NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Protection) is a mandatory set of cybersecurity standards for the bulk electric system in North America. If you work in power generation, transmission, or utilities, NERC CIP compliance is not optional — it carries financial penalties up to $1 million per violation per day.
Who Must Comply with NERC CIP?
Any entity that owns, operates, or uses Bulk Electric System (BES) assets must comply. Covered entities include:
- Generation plants (1,500 MW or more at a single location)
- Transmission substations operating at 200 kV or higher
- Control centres that operate BES assets
- Reliability Coordinators, Balancing Authorities, and Transmission Operators
Note that distribution systems and facilities below the BES threshold are generally exempt, though NERC periodically revises thresholds. If you are unsure whether your facility is covered, review the current NERC BES Definition document and consult your Regional Entity.
The CIP Standards: What They Cover
NERC CIP is a family of standards, each addressing a different security domain. The active standards you need to know are:
- CIP-002: BES Cyber System Categorization. Requires you to identify and classify your BES Cyber Systems as High, Medium, or Low impact based on their role in grid reliability.
- CIP-003: Security Management Controls. Establishes security management plans, policies, and leadership accountability.
- CIP-004: Personnel and Training. Covers background checks, security awareness training, and access authorisation procedures for all personnel with electronic or physical access to High and Medium impact systems.
- CIP-005: Electronic Security Perimeters (ESP). Requires defining and protecting the Electronic Security Perimeters around BES Cyber Systems, including controls on all Interactive Remote Access.
- CIP-006: Physical Security of BES Cyber Systems. Governs physical access controls, visitor logging, and monitoring of Physical Security Perimeters.
- CIP-007: Systems Security Management. Covers patch management, port and service management, security event monitoring, and malicious code prevention for BES Cyber Systems.
- CIP-008: Incident Reporting and Response Planning. Requires an incident response plan, testing of that plan, and mandatory reporting of Cyber Security Incidents to E-ISAC and NERC.
- CIP-009: Recovery Plans for BES Cyber Systems. Establishes recovery plans, backup and restore procedures, and plan testing requirements.
- CIP-010: Configuration Change Management and Vulnerability Assessments. Requires baselining system configurations and managing changes to prevent unauthorised modification.
- CIP-011: Information Protection. Governs the handling, storage, and disposal of BES Cyber System Information.
- CIP-013: Supply Chain Risk Management. Addresses cybersecurity risks introduced through hardware, software, and services from vendors.
- CIP-014: Physical Security. Addresses physical security of Transmission stations and substations that, if damaged, could have significant impact on the bulk electric system.
Impact Levels: What Changes for High vs Medium vs Low
NERC CIP requirements scale with the impact classification of your BES Cyber Systems:
- High Impact: The most stringent requirements. Applies to control centres with operational or backup control of generation or transmission. Requires all controls in CIP-004 through CIP-011, including full Interactive Remote Access (IRA) controls with multi-factor authentication.
- Medium Impact: Applies to generation facilities above threshold and major transmission substations. Requires most controls but with some exceptions — for example, IRA controls are required but certain monitoring requirements have reduced scope.
- Low Impact: The largest number of assets fall here. Low impact assets require a documented cybersecurity policy (CIP-003 Attachment 1) covering physical security, electronic access controls, and incident response, but are not subject to the full rigour of High/Medium requirements.
Common Compliance Challenges for OT Engineers
In practice, OT engineers encounter four recurring NERC CIP challenges:
- Patch management on legacy systems: CIP-007 requires patches to be applied within 35 days of release for High and Medium assets, or documented as a risk exception if the patch is unavailable, breaks operation, or cannot be tested in time. Many process control workstations run Windows versions no longer receiving security patches, requiring formal exception documentation and compensating controls.
- Remote access controls: CIP-005 requires that all Interactive Remote Access sessions use encrypted communications and multi-factor authentication (MFA) for High and Medium assets. Implementing MFA on legacy SCADA systems that do not support it natively requires jump servers or VPN gateways that satisfy the standard.
- Vendor access: CIP-013 requires assessing cybersecurity risk from vendors throughout the supply chain. This means reviewing software integrity, verifying vendor incident response capabilities, and having processes to respond if a vendor notifies you of a vulnerability in a product you use.
- Change management: CIP-010 requires maintaining a baseline configuration for all BES Cyber Systems and documenting every change before it is made. For operations teams accustomed to making quick configuration changes during an outage, this cultural shift is often the hardest part of compliance.
Audit and Enforcement
NERC delegates audit and enforcement to Regional Entities (REs) such as ReliabilityFirst, SERC, WECC, and others. Audits are typically conducted on a three-year cycle for High and Medium impact entities. Auditors review policies, procedure documentation, evidence logs, and may interview personnel.
Penalties for violations are not theoretical. NERC and FERC have levied multi-million dollar fines against utilities for CIP violations. The most common findings in audits are insufficient patch management documentation, gaps in access authorisation reviews, and missing evidence of plan testing.
Getting Started with NERC CIP Compliance
If you are beginning a NERC CIP compliance programme, start with these steps:
- Complete a BES Cyber System inventory and impact categorisation under CIP-002
- Identify all Electronic Security Perimeters and document network diagrams showing all connections into the ESP
- Establish a patch management programme with documented exception procedures
- Implement access authorisation reviews on a quarterly or annual basis as required
- Build an evidence retention programme — NERC requires retaining compliance evidence for three years
NERC CIP compliance is ongoing work, not a one-time project. OT engineers who understand the standards deeply — not just as a compliance checkbox but as a security framework — are among the most valuable professionals in the power sector today.


