NERC CIP compliance touches far more than your security tools. It involves asset categorization, access, physical security, training, incident response, recovery, vendor oversight, and the evidence behind each process.
This NERC CIP compliance checklist brings those activities into one place. Use it to review your program, assign ownership, and identify areas that may need attention.
The North American Electric Reliability Corporation (NERC) maintains separate lists for Critical Infrastructure Protection (CIP) standards currently subject to enforcement and versions subject to future enforcement. Those lists continue to change, so confirm the current version before applying any requirement.
This checklist is a planning aid. Your registered functions, assets, connectivity, and Bulk Electric System (BES) Cyber System impact ratings determine which requirements apply.
Key Takeaways
|
NERC CIP compliance means meeting the applicable mandatory Critical Infrastructure Protection Reliability Standards for your registered functions and covered systems.
NERC develops Reliability Standards for the Bulk Power System. The Federal Energy Regulatory Commission (FERC) reviews and approves those standards in the United States. NERC and its Regional Entities then perform compliance monitoring and enforcement activities.
The requirements can affect registered:
NERC registration is function-based. An organization is responsible for requirements applicable to the functions for which it is registered.
That does not mean every electric utility, energy company, or operational technology system falls under NERC CIP.
Applicability can change based on the registered function, facility, system connectivity, and BES Cyber System impact rating.
Tip: For a broader look at cybersecurity for essential services, explore RADICL’s critical infrastructure cybersecurity resources.
Start by comparing each item with your:
For each applicable requirement, assign an owner, specify a review frequency, set a due date, and identify the location of the evidence.
Treat the document as a working tracker. Update it when systems, personnel, vendors, facilities, or requirements change.
NERC publishes version-specific Reliability Standard Audit Worksheets (RSAWs) to support compliance assessments. Its current Compliance Monitoring and Enforcement Program resources also include the CIP Evidence Request Tool Version 10, updated in February 2026.
Those resources can help you understand what an auditor may ask for. Your own program still needs to reflect the requirements and environment that apply to your organization.
The following groups organize common NERC CIP requirements by the operational work behind them. Confirm applicability against the current standard before treating any item as required for your environment.
CIP-002 establishes the foundation for categorizing BES Cyber Systems, and CIP-003 covers security management controls and related responsibilities.
NERC categorizes BES Cyber Systems according to the potential adverse impact of their loss, compromise, or misuse on the reliable operation of BES. Systems meeting applicable criteria are categorized as High, Medium, or Low Impact.
Do not treat Low Impact as “No Impact.” Low impact assets have a different set of applicable requirements.
FERC’s 2025 CIP audit lessons also advised entities to account for Distributed Energy Resources when evaluating Control Center impact ratings.
CIP-004 addresses personnel and training. CIP-005 covers Electronic Security Perimeters, while CIP-006 addresses physical security for applicable BES Cyber Systems.
The exact architecture can vary. Your controls need to address the requirements applicable to your BES Cyber Systems and their impact level.
CIP-007 focuses on system security management. CIP-010 covers configuration change management and vulnerability assessments.
CIP-010, for example, is designed to prevent and detect unauthorized changes that could contribute to BES Cyber System compromise.
FERC’s FY2025 audit lessons reinforce the importance of proving these processes work in practice. Staff highlighted issues related to vulnerability assessments and the third-party execution of compliance tasks.
RADICL’s Managed Attack Surface can help identify vulnerabilities and prioritize remediation work based on risk. RADICL provides detailed remediation guidance, while your team completes the hands-on changes.
Critical infrastructure teams should also stay aware of threats against operational technology. See RADICL’s analysis of Iranian APT actors targeting PLCs.
CIP-008 addresses Cyber Security Incident reporting and response planning. CIP-009 covers recovery planning for BES Cyber Systems.
Connect your detection, investigation, response, and recovery records.
If an alert turns into an incident, you should be able to show what happened, who evaluated it, what actions followed, and how recovery occurred.
RADICL’s guide to SOC alert triage explains how teams can investigate and prioritize alerts more consistently.
For organizations that need 24/7 detection and response coverage, Managed Detection and Response provides ongoing monitoring across covered environments.
CIP-011 through CIP-014 address areas including BES Cyber System Information (BCSI), control center communications, supply chain risk, and physical security.
Using a third party does not transfer your compliance responsibility.
FERC’s 2025 audit report emphasized this point after identifying cases in which third parties failed to complete assigned activities, and one example involved firewall review work that a vendor did not complete. Another involved required Physical Access Control System testing that a vendor failed to perform on time.
Registered entities remain responsible for oversight and for demonstrating completion of applicable work.
