What is NERC CIP?

NERC CIP (Critical Infrastructure Protection) is the set of mandatory and enforceable cyber security and physical security standards that the North American Electric Reliability Corporation (NERC) imposes on every entity that owns or operates the bulk electric system in the United States and Canada. The standards run from CIP-002 to CIP-015 and cover, among other things, impact categorisation of systems, access control, network segmentation, patching, incident reporting and supply chain risk. Non-compliance can cost more than one and a half million dollars per violation per day. That makes NERC CIP one of the oldest and most strictly enforced OT security regimes in the world.


πŸ—“οΈ How did NERC CIP come about?

The immediate trigger was the great blackout of 14 August 2003, which left around 50 million people in the north-eastern United States and Ontario without power. Until then, NERC’s reliability rules had been voluntary. The Energy Policy Act of 2005 added section 215 to the Federal Power Act, which made reliability standards legally enforceable.

Year Milestone
2003 The 14 August blackout exposes weaknesses in oversight and monitoring
2006 FERC certifies NERC as the Electric Reliability Organization on 20 July
2008 FERC Order No. 706 approves CIP-002-1 to CIP-009-1 (Version 1)
2013 FERC Order No. 791 approves CIP Version 5 with high, medium and low impact tiers
2014 CIP-014 on physical security of transmission stations, after the Metcalf substation attack
2016 CIP Version 5 becomes enforceable on 1 July
2020 CIP-013-1 on supply chain risk management takes effect on 1 October
2025 FERC Order No. 907 approves CIP-015-1 for internal network security monitoring
2026 FERC Order No. 919 approves the virtualisation revisions, effective 1 April 2028

The Federal Energy Regulatory Commission (FERC) approves the standards in the US; in Canada, approval happens province by province. NERC and six Regional Entities carry out audits and enforcement.


🧱 Who and which systems does NERC CIP apply to?

NERC CIP applies to registered entities such as transmission owners and operators, balancing authorities, large generator owners and reliability coordinators. The object of protection is the BES Cyber System: a group of programmable devices whose loss or misuse could affect the reliability of the grid within 15 minutes. Think of SCADA servers in a control centre, protection relays in a substation and the control systems of power stations.

CIP-002 uses fixed criteria in its Attachment 1 to decide which category a system falls into:

  • High impact β€” large control centres, for example those monitoring and controlling 3,000 MW or more of generation
  • Medium impact β€” among others, generation of 1,500 MW or more at a single site, transmission at 500 kV or above, and smaller control centres
  • Low impact β€” all other BES assets; only the baseline requirements of CIP-003 apply

This categorisation is the heart of the regime: the higher the impact, the more requirements apply. An entity that wrongly classifies medium impact systems as low therefore misses not one but dozens of requirements.


πŸ”§ Which CIP standards are there?

Standard Subject Core requirements
CIP-002 BES Cyber System Categorization Inventory and classify as high, medium or low impact
CIP-003 Security Management Controls Policy, an accountable CIP Senior Manager, baseline controls for low impact
CIP-004 Personnel and Training Awareness, training, personnel risk assessment, access revocation
CIP-005 Electronic Security Perimeter Network perimeter around the systems, secure remote access with MFA
CIP-006 Physical Security Physical access control and visitor logging
CIP-007 System Security Management Ports and services, patching, malware prevention, logging, accounts
CIP-008 Incident Reporting and Response Planning Incident response plan and reporting to the E-ISAC and CISA
CIP-009 Recovery Plans Recovery plans, backups and periodic tests
CIP-010 Configuration Change Management Baselines, change control and vulnerability assessments
CIP-011 Information Protection Protection of sensitive BES information and secure media disposal
CIP-012 Communications between Control Centers Protection of real-time data exchanged between control centres
CIP-013 Supply Chain Risk Management Vendor risk in procurement processes
CIP-014 Physical Security Physical protection of critical transmission stations
CIP-015 Internal Network Security Monitoring Monitoring east-west traffic inside the CIP network

The original CIP-001 on sabotage reporting was folded into EOP-004. Each standard carries a version number, such as CIP-007-6 or CIP-004-7, and NERC tracks which version is enforceable from which date.


πŸ”„ What has changed in NERC CIP recently?

Two developments stand out. The first is CIP-015, the standard for internal network security monitoring (INSM). FERC approved CIP-015-1 in June 2025 through Order No. 907. Control centres get 36 months and all other sites 60 months to comply. In the same order, FERC directed NERC to extend the scope to EACMS (systems that control electronic access, such as firewalls and authentication servers) and PACS (physical access control systems). The successor, CIP-015-2, passed its final industry ballot in March 2026 and was approved by FERC in August 2026.

The second is virtualisation. Until now, the standards were written around physical devices. With Order No. 919 of 19 March 2026, FERC approved eleven revised CIP standards plus four new defined terms such as Virtual Cyber Asset, Shared Cyber Infrastructure and Management Interface. Utilities can then use virtual machines and shared infrastructure without landing in a legal grey area. The new versions take effect on 1 April 2028.


πŸ” How is NERC CIP enforced?

