Description
About the NERC CIP Toolkit
Almost every compliance toolkit sold is for a voluntary standard. This one is not. Section 215 of the Federal Power Act makes FERC-approved Reliability Standards mandatory and enforceable, and a Registered Entity is audited against them by its Regional Entity using a Reliability Standard Audit Worksheet — with civil penalties available for violations.
If you are securing operational technology outside the North American bulk electric system, the IEC 62443 Toolkit is the international equivalent and covers industrial automation and control systems generally. European operators of essential services should start with the NIS2 Toolkit.
The NERC CIP Toolkit is written against the 13 CIP standards enforceable in the United States and covers all 46 of their requirements and all 210 requirement parts.
It is organised the way you are audited
Sixteen sections, one per standard, in standard number order. That is not a stylistic choice. A Regional Entity works through an RSAW for CIP-002, then an RSAW for CIP-003, and so on. A document set organised any other way — by control family, by ISO 27001 Annex A, by security domain — forces you to re-map your own evidence under audit conditions, which is where mistakes happen.
Two of the thirteen standards changed this year
If your documentation predates 2026, two specific gaps are almost certainly in it:
| Standard | Enforceable from | What changed |
|---|---|---|
| CIP-003-9 | 1 April 2026 | Added vendor electronic remote access controls to the low-impact Attachment 1 topic list |
| CIP-012-2 | 1 July 2026 | Added loss of availability to the Control Center communications risks, plus a duty to initiate recovery of the links |
Both are checkable in an afternoon. A low-impact plan written to CIP-003-8 has no vendor remote-access section. A CIP-012 plan written to CIP-012-1 covers disclosure and modification and is silent on availability — and because it reads as a complete plan, nothing signals the gap.
Eleven of the thirteen standards go inactive on 30 June 2028
This is the part nobody documents, and it is the reason section 16 of this toolkit exists.
Eleven of the currently enforceable standards carry an inactive date of 30 June 2028. The replacement set — produced principally by NERC’s Project 2016-02 — becomes enforceable on 1 July 2028. That is one coordinated programme event, not eleven separate revisions, and an entity that treats it as eleven will do it eleven times and badly.
The toolkit ships a standard-version register listing every enforceable standard with its enforcement date and inactive date, every approved-but-not-yet-enforceable replacement with its date, and the one standard currently filed and pending at FERC. It also ships a transition plan built around the single cutover date.
We tell you CIP-015 is not yet enforceable, because it is not
You will find a great deal of material selling internal network security monitoring as a present NERC obligation, usually dated from September 2025.
That date is the FERC rule’s effective date. The standard’s enforcement date is 1 October 2028, and a CIP-015-2 already sits behind it at 1 October 2029.
Three different dates circulate for every NERC standard and only one governs what you are audited against:
| Date | What it is | Does it bind you? |
|---|---|---|
| FERC order date | When the Commission issued the order | No |
| FERC rule effective date | When the rule took effect | No |
| Standard enforcement date | When the standard becomes enforceable | Yes |
Section 16 of this toolkit is therefore readiness material, labelled as readiness. It gives you the traffic mapping, the visibility assessment and the phased implementation plan you need to start now — because sensor placement inside an Electronic Security Perimeter usually needs an outage window, and those are scheduled a year out — without pretending you are late for something that has not started.
Low impact is a different, much shorter obligation, and we treat it as one
An entity whose assets contain only low-impact BES Cyber Systems is in scope for CIP-002 and for CIP-003 Requirement R2 and its Attachment 1, and substantially nothing else.
Section 03 carries a dedicated low-impact route — one document per Attachment 1 topic, written to be self-contained, so a low-impact entity never has to read the high and medium impact set. That matters commercially as well as practically: every control you adopt beyond what applies to you becomes evidence a Regional Entity can ask for, and which you must then produce for the whole audit period.
