NERC CIP Compliance Checklist: Cybersecurity & Physical Security for Bulk Electric Systems
NERC CIP (Critical Infrastructure Protection) standards impose the most stringent — and most expensive — compliance requirements of any regulatory framework in the United States. FERC can impose civil penalties of up to $1,000,000 per violation per day for non-compliance with NERC CIP standards. Duke Energy paid $10 million in penalties in 2019. A Midwest utility paid $2.7 million for violations discovered during a single NERC audit. Unlike most regulatory frameworks where enforcement is complaint-triggered, NERC conducts proactive compliance audits on a scheduled rotation for all registered entities.
This guide covers the core NERC CIP standards (CIP-002 through CIP-013), what FERC auditors and NERC Regional Entities look for during compliance audits, and a practical checklist framework for utilities, generation operators, and grid operators.
Who Must Comply with NERC CIP?
NERC CIP applies to entities registered with NERC that own or operate Bulk Electric System (BES) assets within the continental North American interconnected transmission network. This includes:
- Transmission operators (TOP) and transmission owners (TO)
- Generator operators (GOP) and generator owners (GO) above NERC's registration threshold
- Balancing authorities (BA)
- Reliability coordinators (RC)
- Distribution providers operating BES-classified facilities
- Certain large industrial customers with high-voltage connections
The specific standards applicable to each registered entity depend on the entity type and the impact classification of its BES Cyber Systems.
CIP-002 — BES Cyber System Categorization
CIP-002 is the foundation of the entire CIP compliance framework — because how you categorize your assets determines which requirements apply to them. Entities must identify all BES Cyber Systems (BCS) and categorize them as High, Medium, or Low impact based on their potential to adversely affect the reliable operation of the BES if compromised.
High impact BCS typically include Control Centers with real-time monitoring and control capability over the BES at the transmission level, 500 kV or above substations, and associated cyber assets.
Medium impact BCS typically includes 200 kV or above substations, Control Centers with authority to commit generation, and other systems meeting the criteria in Attachment 1 of CIP-002.
Low impact BCS includes BCS not meeting High or Medium criteria but still associated with BES assets — these have the lightest compliance requirements but are still subject to CIP-003 Attachment 1 requirements.
Audit focus: Is the asset inventory complete? Were any newly commissioned assets added to the categorization on time? When was the annual review completed? Were any changes to the BES — new substation equipment, new control system — reflected in updated categorizations? Auditors frequently find that facilities failed to update categorizations after modifications to the BES or its control systems.
Compliance checklist:
- BES Cyber System inventory complete, documented, and reviewed at least annually
- Categorization methodology documented; all BCS classified as High, Medium, or Low with rationale
- Any newly commissioned BES assets identified and categorized within 30 days of commissioning
- Documentation retained for at least three calendar years (the standard audit lookback period)
CIP-004 — Personnel and Training
All personnel with authorized physical or electronic access to BES Cyber Systems must complete cybersecurity awareness training at least quarterly and role-based training before access is authorized (or within 90 days of implementation for initial compliance). Background investigations (criminal history check, identity verification) are required for all personnel with access to High and Medium impact BCS and their associated Physical Security Perimeters (PSPs).
Audit focus: Is there a list of all authorized individuals? Are training records complete and current for all of them? Is training documented before access was granted? Did any contractors receive access before completing required background checks? Quarterly awareness training records are a common gap — entities track initial training but miss the quarterly cadence.
Compliance checklist:
- Quarterly cybersecurity awareness training records for all personnel with BCS access
- Role-based training completed and documented before access authorization for each individual
- Background investigation records for all personnel with access to High/Medium BCS
- Access authorization list current; revoked within 24 hours of personnel departure
- Quarterly access reviews: verify all currently authorized individuals are still eligible
CIP-005 — Electronic Security Perimeters
Entities must define and document Electronic Security Perimeters (ESPs) around all High and Medium impact BCS. All ingress and egress to the ESP must be through documented Electronic Access Points (EAPs). All interactive remote access must use encrypted communications and multi-factor authentication (MFA). Dial-up access is prohibited without compensating controls.
Audit focus: Is the ESP boundary accurately documented and does it match the actual network architecture? Are all EAPs identified — including legacy remote access paths that may have been installed before CIP-005 was adopted? Is MFA implemented for all interactive remote access, including vendor connections? One of the most frequent CIP-005 violations is undocumented or overlooked access paths — dial-up connections, jump servers, or vendor VPN accounts that were set up for convenience and never incorporated into the ESP documentation.
