NERC CIP
The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.
CIP-002 through CIP-015 (per-standard versions) · NERC Reliability Standards — CIP
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
NERC CIP is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Standards are versioned individually with staggered effective dates; no consolidated catalog ingested.
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- BES cyber system categorization · Access control · Change and configuration management · Incident response · Supply chain risk · Internal network monitoring
- Applies to
- electric utilities · North America
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
- Pending change
- Effective dates are staggered per standard: CIP-003-9 took effect 2026-04-01, CIP-012-2 took effect 2026-07-01, and CIP-015-1 (internal network security monitoring, FERC-approved 2025-06-26) requires high- and medium-impact BES Cyber Systems with external routable connectivity to comply by 2028-10-01, with all other in-scope systems following by 2030-10-01.Expected: 2028-10-01 (CIP-015-1, higher-impact systems)
03Version ledger
| CIP-002 through CIP-015 (per-standard versions) | Current edition | date not published |
05Change history
06Related frameworks
- NIST SP 800-172Rev. 3
Commonly assessed together · Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.
- NIS2 DirectiveDirective (EU) 2022/2555
Commonly assessed together · The EU directive establishing a cybersecurity baseline for essential and important entities across 18 critical sectors, with management accountability and incident reporting. Operational obligations depend on each Member State's transposing law.
- PCI DSSv4.0.1
Commonly assessed together · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.
Commonly assessed together · The FBI's security requirements for any agency or vendor that touches criminal justice information — the gate for public-safety software.