NERC CIP low impact obligations are far shorter than most entities assume, and that is the single most valuable thing to understand about them. If your assets contain only low impact BES Cyber Systems, you are in scope for CIP-002 and for CIP-003 Requirement R2 and its Attachment 1 — and substantially nothing else.
The expensive mistake is not under-doing it. It is importing the high and medium impact control set because it looks like good practice, and thereby creating evidence obligations you never had and cannot carry.
What this guide covers
- What NERC CIP low impact actually requires
- The seven NERC CIP low impact topics
- The 2026 change that leaves most NERC CIP low impact plans incomplete
- What the NERC CIP low impact vendor remote access controls require
- Getting the other six NERC CIP low impact topics proportionate
- Why NERC CIP low impact scoping pays for itself
- Mixed estates and NERC CIP low impact drift
- Evidencing a NERC CIP low impact programme
- Where NERC CIP low impact work goes next
- Frequently asked questions about NERC CIP low impact

What NERC CIP low impact actually requires
CIP-002 asks you to identify the assets containing low impact BES Cyber Systems. Note what that does not say: it does not require a discrete list of the systems themselves. Recording the assets is the obligation. Enumerating every device inside them is voluntary — and voluntary work here becomes an inventory you must keep accurate for the whole audit period.
CIP-003 R2 then requires you to implement the plans in Attachment 1. The cyber security policy for these assets must address seven topics, and that topic list is closed. Adding CIP-007 patch management or CIP-010 baselines to a low impact plan does not make it stronger; it makes it auditable against things the requirement never asked for.
The seven NERC CIP low impact topics
| Requirement part | Topic |
|---|---|
| CIP-003-9 R1.2.1 | Cyber security awareness |
| CIP-003-9 R1.2.2 | Physical security controls |
| CIP-003-9 R1.2.3 | Electronic access controls |
| CIP-003-9 R1.2.4 | Cyber Security Incident response |
| CIP-003-9 R1.2.5 | Transient Cyber Assets and Removable Media |
| CIP-003-9 R1.2.6 | Vendor electronic remote access security controls |
| CIP-003-9 R1.2.7 | Declaring and responding to CIP Exceptional Circumstances |
Seven topics, one policy, and a plan that implements them. That is the shape of a NERC CIP low impact programme.
The 2026 change that leaves most NERC CIP low impact plans incomplete
CIP-003-9 became enforceable on 1 April 2026, and what it added is R1.2.6 — vendor electronic remote access security controls.
That single addition is why a NERC CIP low impact plan written against the previous version is now incomplete. It will read as a finished document, cover six topics competently, and be silent on the seventh. Nothing about it signals the gap.
If you are carrying forward a plan from before April 2026, check that topic specifically. It is the most likely deficiency in any low impact programme in North America right now, and it is checkable in an afternoon.
What the NERC CIP low impact vendor remote access controls require
Three capabilities, per access path: determining that vendor electronic remote access is taking place, detecting it, and disabling it.
Detecting is the one usually absent, because remote access frequently runs over a vendor-supplied appliance the entity does not monitor. Disabling is the one usually untested — and a disable method nobody has ever exercised is a claim rather than a control. Test it in a maintenance window and record what happened, including how long it took and whether anything operational turned out to depend on the connection.
Where a low impact asset has no vendor remote access at all, record that explicitly with a date. An absence of rows is ambiguous; a statement is not.
Getting the other six NERC CIP low impact topics proportionate
Each topic has a proportionate answer, and the discipline is to give it that and stop.
Awareness means reinforcing cyber security practices at least once every 15 calendar months. It does not mean per-person training records or comprehension testing — those belong to CIP-004 and the high and medium impact path. Keep the material, not just the fact of sending it.
Physical security controls means controlling access. It does not import the CIP-006 Physical Security Perimeter construct, the visitor escort programme or the access log retention rules. For an unmanned site, say how access is controlled in the absence of anyone being there, because that is the case an auditor picks.
Electronic access controls means permitting only necessary inbound and outbound access, with the necessity documented. Outbound is the direction routinely left blank and the one that matters for data leaving a site. Record specific ports and services, not the name of a firewall rule.
Incident response means a plan proportionate to these assets, tested on the required cycle. A paper exercise is a permitted method and is usually the right choice.
Transient assets and removable media means mitigating malicious code risk before connection. A USB stick used once for a firmware update is in scope, and a scanning kiosk converts the weakest control into the strongest for the cost of a workstation.
CIP Exceptional Circumstances means a declared, recorded deviation under a process you wrote in advance. The declaration must precede or accompany the deviation — characterising something as an exceptional circumstance afterwards does not work, because the evidence an auditor asks for is the contemporaneous record.
