NERC CIP standards

Every CIP standard, in plain English.

Current versions, what each requirement asks for, the recurring deadlines behind them and the evidence auditors expect. Reviewed against nerc.com every quarter.

What’s changing

The CIP timeline through 2030

FERC’s 2025 and 2026 orders set a busy calendar. Here is what is already in force and what is coming.

  1. Apr 1, 2026

    CIP-003-9 in force

    Low impact vendor electronic remote access controls (Attachment 1 Section 6)

  2. Jul 1, 2026

    CIP-012-2 in force

    Adds availability and link recovery to Control Center communication plans

  3. Oct 1, 2028

    CIP-015-1 phase 1

    INSM for high impact and medium impact with ERC at Control Centers

  4. Jul 1, 2029

    CIP-003-11

    Further low impact controls against coordinated attacks (FERC Order No. 918)

  5. Oct 1, 2029

    CIP-015-2

    INSM extended to EACMS and PACS outside the ESP

  6. Oct 1, 2030

    CIP-015 phase 2

    Remaining medium impact BES Cyber Systems with ERC

At a glance

Enforceable versions today

StandardTitleEnforceable nowNext version
CIP-002BES Cyber System CategorizationCIP-002-5.1a (effective December 27, 2016)CIP-002-8 (July 1, 2028) with the virtualization package
CIP-003Security Management ControlsCIP-003-9 (effective April 1, 2026)CIP-003-10 (July 1, 2028), then CIP-003-11 (July 1, 2029)
CIP-004Personnel & TrainingCIP-004-7 (effective January 1, 2024)CIP-004-8 (July 1, 2028) with the virtualization package
CIP-005Electronic Security Perimeter(s)CIP-005-7 (effective October 1, 2022)CIP-005-8 “BES Cyber System Logical Isolation” (July 1, 2028)
CIP-006Physical Security of BES Cyber SystemsCIP-006-6 (effective July 1, 2016)CIP-006-7.1 (July 1, 2028) with the virtualization package
CIP-007System Security ManagementCIP-007-6 (effective July 1, 2016)CIP-007-7.1 (July 1, 2028) with the virtualization package
CIP-008Incident Reporting and Response PlanningCIP-008-6 (effective January 1, 2021)CIP-008-7.1 (July 1, 2028) with the virtualization package
CIP-009Recovery Plans for BES Cyber SystemsCIP-009-6 (effective July 1, 2016)CIP-009-7.1 (July 1, 2028) with the virtualization package
CIP-010Configuration Change Management and Vulnerability AssessmentsCIP-010-4 (effective October 1, 2022)CIP-010-5 (July 1, 2028) with the virtualization package
CIP-011Information ProtectionCIP-011-3 (effective January 1, 2024)CIP-011-4.1 (July 1, 2028) with the virtualization package
CIP-012Communications between Control CentersCIP-012-2 (effective July 1, 2026)—
CIP-013Supply Chain Risk ManagementCIP-013-2 (effective October 1, 2022)CIP-013-3 (July 1, 2028); CIP-013-4 in development after FERC Order No. 912
CIP-014Physical SecurityCIP-014-3 (effective June 16, 2022)CIP-014-4 (filed with FERC; effective 24 months after approval)
CIP-015Internal Network Security MonitoringNot yet enforceable. CIP-015-1 phase 1 begins October 1, 2028CIP-015-2 (October 1, 2029) extends INSM to EACMS and PACS outside the ESP

Source: NERC standards list and FERC orders, reviewed September 30, 2026. Always confirm on nerc.com.

Request a quote

See CIP Sentry on your own terms.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.