What is NERC CIP?
NERC CIP (Critical Infrastructure Protection) is the set of mandatory and enforceable cyber security and physical security standards that the North American Electric Reliability Corporation (NERC) imposes on every entity that owns or operates the bulk electric system in the United States and Canada. The standards run from CIP-002 to CIP-015 and cover, among other things, impact categorisation of systems, access control, network segmentation, patching, incident reporting and supply chain risk. Non-compliance can cost more than one and a half million dollars per violation per day. That makes NERC CIP one of the oldest and most strictly enforced OT security regimes in the world.
ποΈ How did NERC CIP come about?
The immediate trigger was the great blackout of 14 August 2003, which left around 50 million people in the north-eastern United States and Ontario without power. Until then, NERCβs reliability rules had been voluntary. The Energy Policy Act of 2005 added section 215 to the Federal Power Act, which made reliability standards legally enforceable.
| Year | Milestone |
|---|---|
| 2003 | The 14 August blackout exposes weaknesses in oversight and monitoring |
| 2006 | FERC certifies NERC as the Electric Reliability Organization on 20 July |
| 2008 | FERC Order No. 706 approves CIP-002-1 to CIP-009-1 (Version 1) |
| 2013 | FERC Order No. 791 approves CIP Version 5 with high, medium and low impact tiers |
| 2014 | CIP-014 on physical security of transmission stations, after the Metcalf substation attack |
| 2016 | CIP Version 5 becomes enforceable on 1 July |
| 2020 | CIP-013-1 on supply chain risk management takes effect on 1 October |
| 2025 | FERC Order No. 907 approves CIP-015-1 for internal network security monitoring |
| 2026 | FERC Order No. 919 approves the virtualisation revisions, effective 1 April 2028 |
The Federal Energy Regulatory Commission (FERC) approves the standards in the US; in Canada, approval happens province by province. NERC and six Regional Entities carry out audits and enforcement.
π§± Who and which systems does NERC CIP apply to?
NERC CIP applies to registered entities such as transmission owners and operators, balancing authorities, large generator owners and reliability coordinators. The object of protection is the BES Cyber System: a group of programmable devices whose loss or misuse could affect the reliability of the grid within 15 minutes. Think of SCADA servers in a control centre, protection relays in a substation and the control systems of power stations.
CIP-002 uses fixed criteria in its Attachment 1 to decide which category a system falls into:
- High impact β large control centres, for example those monitoring and controlling 3,000 MW or more of generation
- Medium impact β among others, generation of 1,500 MW or more at a single site, transmission at 500 kV or above, and smaller control centres
- Low impact β all other BES assets; only the baseline requirements of CIP-003 apply
This categorisation is the heart of the regime: the higher the impact, the more requirements apply. An entity that wrongly classifies medium impact systems as low therefore misses not one but dozens of requirements.
π§ Which CIP standards are there?
| Standard | Subject | Core requirements |
|---|---|---|
| CIP-002 | BES Cyber System Categorization | Inventory and classify as high, medium or low impact |
| CIP-003 | Security Management Controls | Policy, an accountable CIP Senior Manager, baseline controls for low impact |
| CIP-004 | Personnel and Training | Awareness, training, personnel risk assessment, access revocation |
| CIP-005 | Electronic Security Perimeter | Network perimeter around the systems, secure remote access with MFA |
| CIP-006 | Physical Security | Physical access control and visitor logging |
| CIP-007 | System Security Management | Ports and services, patching, malware prevention, logging, accounts |
| CIP-008 | Incident Reporting and Response Planning | Incident response plan and reporting to the E-ISAC and CISA |
| CIP-009 | Recovery Plans | Recovery plans, backups and periodic tests |
| CIP-010 | Configuration Change Management | Baselines, change control and vulnerability assessments |
| CIP-011 | Information Protection | Protection of sensitive BES information and secure media disposal |
| CIP-012 | Communications between Control Centers | Protection of real-time data exchanged between control centres |
| CIP-013 | Supply Chain Risk Management | Vendor risk in procurement processes |
| CIP-014 | Physical Security | Physical protection of critical transmission stations |
| CIP-015 | Internal Network Security Monitoring | Monitoring east-west traffic inside the CIP network |
The original CIP-001 on sabotage reporting was folded into EOP-004. Each standard carries a version number, such as CIP-007-6 or CIP-004-7, and NERC tracks which version is enforceable from which date.
π What has changed in NERC CIP recently?
Two developments stand out. The first is CIP-015, the standard for internal network security monitoring (INSM). FERC approved CIP-015-1 in June 2025 through Order No. 907. Control centres get 36 months and all other sites 60 months to comply. In the same order, FERC directed NERC to extend the scope to EACMS (systems that control electronic access, such as firewalls and authentication servers) and PACS (physical access control systems). The successor, CIP-015-2, passed its final industry ballot in March 2026 and was approved by FERC in August 2026.
The second is virtualisation. Until now, the standards were written around physical devices. With Order No. 919 of 19 March 2026, FERC approved eleven revised CIP standards plus four new defined terms such as Virtual Cyber Asset, Shared Cyber Infrastructure and Management Interface. Utilities can then use virtual machines and shared infrastructure without landing in a legal grey area. The new versions take effect on 1 April 2028.
π How is NERC CIP enforced?
