CIP-014 physical security is the odd standard in the NERC CIP set, and treating it like the others is the fastest way to fail it. It applies to Transmission Owners and Transmission Operators only, it protects physical facilities rather than cyber systems, and it requires an unaffiliated third party twice — through two separate gates that most entities run as one.
It also carries two of the three High Violation Risk Factors in the whole enforceable set, at R1 and R5. The standard is telling you where the consequence sits.
What this guide covers
- CIP-014 physical security is not CIP-006
- CIP-014 physical security starts with a power system study
- The two third-party gates in CIP-014 physical security
- Testing affiliation in CIP-014 physical security engagements
- Recommendations are not automatically accepted
- The six functions in the CIP-014 physical security plan
- The timeline you write becomes the deadline you are measured against
- Confidentiality across both CIP-014 physical security gates
- Sequencing a CIP-014 physical security programme
- Where CIP-014 physical security sits
- Frequently asked questions about CIP-014 physical security

CIP-014 physical security is not CIP-006
Both are called physical security and they share no requirement parts. CIP-006 protects BES Cyber Systems — the Physical Security Perimeter around the equipment. CIP-014 protects Transmission stations, substations and primary control centres whose loss could cause widespread instability, uncontrolled separation or cascading within an Interconnection.
Different scope, different audience, different evidence. An entity that files its CIP-006 perimeter records against CIP-014 has answered a question nobody asked.
The audience difference matters most. CIP-006 reaches every registered function that owns applicable BES Cyber Systems. CIP-014 reaches Transmission Owners, and Transmission Operators for the obligations attaching to a primary control centre they operate. A Generator Owner has CIP-006 obligations and no CIP-014 ones at all, which is why the two are worth keeping in separate parts of a programme rather than under a single physical security heading.
CIP-014 physical security starts with a power system study
The CIP-014 physical security process begins with a risk assessment that identifies which of your Transmission stations and substations matter at that level. That is a transmission planning study, performed by people who model the power system. It is not a security risk assessment and the security team does not produce it.
Two things about R1 catch entities out. The interval for subsequent assessments depends on the entity’s circumstances rather than being one fixed cycle for everyone — determine which applies to you, record the basis, and compute the next due date from it. And R1.2 requires you to identify the primary control centre that operationally controls each identified station, which is a separate deliverable from the station list and is routinely treated as an afterthought.
The two third-party gates in CIP-014 physical security
| Requirement R2 | Requirement R6 | |
|---|---|---|
| What is examined | The R1 risk assessment | The R4 evaluation and the R5 security plan |
| Third party acts as | Verifying entity | Reviewer |
| Permitted pool | Set by R2.1 | Set by R6.1 — different |
| Confidentiality duty | R2.4 | R6.4 |
This is the structural point of the whole standard. R2 verifies the risk assessment. R6 reviews the evaluation and the plan. They happen at different points, cover different documents, and draw on different permitted reviewer pools.
Running one engagement to answer both leaves one gate with no evidence at all — and because the two reports address different subject matter, the deficiency is obvious to an auditor on sight. Read R2.1 and R6.1 side by side before selecting anyone, and do not carry an affiliation determination from one gate to the other.
Testing affiliation in CIP-014 physical security engagements
“Unaffiliated” is the criterion most likely to be got wrong, because affiliation is not only corporate ownership. Consider shared parentage, a consultancy currently engaged on your transmission planning, and personnel who moved between the organisations recently.
Record the determination, the permitted category you relied on, who decided and when. And plan the engagement early: suitable reviewers are a small pool, and an entity that starts looking a month before the deadline will struggle to find one that is both qualified and genuinely unaffiliated.
Recommendations are not automatically accepted
Both gates can produce recommendations — R2.3 where the verifying entity proposes adding a station, R6.3 where the reviewer proposes changes to the evaluation or the plan. Neither part says “accept”.
Record every recommendation, your response, the reasoning and the date. Where you do not adopt one, the reasoning is the evidence. An unexplained rejection of your own independent reviewer’s recommendation, on a standard carrying a High Violation Risk Factor, is the weakest position available under CIP-014 physical security.
