NERC CIP standards are the mandatory cyber security rules for the North American bulk electric system, and they are unusual among the frameworks in this field. They are not voluntary, not advisory, and not a maturity model you climb at your own pace. Section 215 of the Federal Power Act makes FERC-approved Reliability Standards enforceable, and a registered entity is audited against them by its Regional Entity, with civil penalties available for violations.
That single fact changes how you should approach them. Most security frameworks reward a good-faith programme. These reward evidence, produced on time, for every day of an audit period.
What this guide covers
- What the NERC CIP standards actually cover
- The 13 NERC CIP standards enforceable today
- How the NERC CIP standards are enforced
- Which NERC CIP standards apply to you
- The 2028 cutover: eleven NERC CIP standards are being replaced
- Where CIP-015 fits, and why it is not yet enforceable
- The intervals in the NERC CIP standards are unforgiving
- How to start with the NERC CIP standards
- Frequently asked questions about the NERC CIP standards

What the NERC CIP standards actually cover
CIP stands for Critical Infrastructure Protection. The NERC CIP standards protect the cyber systems that operate the bulk electric system — generation, transmission and the control centres that run them — by requiring a registered entity to identify those systems, categorise them by impact, and then apply a defined set of controls to each category.
Thirteen of them are enforceable in the United States today. Between them they carry 46 requirements and 210 requirement parts. That second number matters more than the first, because a requirement part is the unit an auditor tests: each one names the systems it applies to and each one needs its own evidence.
The 13 NERC CIP standards enforceable today
The set below is current as at September 2026. Enforcement dates are the dates each standard became enforceable — not the date FERC issued an order, and not the date a FERC rule took effect. Those three dates are different and are constantly conflated.
| Standard | Subject | Enforceable from |
|---|---|---|
| CIP-002-5.1a | BES Cyber System categorization | 27 Dec 2016 |
| CIP-003-9 | Security management controls | 1 Apr 2026 |
| CIP-004-7 | Personnel and training | 1 Jan 2024 |
| CIP-005-7 | Electronic security perimeters | 1 Oct 2022 |
| CIP-006-6 | Physical security of BES Cyber Systems | 1 Jul 2016 |
| CIP-007-6 | System security management | 1 Jul 2016 |
| CIP-008-6 | Incident reporting and response planning | 1 Jan 2021 |
| CIP-009-6 | Recovery plans | 1 Jul 2016 |
| CIP-010-4 | Change management and vulnerability assessments | 1 Oct 2022 |
| CIP-011-3 | Information protection | 1 Jan 2024 |
| CIP-012-2 | Communications between control centres | 1 Jul 2026 |
| CIP-013-2 | Supply chain risk management | 1 Oct 2022 |
| CIP-014-3 | Physical security of transmission facilities | 16 Jun 2022 |
Two of these came into force during 2026, which is why documentation written even a year ago is likely to have a hole in it. CIP-003-9 added vendor electronic remote access controls to the low-impact topic list. CIP-012-2 added loss of availability to the control-centre communications risks, alongside a duty to initiate recovery of the links.
How the NERC CIP standards are enforced
Compliance is assessed against a Reliability Standard Audit Worksheet, one per standard. An auditor works through it requirement by requirement, asks what you did, and asks what proves it. The proof has to cover the whole audit period, not the week before the audit.
This is where entities arriving from an ISO 27001 background are most often caught out. There is no concept here of an auditor accepting that something is obviously happening. A control you genuinely operate but cannot evidence for the period is a possible violation.
Each requirement also carries a Violation Risk Factor. Across the enforceable set there are three High, thirty Medium and thirteen Low. The High ones are CIP-002-5.1a R1 — the categorization itself — and CIP-014-3 R1 and R5.
Which NERC CIP standards apply to you
Two things determine your scope, and they are independent of each other.
The first is your registered function. Transmission Owner is the only function in scope for all 46 requirements, which is why CIP-014 belongs inside a CIP programme rather than beside it. Transmission Operator sits at 43, Balancing Authority, Generator Owner, Generator Operator and Reliability Coordinator at 40, Distribution Provider at 39, and Interchange Authority at just 13.
The second is impact rating. CIP-002 sorts your BES Cyber Systems into high, medium and low impact, and that rating decides which of the other NERC CIP standards reach them. An entity whose assets contain only low-impact systems is in scope for CIP-002 and for CIP-003 Requirement R2 and its Attachment 1 — and substantially nothing else.
