NERC CIP Compliance Checklist for 2026

by Jordan Dean on Sep 23, 2026

NERC CIP Compliance Checklist for 2026

woman-and-man-collaborating-on-data-in-a-high-tech-2026-07-23-19-19-23-utc

NERC CIP compliance touches far more than your security tools. It involves asset categorization, access, physical security, training, incident response, recovery, vendor oversight, and the evidence behind each process.

This NERC CIP compliance checklist brings those activities into one place. Use it to review your program, assign ownership, and identify areas that may need attention.

The North American Electric Reliability Corporation (NERC) maintains separate lists for Critical Infrastructure Protection (CIP) standards currently subject to enforcement and versions subject to future enforcement. Those lists continue to change, so confirm the current version before applying any requirement.

This checklist is a planning aid. Your registered functions, assets, connectivity, and Bulk Electric System (BES) Cyber System impact ratings determine which requirements apply.

Key Takeaways

  • Applicability comes first. Confirm registration, identify relevant assets, and categorize BES Cyber Systems before mapping requirements.
  • Evidence needs to match operations. Policies alone are not enough if daily processes, configurations, or reviews work differently.
  • Compliance changes over time. Track standards already subject to enforcement, as well as approved versions scheduled for future enforcement.

What Is NERC CIP Compliance?

NERC CIP compliance means meeting the applicable mandatory Critical Infrastructure Protection Reliability Standards for your registered functions and covered systems.

NERC develops Reliability Standards for the Bulk Power System. The Federal Energy Regulatory Commission (FERC) reviews and approves those standards in the United States. NERC and its Regional Entities then perform compliance monitoring and enforcement activities.

The requirements can affect registered:

  • Owners, operators, and users of the Bulk-Power System
  • Generation, transmission, balancing, and reliability functions
  • Entities responsible for covered BES Cyber Systems

NERC registration is function-based. An organization is responsible for requirements applicable to the functions for which it is registered.

That does not mean every electric utility, energy company, or operational technology system falls under NERC CIP.

Applicability can change based on the registered function, facility, system connectivity, and BES Cyber System impact rating.

Tip: For a broader look at cybersecurity for essential services, explore RADICL’s critical infrastructure cybersecurity resources.

How to Use This Checklist

Start by comparing each item with your:

  • Current NERC registration
  • Applicable CIP standard versions
  • BES Cyber System impact ratings
  • Regional Entity guidance
  • Internal policies and procedures
  • Reliability Standard Audit Worksheets (RSAWs)
  • Existing compliance evidence

For each applicable requirement, assign an owner, specify a review frequency, set a due date, and identify the location of the evidence.

Treat the document as a working tracker. Update it when systems, personnel, vendors, facilities, or requirements change.

NERC publishes version-specific Reliability Standard Audit Worksheets (RSAWs) to support compliance assessments. Its current Compliance Monitoring and Enforcement Program resources also include the CIP Evidence Request Tool Version 10, updated in February 2026.

Those resources can help you understand what an auditor may ask for. Your own program still needs to reflect the requirements and environment that apply to your organization.

NERC CIP Compliance Checklist

The following groups organize common NERC CIP requirements by the operational work behind them. Confirm applicability against the current standard before treating any item as required for your environment.

1. Confirm Applicability and Categorize BES Cyber Systems

CIP-002 establishes the foundation for categorizing BES Cyber Systems, and CIP-003 covers security management controls and related responsibilities.

NERC categorizes BES Cyber Systems according to the potential adverse impact of their loss, compromise, or misuse on the reliable operation of BES. Systems meeting applicable criteria are categorized as High, Medium, or Low Impact.

  • Confirm your current NERC registration and applicable registered functions
  • Maintain an accurate inventory of BES assets, Cyber Assets, and supporting systems
  • Identify applicable BES Cyber Systems
  • Categorize BES Cyber Systems using current CIP-002 criteria
  • Document the methodology, assumptions, inclusions, and exclusions behind categorization
  • Retain evidence supporting each impact determination
  • Review categorization following material operational or architecture changes
  • Document the designated CIP Senior Manager and required delegated authorities
  • Maintain required cybersecurity policies and approvals
  • Track exceptions and other approved departures from normal processes

Do not treat Low Impact as “No Impact.” Low impact assets have a different set of applicable requirements.

FERC’s 2025 CIP audit lessons also advised entities to account for Distributed Energy Resources when evaluating Control Center impact ratings.

2. Manage Personnel, Electronic Access, and Physical Access

CIP-004 addresses personnel and training. CIP-005 covers Electronic Security Perimeters, while CIP-006 addresses physical security for applicable BES Cyber Systems.

  • Identify personnel with authorized electronic or physical access
  • Complete applicable personnel risk assessments before granting access
  • Provide required cybersecurity training before authorizing access
  • Maintain recurring training and completion records
  • Review access privileges at the required frequency
  • Revoke access when employment, responsibilities, or authorization changes
  • Define applicable Electronic Security Perimeters
  • Identify and manage Electronic Access Points
  • Document permitted inbound and outbound electronic access
  • Protect Interactive Remote Access
  • Apply required authentication and session protections
  • Monitor relevant remote and privileged access
  • Define applicable Physical Security Perimeters
  • Retain physical access records
  • Investigate unauthorized physical access attempts
  • Complete required physical access control maintenance and testing

The exact architecture can vary. Your controls need to address the requirements applicable to your BES Cyber Systems and their impact level.

