BES Cyber System categorization is the first thing you do under NERC CIP and the thing everything else inherits. CIP-002 decides which of your cyber systems are in scope at all and sorts them into high, medium and low impact — and that rating determines which requirements in the other twelve standards reach them.
Get it wrong and nothing downstream can save you. A system you never identified is out of scope everywhere, which is precisely how equipment ends up unprotected while the programme around it looks healthy.
What this guide covers
- Why BES Cyber System categorization carries the highest risk factor
- BES Cyber System categorization is assessed on process, not just the answer
- Identify BES Cyber Assets, then group them into systems
- Applying the impact rating criteria in BES Cyber System categorization
- Low impact is an identification of assets, not of systems
- The associated systems everyone under-scopes
- Reviewing BES Cyber System categorization on the 15-month clock
- What good BES Cyber System categorization evidence looks like
- Where BES Cyber System categorization leads next
- Frequently asked questions about BES Cyber System categorization

Why BES Cyber System categorization carries the highest risk factor
CIP-002-5.1a Requirement R1 carries a High Violation Risk Factor. Only three requirements in the whole enforceable set do — this one, and CIP-014-3 R1 and R5. That is a deliberate signal about consequence.
The standard has just two requirements and five requirement parts, making it the smallest in the pack by volume and by some distance the most consequential. R1 covers the identification process itself. R2 covers review and CIP Senior Manager approval at least once every 15 calendar months.
BES Cyber System categorization is assessed on process, not just the answer
This is the single most misunderstood thing about BES Cyber System categorization. R1 requires a process that considers each of the asset types the standard lists. An auditor tests whether you considered them — not only whether you arrived at a defensible result.
So record the assets you assessed and rejected as carefully as the ones you identified. An entity that reached exactly the right answer and kept no record of the consideration has a finding on R1 even though every rating is correct. The record is the evidence; the result is not.
Write down the methodology too: which source list your asset types came from, how you applied the tests, and any interpretation you had to adopt where the criteria required judgement. An interpretation that is written down can be discussed with an auditor. One that is not has to be reconstructed under pressure, and it will sound improvised whether or not it is.
Identify BES Cyber Assets, then group them into systems
A Cyber Asset becomes a BES Cyber Asset by reference to the adverse impact its loss, compromise or misuse would have within 15 minutes. Two habits cause most of the trouble here.
The first is applying the test to the device rather than to the reliability task it performs. The second is treating “would be noticed within 15 minutes” as if it meant “would have an adverse impact within 15 minutes”. Those are different tests, and only the second one is being asked.
BES Cyber System categorization then groups the identified assets into BES Cyber Systems. The grouping is your own decision and it should be a deliberate one, because the system — not the device — is the unit that carries the rating and the unit most requirement parts apply to. A grouping chosen for administrative convenience will be inherited by every downstream obligation for years. Record the grouping and the reason for it.
Applying the impact rating criteria in BES Cyber System categorization
BES Cyber System categorization works the criteria in order, and you record the criterion you cited rather than merely the outcome.
| Step | Question | If yes | If no |
|---|---|---|---|
| 1 | Does it meet a high impact criterion? | High impact | Go to step 2 |
| 2 | Does it meet a medium impact criterion? | Medium impact | Go to step 3 |
| 3 | Neither applies | — | Low impact |
Low impact is a rating, not an exclusion. A system that meets no high or medium criterion is still in scope — for CIP-002 and for CIP-003 Requirement R2 and its Attachment 1.
Work high first, then medium, then default. Running the criteria in the other order invites you to stop at the first plausible fit, and a system that satisfies both a medium and a high criterion must be rated high. Record the criteria you tested and rejected on the way, not only the one you settled on — that sequence is what makes the rating reviewable rather than merely asserted.
Where BES Cyber System categorization lands a system at medium impact, separately determine and record whether it has External Routable Connectivity. That single attribute splits obligations in CIP-005 and CIP-006, and it is not part of the rating itself. Deciding it as an afterthought is how medium-impact estates end up with the wrong control set.