The workbooks arrive filled in
Five of the 40 Excel workbooks ship pre-loaded from the requirement register, not empty:
| Workbook | What is already in it |
|---|---|
| CIP Evidence Register | All 256 identifiers — every requirement and every part — with VRF and functional-entity applicability |
| Applicability Matrix | All 210 requirement parts, ready for the applies / does not apply decision an auditor tests first |
| Internal Audit Checklist | All 210 parts, phrased as the question an auditor asks |
| Roles and RACI Matrix | All 256 identifiers, so no requirement can be left without an accountable owner |
| Standard Version Register | The 13 enforceable standards, the 14 approved replacements, the one pending at FERC |
They come from one data module, which is what stops them drifting from each other or from the documents.
The intervals are stated, not left for you to look up
NERC’s clocks are unforgiving and they are easy to merge by accident. The toolkit states them, per requirement part, with the trigger each one runs from:
- CIP-004-7 R5 — remove the ability for unescorted physical and Interactive Remote Access
within 24 hours of a termination action, but revoke the non-shared accounts within 30 calendar days. Different things, different clocks, routinely conflated.
- CIP-007-6 R2 — two separate 35-calendar-day clocks, one running from a patch becoming
available at its source, the other from the evaluation being completed.
- CIP-008-6 R4 — one hour after determining a Reportable Cyber Security Incident, but
by the end of the next calendar day after determining an attempt to compromise. Two triggers, an order of magnitude apart, and a single “notify within 24 hours” rule is more than twenty hours late on the first.
- CIP-009-6 R2 — 15 calendar months for the plan test and the information sample, **36 calendar
months** for the test in a representative environment. One annual exercise satisfies the first only.
CIP-014 has two separate third-party gates, and we keep them separate
CIP-014 requires an unaffiliated third party twice, and they are not the same engagement:
- Requirement R2 verifies the R1 risk assessment.
- Requirement R6 reviews the R4 evaluation and the R5 security plan.
They happen at different points, cover different subject matter, and draw on different permitted reviewer pools. Running one engagement to answer both leaves one gate with no evidence at all — and because the two reports address different documents, the gap is immediately visible to an auditor. Section 14 gives each gate its own procedure and shares one confidentiality procedure between them, which is what CIP-014 R2.4 and R6.4 both require.
Who the NERC CIP Toolkit is for, and who it is not for
It is for US-registered Responsible Entities — the asset owners and operators who face a Regional Entity audit. How much of the pack applies depends on the functions you are registered under, and the spread is wider than most summaries suggest:
| Registered function | Requirements in scope |
|---|---|
| Transmission Owner | 46 of 46 |
| Transmission Operator | 43 of 46 |
| Balancing Authority, Generator Owner, Generator Operator, Reliability Coordinator | 40 of 46 |
| Distribution Provider | 39 of 46 |
| Interchange Authority | 13 of 46 |
Transmission Owner is the only function in scope for every requirement — which is why CIP-014 belongs inside this pack rather than beside it. An Interchange Authority, at the other end, is in scope for well under a third and should expect to use a small part of the toolkit.
It is not for vendors selling into the sector. If you supply products to a Responsible Entity, the obligations you will be asked to meet come through your customer’s CIP-013 procurement process, not directly — and this pack is written from the customer’s side of that conversation.
It covers the United States only. Adoption of the CIP standards in Canada differs by province and Mexico differs again. Where you operate across borders, the differences are yours to establish and the toolkit says so rather than implying a coverage it does not have.
What a document pack can and cannot do
It can give you the documented processes, the registers, the evidence structure and the audit readiness material — which is the great majority of what a CIP programme consists of, because CIP compliance is evidence-driven by construction.
It cannot perform your CIP-014 Requirement R1 risk assessment. That is a transmission planning study, run by people who model the power system, and no template performs it. Section 14 documents the process around it — the intervals, the record of what was considered, the identification of the primary control center, the two third-party gates — and is explicit that the study itself is yours.
Nor does buying a toolkit make you compliant. Compliance is evidence covering the whole audit period. The toolkit is what turns your practice into that evidence.
The source standards are free, and that is worth saying
Unlike ISO and IEC standards, NERC Reliability Standards download free from nerc.com — no subscription, no per-seat licence, no purchase before you can read what you are being asked to do.
