CIP-003

CIP-003-9 vendor remote access: a practical guide for low impact sites

Since April 1, 2026, CIP-003-9 Attachment 1 Section 6 requires low impact entities to determine, disable and monitor vendor electronic remote access. Here is how to build a plan that holds up in an audit.

· 7 min read · CIP Sentry

On April 1, 2026, CIP-003-9 became enforceable and added a sixth section to Attachment 1: vendor electronic remote access security controls for assets containing low impact BES Cyber Systems. For many generator owners, co-ops and municipal utilities, it is the first CIP requirement that reaches directly into how their vendors work.

This guide walks through what Section 6 asks for and how to turn it into a plan you can prove.

What Section 6 requires

For each asset containing low impact BES Cyber Systems where vendors have electronic remote access, your plan must include:

  1. One or more methods to determine vendor electronic remote access, meaning you can tell when a vendor is connected.
  2. One or more methods to disable vendor electronic remote access, meaning you can cut it off.
  3. One or more methods to detect known or suspected malicious communications for both inbound and outbound vendor electronic remote access.

The standard is objective-based. It does not name a product or architecture. That flexibility is useful, but it also means the burden is on you to explain why your methods work.

Step 1: find every vendor path

Most findings start with a path nobody knew about. Walk each site and ask:

Record each path with the asset, the vendor, the technology and the business reason.

Step 2: choose methods you can demonstrate

Obligation Example methods
Determine Firewall or VPN session logs, a remote access gateway that shows active sessions, alerts when a vendor account logs in, a documented request-and-approve process
Disable Firewall rule or VPN account disabled on demand, physically disconnecting a modem, a remote access gateway “kill session” function
Detect malicious communications IDS/IPS signatures at the access point, firewall threat prevention, monitored logs with alerting, a managed security service watching the connection

Pick methods that match the site. A single cellular gateway might be handled by keeping it powered off until a vendor requests access, with the request logged. A site with permanent vendor monitoring may need an intrusion detection capability at its access point.

Step 3: write it into the plan

Add Section 6 to your low impact plan (CIP-003-9 R2), per asset or asset group. For each path, record which method covers determine, disable and detect, and who is responsible. Keep it short and specific. Auditors prefer a table they can test to pages of generic language.

Step 4: collect evidence as you go

Evidence that tends to satisfy auditors:

Step 5: keep it current

Vendor relationships change. Add a check to your change process: when a new vendor, service contract or remote connection appears, update the Section 6 inventory. Reinforce the process in your 15-month security awareness cycle.

What comes next: CIP-003-11

FERC approved CIP-003-11 in March 2026 (Order No. 918). It takes effect July 1, 2029 and adds further low impact controls aimed at coordinated attacks across many sites. A well-structured Section 6 inventory now will make that update much easier.


CIP Sentry’s Policy & Low Impact module builds the Attachment 1 plan section by section, including Section 6, and tracks the 15-month and 36-month clocks that go with it. See how it works.

Request a quote

See CIP Sentry on your own terms.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.