Low impact is an identification of assets, not of systems
Part 1.3 asks you to identify the assets containing low impact BES Cyber Systems. It does not require a discrete list of the low impact systems themselves.
That distinction is worth money. Recording the assets is the obligation. Enumerating every system inside them is not — and if you do it voluntarily, you have created an inventory you must now keep accurate for the whole audit period.
The associated systems everyone under-scopes
Your BES Cyber System categorization is not finished when the systems are rated. High and medium impact systems have associated Electronic Access Control or Monitoring Systems, Physical Access Control Systems and Protected Cyber Assets, and those inherit obligations from the system they serve.
They have no impact rating of their own, so they never go through the rating process — which is exactly why they get left out of it. The ones most often missed are the jump host used for remote access, the badge reader controller and its server, the dual-homed engineering workstation, the log collector, and the authentication server the operator console depends on.
Find Protected Cyber Assets by enumerating what sits inside each electronic security perimeter and subtracting the BES Cyber Systems. Anything left is a PCA, and it carries real obligations. A spare laptop or a printer left inside a perimeter without being identified is an avoidable finding.
Reviewing BES Cyber System categorization on the 15-month clock
R2 requires your BES Cyber System categorization to be reviewed and approved by the CIP Senior Manager at least once every 15 calendar months. Compute the next due date from the last review date.
Fifteen calendar months is not “annually” and not “12 months”, and a programme that treats it as either will eventually miss it — there is no annual ritual for it to attach to. Check the approver too: if a delegate signed, the delegation must have been recorded and in force on that date and must have covered this specific action.
Re-run the categorization rather than merely reviewing it whenever the estate materially changes — a new substation, a control centre change, a retirement. And where a rating moves downward, record the reason. That is the first thing an auditor asks about.
What good BES Cyber System categorization evidence looks like
An auditor sampling CIP-002 is looking for four artefacts, and they are easier to produce continuously than to reconstruct.
The first is the record of consideration — every asset of the required types, assessed, with the date and the assessor. The second is the identification list, with the criterion cited per system rather than a bare rating. The third is the grouping rationale. The fourth is the dated approval, naming the person who held the CIP Senior Manager role on that date.
Two columns repay the effort of maintaining them. Record, per system, the reliability tasks it performs — that is what makes the 15-minute test reviewable a year later by someone who was not there. And record External Routable Connectivity as its own field rather than folding it into the rating, because CIP-005 and CIP-006 both read it independently.
Keep the exclusions in the same register as the inclusions. Separating them into a different document is how the record of consideration quietly stops being maintained, and the consideration is the part R1 is actually assessed on.
Where BES Cyber System categorization leads next
Read the requirement text directly before designing anything; the NERC Reliability Standards are published free, so there is no reason to work from a summary of CIP-002.
Once the categorization is settled, the thirteen enforceable standards show what each rating pulls in, and the compliance guide covers the evidence those obligations produce. If you also run industrial systems outside this jurisdiction, the IEC 62443 series is the international equivalent.
Our NERC CIP Toolkit includes the categorization procedure, the asset inventory register, an impact rating worksheet and the approval record, plus the associated-systems identification most estates get wrong.
Frequently asked questions about BES Cyber System categorization
How often must BES Cyber System categorization be reviewed?
At least once every 15 calendar months, with CIP Senior Manager approval. Compute the due date from the last review rather than setting it to the same date each year.
Are low impact systems out of scope?
No. Low impact is a rating. Those assets remain in scope for CIP-002 and for CIP-003 Requirement R2 and its Attachment 1, which covers seven topics including vendor electronic remote access.
Do EACMS, PACS and PCAs get their own impact rating?
No. They inherit obligations from the BES Cyber System they serve. Where one serves both a high and a medium impact system, record that it takes the more onerous set.
What evidence does an auditor want for CIP-002?
The record of assets considered, the identification list with the criterion cited per system, the grouping rationale, and the dated approval — in that order.