The six functions in the CIP-014 physical security plan
R5.1 requires resiliency or security measures designed collectively to deter, detect, delay, assess, communicate and respond. Collectively means the set must cover all six; no single measure has to.
Map measures to functions explicitly — it is a six-cell checklist and the omission is always the same one or two. Assess and communicate are the ones usually missing. Detection without assessment produces alarms nobody can interpret; assessment without communication produces knowledge that never reaches a responder.
Trace each measure back to a vulnerability identified in the R4 evaluation, and make sure each identified vulnerability is either addressed or explicitly accepted. That traceability is exactly what the R6 reviewer looks for.
The timeline you write becomes the deadline you are measured against
R5.3 requires a timeline for executing the enhancements, and R5 requires the plan to be implemented. So you set your own deadline and are then held to it. A plan promising works within twelve months that slip to twenty-four is a self-inflicted violation.
Set achievable dates, track them monthly, and where a date must move, record the change and the reason at the time rather than letting it pass silently. Evidence both halves — the plan document, and records showing the measures are actually in place and operating. A plan with an unexecuted timeline evidences development only.
Confidentiality across both CIP-014 physical security gates
R2.4 and R6.4 each require procedures for protecting sensitive information given to the third party. Have the agreement executed before anything is shared — prospective reviewers are frequently sent material during selection, before anyone treats the agreement as live, and an agreement signed afterwards does not protect what was already sent.
The same discipline applies internally. The R4 evaluation names the vulnerabilities of critical transmission facilities and the R5 plan describes what protects them; together they are the most damaging combination of documents you hold. Control the drafts, not just the final versions, because drafts are where exposure usually happens.
Keep a record of what was provided to whom and when. Without it you cannot enforce return or destruction at the end of the engagement, and you cannot assess exposure if that third party is later breached.
Sequencing a CIP-014 physical security programme
The requirements run in a chain and each one gates the next, so sequencing errors are expensive rather than merely untidy.
R1 identifies the stations. R2 has an unaffiliated verifying entity confirm that identification. R3 notifies the Transmission Operator of the primary control centre where you do not operate it yourself. R4 evaluates threats and vulnerabilities to what was identified and verified. R5 produces and implements the plan. R6 has a different unaffiliated third party review the R4 evaluation and the R5 plan.
Running R4 before R2 completes is the common shortcut, and it wastes the work: if the verifying entity recommends adding a station, that station has no evaluation and no plan, and the timeline you have already committed to under R5.3 no longer covers the estate.
Build the calendar backwards from the R6 review, because that is the engagement with the smallest pool of qualified reviewers and the least flexibility. A CIP-014 physical security programme that leaves reviewer selection until the plan is finished routinely discovers that everyone suitable is either affiliated or unavailable.
Record dates at every step. The chain is what an auditor walks, and a step with no date cannot be placed in it.
Where CIP-014 physical security sits
Read the requirement directly before scoping — the NERC Reliability Standards are published free, and R2.1 and R6.1 are worth reading side by side in the original.
The thirteen enforceable standards show why a Transmission Owner is in scope for all 46 requirements while other functions are not, the CIP-002 categorization covers the cyber-side scoping that runs alongside this, and the compliance guide covers evidence discipline.
Our NERC CIP Toolkit gives each CIP-014 gate its own procedure — R2 verification and R6 review kept deliberately separate — with a shared confidentiality procedure satisfying R2.4 and R6.4.
Frequently asked questions about CIP-014 physical security
Who does CIP-014 physical security apply to?
Transmission Owners, and Transmission Operators for the R4, R5 and R6 obligations relating to a primary control centre they operate. Other registered functions are not in scope.
Can one third party do both the R2 and R6 work?
Only if they independently satisfy both permitted pools, which differ. Even then the engagements, reports and records must be separate, because the two gates examine different documents.
Is the CIP-014 risk assessment a security assessment?
No. R1 is a power system study identifying stations whose loss could cause widespread instability, uncontrolled separation or cascading. The security work begins at R4.
What happens if a station is later removed from the list?
R3.1 covers it, and there is a notification obligation. It is the notification most often missed, because a removal feels like the end of an obligation rather than the start of one.