Standards & Codes

NERC CIP Standards Overview: What CIP-002 Through CIP-014 Actually Cover, Explained

Published: July 24, 2026 American Power Engineers Team Power Engineering Resource

If you own, operate or are interconnecting an asset to the Bulk Electric System, “NERC CIP” is a term that shows up long before anyone hands you a clear explanation of what it actually requires. It appears in interconnection agreements, in your Regional Entity registration paperwork, and eventually in an audit notice that asks for evidence you didn’t know you needed to keep.

The confusion is understandable. NERC CIP isn’t one standard; it’s a family of thirteen interlocking standards, each covering a different layer of cybersecurity and physical security for the grid, and they don’t apply the same way to every entity. A distribution-level generator, a transmission owner, and a control center operator can all be “subject to NERC CIP” while facing completely different obligations.

This guide walks through what CIP-002 through CIP-014 actually cover, in plain terms, so you know which standards apply to your facility, where compliance programs typically break down, and what to check first.

What Is NERC CIP, in One Sentence?

NERC CIP (Critical Infrastructure Protection) is the set of mandatory, FERC-enforceable reliability standards that require registered entities to identify, categorize, and protect the cyber systems and physical assets that keep the Bulk Electric System (BES) operating reliably.

It’s important to separate this from NERC’s Operations and Planning (O&P) standards. CIP standards protect against cyber and physical security threats access control, system hardening, incident response, physical perimeter security. 

Need Engineering Support for Your Power Project?

American Power Engineers delivers power system studies, substation design, renewable energy engineering, BESS projects, NERC compliance, MEP engineering, and POI interconnection services.

Explore Our Engineering Services

O&P standards (facility ratings, protection coordination, dynamic modeling) protect against physical and operational reliability failures. Many entities are subject to both, but they are audited separately, by different teams, against different evidence.

For a full breakdown of the O&P side, see our NERC 693 O&P compliance overview.

Need Engineering Support for Your NERC Compliance Program?

American Power Engineers delivers NERC compliance gap analysis, documentation support, and audit-readiness services for developers, owners, and operators across North America.

Explore Our NERC O&P 693 Compliance Services

Why Everything Starts With CIP-002

Every other CIP standard in the family depends on a categorization decision made under CIP-002, BES Cyber System Categorization. This is the standard that requires entities to inventory their BES Cyber Systems and assign each one an impact rating of high, medium, or low, using bright-line criteria (control center function, facility size, connectivity, and reliability impact).

That rating is what determines which of the remaining CIP requirements apply to a given system. Get the categorization wrong or fail to keep it current as facilities change and every downstream compliance decision inherits that error. 

Planning a Solar, Wind, BESS, or Grid Interconnection Project?

Our engineering team helps project owners, developers, utilities, and facility teams move from technical planning to reliable project execution.

View Engineering Services

NERC has also adopted an updated version of CIP-002 that introduces a more quantified scoring method for control centers, so entities previously sitting comfortably in “low impact” should confirm that classification still holds before it changes their obligations without warning.

CIP-002 Through CIP-014: What Each Standard Actually Covers

CIP-002 — BES Cyber System Categorization

Identifies and classifies BES Cyber Systems as high, medium, or low impact. This is the scoping foundation for the entire CIP framework and must be reviewed on a recurring cycle, not filed once and forgotten.

CIP-003 — Security Management Controls

Requires a documented cybersecurity policy, a named CIP Senior Manager accountable for compliance and for low-impact assets — specific controls around vendor remote access, transient electronic devices (USB drives, laptops), and declared cyber security exceptional circumstances.

CIP-004 — Personnel and Training

Covers personnel risk assessments, cybersecurity training, and access management for anyone with authorized electronic or physical access to BES Cyber Systems, including timely revocation when someone changes roles or leaves the organization.

CIP-005 — Electronic Security Perimeter(s)

Requires defined Electronic Security Perimeters (ESPs) around high- and medium-impact BES Cyber Systems, with controlled access points and specific requirements for interactive remote access — an area under increasing scrutiny as remote connectivity and third-party vendor access expand.

CIP-006 — Physical Security of BES Cyber Systems

Requires a physical security plan for the physical access points into the ESP itself badge systems, monitoring, and visitor logging around the facilities housing high- and medium-impact cyber systems.

