CIP-012 · Communications between Control Centers

CIP-012: protect real-time data moving between Control Centers.

CIP-012-2 took effect on July 1, 2026. It requires a documented plan to protect real-time assessment and real-time monitoring data sent between Control Centers against unauthorized disclosure, modification and, new in version 2, loss of availability.

Enforceable nowCIP-012-2 (effective July 1, 2026)
Applies toResponsible Entities that own or operate a Control Center (BAs, GOs, GOPs, RCs, TOs and TOPs), regardless of BES Cyber System impact rating

Requirements at a glance

R1

Documented plan(s) for data between Control Centers

Implement one or more documented plans to mitigate the risks posed by unauthorized disclosure, unauthorized modification and loss of availability of Real-time Assessment and Real-time monitoring data while it is transmitted between Control Centers (oral communications excluded, CIP Exceptional Circumstances excepted).

R1.1

Protection against disclosure and modification

Identify the method(s) used to mitigate unauthorized disclosure and modification of the data.

R1.2

Protection of availability

Identify the method(s) used to mitigate the loss of availability of the data (new in CIP-012-2).

R1.3

Recovery of communication links

Identify the method(s) used to initiate the recovery of communication links used to transmit the data.

R1.4

Where the protection is applied

Identify where the R1.1 and R1.2 methods are implemented.

R1.5

Shared responsibilities

Where Control Centers are owned or operated by different entities, identify each entity's responsibilities for applying the methods.

Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.

New obligations as of July 2026

CIP-012-2 is one of the newest enforceable CIP requirements. If your plan was written for CIP-012-1, it probably covers confidentiality and integrity but not availability and recovery. Review each link: what happens if the primary path fails, how do you know, and how is recovery started?

Start with an inventory: every Control Center pair that exchanges real-time assessment or monitoring data (ICCP links to your RC or neighboring TOP, SCADA data to a backup Control Center, and so on). For each link, record the path, who owns each end and each segment, and the protection in place.

Shared responsibility

When the other end belongs to a different entity, R1.5 requires you to identify who is responsible for what. A short signed agreement or MOU for each external link avoids arguments during an audit.

Evidence auditors typically ask for

  • The documented CIP-012 plan(s) covering each part of R1
  • An inventory of Control Center-to-Control Center links carrying real-time data
  • Evidence of the protection methods (for example encryption configuration, private network contracts, physical protection of unencrypted segments)
  • Availability and recovery methods, which may reference your CIP-009 recovery plans
  • Agreements or MOUs defining responsibilities with neighboring entities

How CIP Sentry helps with CIP-012

Control Center Links module

Record every link between Control Centers, the data it carries, and the protection, availability and recovery methods for each.

Where and who

Capture where each method is applied and which entity is responsible, with the supporting agreements attached.

Recovery linked to CIP-009

Point a link's recovery method directly at the relevant recovery plan record.

Ready for audit

Produce a link-by-link report showing each R1 part and its evidence.

CIP-012 FAQ

Does CIP-012 require encryption?

No. CIP-012 is technology-neutral. Encryption is a common method, but you can also use other methods such as physically protecting unencrypted segments, as long as your plan identifies them and where they are applied.

Does CIP-012 depend on impact ratings?

No. Applicability is based on owning or operating a Control Center that exchanges Real-time Assessment or Real-time monitoring data with another Control Center, not on the BES Cyber System impact rating.

What changed from CIP-012-1?

CIP-012-2 adds protection against loss of availability of the data and methods to initiate recovery of the communication links. It replaced CIP-012-1 on July 1, 2026.

Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

Related standards

Request a quote

Run CIP-012 without the spreadsheet.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.