A mature compliance program can show how requirements translate into daily operations.
One practical approach is an evidence matrix:
|
Field |
What to Track |
|
Standard and requirement |
The exact requirement that applies |
|
Owner |
Person or team accountable for the process |
|
Process or control |
How the requirement is addressed |
|
Frequency |
How often the activity must occur |
|
Evidence source |
Where proof is generated or stored |
|
Review date |
When someone last validated the evidence |
|
Open actions |
Exceptions, remediation, or follow-up work |
Evidence can include:
Review the current RSAW for each applicable standard rather than relying on an older worksheet.
NERC’s 2026 CMEP resources include Version 10 of the CIP Evidence Request Tool. The accompanying Version 10 user guide explains how the tool structures initial and detailed evidence requests for audits and other compliance actions.
Most importantly, make sure the evidence reflects your production environment.
A policy saying you review access regularly does little good if the corresponding reviews cannot be demonstrated.
RADICL’s Managed Log Analytics can maintain visibility into security activity and the log data supporting investigations and operational evidence.
Recent FERC audit findings provide useful areas to test before an auditor does. Review whether your program has:
Cloud services deserve particular attention.
FERC reported instances where registered entities could not demonstrate compliance when cloud services performed functions associated with covered Cyber Assets. Challenges included oversight of personnel, baseline configuration information, access to vulnerability assessments, and documented responsibilities with cloud providers.
That does not mean every cloud use case creates noncompliance. It means teams need to evaluate whether the service model allows them to meet and demonstrate each applicable requirement.
FERC’s report also separates potential noncompliance from voluntary cybersecurity recommendations. Treat those categories differently. An audit lesson does not automatically create a new Reliability Standard requirement.
Your compliance program needs to account for the standards in force today and the ones coming next.
As of August 2026, NERC lists several revised NERC CIP standards as subject to future enforcement. These include updated versions affecting:
Many of these revisions address virtualization and technologies that were difficult to accommodate under earlier CIP language. NERC’s current standards list distinguishes these future versions from the versions organizations must follow today.
CIP-015-1, Cyber Security – Internal Network Security Monitoring, is also listed as subject to future enforcement. It introduces requirements for monitoring applicable networks supporting high-impact BES Cyber Systems and medium-impact systems with External Routable Connectivity.
Maintain a change register containing:
Verify NERC’s standards page before building implementation plans around any future date.
NERC CIP compliance depends on three connected activities: knowing what applies, operating the required processes, and maintaining evidence that those processes work.
A checklist can help you organize the work. Keeping it current is what makes it useful.
Review the environment whenever systems, personnel, vendors, or architectures change. Connect security operations to compliance evidence. Track upcoming standards before they reach their enforcement dates.
RADICL can support critical infrastructure teams with managed 24/7 monitoring, log analytics, vulnerability prioritization, incident response, and security expertise. The registered entity remains responsible for its NERC CIP applicability and compliance obligations.
Speak with RADICL about strengthening security operations and evidence readiness across your critical infrastructure environment.
NERC Reliability Standards apply to registered owners, operators, and users of the Bulk-Power System based on the functions they perform. NERC describes Registered Entities as Bulk-Power System users, owners, and operators responsible for specified reliability functions covered by mandatory Reliability Standards.
The specific CIP requirements depend on factors including registered function, assets, connectivity, and BES Cyber System categorization.
For more background, see our upcoming guide to what NERC CIP means.
No. NERC CIP does not automatically apply to every utility, facility, or operational technology system.
Applicability generally centers on registered Bulk-Power System users, owners, and operators and the requirements tied to their functions and covered assets. The federal definition of the Bulk-Power System excludes facilities used in local electric distribution.
Each organization should confirm its status and applicable requirements rather than relying on industry type alone.
The evidence depends on the standard and requirement.
Examples can include asset inventories, policies, approvals, access records, training documentation, patch evaluations, logs, configuration records, vulnerability assessments, incident exercises, recovery testing, and vendor documentation.
NERC publishes RSAWs and a CIP Evidence Request Tool to help entities prepare and organize compliance evidence.
Evidence should demonstrate that the required activity actually occurred.
There is no single audit interval that applies identically to every registered entity.
NERC uses a risk-based Compliance Monitoring and Enforcement Program. Monitoring can include compliance audits, self-certifications, spot checks, investigations, periodic data submissions, and other processes.
Reliability Coordinators, Balancing Authorities, and Transmission Operators are generally on a minimum three-year audit schedule. Other timing and scope can depend on the entity’s risk profile and Regional Entity oversight.