That is worth dwelling on, because the commonest expensive mistake is adopting controls you do not need. Every control you take on becomes evidence a Regional Entity can ask for, and which you must then produce for the whole period.
The 2028 cutover: eleven NERC CIP standards are being replaced
Eleven of the thirteen carry an inactive date of 30 June 2028. The replacement set — produced principally by NERC’s Project 2016-02 — becomes enforceable on 1 July 2028.
Treat that as one programme event rather than eleven revisions. The gap analysis you need is a part-to-part mapping, and the dangerous category is not withdrawal but renumbering: a part that keeps its number and changes its meaning will pass a superficial review and leave your evidence pointing at the wrong identifier.
Where CIP-015 fits, and why it is not yet enforceable
You will find a great deal of material presenting internal network security monitoring as a current NERC obligation, usually dated from September 2025. That date is the FERC rule’s effective date. The standard itself is not enforceable until 1 October 2028, and a CIP-015-2 already sits behind it at 1 October 2029.
Starting early is still sensible, because the work has long lead times — placing a sensor inside an electronic security perimeter usually needs an outage window, and those are scheduled a year out. Just label it readiness rather than compliance, so that a future auditor is not shown a half-built capability described as conformance with something that had not started.
The intervals in the NERC CIP standards are unforgiving
More findings come from missed clocks than from missing controls, because the intervals are precise and are easy to paraphrase into something slightly wrong.
Three traps recur. A quarterly obligation means each calendar quarter, not every three months — a programme delivering reliably every ninety days can still leave a calendar quarter empty, and that is a violation however good the other three were. A fifteen-calendar-month cycle is not an annual one, and it does not reset to a fixed date each year; compute the next due date from the last occurrence. And where the NERC CIP standards set two intervals in the same requirement, they usually start from different events.
CIP-007-6 R2 is the clearest example. It contains two separate 35-calendar-day clocks: one runs from a security patch becoming available at its source to your evaluation of it, the other from that evaluation to installation or a dated mitigation plan. A single “patch within 35 days” rule satisfies neither cleanly, because an unevaluated patch is a missed evaluation regardless of whether it was eventually installed.
CIP-008-6 R4 shows the same shape with more at stake. Notification runs one hour after you determine an incident is a Reportable Cyber Security Incident, but by the end of the next calendar day after you determine an event was an attempt to compromise. Two triggers, an order of magnitude apart. A blanket “notify within 24 hours” procedure is more than twenty hours late on the first of them.
Because the clocks in the NERC CIP standards run from determinations rather than from detections, record the time of every determination. That timestamp is the start of the interval an auditor will measure.
How to start with the NERC CIP standards
Work in this order. Confirm your registered functions first, because everything downstream inherits that scope. Then run CIP-002 properly, recording the assets you considered and rejected as carefully as the ones you identified — R1 is assessed on the process, not only the result. Then build the evidence structure before the controls, so that each control you stand up has somewhere to put its records.
You can read the source material for nothing. Unlike ISO and IEC documents, the NERC Reliability Standards are published free — no subscription and no per-seat licence. What is scarce is not the requirement text but the documented processes, the interval arithmetic and the evidence register that turns practice into proof.
If you are securing industrial systems outside this jurisdiction, the international equivalent is the IEC 62443 series, and the Purdue model remains the common vocabulary for describing where those systems sit. European operators should start from the NIS2 mapping instead.
Our NERC CIP Toolkit gives you 130 editable templates covering all 46 requirements and 210 requirement parts, with the evidence register pre-loaded so you can see immediately where you have proof and where you do not.
Frequently asked questions about the NERC CIP standards
How many NERC CIP standards are there?
Thirteen are enforceable in the United States today, numbered CIP-002 to CIP-014. CIP-015 exists and is approved, but does not become enforceable until 1 October 2028.
Do the NERC CIP standards cost money to read?
No. NERC publishes them free. That is unusual for a mandatory framework and it means there is no barrier to checking what a requirement actually says before you buy anything.
Do the NERC CIP standards apply outside the United States?
Adoption in Canada differs by province and Mexico differs again. If you operate across borders, establish the position for each jurisdiction rather than assuming the US set carries over.
What is the difference between the NERC CIP standards and IEC 62443?
NERC CIP is mandatory and jurisdictional, aimed at the North American bulk electric system and enforced by audit. IEC 62443 is an international, voluntary series covering industrial automation and control systems generally, and it uses a maturity model rather than an audit-and-penalty regime.