That is unusual and it changes what a toolkit should be. There is no value in us restating requirement text you can read for nothing. What is scarce is the documented processes, the registers, the interval arithmetic, the evidence structure and the version matrix — which is what these 130 documents are.
NERC CIP Toolkit structure
| # | Section | Documents |
|---|---|---|
| 01 | CIP Programme Foundation | 8 |
| 02 | CIP-002 Categorization | 6 |
| 03 | CIP-003 Security Management | 12 |
| 04 | CIP-004 Personnel and Training | 13 |
| 05 | CIP-005 Electronic Perimeter | 7 |
| 06 | CIP-006 Physical Security | 7 |
| 07 | CIP-007 System Security | 12 |
| 08 | CIP-008 Incident Response | 9 |
| 09 | CIP-009 Recovery Plans | 7 |
| 10 | CIP-010 Change and Vulnerability | 11 |
| 11 | CIP-011 Information Protection | 5 |
| 12 | CIP-012 Control Centers | 4 |
| 13 | CIP-013 Supply Chain | 7 |
| 14 | CIP-014 Transmission Security | 8 |
| 15 | Evidence and Audit Readiness | 9 |
| 16 | Transition and CIP-015 | 5 |
Every document names the requirements it answers
Each of the 90 Word documents carries a Requirements addressed table immediately after its standard basis, citing the requirement identifiers exactly as NERC writes them — CIP-007-6 R4.1.1, not “logging”. That is the string an auditor searches for, and it is what lets you hand over a document and have it map to the RSAW without argument.
List of Documentation Toolkit:
01 — CIP Programme Foundation (8 documents)
- NERC CIP Compliance Programme Manual.docx
- CIP Roles, Responsibilities and RACI Matrix.xlsx
- NERC CIP Glossary and Defined Terms Register.docx
- CIP Exceptional Circumstances Procedure.docx
- Technical Feasibility Exception Procedure.docx
- CIP Document and Record Control Procedure.docx
- Internal Compliance Programme and Self-Reporting Procedure.docx
- CIP Programme Annual Review and Management Report.docx
02 — CIP-002 Categorization (6 documents)
- BES Cyber System Identification and Categorization Procedure.docx
- BES Asset and Cyber Asset Inventory Register.xlsx
- Impact Rating Worksheet — High, Medium and Low.xlsx
- EACMS, PACS and PCA Identification Procedure.docx
- Categorization Approval and 15-Month Review Record.xlsx
- Categorization Methodology Justification Statement.docx
03 — CIP-003 Security Management (12 documents)
- Cyber Security Policy — High and Medium Impact.docx
- Cyber Security Policy — Low Impact Assets.docx
- CIP Senior Manager Designation Record.docx
- CIP Senior Manager Delegation Procedure and Register.docx
- Annual Policy Review and Approval Record.xlsx
- Low Impact Cyber Security Awareness Programme.docx
- Low Impact Physical Security Controls Procedure.docx
- Low Impact Electronic Access Controls Procedure.docx
- Low Impact Cyber Security Incident Response Plan.docx
- Low Impact Transient Cyber Asset and Removable Media Procedure.docx
- Low Impact Vendor Electronic Remote Access Controls Procedure.docx
- Low Impact Asset Register and Attachment 1 Applicability Workbook.xlsx
04 — CIP-004 Personnel and Training (13 documents)
- Security Awareness Programme.docx
- Quarterly Security Awareness Reinforcement Log.xlsx
- Cyber Security Training Programme.docx
- Role-Based Training Content Matrix.xlsx
- Training Completion and 15-Month Refresher Register.xlsx
- Personnel Risk Assessment Programme.docx
- Identity Verification and Criminal History Records Check Procedure.docx
- Personnel Risk Assessment Record and Seven-Year Renewal Register.xlsx
- Access Management Programme.docx
- Quarterly Access Verification Record.xlsx
- Access Revocation Programme.docx
- BES Cyber System Information Access Management Programme.docx
- Authorisation and Provisioning Register.xlsx
05 — CIP-005 Electronic Perimeter (7 documents)
- Electronic Security Perimeter Procedure.docx
- ESP and Network Diagram Set.docx
- Electronic Access Point Register.xlsx
