Requirements at a glance
Supply chain risk management plan
Develop plan(s) with processes used in planning the procurement of applicable systems to identify and assess cyber security risks from vendor products and services, and from transitions between vendors (R1.1).
Six vendor processes
The plan must include processes for: (1) vendor notification of vendor-identified incidents, (2) coordination of responses to vendor-identified incidents, (3) vendor notification when remote or onsite access should no longer be granted to vendor representatives, (4) disclosure by vendors of known vulnerabilities, (5) verification of software integrity and authenticity of software and patches provided by the vendor, and (6) coordination of controls for vendor-initiated remote access.
Implement the plan
Implement the plan(s). Contract terms are not required to change, and implementation does not require renegotiating or abrogating existing contracts.
Review and approve every 15 months
Review and obtain CIP Senior Manager or delegate approval of the plan(s) at least once every 15 calendar months.
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
Recurring deadlines
| Obligation | Interval | Requirement | In CIP Sentry |
|---|---|---|---|
| Review and approve the supply chain risk management plan | 15 calendar months | CIP-013-2 R3 | Auto-tracked |
Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines
Turning the plan into a routine
A CIP-013 plan fails in practice when it lives only in a policy document. Build the vendor processes into procurement: a risk questionnaire before purchase, contract terms (or documented alternatives) for the six R1.2 items, and a record of how risks were identified and addressed for each purchase.
Industry tools you can reuse
- NATF Supply Chain Security Criteria and Energy Sector Supply Chain Risk Questionnaire (version 7.0, May 2026) give you a common set of questions that many vendors have already answered.
- EEI Model Procurement Contract Language (version 4.0, June 2026) provides clauses aligned to the R1.2 processes.
- Independent assessments shared across utilities can reduce duplicate questionnaires for widely used vendors.
Software integrity in practice
R1.2.5 and CIP-010 R1.6 work together. Your plan asks vendors to provide a way to verify software (signed installers, published hashes), and your change process records that you used it. Choosing vendors who publish this by default makes both standards easier.
Evidence auditors typically ask for
- The supply chain cyber security risk management plan(s) addressing R1.1 and each R1.2 process
- Procurement records showing risk identification and assessment for applicable purchases
- Vendor questionnaires or assessments (many entities use the NATF Energy Sector Supply Chain Risk Questionnaire)
- Contract language or other vendor commitments covering the R1.2 processes (often based on EEI model language)
- CIP Senior Manager or delegate approvals no more than 15 months apart
How CIP Sentry helps with CIP-013
Supply Chain Risk module
Keep your supply chain risk management plan and a prequalified vendor list for procurement in one place.
15-month approval clock
The CIP Senior Manager approval of the plan is tracked like every other periodic obligation.
Integrity checks recorded
Software integrity verification from CIP-010 R1.6 is recorded on each change, supporting your R1.2.5 process.
A vendor that answers first
CIP Sentry's own Trust Center answers the R1.2 questions about us before you ask, and we complete the NATF questionnaire on request.
CIP-013 FAQ
Does CIP-013 apply to low impact systems?
CIP-013-2 applies to high and medium impact BES Cyber Systems and their associated EACMS and PACS. Low impact vendor remote access is addressed separately in CIP-003-9 Attachment 1 Section 6.
Do we have to rewrite existing contracts?
No. CIP-013 applies to procurement going forward, and R2 notes that implementation does not require renegotiating existing contracts. New procurements should reflect your plan.
What is coming next?
CIP-013-3 takes effect with the virtualization package on July 1, 2028. In September 2025 FERC Order No. 912 directed further supply chain improvements, which NERC is developing as CIP-013-4 (Project 2025-06). Expect more rigorous vendor risk assessment.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

