NERC CIP audit preparation is mostly arithmetic and assembly, not security work. By the time an audit is scheduled the controls are what they are; what determines the outcome is whether you can produce the evidence, whether your dates survive being recomputed, and whether the people interviewed answer the question they were asked.
All three are things you can fix in advance, and the last one is the cheapest.
What this guide covers
- How a NERC CIP audit is actually conducted
- Writing the NERC CIP audit RSAW narrative
- Bring the arithmetic to your NERC CIP audit
- Three NERC CIP audit checks worth running before they do
- Evidence retention, and the failure you cannot fix
- Preparing people for a NERC CIP audit interview
- Internal audit as NERC CIP audit rehearsal
- The 90 days before a NERC CIP audit
- What to have ready for a NERC CIP audit
- Frequently asked questions about NERC CIP audit preparation

How a NERC CIP audit is actually conducted
Your Regional Entity works through a Reliability Standard Audit Worksheet, one per standard. The RSAW takes each requirement part in order and asks what you did and what proves it.
The auditor reads your narrative first. That narrative frames how everything after it is read, which cuts both ways: a narrative that overstates produces findings the evidence alone would not have produced, and one that is precise makes the evidence easy to accept.
Then they sample — across the whole audit period, chosen by them, and weighted toward whatever is most likely to have slipped. That is almost always the interval-based controls and anything involving an approval.
Writing the NERC CIP audit RSAW narrative
Three rules make a narrative work in a NERC CIP audit.
Describe what actually happens, not what the procedure says should happen. Where the two differ, fix the process or the document before the audit — never paper over it in the narrative.
Use the identifiers. “We review access quarterly” invites a question. “GDL-style register X records the quarterly verification required by CIP-004-7 R4.2, performed by the compliance manager” answers one.
Answer the requirement part and stop. A narrative that ranges beyond the part invites questions about everything it touched. Volunteering scope is the single most common self-inflicted wound in an audit.
Bring the arithmetic to your NERC CIP audit
For every interval-based control, produce the dates and the computed next-due dates rather than the raw records alone.
An auditor checking a 15-calendar-month cycle across a three-year period is doing arithmetic on your behalf. Doing it for them, and being right, changes the character of the conversation entirely — it moves you from being examined to being checked.
Run the same computation on yourself first. Take every occurrence of every interval control in the period, compute the due dates, and find the ones that slipped. Where you find a miss, say so in the narrative rather than letting it be discovered. A self-identified miss with a mitigation already under way is a materially different conversation from one the auditor surfaces.
Three NERC CIP audit checks worth running before they do
These find real problems and almost nothing else surfaces them.
Approvals against delegations. Sample approvals from the period and confirm the signatory either held the CIP Senior Manager role on that date or held a delegation that was in force and covered that specific action. Approvals signed under a lapsed or too-narrow delegation are invisible unless somebody checks.
Technical Feasibility Exceptions. Confirm every TFE you rely on is approved, unexpired, and that its compensating measures are actually operating. A TFE that is quietly working attracts no attention until it is asked for.
Applicability decisions. Sample the rows you marked “does not apply” and test the reason. This is the first thing an auditor examines, and a row with no recorded reason is the weakest position in the programme.
Evidence retention, and the failure you cannot fix
Two retention duties operate at once in a NERC CIP audit and they stack. Some records carry a retention period set by the standard itself. Every record also has to cover the audit period. Whichever is longer governs.
Retain superseded document versions too. An auditor sampling an activity from two years ago asks which version of the procedure governed it, and a library holding only the current version cannot answer.
The one irreversible mistake in a NERC CIP audit is an automated retention policy that deleted evidence at the standard’s minimum while the audit period reached further back. Confirm the audit period before any scheduled destruction, and record the confirmation. Once the records are gone you cannot evidence a control you genuinely operated.
