Requirements at a glance
Documented plan(s) for data between Control Centers
Implement one or more documented plans to mitigate the risks posed by unauthorized disclosure, unauthorized modification and loss of availability of Real-time Assessment and Real-time monitoring data while it is transmitted between Control Centers (oral communications excluded, CIP Exceptional Circumstances excepted).
Protection against disclosure and modification
Identify the method(s) used to mitigate unauthorized disclosure and modification of the data.
Protection of availability
Identify the method(s) used to mitigate the loss of availability of the data (new in CIP-012-2).
Recovery of communication links
Identify the method(s) used to initiate the recovery of communication links used to transmit the data.
Where the protection is applied
Identify where the R1.1 and R1.2 methods are implemented.
Shared responsibilities
Where Control Centers are owned or operated by different entities, identify each entity's responsibilities for applying the methods.
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
New obligations as of July 2026
CIP-012-2 is one of the newest enforceable CIP requirements. If your plan was written for CIP-012-1, it probably covers confidentiality and integrity but not availability and recovery. Review each link: what happens if the primary path fails, how do you know, and how is recovery started?
Map the links first
Start with an inventory: every Control Center pair that exchanges real-time assessment or monitoring data (ICCP links to your RC or neighboring TOP, SCADA data to a backup Control Center, and so on). For each link, record the path, who owns each end and each segment, and the protection in place.
Shared responsibility
When the other end belongs to a different entity, R1.5 requires you to identify who is responsible for what. A short signed agreement or MOU for each external link avoids arguments during an audit.
Evidence auditors typically ask for
- The documented CIP-012 plan(s) covering each part of R1
- An inventory of Control Center-to-Control Center links carrying real-time data
- Evidence of the protection methods (for example encryption configuration, private network contracts, physical protection of unencrypted segments)
- Availability and recovery methods, which may reference your CIP-009 recovery plans
- Agreements or MOUs defining responsibilities with neighboring entities
How CIP Sentry helps with CIP-012
Control Center Links module
Record every link between Control Centers, the data it carries, and the protection, availability and recovery methods for each.
Where and who
Capture where each method is applied and which entity is responsible, with the supporting agreements attached.
Recovery linked to CIP-009
Point a link's recovery method directly at the relevant recovery plan record.
Ready for audit
Produce a link-by-link report showing each R1 part and its evidence.
CIP-012 FAQ
Does CIP-012 require encryption?
No. CIP-012 is technology-neutral. Encryption is a common method, but you can also use other methods such as physically protecting unencrypted segments, as long as your plan identifies them and where they are applied.
Does CIP-012 depend on impact ratings?
No. Applicability is based on owning or operating a Control Center that exchanges Real-time Assessment or Real-time monitoring data with another Control Center, not on the BES Cyber System impact rating.
What changed from CIP-012-1?
CIP-012-2 adds protection against loss of availability of the data and methods to initiate recovery of the communication links. It replaced CIP-012-1 on July 1, 2026.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