- Malicious Communications Detection Procedure.docx
- Interactive Remote Access Procedure.docx
- Vendor Remote Access Management Procedure.docx
- Vendor Remote Access Session Register.xlsx
06 — CIP-006 Physical Security (7 documents)
- Physical Security Plan for BES Cyber Systems.docx
- Physical Access Control and Monitoring Procedure.docx
- Physical Security Perimeter and Defined Area Register.xlsx
- Physical Access Log and Retention Register.xlsx
- Visitor Control Programme.docx
- Visitor Log and Retention Record.xlsx
- PACS Maintenance and Testing Programme.docx
07 — CIP-007 System Security (12 documents)
- Ports and Services Procedure.docx
- Logical Network Accessible Port Register.xlsx
- Security Patch Management Procedure.docx
- Patch Source and Evaluation Register.xlsx
- Patch Mitigation Plan Template.docx
- Malicious Code Prevention Procedure.docx
- Security Event Monitoring Procedure.docx
- Event Log Review and Retention Record.xlsx
- System Access Control Procedure.docx
- Password and Authentication Standard.docx
- Default and Generic Account Register.xlsx
- Failed Authentication Alerting Procedure.docx
08 — CIP-008 Incident Response (9 documents)
- Cyber Security Incident Response Plan.docx
- Incident Classification and Reportable Incident Criteria.docx
- Incident Response Roles and Contact Directory.docx
- Incident Handling Record.xlsx
- Incident Response Test Plan and Record.docx
- Incident Response Plan Review and Update Procedure.docx
- Lessons Learned and Plan Update Record.xlsx
- E-ISAC and CISA Notification Procedure.docx
- Attribute Notification and Update Log.xlsx
09 — CIP-009 Recovery Plans (7 documents)
- BES Cyber System Recovery Plan.docx
- Backup and Restore Procedure.docx
- Backup Media Register and Verification Log.xlsx
- Recovery Plan Test Plan and Record.docx
- Recovery Roles and Responsibilities Matrix.xlsx
- Recovery Plan Review, Update and Communication Procedure.docx
- Recovery Plan Test Evidence Register.xlsx
10 — CIP-010 Change and Vulnerability (11 documents)
- Configuration Change Management Procedure.docx
- Baseline Configuration Register.xlsx
- Change Authorisation and Test Record.xlsx
- Software Integrity and Authenticity Verification Procedure.docx
- Configuration Monitoring Procedure.docx
- Vulnerability Assessment Programme.docx
- Active Vulnerability Assessment Procedure.docx
- Vulnerability Assessment Record and Remediation Plan.xlsx
- Transient Cyber Asset and Removable Media Procedure.docx
- Transient Cyber Asset and Removable Media Register.xlsx
- Vendor-Managed Transient Cyber Asset Controls.docx
11 — CIP-011 Information Protection (5 documents)
- BES Cyber System Information Protection Programme.docx
- BCSI Identification and Labelling Procedure.docx
- BCSI Handling, Storage and Transit Standard.docx
- BES Cyber Asset Reuse and Disposal Procedure.docx
- Media Sanitisation and Disposal Record.xlsx
12 — CIP-012 Control Centers (4 documents)
- Control Center Communications Security Plan.docx
- Communication Link Recovery Procedure.docx
- Real-time Assessment and Monitoring Data Flow Register.xlsx
- Inter-Entity Control Center Responsibility Agreement.docx
13 — CIP-013 Supply Chain (7 documents)
- Supply Chain Cyber Security Risk Management Plan.docx
- Vendor Risk Assessment Procedure.docx
- Procurement Security Requirements Schedule.docx
- Vendor Incident Notification and Coordination Procedure.docx
- Vendor Vulnerability Disclosure Procedure.docx
- Supply Chain Plan Implementation Evidence Register.xlsx
- Supply Chain Plan 15-Month Review and Approval Record.docx
14 — CIP-014 Transmission Security (8 documents)
- Transmission Station and Substation Risk Assessment Procedure.docx
- Risk Assessment Record and Applicability Worksheet.xlsx
- Unaffiliated Third-Party Verification Procedure.docx
- Notification to Transmission Operator Procedure.docx