Compliance checklist:
- ESP documentation current and reviewed after any network change
- All EAPs identified; each EAP uses deny-by-default access control (least privilege)
- Interactive remote access: encrypted (TLS 1.2 or higher) with MFA for all connections
- No direct internet connections exist within or passing through the ESP boundary
- Security event logging at all EAPs; alerts reviewed within 15 calendar days
- Annual ESP review to confirm all access paths are identified and documented
CIP-006 — Physical Security of BES Cyber Systems
Entities must document Physical Security Plans that define Physical Security Perimeters (PSPs) around High and Medium impact BCS. Access to PSPs must be controlled, monitored, and logged. Visitors must be escorted within PSPs for High impact facilities. PSPs must be tested for integrity at defined intervals.
Compliance checklist:
- Physical Security Plan documented; PSP boundaries defined with controlled access points identified
- Electronic access control (badge readers, PIN pads) at all PSP entry points
- Physical access monitoring (CCTV or equivalent) at High impact PSPs
- Visitor log maintained: name, purpose, time in/out, escort identification
- Physical access logs reviewed within 15 calendar days of generation
- Physical security testing completed annually; results documented with deficiencies resolved
- Alarms on all PSP access points; alarm response procedures documented and tested
CIP-007 — Systems Security Management
CIP-007 is where the technical cyber controls are specified: ports and services management, patch management, malicious code prevention, security event monitoring, and system access controls. This standard generates the most violations in NERC enforcement actions, primarily because of patch management failures.
Audit focus: Patch management is the most-cited CIP-007 gap. Entities must assess and apply or document mitigation for all applicable security patches within 35 days of availability (for High and Medium impact BCS). NERC auditors request the patch assessment log and verify each patch was either applied within 35 days or has a documented, accepted mitigation for deferral. A single missed patch deadline is a violation. Entities with large populations of legacy ICS/SCADA equipment struggle because vendors are slow to release patches or patches cannot be applied without taking critical systems offline.
Compliance checklist:
- All enabled ports and services on BCS documented and justified as necessary
- Patch management program: security patches assessed within 35 days; applied or mitigation documented
- Antivirus or alternative malicious code prevention deployed; signatures updated automatically where possible
- Security event logging enabled on all BCS; log retention meets CIP-007 R4 requirements
- Logs reviewed at least every 15 calendar days; alerts actioned and documented
- Failed login attempts generate alerts; alert review process documented
- No shared accounts on BCS; each user individually authenticated
CIP-010 — Configuration Change Management and Vulnerability Management
CIP-010 requires baseline configurations for all High and Medium impact BCS, documented change management for all changes to those baselines, and regular vulnerability assessments to identify potential vulnerabilities. Transient cyber assets (laptops, USB drives) that connect to BCS must be protected and managed.
Compliance checklist:
- Baseline configurations documented for all High and Medium impact BCS within 30 days of commissioning
- All changes to BCS go through documented change management; unauthorized changes detected through monitoring
- Vulnerability assessments completed at least every 15 months (paper-based assessment)
- Active vulnerability assessment (network port scan or equivalent) completed at least every 36 months
- Transient cyber asset policy: authorized devices listed; protective measures documented and verified
- CIP Senior Manager approval for any deviations from transient device policy
CIP-013 — Supply Chain Risk Management
Added to the standards suite with mandatory compliance effective July 1, 2020, CIP-013 requires supply chain risk management plans that address cyber security risks in the supply chain for hardware, software, and services associated with BES Cyber Systems. This is an increasingly enforced standard as supply chain attacks against critical infrastructure have become a top national security priority.
Compliance checklist:
- Supply chain risk management plan approved by CIP Senior Manager; reviewed every 15 months
- Vendor risk assessment process for new hardware and software acquisitions affecting BCS
- Software integrity verification methods in place for software updates from vendors
- Documented process to receive and respond to vendor notifications of software vulnerabilities
- Vendor access controls reviewed; vendor remote access terminated when no longer needed
How POPProbe Supports NERC CIP Compliance
POPProbe's NERC CIP checklists cover the key evidence requirements for CIP-002 through CIP-013, giving compliance teams a systematic way to verify controls are in place and generate audit-ready documentation. Digital checklists with timestamps, named reviewers, and evidence attachments match the documentation format NERC Regional Entity auditors expect to review during compliance audits.
Access NERC CIP compliance checklists in our regulatory compliance checklist hub, including BES Cyber System categorization templates, physical security plan audit forms, electronic security perimeter review checklists, and the CIP-007 systems security management audit in the checklist library.
Conclusion
NERC CIP compliance at a large utility is a multi-year program requiring dedicated compliance staff, systematic evidence collection, and continuous monitoring. The entities that perform best in NERC audits are those that treat compliance not as a documentation exercise but as a genuine security program — maintaining accurate asset inventories, applying patches on schedule, reviewing access logs, and testing physical security. The financial exposure ($1M/day per violation) makes robust compliance programs not just a regulatory obligation but a sound business investment.