NERC and the Regional Entities audit registered entities periodically. Violations are rated by risk and can lead to settlements, mitigation plans or penalties. The statutory maximum under section 316A of the Federal Power Act is adjusted for inflation every year and stood at USD 1,584,648 per violation per day in 2025. The best-known case is Duke Energy, which received a USD 10 million penalty in early 2019 for 127 violations committed between 2015 and 2018.

Typical intervals from the standards show how concrete NERC CIP is:

Requirement Typical interval
Evaluate new security patches (CIP-007) At least every 35 calendar days
Repeat security training (CIP-004) At least every 15 months
Repeat personnel risk assessment (CIP-004) At least every 7 years
Revoke access on termination (CIP-004) Within 24 hours
Vulnerability assessment (CIP-010) Every 15 months; active test for high impact every 36 months
Test the recovery plan (CIP-009) At least every 15 months

πŸ‡ͺπŸ‡Ί Why does NERC CIP matter to European organisations?

European utilities, manufacturers and service providers with subsidiaries or customers in the US and Canada deal with it directly. Suppliers of protection relays, SCADA software and network equipment feel it through the procurement requirements of CIP-013. NERC CIP is also a reference model: European regulators and grid operators draw on its experience when shaping their own rules.

Feature NERC CIP IEC 62443 NIS2 / Dutch Cybersecurity Act Network Code on Cybersecurity
Type Mandatory sector standard Voluntary international series of standards Law for essential and important entities EU regulation (2024/1366)
Sector Electricity, North America All industrial automation Eighteen sectors Cross-border electricity flows
Approach Prescriptive, concrete requirements and intervals Risk-based with security levels Risk-based, duty of care and reporting duty Risk assessment at sector and entity level
Enforcement Audits, penalties per violation per day Certification, no statutory enforcement National supervisors, fines up to EUR 10 million or 2% of worldwide annual turnover National authorities; ENTSO-E and the EU DSO Entity develop methodologies

The biggest difference is style. NERC CIP prescribes exactly what must be done and when, whereas NIS2 and the Dutch Cybersecurity Act impose a duty of care that you fill in yourself based on a risk assessment, for example following ISO 31000.


πŸ› οΈ What can you learn from NERC CIP?

  1. Start by categorising β€” as CIP-002 requires, build a complete inventory and classify systems by their impact on the primary process
  2. Draw a hard perimeter β€” put an electronic perimeter around critical systems and force remote access through an intermediate system such as a jump server, with MFA
  3. Make intervals measurable β€” a fixed cycle for patch evaluation and vulnerability assessment is easier to audit than β€œas soon as possible”
  4. Record baselines β€” configuration management with documented baselines makes unauthorised changes visible
  5. Rehearse recovery and response β€” test recovery plans and the incident response plan periodically, not just on paper
  6. Look inside β€” CIP-015 shows that perimeter security is not enough; also monitor traffic within the trusted zone
  7. Manage the chain β€” include security requirements in contracts, as CIP-013 requires for supply chain risk

❓ Frequently asked questions

Is NERC CIP mandatory?

Yes, NERC CIP is mandatory for all registered entities that own or operate the bulk electric system in the US, and in most Canadian provinces. FERC approved the first version in 2008, after which NERC CIP was phased in and became legally enforceable. Violations can lead to penalties of more than USD 1.5 million per violation per day.

What is the difference between high, medium and low impact in NERC CIP?

NERC CIP uses CIP-002 to categorise systems by their potential impact on the grid. High impact covers the largest control centres, medium impact covers among others large power stations and transmission at 500 kV or above, and low impact covers all other assets. The higher the category, the more NERC CIP requirements apply.

Does NERC CIP apply in Europe?

No, NERC CIP applies only to the North American grid in the US and Canada. European organisations do encounter it through North American subsidiaries, customers or procurement requirements. In Europe, NIS2, national laws such as the Dutch Cybersecurity Act and the Network Code on Cybersecurity play a comparable role.

What is CIP-015?

CIP-015 is the NERC CIP standard for Internal Network Security Monitoring, approved by FERC in 2025 through Order No. 907. It requires entities with high impact systems, and medium impact systems with External Routable Connectivity, to monitor traffic inside their trusted network zone, so that attackers who have already passed the perimeter are detected sooner. Its successor, CIP-015-2, approved by FERC in August 2026, extends monitoring to electronic and physical access control systems.

How does NERC CIP relate to IEC 62443?

NERC CIP is a mandatory, prescriptive standard for the North American electricity sector, whereas IEC 62443 is a voluntary, risk-based series of standards for all industrial automation. Many organisations use IEC 62443 to design zones and select components, and NERC CIP as their compliance framework. The two complement each other.

Does NERC CIP support virtualisation?

Explicitly, from 1 April 2028: that is when the virtualisation revisions of NERC CIP approved by FERC in March 2026 through Order No. 919 take effect. They introduce terms such as Virtual Cyber Asset and Shared Cyber Infrastructure. Until then, virtualisation under the older NERC CIP versions requires additional interpretation.


πŸ“Œ In summary

Since 2008, NERC CIP has been the mandatory cyber security regime for the North American grid, with concrete requirements ranging from system categorisation to internal network monitoring and penalties per violation per day. Outside North America too, it is a useful example of how measurable intervals, hard perimeters and supply chain control better protect critical infrastructure.