CIP-007 — System Security Management

Covers the technical hardening of individual systems: patch management, disabling unnecessary ports and services, malicious code prevention, security event monitoring, and account/access management at the system level.

CIP-008 — Incident Reporting and Response Planning

Requires a documented incident response plan, testing of that plan, and mandatory reporting of qualifying Cyber Security Incidents (including attempts) to the E-ISAC within defined timeframes.

CIP-009 — Recovery Plans for BES Cyber Systems

Requires recovery plans for BES Cyber Systems, including backup and restoration procedures and periodic testing to confirm the plans actually work when needed.

CIP-010 — Configuration Change Management and Vulnerability Assessments

Requires a documented baseline configuration for BES Cyber Systems, a change management process for any deviation from that baseline, and periodic vulnerability assessments to catch drift before it becomes an exposure.

CIP-011 — Information Protection

Covers the identification and protection of BES Cyber System Information the data itself, not just the systems including secure handling and sanitization when hardware is reused or retired.

CIP-012 — Communications Between Control Centers

Requires protection of sensitive Real-time Assessment and Real-time monitoring data communicated between Control Centers, closing a gap that earlier standards didn’t fully address.

CIP-013 — Supply Chain Risk Management

Requires a documented supply chain cybersecurity risk management plan covering vendor risk assessment, procurement controls, and how software integrity and authenticity are verified before deployment one of the fastest-evolving areas of CIP given how much control system hardware and software is vendor-supplied.

CIP-014 — Physical Security

Requires risk assessments of transmission stations and substations to identify facilities whose loss, damage, or misuse could result in widespread instability, and requires a physical security plan and third-party verification for facilities identified as critical. 

CIP-014 exists largely because of real, physical attacks on grid infrastructure most notably the 2013 Metcalf substation shooting in California and later incidents in Moore County, North Carolina and the Pacific Northwest that made clear grid risk isn’t limited to cyberspace.

A Note on What Comes Next: CIP-015

The CIP framework hasn’t stopped at CIP-014. CIP-015 (Internal Network Security Monitoring) has been developed to address monitoring inside the ESP, not just at its perimeter recognizing that a well-defended perimeter isn’t enough if there’s no visibility into what’s happening once someone (or something) is already inside it. If your facility is approaching medium- or high-impact status, this is worth tracking even though it sits just outside the CIP-002–014 range this guide focuses on.

Planning a Project That Will Cross These Thresholds?

Whether you’re developing a new BESS, solar, or wind project or managing an operating fleet approaching a higher impact rating, getting the categorization and compliance scope right early avoids costly rework later.

View Engineering Services

Common Problems With NERC CIP Compliance And How to Solve Them

Problem: The impact categorization was never formally reviewed after the facility changed.

Equipment upgrades, added connectivity, or a change in control center function can shift a system from low to medium impact without anyone updating the CIP-002 categorization. Solve it by tying your categorization review to your equipment change management process, not just the calendar deadline.

Problem: “Low impact” is treated as “low effort.”

Low-impact BES Cyber Systems still carry real obligations under CIP-003, including cybersecurity plans, vendor remote access controls, and transient device policies. Entities that treat low impact as “exempt” are consistently surprised by audit findings here.

Problem: Evidence exists, but it’s scattered.

CIP audits can request evidence spanning multiple years, across dozens of individual requirements. If patch records, training logs, and access reviews live in separate inboxes and spreadsheets, reconstructing a defensible record under audit pressure is where entities lose the most time. 

Our step-by-step NERC audit readiness checklist walks through how to build this before the audit notice arrives, not after.

Problem: Physical and cyber security are managed as separate silos.

CIP-006 and CIP-014 both deal with physical security, but at different scopes access control around the ESP versus risk assessment of entire transmission stations. Facilities that assign these to disconnected teams often miss the overlap between the two.

Problem: Regional interconnection requirements get treated as generic.

CIP compliance obligations layer on top of the specific interconnection and operational requirements of your ISO or RTO footprint. A facility interconnecting in ERCOT, for example, carries different registration and coordination expectations than one in PJM or MISO. 

See our ERCOT interconnection services for how we align interconnection-stage engineering with downstream compliance obligations from the start.

