NERC CIP standards
Every CIP standard, in plain English.
Current versions, what each requirement asks for, the recurring deadlines behind them and the evidence auditors expect. Reviewed against nerc.com every quarter.
- CIP-002BES Cyber System CategorizationRate every BES Cyber System high, medium or low impact and keep the list current.Read the guide
- CIP-003Security Management ControlsPolicies, CIP Senior Manager approvals and a low impact plan that stays reviewed.Read the guide
- CIP-004Personnel & TrainingTraining, personnel risk assessments, access authorization and timely revocation.Read the guide
- CIP-005Electronic Security Perimeter(s)Document ESPs, access points and interactive remote access controls.Read the guide
- CIP-006Physical Security of BES Cyber SystemsPhysical security plans, visitor control and PACS maintenance and testing.Read the guide
- CIP-007System Security ManagementPorts and services, 35-day patch cycles, malware, logging and accounts.Read the guide
- CIP-008Incident Reporting and Response PlanningResponse plans, reportable incident handling and 15-month plan tests.Read the guide
- CIP-009Recovery Plans for BES Cyber SystemsRecovery plans, backup verification and exercised restoration.Read the guide
- CIP-010Configuration Change Management and Vulnerability AssessmentsBaselines, authorized changes, 35-day monitoring and vulnerability assessments.Read the guide
- CIP-011Information ProtectionIdentify, protect and dispose of BES Cyber System Information correctly.Read the guide
- CIP-012Communications between Control CentersProtect real-time assessment and monitoring data between control centers.Read the guide
- CIP-013Supply Chain Risk ManagementVendor risk plans, procurement controls and 15-month plan approval.Read the guide
- CIP-014Physical SecurityTransmission risk assessments, third-party verification and security plans.Read the guide
- CIP-015Internal Network Security MonitoringPlan, collect, evaluate and retain INSM data inside the ESP.Read the guide Enforceable Oct 2028
What’s changing
The CIP timeline through 2030
FERC’s 2025 and 2026 orders set a busy calendar. Here is what is already in force and what is coming.
- Apr 1, 2026
CIP-003-9 in force
Low impact vendor electronic remote access controls (Attachment 1 Section 6)
- Jul 1, 2026
CIP-012-2 in force
Adds availability and link recovery to Control Center communication plans
- Jul 1, 2028
Virtualization package
CIP-002-7/-8, CIP-003-10, CIP-004-8, CIP-005-8, CIP-006-7.1, CIP-007-7.1, CIP-008-7.1, CIP-009-7.1, CIP-010-5, CIP-011-4.1, CIP-013-3
- Oct 1, 2028
CIP-015-1 phase 1
INSM for high impact and medium impact with ERC at Control Centers
- Jul 1, 2029
CIP-003-11
Further low impact controls against coordinated attacks (FERC Order No. 918)
- Oct 1, 2029
CIP-015-2
INSM extended to EACMS and PACS outside the ESP
- Oct 1, 2030
CIP-015 phase 2
Remaining medium impact BES Cyber Systems with ERC
At a glance
Enforceable versions today
| Standard | Title | Enforceable now | Next version |
|---|---|---|---|
| CIP-002 | BES Cyber System Categorization | CIP-002-5.1a (effective December 27, 2016) | CIP-002-8 (July 1, 2028) with the virtualization package |
| CIP-003 | Security Management Controls | CIP-003-9 (effective April 1, 2026) | CIP-003-10 (July 1, 2028), then CIP-003-11 (July 1, 2029) |
| CIP-004 | Personnel & Training | CIP-004-7 (effective January 1, 2024) | CIP-004-8 (July 1, 2028) with the virtualization package |
| CIP-005 | Electronic Security Perimeter(s) | CIP-005-7 (effective October 1, 2022) | CIP-005-8 “BES Cyber System Logical Isolation” (July 1, 2028) |
| CIP-006 | Physical Security of BES Cyber Systems | CIP-006-6 (effective July 1, 2016) | CIP-006-7.1 (July 1, 2028) with the virtualization package |
| CIP-007 | System Security Management | CIP-007-6 (effective July 1, 2016) | CIP-007-7.1 (July 1, 2028) with the virtualization package |
| CIP-008 | Incident Reporting and Response Planning | CIP-008-6 (effective January 1, 2021) | CIP-008-7.1 (July 1, 2028) with the virtualization package |
| CIP-009 | Recovery Plans for BES Cyber Systems | CIP-009-6 (effective July 1, 2016) | CIP-009-7.1 (July 1, 2028) with the virtualization package |
| CIP-010 | Configuration Change Management and Vulnerability Assessments | CIP-010-4 (effective October 1, 2022) | CIP-010-5 (July 1, 2028) with the virtualization package |
| CIP-011 | Information Protection | CIP-011-3 (effective January 1, 2024) | CIP-011-4.1 (July 1, 2028) with the virtualization package |
| CIP-012 | Communications between Control Centers | CIP-012-2 (effective July 1, 2026) | — |
| CIP-013 | Supply Chain Risk Management | CIP-013-2 (effective October 1, 2022) | CIP-013-3 (July 1, 2028); CIP-013-4 in development after FERC Order No. 912 |
| CIP-014 | Physical Security | CIP-014-3 (effective June 16, 2022) | CIP-014-4 (filed with FERC; effective 24 months after approval) |
| CIP-015 | Internal Network Security Monitoring | Not yet enforceable. CIP-015-1 phase 1 begins October 1, 2028 | CIP-015-2 (October 1, 2029) extends INSM to EACMS and PACS outside the ESP |
Source: NERC standards list and FERC orders, reviewed September 30, 2026. Always confirm on nerc.com.
Request a quote
See CIP Sentry on your own terms.
Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.