Why NERC CIP low impact scoping pays for itself
Every control you adopt becomes evidence a Regional Entity can ask for, and which you must then produce for the whole audit period. That is the arithmetic behind keeping a low impact programme narrow.
A NERC CIP low impact entity that adopts quarterly access verification, baseline configuration management and 35-day patch evaluation has not become more secure in any way an auditor will credit. It has created three recurring obligations it did not have, each of which will eventually be missed, and each miss is now a finding against a control it volunteered for.
Do the seven topics well. Evidence them properly. That is a stronger position than a broad programme that is thinly evidenced.
Mixed estates and NERC CIP low impact drift
Many entities have both. Where you do, run both paths and keep them separate in the documentation, because the evidence sets are different and an auditor tests them separately.
The trap in a mixed estate is drift: a control designed for the high impact systems quietly gets applied to the low impact assets too, usually because the same team operates both. That is fine operationally and expensive at audit, because you have now represented that the control applies there. Decide deliberately which assets each control covers, and record the decision.
Evidencing a NERC CIP low impact programme
The evidence set is small, which means there is nowhere to hide a gap. Six artefacts carry it.
Keep a register of the assets identified under CIP-002 as containing low impact BES Cyber Systems, with the date each was identified. Alongside it, track which Attachment 1 topics apply to each asset — for most estates that is all seven, but recording it explicitly is what lets you show the scoping was decided rather than assumed.
Then, per topic: the awareness delivery record with the material itself and the computed next-due date; the physical control in force per asset; the electronic access record showing direction, port, service and the documented necessity; the incident response plan with its test record; the transient asset control applied before each connection; and the vendor remote access methods with the date each was last tested.
Two habits make the difference at audit. Record the negatives — “no vendor remote access at this asset, confirmed on this date” is stronger evidence than an empty table. And keep the whole NERC CIP low impact evidence set in one place rather than distributed across the teams that operate each control, because an auditor asks for it as a set and the assembly is where the gaps surface.
Where NERC CIP low impact work goes next
Read CIP-003 directly before designing anything — the NERC Reliability Standards are published free, and Attachment 1 is short enough to read in one sitting.
Start from the categorization, because low impact is a rating CIP-002 assigns rather than a status you elect. The thirteen enforceable standards show what the other ratings pull in, and the compliance guide covers the evidence discipline that applies to both paths.
When an audit comes, the preparation guide covers how the evidence is sampled, and CIP-015 is worth reading for the 2028 dates even though it will not reach most low impact estates.
Our NERC CIP Toolkit carries a dedicated low impact route — one document per Attachment 1 topic, written to be read on its own, plus an applicability workbook that tracks which topics apply to which assets.
A worked NERC CIP low impact example
Take a distribution utility with four substations identified under CIP-002 as containing low impact BES Cyber Systems, no high or medium impact systems anywhere, and one relay vendor who dials in twice a year.
Its entire obligation is CIP-002 and CIP-003 R2. There is no Electronic Security Perimeter to define, no baseline configuration to maintain, no 35-day patch evaluation clock, no quarterly access verification and no personnel risk assessment programme. That is not a loophole; it is what the requirement says.
What it does need is seven topics covered and evidenced. The awareness reinforcement, delivered and dated, with the material retained. The physical control at each of the four sites, which for unmanned substations means saying how access is controlled when nobody is there. The electronic access record showing what is permitted inbound and outbound and why. An incident response plan, tested by tabletop. A rule for the engineer laptop and any USB media before they touch a relay. The three vendor remote access capabilities, with the disable method tested rather than assumed. And a CIP Exceptional Circumstances process written before it is needed.
That is perhaps a dozen live records rather than several hundred. The failure mode for an entity this size is almost never insufficient control; it is a missed awareness cycle, or a vendor remote access topic that was never added when CIP-003-9 landed in April 2026, or a disable capability nobody has exercised.
Scope it that way and the programme is genuinely maintainable by one person alongside other duties. Scope it as though the high and medium impact set applied and it will not be maintained by anyone.
Frequently asked questions about NERC CIP low impact
Do NERC CIP low impact assets need an inventory of every system?
No. CIP-002 asks for the assets containing low impact BES Cyber Systems, not a list of the systems inside them. Building that list voluntarily creates an accuracy obligation you did not have.
What changed for low impact in 2026?
CIP-003-9 became enforceable on 1 April 2026 and added vendor electronic remote access security controls as a seventh Attachment 1 topic. Plans written before that date do not contain it.
How often must low impact awareness be delivered?
At least once every 15 calendar months. Compute the next due date from the last delivery rather than setting it to a fixed annual date.
Does a low impact entity need an Electronic Security Perimeter?
No. The Electronic Security Perimeter construct belongs to CIP-005 and the high and medium impact path. Low impact requires electronic access controls with documented necessity, which is a different and lighter obligation.