NERC and the Regional Entities audit registered entities periodically. Violations are rated by risk and can lead to settlements, mitigation plans or penalties. The statutory maximum under section 316A of the Federal Power Act is adjusted for inflation every year and stood at USD 1,584,648 per violation per day in 2025. The best-known case is Duke Energy, which received a USD 10 million penalty in early 2019 for 127 violations committed between 2015 and 2018.
Typical intervals from the standards show how concrete NERC CIP is:
| Requirement | Typical interval |
|---|---|
| Evaluate new security patches (CIP-007) | At least every 35 calendar days |
| Repeat security training (CIP-004) | At least every 15 months |
| Repeat personnel risk assessment (CIP-004) | At least every 7 years |
| Revoke access on termination (CIP-004) | Within 24 hours |
| Vulnerability assessment (CIP-010) | Every 15 months; active test for high impact every 36 months |
| Test the recovery plan (CIP-009) | At least every 15 months |
πͺπΊ Why does NERC CIP matter to European organisations?
European utilities, manufacturers and service providers with subsidiaries or customers in the US and Canada deal with it directly. Suppliers of protection relays, SCADA software and network equipment feel it through the procurement requirements of CIP-013. NERC CIP is also a reference model: European regulators and grid operators draw on its experience when shaping their own rules.
| Feature | NERC CIP | IEC 62443 | NIS2 / Dutch Cybersecurity Act | Network Code on Cybersecurity |
|---|---|---|---|---|
| Type | Mandatory sector standard | Voluntary international series of standards | Law for essential and important entities | EU regulation (2024/1366) |
| Sector | Electricity, North America | All industrial automation | Eighteen sectors | Cross-border electricity flows |
| Approach | Prescriptive, concrete requirements and intervals | Risk-based with security levels | Risk-based, duty of care and reporting duty | Risk assessment at sector and entity level |
| Enforcement | Audits, penalties per violation per day | Certification, no statutory enforcement | National supervisors, fines up to EUR 10 million or 2% of worldwide annual turnover | National authorities; ENTSO-E and the EU DSO Entity develop methodologies |
The biggest difference is style. NERC CIP prescribes exactly what must be done and when, whereas NIS2 and the Dutch Cybersecurity Act impose a duty of care that you fill in yourself based on a risk assessment, for example following ISO 31000.
π οΈ What can you learn from NERC CIP?
- Start by categorising β as CIP-002 requires, build a complete inventory and classify systems by their impact on the primary process
- Draw a hard perimeter β put an electronic perimeter around critical systems and force remote access through an intermediate system such as a jump server, with MFA
- Make intervals measurable β a fixed cycle for patch evaluation and vulnerability assessment is easier to audit than βas soon as possibleβ
- Record baselines β configuration management with documented baselines makes unauthorised changes visible
- Rehearse recovery and response β test recovery plans and the incident response plan periodically, not just on paper
- Look inside β CIP-015 shows that perimeter security is not enough; also monitor traffic within the trusted zone
- Manage the chain β include security requirements in contracts, as CIP-013 requires for supply chain risk
β Frequently asked questions
Is NERC CIP mandatory?
Yes, NERC CIP is mandatory for all registered entities that own or operate the bulk electric system in the US, and in most Canadian provinces. FERC approved the first version in 2008, after which NERC CIP was phased in and became legally enforceable. Violations can lead to penalties of more than USD 1.5 million per violation per day.
What is the difference between high, medium and low impact in NERC CIP?
NERC CIP uses CIP-002 to categorise systems by their potential impact on the grid. High impact covers the largest control centres, medium impact covers among others large power stations and transmission at 500 kV or above, and low impact covers all other assets. The higher the category, the more NERC CIP requirements apply.
Does NERC CIP apply in Europe?
No, NERC CIP applies only to the North American grid in the US and Canada. European organisations do encounter it through North American subsidiaries, customers or procurement requirements. In Europe, NIS2, national laws such as the Dutch Cybersecurity Act and the Network Code on Cybersecurity play a comparable role.
What is CIP-015?
CIP-015 is the NERC CIP standard for Internal Network Security Monitoring, approved by FERC in 2025 through Order No. 907. It requires entities with high impact systems, and medium impact systems with External Routable Connectivity, to monitor traffic inside their trusted network zone, so that attackers who have already passed the perimeter are detected sooner. Its successor, CIP-015-2, approved by FERC in August 2026, extends monitoring to electronic and physical access control systems.
How does NERC CIP relate to IEC 62443?
NERC CIP is a mandatory, prescriptive standard for the North American electricity sector, whereas IEC 62443 is a voluntary, risk-based series of standards for all industrial automation. Many organisations use IEC 62443 to design zones and select components, and NERC CIP as their compliance framework. The two complement each other.
Does NERC CIP support virtualisation?
Explicitly, from 1 April 2028: that is when the virtualisation revisions of NERC CIP approved by FERC in March 2026 through Order No. 919 take effect. They introduce terms such as Virtual Cyber Asset and Shared Cyber Infrastructure. Until then, virtualisation under the older NERC CIP versions requires additional interpretation.
π In summary
Since 2008, NERC CIP has been the mandatory cyber security regime for the North American grid, with concrete requirements ranging from system categorisation to internal network monitoring and penalties per violation per day. Outside North America too, it is a useful example of how measurable intervals, hard perimeters and supply chain control better protect critical infrastructure.
