Requirements at a glance
Risk assessment
Perform a risk assessment of applicable transmission stations and substations (existing and planned within 24 months) to identify those that, if rendered inoperable or damaged, could cause instability, uncontrolled separation or cascading. Repeat every 30 calendar months if any were identified, or every 60 months if none were. Identify the primary control center for each.
Unaffiliated third-party verification
Have an unaffiliated verifier with the required planning expertise verify the risk assessment within 90 calendar days of its completion. Modify the assessment or document the reason for not doing so within 60 days of the verification.
Notify the Transmission Operator
If the primary control center is operated by another entity, notify that Transmission Operator within 7 calendar days of completing the R2 verification.
Threat and vulnerability evaluation
Evaluate potential threats and vulnerabilities of a physical attack on each identified station and its primary control center, considering unique characteristics, prior attacks and intelligence from government and industry.
Physical security plan
Develop and implement a physical security plan within 120 calendar days of completing R2, covering resiliency or security measures, law enforcement contacts, a timeline for execution and provisions to evaluate evolving threats.
Third-party review of the evaluation and plan
Have an unaffiliated reviewer with appropriate physical security expertise (for example a CPP or PSP credential) review the R4 evaluation and R5 plan within 90 calendar days of plan completion, then adopt or document reasons for not adopting recommendations within 60 days.
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
Recurring deadlines
| Obligation | Interval | Requirement | In CIP Sentry |
|---|---|---|---|
| Subsequent risk assessment (stations identified last time) | 30 calendar months | CIP-014-3 R1.1 | |
| Subsequent risk assessment (none identified last time) | 60 calendar months | CIP-014-3 R1.1 | |
| Third-party verification of the risk assessment | 90 calendar days | CIP-014-3 R2.2 | Auto-tracked |
| Notify the Transmission Operator | 7 calendar days | CIP-014-3 R3 | Auto-tracked |
| Develop and implement the physical security plan | 120 calendar days | CIP-014-3 R5 | Auto-tracked |
| Third-party review of evaluation and plan | 90 calendar days | CIP-014-3 R6.2 | Auto-tracked |
Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines
A different kind of CIP standard
CIP-014 is about physical attack on the transmission system, not cyber assets. It is a chain of steps with independent reviewers and tight deadlines, which makes it more like case management than a checklist. Missing one link (for example, the 7-day notification to a Transmission Operator) is a violation even if everything else was done well.
Protecting what you learn
The assessment identifies which stations would hurt the grid most, which is exactly what an attacker would want to know. R2 and R6 require confidentiality procedures with third parties. Keep the fewest possible copies, and prefer systems you control over shared cloud folders.
Preparing for CIP-014-4
NERC’s Project 2023-06 revised the standard after FERC’s 2022 order and the NERC evaluation of physical attacks. CIP-014-4 tightens applicability screening (every 36 months, including stations planned within 36 months), adds a proximity review of other BES stations within 1,500 feet, and requires a documented risk assessment methodology with specific simulation requirements. Start documenting your methodology now.
Evidence auditors typically ask for
- Risk assessments with the study methodology, cases and results
- The verifier's qualifications, independence and dated verification
- Notifications to Transmission Operators
- Threat and vulnerability evaluations for each identified station
- Physical security plans with execution timelines and law enforcement contacts
- Reviewer qualifications, the dated review and responses to recommendations
- Non-disclosure agreements and procedures protecting sensitive information
How CIP Sentry helps with CIP-014
Transmission Station Security
A dedicated workspace in the Physical Security module for risk assessments, verifications, evaluations and security plans.
Chained deadlines
Each step starts the next clock automatically: 90-day verification, 7-day notification, 120-day plan and 90-day review.
Every stage on the record
Verifier and reviewer qualifications, their recommendations and your documented responses stay with each station.
Sensitive by design
CIP-014 records are among your most sensitive. Keeping them on-premises limits who can ever see them.
CIP-014 FAQ
Does CIP-014 apply to most utilities?
No. It applies only to Transmission Owners whose stations meet the applicability criteria (for example Transmission Facilities at 500 kV or above, or 200–499 kV stations above the weighted-value threshold) and to the Transmission Operators that control identified stations. Many entities that screen in never identify a critical station.
What will CIP-014-4 change?
CIP-014-4 refines the risk assessment: identifying applicable stations every 36 months, reviewing proximate stations within 1,500 feet, and documenting a methodology with defined simulation cases. It has been filed with FERC and would take effect on the first day of the first calendar quarter 24 months after approval.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