3. Secure Systems and Manage Vulnerabilities

CIP-007 focuses on system security management. CIP-010 covers configuration change management and vulnerability assessments.

CIP-010, for example, is designed to prevent and detect unauthorized changes that could contribute to BES Cyber System compromise.

  • Document enabled ports and services with appropriate business justification
  • Maintain a security patch evaluation and installation process
  • Document patch decisions, deferrals, and applicable mitigation measures
  • Maintain required malicious code protections
  • Configure appropriate security event monitoring and log collection
  • Maintain account, password, and authentication controls
  • Establish documented baseline configurations
  • Review and authorize applicable configuration changes
  • Detect and investigate unauthorized configuration changes
  • Conduct required vulnerability assessments
  • Document findings and subsequent remediation or risk treatment
  • Track unsupported and end-of-life systems
  • Manage Transient Cyber Assets and removable media
  • Verify required protections when vendors perform maintenance or assessment activities

FERC’s FY2025 audit lessons reinforce the importance of proving these processes work in practice. Staff highlighted issues related to vulnerability assessments and the third-party execution of compliance tasks.

RADICL’s Managed Attack Surface can help identify vulnerabilities and prioritize remediation work based on risk. RADICL provides detailed remediation guidance, while your team completes the hands-on changes.

Critical infrastructure teams should also stay aware of threats against operational technology. See RADICL’s analysis of Iranian APT actors targeting PLCs.

4. Prepare for Incidents and System Recovery

CIP-008 addresses Cyber Security Incident reporting and response planning. CIP-009 covers recovery planning for BES Cyber Systems.

  • Maintain a documented Cyber Security Incident response plan
  • Define incident classification and escalation criteria
  • Document internal decision-making authority
  • Identify applicable external reporting requirements
  • Maintain current internal and external contact information
  • Exercise or test response plans at the required frequency
  • Document lessons learned from exercises and incidents
  • Update response plans when required
  • Preserve evidence supporting incident classification and reporting decisions
  • Maintain recovery plans for applicable BES Cyber Systems
  • Verify required backups are available and usable
  • Test recovery using representative systems and data
  • Document system dependencies and recovery priorities
  • Update recovery procedures after significant environment changes

Connect your detection, investigation, response, and recovery records.

If an alert turns into an incident, you should be able to show what happened, who evaluated it, what actions followed, and how recovery occurred.

RADICL’s guide to SOC alert triage explains how teams can investigate and prioritize alerts more consistently.

For organizations that need 24/7 detection and response coverage, Managed Detection and Response provides ongoing monitoring across covered environments.

5. Protect Information, Communications, Vendors, and Critical Facilities

CIP-011 through CIP-014 address areas including BES Cyber System Information (BCSI), control center communications, supply chain risk, and physical security.

  • Identify and protect BCSI
  • Document approved BCSI storage, access, transmission, reuse, and disposal processes
  • Identify locations and services where BCSI is stored
  • Maintain procedures for suspected BCSI exposure
  • Protect applicable communications between control centers
  • Maintain required supply chain cybersecurity risk management plans
  • Evaluate vendor access, services, products, and security responsibilities
  • Include appropriate security expectations in applicable agreements
  • Monitor vendors performing compliance-related work
  • Maintain a response plan for relevant vendor compromise or service disruption
  • Complete CIP-014 physical security assessments where applicable
  • Maintain required physical security plans
  • Retain approvals, notifications, reviews, and supporting evidence

Using a third party does not transfer your compliance responsibility.

FERC’s 2025 audit report emphasized this point after identifying cases in which third parties failed to complete assigned activities, and one example involved firewall review work that a vendor did not complete. Another involved required Physical Access Control System testing that a vendor failed to perform on time.

Registered entities remain responsible for oversight and for demonstrating completion of applicable work.

Build and Maintain Audit-Ready Evidence

A mature compliance program can show how requirements translate into daily operations.

One practical approach is an evidence matrix:

Field

What to Track

Standard and requirement

The exact requirement that applies

Owner

Person or team accountable for the process

Process or control

How the requirement is addressed

Frequency

How often the activity must occur

Evidence source

Where proof is generated or stored

Review date

When someone last validated the evidence

Open actions

Exceptions, remediation, or follow-up work

Evidence can include:

  • Asset inventories and categorization records
  • Policies and CIP Senior Manager approvals
  • Access lists and access-review records
  • Training completion reports
  • Firewall and remote-access records
  • Patch evaluations
  • System and security logs
  • Vulnerability assessment results
  • Configuration baselines
  • Incident-response exercise records
  • Recovery and restoration test results
  • Vendor contracts and risk reviews
  • Media handling and disposal records

Review the current RSAW for each applicable standard rather than relying on an older worksheet.

