CIP-014 · Physical Security

CIP-014: find the stations that matter most, then protect them.

CIP-014 applies to a small set of Transmission Owners and Operators. It asks which transmission stations and substations, if attacked, could cause instability or cascading, and requires security plans for them, verified by unaffiliated third parties.

Enforceable nowCIP-014-3 (effective June 16, 2022)
Next versionCIP-014-4 (filed with FERC; effective 24 months after approval)
Applies toTransmission Owners with stations meeting the applicability criteria, and the Transmission Operators that control them

Requirements at a glance

R1

Risk assessment

Perform a risk assessment of applicable transmission stations and substations (existing and planned within 24 months) to identify those that, if rendered inoperable or damaged, could cause instability, uncontrolled separation or cascading. Repeat every 30 calendar months if any were identified, or every 60 months if none were. Identify the primary control center for each.

R2

Unaffiliated third-party verification

Have an unaffiliated verifier with the required planning expertise verify the risk assessment within 90 calendar days of its completion. Modify the assessment or document the reason for not doing so within 60 days of the verification.

R3

Notify the Transmission Operator

If the primary control center is operated by another entity, notify that Transmission Operator within 7 calendar days of completing the R2 verification.

R4

Threat and vulnerability evaluation

Evaluate potential threats and vulnerabilities of a physical attack on each identified station and its primary control center, considering unique characteristics, prior attacks and intelligence from government and industry.

R5

Physical security plan

Develop and implement a physical security plan within 120 calendar days of completing R2, covering resiliency or security measures, law enforcement contacts, a timeline for execution and provisions to evaluate evolving threats.

R6

Third-party review of the evaluation and plan

Have an unaffiliated reviewer with appropriate physical security expertise (for example a CPP or PSP credential) review the R4 evaluation and R5 plan within 90 calendar days of plan completion, then adopt or document reasons for not adopting recommendations within 60 days.

Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.

Recurring deadlines

ObligationIntervalRequirementIn CIP Sentry
Subsequent risk assessment (stations identified last time)30 calendar monthsCIP-014-3 R1.1
Subsequent risk assessment (none identified last time)60 calendar monthsCIP-014-3 R1.1
Third-party verification of the risk assessment90 calendar daysCIP-014-3 R2.2Auto-tracked
Notify the Transmission Operator7 calendar daysCIP-014-3 R3Auto-tracked
Develop and implement the physical security plan120 calendar daysCIP-014-3 R5Auto-tracked
Third-party review of evaluation and plan90 calendar daysCIP-014-3 R6.2Auto-tracked

Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines

A different kind of CIP standard

CIP-014 is about physical attack on the transmission system, not cyber assets. It is a chain of steps with independent reviewers and tight deadlines, which makes it more like case management than a checklist. Missing one link (for example, the 7-day notification to a Transmission Operator) is a violation even if everything else was done well.

Protecting what you learn

The assessment identifies which stations would hurt the grid most, which is exactly what an attacker would want to know. R2 and R6 require confidentiality procedures with third parties. Keep the fewest possible copies, and prefer systems you control over shared cloud folders.

Preparing for CIP-014-4

NERC’s Project 2023-06 revised the standard after FERC’s 2022 order and the NERC evaluation of physical attacks. CIP-014-4 tightens applicability screening (every 36 months, including stations planned within 36 months), adds a proximity review of other BES stations within 1,500 feet, and requires a documented risk assessment methodology with specific simulation requirements. Start documenting your methodology now.

Evidence auditors typically ask for

  • Risk assessments with the study methodology, cases and results
  • The verifier's qualifications, independence and dated verification
  • Notifications to Transmission Operators
  • Threat and vulnerability evaluations for each identified station
  • Physical security plans with execution timelines and law enforcement contacts
  • Reviewer qualifications, the dated review and responses to recommendations
  • Non-disclosure agreements and procedures protecting sensitive information

How CIP Sentry helps with CIP-014

Transmission Station Security

A dedicated workspace in the Physical Security module for risk assessments, verifications, evaluations and security plans.

Chained deadlines

Each step starts the next clock automatically: 90-day verification, 7-day notification, 120-day plan and 90-day review.

Every stage on the record

Verifier and reviewer qualifications, their recommendations and your documented responses stay with each station.

Sensitive by design

CIP-014 records are among your most sensitive. Keeping them on-premises limits who can ever see them.

CIP-014 FAQ

Does CIP-014 apply to most utilities?

No. It applies only to Transmission Owners whose stations meet the applicability criteria (for example Transmission Facilities at 500 kV or above, or 200–499 kV stations above the weighted-value threshold) and to the Transmission Operators that control identified stations. Many entities that screen in never identify a critical station.

What will CIP-014-4 change?

CIP-014-4 refines the risk assessment: identifying applicable stations every 36 months, reviewing proximate stations within 1,500 feet, and documenting a methodology with defined simulation cases. It has been filed with FERC and would take effect on the first day of the first calendar quarter 24 months after approval.

Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

Related standards

Request a quote

Run CIP-014 without the spreadsheet.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.