Preparing people for a NERC CIP audit interview
The evidence is usually fine. What causes findings is what people say.
| What goes wrong | Why it happens |
|---|---|
| Volunteering scope | Mentioning a system or site the auditor had not asked about |
| Speculating | Guessing at a date, or answering for someone else’s system |
| Answering a bigger question | Being helpful, and inviting three follow-ups |
| Describing the aspiration | Saying what the team intends rather than what it does |
None of that is dishonesty. It is what people do when they want to be helpful. Brief them: answer the question asked and then stop; if you do not know, say so and say who does; do not speculate; describe what happens, not what should happen.
And tell them not to correct the record on their own. If someone realises mid-interview that something said earlier was wrong, it goes to the compliance manager at the break — corrections are made deliberately, in writing, through a single point of contact. An improvised correction usually creates two problems where there was one.
Internal audit as NERC CIP audit rehearsal
Run your internal audits the way the Regional Entity will, or they are not testing anything.
Sample across the period rather than the recent past. Compute intervals rather than accepting descriptions. Ask for evidence rather than accepting an explanation. Test the negative cases — the quarter where nothing happened, the system that was decommissioned, the person who left.
Cover every requirement part across a cycle rather than everything every year, weighted toward High Violation Risk Factor requirements, short-interval controls, standards that changed, and areas with prior findings. And make sure the auditor is not the person who operates the control; in a small team that means cross-assignment rather than abandoning independence.
An internal audit programme that finds nothing across a full cycle is not evidence of a clean programme. It is evidence that the audits are not testing anything, and an experienced auditor reads it that way.
The 90 days before a NERC CIP audit
Most of the value is in a short, structured run-up rather than a year of anxiety.
Start by confirming scope: the registered functions, the current categorization, and the applicability decisions. If any of those have changed since the last audit and the evidence register has not caught up, everything downstream is being tested against the wrong scope.
Then run the interval arithmetic across the whole period and produce the exception list. Expect to find one or two. Deal with each under your self-reporting process rather than hoping the sample misses them — the sample is weighted toward exactly these.
Next, assemble by requirement part rather than by document. An auditor asks for evidence against CIP-007-6 R4.3, not for “the logging folder”, and the assembly step is where you discover that a control everyone believed was evidenced produces records nobody can locate.
Finally, brief the people. An hour of briefing prevents more findings than a week of evidence assembly, and it is the cheapest thing in the whole NERC CIP audit preparation. Cover which of their controls are in scope, what they are likely to be asked, and the four rules for answering.
Keep the completed RSAWs and the evidence set exactly as submitted. The next audit begins from the last one, and reconstructing what you said is harder than keeping it.
What to have ready for a NERC CIP audit
The evidence register mapped to every requirement and part, with a status you have set honestly. The dates, computed. The superseded document versions. The applicability decisions with reasons. The delegation register. The mitigation register showing findings through to verified closure.
Read the RSAWs and the requirement text directly while preparing — the NERC Reliability Standards are published free, so there is no reason to prepare against a summary of what you think is being asked.
The compliance guide covers the evidence discipline this rests on, the thirteen enforceable standards show the scope, and CIP-002 categorization is where an auditor starts because everything else inherits it.
Our NERC CIP Toolkit includes an RSAW preparation guide, an internal audit checklist pre-loaded with all 210 requirement parts, and an interview preparation pack.
Frequently asked questions about NERC CIP audit preparation
How far back does a NERC CIP audit look?
Across the audit period your Regional Entity specifies, which commonly spans several years. Both your evidence and your superseded document versions need to reach back across it.
Should we disclose a miss we found ourselves?
Generally yes, with the mitigation already under way. Self-identification is treated very differently from a finding the auditor makes, and an incomplete set presented as complete costs credibility on everything else.
Who should speak to the auditor?
The people who operate the controls, briefed beforehand, with all communication routed through a single point of contact. Requests made directly to an interviewee go to that contact rather than being answered on the spot.
What is sampled most heavily?
Interval-based controls and anything involving an approval or a delegation, weighted toward the earlier part of the period where a programme that has since improved is weakest.