- Physical Security Threat and Vulnerability Evaluation.docx
- Physical Security Plan for Identified Transmission Facilities.docx
- Unaffiliated Third-Party Review Procedure.docx
- Confidentiality and Non-Disclosure Procedure for CIP-014 Information.docx
15 — Evidence and Audit Readiness (9 documents)
- CIP Evidence Register — 46 Requirements and 210 Parts.xlsx
- Applicability Matrix — Parts by Impact Rating and Functional Entity.xlsx
- Internal Audit Checklist — All Requirement Parts.xlsx
- RSAW Response Preparation Guide.docx
- Internal Audit Programme and Schedule.docx
- Self-Certification and Self-Report Procedure.docx
- Mitigation Plan Template and Register.xlsx
- Compliance Evidence Retention Schedule.docx
- Spot Check and Audit Interview Preparation Pack.docx
16 — Transition and CIP-015 (5 documents)
- Standard Version and Enforcement Date Register.xlsx
- Project 2016-02 Transition Plan — 1 July 2028 Cutover.docx
- CIP-015 Internal Network Security Monitoring Readiness Guide.docx
- CIP-015 INSM Implementation Plan Template.docx
- NERC Standards Development Change Watch Procedure.docx
Frequently Asked Questions (FAQ)
Which CIP standards does the toolkit cover? The 13 enforceable in the United States: CIP-002-5.1a, CIP-003-9, CIP-004-7, CIP-005-7, CIP-006-6, CIP-007-6, CIP-008-6, CIP-009-6, CIP-010-4, CIP-011-3, CIP-012-2, CIP-013-2 and CIP-014-3 — covering all 46 requirements and 210 requirement parts between them.
Do I need to buy the NERC standards as well? No. NERC Reliability Standards are published free at nerc.com. You should read the ones that apply to you, and the toolkit cites requirement identifiers throughout so you can follow along, but there is nothing to purchase.
Does this cover CIP-015 and internal network security monitoring? It covers readiness, and it labels it as readiness. CIP-015-1 is not enforceable until 1 October 2028. The toolkit gives you the internal traffic mapping, the visibility assessment and a phased implementation plan so you can start on the work with long lead times, and it states the enforcement date plainly rather than presenting the work as a current obligation.
What happens to the toolkit on 1 July 2028? Eleven of the thirteen standards are replaced that day. Section 16 carries a transition plan and a version register for exactly that. Updates are free for the life of the product, so you will receive the revised pack.
We only have low-impact assets. Is this over-specified for us? No — section 03 has a dedicated low-impact route covering CIP-002 and the CIP-003 Attachment 1 topics, written to be read on its own. You will use a fraction of the pack, which is the correct outcome, and the toolkit is explicit that adopting high and medium impact controls you do not need creates evidence obligations you will then be audited against.
Will this make us compliant? No toolkit can. Compliance is evidence covering your whole audit period, produced by controls you actually operate. The toolkit gives you the documented processes and the evidence structure — the evidence register ships pre-loaded with all 256 requirement identifiers so you can see immediately where you have evidence and where you do not.
Is it US-only? Yes. It is written for US-registered Responsible Entities. Canadian adoption of the CIP standards differs by province and Mexico differs again; those differences are out of scope and the toolkit says so.
What format are the files? Microsoft Word (.docx) and Microsoft Excel (.xlsx) — 90 Word documents and 40 Excel workbooks. Fully editable, no macros, no add-ins, no online account.
What do we get after purchase? Immediate download of the complete toolkit, free updates for the life of the product, and free email support.
Project Management Toolkit - Comprehensive 370 Templates 




































Reviews
There are no reviews yet