Skip to main content
—
Framework library
Framework module · nerc-cip-v6

NERC CIP

The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.

CIP-002 through CIP-015 (per-standard versions) · NERC Reliability Standards — CIP

Standing today
Directory entry

00Answer

from the registry record
What is NERC CIP?
The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.
Who does NERC CIP apply to?
NERC CIP applies to electric utilities, North America, per NERC Reliability Standards — CIP.
What is the current version of NERC CIP?
The current edition is CIP-002 through CIP-015 (per-standard versions), issued by NERC Reliability Standards — CIP. Source: https://www.nerc.com/pa/Stand/Pages/CIPStandards.aspx.
What does an assessment under NERC CIP require?
No control catalog has been ingested for NERC CIP yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

NERC CIP is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Standards are versioned individually with staggered effective dates; no consolidated catalog ingested.

02Registry record

checked 2026-09-06
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
BES cyber system categorization · Access control · Change and configuration management · Incident response · Supply chain risk · Internal network monitoring
Applies to
electric utilities · North America
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06
Pending change
Effective dates are staggered per standard: CIP-003-9 took effect 2026-04-01, CIP-012-2 took effect 2026-07-01, and CIP-015-1 (internal network security monitoring, FERC-approved 2025-06-26) requires high- and medium-impact BES Cyber Systems with external routable connectivity to comply by 2028-10-01, with all other in-scope systems following by 2030-10-01.Expected: 2028-10-01 (CIP-015-1, higher-impact systems)

03Version ledger

1 edition
CIP-002 through CIP-015 (per-standard versions)Current editiondate not published

05Change history

06Related frameworks

scored from registry facts
  1. Commonly assessed together · Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.

  2. NIS2 DirectiveDirective (EU) 2022/2555

    Commonly assessed together · The EU directive establishing a cybersecurity baseline for essential and important entities across 18 critical sectors, with management accountability and incident reporting. Operational obligations depend on each Member State's transposing law.

  3. PCI DSSv4.0.1

    Commonly assessed together · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.

  4. Commonly assessed together · The FBI's security requirements for any agency or vendor that touches criminal justice information — the gate for public-safety software.

NERC CIP | ControlFrame