Building a NERC CIP Compliance Program That Holds Up

A durable program generally includes:

  1. A living asset inventory — every BES Cyber System identified, categorized under CIP-002, and reviewed on schedule.
  2. Documented policies and ownership — a named CIP Senior Manager and current policies satisfying CIP-003.
  3. Layered technical controls — ESPs, system hardening, patch and configuration management mapped to CIP-005, CIP-007, and CIP-010.
  4. Incident and recovery readiness — tested plans under CIP-008 and CIP-009, not just written ones.
  5. Supply chain and information protection controls — vendor risk management under CIP-013 and data handling under CIP-011.
  6. Physical security assessment — CIP-006 for perimeter access and CIP-014 risk assessments for critical transmission facilities.
  7. A centralized evidence repository — built continuously, so an audit request doesn’t trigger a scramble.

Entities that build these habits into normal operations rather than reconstructing them right before an audit consistently spend less on remediation and face fewer surprises when the Regional Entity comes calling.

How American Power Engineers Supports NERC Compliance

American Power Engineers helps developers, owners and operators connect the engineering side of compliance facility documentation, interconnection studies and technical evidence to a defensible NERC compliance program. Our support includes:

  • Compliance scoping and applicability review across CIP and O&P standards
  • Documentation and evidence-package support for audit readiness
  • Coordination between interconnection engineering and compliance obligations
  • Support across PJM, MISO, ERCOT, CAISO, NYISO, ISO-NE, SPP, and WECC footprints

For the full scope of our program, visit our NERC O&P 693 Compliance Services page.

FAQs

How many NERC CIP standards are there?

The CIP framework currently spans CIP-002 through CIP-014, with CIP-015 (Internal Network Security Monitoring) developed as a newer addition. Each standard contains multiple individual requirements, and not every requirement applies to every entity applicability depends on your impact categorization under CIP-002.

What’s the difference between NERC CIP and NERC O&P (693) standards?

NERC CIP governs cybersecurity and physical security of critical infrastructure. NERC O&P standards (often shorthanded as “NERC 693”) govern the physical and operational reliability of generation and transmission facilities — facility ratings, protection coordination, and dynamic modeling. Many entities are subject to both, but they’re audited separately with different evidence requirements.

Do low-impact facilities have to comply with NERC CIP?

Yes. Low-impact BES Cyber Systems are still subject to CIP-003 requirements, including a documented cybersecurity plan, vendor electronic remote access controls, and transient device policies. Low impact reduces the scope of controls required it doesn’t eliminate the obligation.

What is a BES Cyber System?

A BES Cyber System is a grouping of one or more BES Cyber Assets whose loss, degradation, or misuse could adversely affect the reliable operation of the Bulk Electric System within a defined time period. Determining what belongs in a given BES Cyber System, and drawing defensible boundaries around it, is one of the more difficult judgment calls under CIP-002.

How often does CIP-002 categorization need to be reviewed?

Categorization and its approval by the CIP Senior Manager (or delegate) must be reviewed on a recurring cycle commonly at least every 15 calendar months and revisited any time facility characteristics, connectivity, or function change in a way that could shift the impact rating.

What actually triggered CIP-014’s physical security requirements?

CIP-014 exists largely in response to real physical attacks on substations, most notably the 2013 Metcalf substation shooting in California, which caused significant equipment damage without any cyber intrusion at all. Later incidents, including a 2022 attack in Moore County, North Carolina, reinforced why physical security risk assessments remain a mandatory, ongoing requirement rather than a one-time exercise.

Can NERC CIP compliance be outsourced?

Technical work documentation, gap assessments, and evidence packages can be supported by outside engineering and compliance expertise. The underlying compliance obligation and program ownership remain with the registered entity, which is why most organizations pair external technical support with an internal compliance lead.

Work With American Power Engineers

Expert engineering support for power system studies, substation design, renewable energy projects, BESS engineering, NERC compliance, MEP engineering, and interconnection services.

Request a Proposal

Related Services:

Related Reading:

Work With American Power Engineers

Expert engineering support for power system studies, substation design, renewable energy projects, BESS engineering, NERC compliance, MEP engineering, and POI interconnection services.

Explore All Engineering Services