On April 1, 2026, CIP-003-9 became enforceable and added a sixth section to Attachment 1: vendor electronic remote access security controls for assets containing low impact BES Cyber Systems. For many generator owners, co-ops and municipal utilities, it is the first CIP requirement that reaches directly into how their vendors work.
This guide walks through what Section 6 asks for and how to turn it into a plan you can prove.
What Section 6 requires
For each asset containing low impact BES Cyber Systems where vendors have electronic remote access, your plan must include:
- One or more methods to determine vendor electronic remote access, meaning you can tell when a vendor is connected.
- One or more methods to disable vendor electronic remote access, meaning you can cut it off.
- One or more methods to detect known or suspected malicious communications for both inbound and outbound vendor electronic remote access.
The standard is objective-based. It does not name a product or architecture. That flexibility is useful, but it also means the burden is on you to explain why your methods work.
Step 1: find every vendor path
Most findings start with a path nobody knew about. Walk each site and ask:
- Does an OEM have a cellular modem or gateway for remote diagnostics (common at solar, wind and battery sites)?
- Does an integrator or O&M contractor use a site-to-site VPN or a remote desktop tool?
- Are there dial-up or out-of-band connections to relays or controllers?
- Does a vendor manage the firewall itself, and can they reach it remotely?
- Are there cloud-connected monitoring platforms with a return path into the plant network?
Record each path with the asset, the vendor, the technology and the business reason.
Step 2: choose methods you can demonstrate
| Obligation | Example methods |
|---|---|
| Determine | Firewall or VPN session logs, a remote access gateway that shows active sessions, alerts when a vendor account logs in, a documented request-and-approve process |
| Disable | Firewall rule or VPN account disabled on demand, physically disconnecting a modem, a remote access gateway “kill session” function |
| Detect malicious communications | IDS/IPS signatures at the access point, firewall threat prevention, monitored logs with alerting, a managed security service watching the connection |
Pick methods that match the site. A single cellular gateway might be handled by keeping it powered off until a vendor requests access, with the request logged. A site with permanent vendor monitoring may need an intrusion detection capability at its access point.
Step 3: write it into the plan
Add Section 6 to your low impact plan (CIP-003-9 R2), per asset or asset group. For each path, record which method covers determine, disable and detect, and who is responsible. Keep it short and specific. Auditors prefer a table they can test to pages of generic language.
Step 4: collect evidence as you go
Evidence that tends to satisfy auditors:
- configuration exports showing the relevant rules and settings, with dates;
- session logs showing vendor connections being recorded;
- a record of at least one test where access was disabled on demand;
- alert samples or monitoring reports for malicious communication detection.
Step 5: keep it current
Vendor relationships change. Add a check to your change process: when a new vendor, service contract or remote connection appears, update the Section 6 inventory. Reinforce the process in your 15-month security awareness cycle.
What comes next: CIP-003-11
FERC approved CIP-003-11 in March 2026 (Order No. 918). It takes effect July 1, 2029 and adds further low impact controls aimed at coordinated attacks across many sites. A well-structured Section 6 inventory now will make that update much easier.
CIP Sentry’s Policy & Low Impact module builds the Attachment 1 plan section by section, including Section 6, and tracks the 15-month and 36-month clocks that go with it. See how it works.

