CIP-009 · Recovery Plans for BES Cyber Systems

CIP-009: prove you can bring systems back.

CIP-009 requires documented recovery plans for BES Cyber Systems, backups that are actually verified, tests every 15 months, and plan updates within 90 days of each test or recovery.

Enforceable nowCIP-009-6 (effective July 1, 2016)
Next versionCIP-009-7.1 (July 1, 2028) with the virtualization package
Applies toHigh impact and medium impact BES Cyber Systems and associated EACMS and PACS

Requirements at a glance

R1

Recovery plan specifications

Recovery plans must define the conditions for activation, roles and responsibilities, processes for backup and storage of information needed to recover, processes to verify successful backups, and processes to preserve data for determining the cause of a Cyber Security Incident.

R2

Implementation and testing

Test each plan at least once every 15 calendar months (actual recovery, paper drill/tabletop, or operational exercise); test a representative sample of backup information every 15 months; and for high impact systems, perform an operational exercise at least once every 36 calendar months.

R3

Review, update and communicate

Within 90 calendar days of a recovery test or actual recovery, document lessons learned, update the plan and notify people with roles. Within 60 days of changes to roles, groups or technology, update the plan and notify them.

Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.

Recurring deadlines

ObligationIntervalRequirementIn CIP Sentry
Test each recovery plan15 calendar monthsCIP-009-6 R2.1Auto-tracked
Test a representative sample of backup information15 calendar monthsCIP-009-6 R2.2Auto-tracked
Operational exercise of the recovery plan (high impact)36 calendar monthsCIP-009-6 R2.3Auto-tracked
Lessons learned and plan update after a test or recovery90 calendar daysCIP-009-6 R3.1Auto-tracked
Update plan after role or technology changes60 calendar daysCIP-009-6 R3.2

Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines

Recovery plans that work on a bad day

Auditors increasingly ask whether a plan would really work, not just whether it exists. Make sure it names who does what, where the backups live, how to get installation media and licenses, and how to rebuild a system to its CIP-010 baseline. Store a copy where it can be reached if the network is down.

Testing backups, not just taking them

A representative sample restore every 15 months proves your backups are usable. Pick systems that are hard to rebuild, restore them to a test environment, compare them to the baseline, and write down what you learned.

High impact operational exercises

For high impact systems, an operational exercise at least once every 36 months means actually performing recovery steps in a representative environment, not only talking through them.

Evidence auditors typically ask for

  • Recovery plans covering each R1 part for each applicable system or group
  • Backup procedures and records verifying backups completed successfully
  • Dated records of plan tests and backup sample restoration tests
  • Operational exercise records for high impact systems every 36 months
  • Lessons learned, plan updates and notifications within 90 days

How CIP Sentry helps with CIP-009

Plans with their own clocks

Each recovery plan carries its 15-month test and, for high impact, the 36-month operational exercise.

Lessons learned tracked

Tests and actual recoveries open a 90-day lessons-learned clock that closes only when the plan is updated.

Connected records

Recovery plans link to the BES Cyber Systems they cover and to CIP-008 incidents and CIP-012 recovery methods.

Practice what you preach

CIP Sentry itself backs up its database nightly and before every update, and the restore steps are documented.

CIP-009 FAQ

Is a backup job's success message enough?

Usually not. R1.4 asks for a process to verify that backups complete successfully and address failures, and R2.2 requires restoring a representative sample of backup information to prove it is usable.

Can the CIP-008 tabletop also test CIP-009?

Many entities combine them. If the exercise covers recovery steps and you document it against both plans, it can serve as evidence for both, as long as each standard's requirements are clearly met.

Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

Related standards

Request a quote

Run CIP-009 without the spreadsheet.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.