored, and logged. Visitor management and escorted access procedures are required.
CIP-007: Systems Security Management
One of the most technically intensive standards. Requirements include: ports and services management (disable all unnecessary listening ports), security patch management (35-day assessment cycle, 35-day remediation tracking), malicious code prevention, security event monitoring, and system access control (password management, account management).
CIP-008: Incident Reporting and Response Planning
Documented Cyber Security Incident Response Plans are required, with at least annual tabletop exercises. Reportable Cyber Security Incidents must be reported to E-ISAC and ICS-CERT within specified timeframes.
CIP-009: Recovery Plans
Recovery plans for BES Cyber Systems must be documented, exercised annually, and updated after incidents or significant changes. Backup and restoration capabilities must be tested.
CIP-010: Configuration Change Management and Vulnerability Management
Baseline configurations must be documented for all High and Medium impact BES Cyber Systems. All changes must be assessed against the baseline. Vulnerability assessments are required at least every 15 months for High impact systems.
CIP-011: Information Protection
BES Cyber System Information (BCSI) — documentation, configurations, network diagrams — must be protected from unauthorized access, both in storage and in transit. Disposal procedures must prevent data recovery from decommissioned media.
CIP-013: Supply Chain Risk Management
One of the newer standards (effective 2020), CIP-013 requires a documented supply chain cybersecurity risk management plan addressing software integrity and authenticity verification, vendor remote access controls, and notification procedures for vendor-identified vulnerabilities in applicable products.
Building a Practical NERC CIP Compliance Program
Successful NERC CIP compliance programs share common characteristics: executive sponsorship with dedicated budget, clear ownership of each standard mapped to specific roles, a robust evidence management system for audit documentation, and integration of compliance into change management and procurement processes — not treated as a separate activity.
The most common compliance gaps found during NERC audits are: outdated asset inventories that miss new BES Cyber Systems, patch management processes that can't demonstrate 35-day assessment compliance, and inadequate evidence for personnel training and access management requirements.
NERC CIP Training and Tools at SCADA.Store
Browse our NERC CIP compliance training resources including NERC CIP standards courseware, evidence management tools, and audit preparation guides. Pair training with the right cybersecurity technology — including patch management solutions, security monitoring platforms, and secure remote access tools — to build a defensible, audit-ready compliance program.