NERC’s 2026 CMEP resources include Version 10 of the CIP Evidence Request Tool. The accompanying Version 10 user guide explains how the tool structures initial and detailed evidence requests for audits and other compliance actions.

Most importantly, make sure the evidence reflects your production environment.

A policy saying you review access regularly does little good if the corresponding reviews cannot be demonstrated.

RADICL’s Managed Log Analytics can maintain visibility into security activity and the log data supporting investigations and operational evidence.

Common NERC CIP Compliance Gaps to Review

Recent FERC audit findings provide useful areas to test before an auditor does. Review whether your program has:

  • Asset categorization that reflects recent operational changes
  • Clear oversight of vendors performing compliance-related work
  • Cloud services that allow you to demonstrate applicable requirements
  • Documented configuration and access changes
  • Complete patch evaluation records
  • Evidence supporting vulnerability assessment work
  • A documented approach to unsupported systems
  • Incident and recovery exercises that reflect real operations
  • Procedures that match what teams actually do
  • Proof of required approvals and follow-up activities

Cloud services deserve particular attention.

FERC reported instances where registered entities could not demonstrate compliance when cloud services performed functions associated with covered Cyber Assets. Challenges included oversight of personnel, baseline configuration information, access to vulnerability assessments, and documented responsibilities with cloud providers.

That does not mean every cloud use case creates noncompliance. It means teams need to evaluate whether the service model allows them to meet and demonstrate each applicable requirement.

FERC’s report also separates potential noncompliance from voluntary cybersecurity recommendations. Treat those categories differently. An audit lesson does not automatically create a new Reliability Standard requirement.

Prepare for Upcoming NERC CIP Changes

Your compliance program needs to account for the standards in force today and the ones coming next.

As of August 2026, NERC lists several revised NERC CIP standards as subject to future enforcement. These include updated versions affecting:

  • BES Cyber System categorization
  • Security management controls
  • Personnel and training
  • Electronic and physical access
  • System security
  • Incident response
  • Recovery
  • Configuration management
  • Information protection
  • Supply chain risk management

Many of these revisions address virtualization and technologies that were difficult to accommodate under earlier CIP language. NERC’s current standards list distinguishes these future versions from the versions organizations must follow today.

CIP-015-1, Cyber Security – Internal Network Security Monitoring, is also listed as subject to future enforcement. It introduces requirements for monitoring applicable networks supporting high-impact BES Cyber Systems and medium-impact systems with External Routable Connectivity.

Maintain a change register containing:

  • Current enforceable versions
  • Approved future versions
  • Applicable implementation dates
  • Regional Entity communications
  • Expected policy changes
  • Technology dependencies
  • New evidence requirements

Verify NERC’s standards page before building implementation plans around any future date.

Make NERC CIP Compliance an Ongoing Process

NERC CIP compliance depends on three connected activities: knowing what applies, operating the required processes, and maintaining evidence that those processes work.

A checklist can help you organize the work. Keeping it current is what makes it useful.

Review the environment whenever systems, personnel, vendors, or architectures change. Connect security operations to compliance evidence. Track upcoming standards before they reach their enforcement dates.

RADICL can support critical infrastructure teams with managed 24/7 monitoring, log analytics, vulnerability prioritization, incident response, and security expertise. The registered entity remains responsible for its NERC CIP applicability and compliance obligations.

Speak with RADICL about strengthening security operations and evidence readiness across your critical infrastructure environment.

FAQs

Who must comply with NERC CIP?

NERC Reliability Standards apply to registered owners, operators, and users of the Bulk-Power System based on the functions they perform. NERC describes Registered Entities as Bulk-Power System users, owners, and operators responsible for specified reliability functions covered by mandatory Reliability Standards.

The specific CIP requirements depend on factors including registered function, assets, connectivity, and BES Cyber System categorization.

For more background, see our upcoming guide to what NERC CIP means.

Does NERC CIP apply to every electric utility?

No. NERC CIP does not automatically apply to every utility, facility, or operational technology system.

Applicability generally centers on registered Bulk-Power System users, owners, and operators and the requirements tied to their functions and covered assets. The federal definition of the Bulk-Power System excludes facilities used in local electric distribution.

Each organization should confirm its status and applicable requirements rather than relying on industry type alone.

What evidence is required for NERC CIP compliance?

The evidence depends on the standard and requirement.

Examples can include asset inventories, policies, approvals, access records, training documentation, patch evaluations, logs, configuration records, vulnerability assessments, incident exercises, recovery testing, and vendor documentation.

NERC publishes RSAWs and a CIP Evidence Request Tool to help entities prepare and organize compliance evidence.

Evidence should demonstrate that the required activity actually occurred.

How often are NERC CIP audits conducted?

There is no single audit interval that applies identically to every registered entity.

NERC uses a risk-based Compliance Monitoring and Enforcement Program. Monitoring can include compliance audits, self-certifications, spot checks, investigations, periodic data submissions, and other processes.

Reliability Coordinators, Balancing Authorities, and Transmission Operators are generally on a minimum three-year audit schedule. Other timing and scope can depend on the entity’s risk profile and Regional Entity oversight.

Get Email Notifications

No Comments Yet

Let us know what you think