Back to Blog
Industry Specific
4 min read

NERC CIP Compliance: Protecting Bulk Electric System Assets

Asset categorisation drives everything, the penalties are per-violation per-day, and the evidence burden is the real operational load.

GuardsArm Team

Security Experts

September 25, 2026

NERC CIP compliance for electric utilities

NERC CIP governs cyber security for the bulk electric system in North America. It is unusual among security frameworks in two respects: the penalties are substantial and assessed per violation per day, and the compliance burden falls as heavily on evidence as on the controls themselves.

Utilities with mature CIP programmes describe the same experience — the controls are manageable, and proving continuously that they operated is the work.

Categorisation drives all of it
And it changes when the estate changes
Evidence is the real burden
Unevidenced controls count as absent
Low impact is not exempt
Reduced requirements, multiplied by many sites

Categorisation determines everything

Before any control applies, you categorise your BES cyber systems as high, medium or low impact. That categorisation sets which requirements apply, and getting it wrong is expensive in both directions: under-categorising creates violations, over-categorising imposes requirements you did not need.

BES cyber system categorisationHigh and medium impact systems carry the full or near-full requirement set. Low impact carries a reduced but genuine set of obligations.High impactLarge control centres — the full requirement setMedium impactSignificant generation and transmission — most requirementsLow impactReduced set, but real — policies, access control, incident responseOut of scopeNon-BES assets — but verify, do not assume
Under-categorising creates violations; over-categorising buys requirements you did not owe.

Categorisation is not a one-off. System changes, facility changes and interconnection changes can move an asset between categories, and the requirement follows automatically. Programmes need a trigger that re-evaluates categorisation when the estate changes.


The requirement areas

AreaWhat it covers
Security management controlsGovernance, a senior manager with delegated authority
Personnel and trainingRisk assessment, training, access revocation
Electronic security perimetersDefined perimeters with controlled access points
Physical securityPhysical access control and monitoring of cyber assets
System security managementPorts and services, patching, malware prevention, logging
Incident reporting and responsePlans, testing, and reporting obligations
Recovery plansBackup, restoration, and testing of recovery
Configuration change and vulnerability assessmentBaselines, change control, periodic assessment
Information protectionHandling of BES cyber system information
Supply chain risk managementVendor risk in procurement and remote access

Two of these dominate the operational load in practice.

Configuration change management requires baselines and documented authorisation for changes against them. In an environment where a vendor engineer might adjust a setting during maintenance, capturing that as an authorised change is a discipline problem more than a technical one.

Personnel risk assessment and access revocation carries tight timelines for removing access, and the evidence must show you met them.


The evidence burden

An unevidenced control is a failed control
CIP audits examine defined periods and expect complete evidence throughout them. A patch that was applied, an access review that happened, a change that was authorised — none of it counts without the record. Automating evidence capture is not an efficiency measure here; it is the difference between passing and not.

This is what distinguishes CIP from frameworks assessed by sampling. Audits examine defined periods and expect complete evidence throughout. A control that operated but was not evidenced is treated as a control that did not operate.

What that means practically:

  • Automate evidence capture wherever possible, because manual collection across a multi-year audit period is not sustainable
  • Timestamp everything, since many requirements have deadlines
  • Retain according to the audit period, not according to convenience
  • Test your ability to produce evidence before an audit asks for it

Supply chain and vendor remote access

Supply chain requirements brought vendor risk formally into scope. The recurring finding is the same one seen across every OT sector: persistent vendor tunnels into control systems, shared credentials, no logging, installed at commissioning and forgotten.

Brokered, authenticated, time-boxed and recorded vendor access is the expectation. See third-party remote access and OT and ICS security.


Low-impact assets are not exempt

A common misreading. Low-impact BES cyber systems carry a reduced but real set of requirements, including cyber security policies, physical and electronic access controls, incident response, and vendor access management. Utilities with many low-impact sites often find the aggregate burden significant precisely because there are so many of them.


Building a programme that survives an audit

Utilities with working CIP programmes tend to share the same structural choices:

  1. A single owner with authority. The regulation expects a senior manager with delegated authority, and programmes without one fragment across operations, IT and compliance.
  2. Evidence generated by the process, not collected for the audit. Change tickets, access requests and training records that are created as work happens.
  3. A categorisation trigger tied to change management, so an asset that moves category is noticed.
  4. Internal controls testing ahead of the audit, on the same samples an auditor would take.
  5. Vendor access brokered centrally, so supply chain requirements are met by architecture rather than by asking vendors to behave.

The self-report question

Where you find a violation yourself, self-reporting is generally treated more favourably than having it found for you. That creates an internal tension: teams that fear the consequence of reporting will not look hard.

Programmes that work resolve this deliberately — internal discovery is treated as the system working, not as a failure by the person who found it. Programmes that punish discovery get fewer reports and more audit findings, which is the worse outcome on every measure.


Where to start

Verify your categorisation, and verify that something re-triggers it when the estate changes. Everything else in CIP is downstream of that determination, and a stale categorisation quietly produces violations across every requirement that follows from it.

GuardsArm supports utilities with CIP readiness, OT assessment and evidence programmes. See NERC CIP compliance or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “NERC CIP Compliance: Protecting Bulk Electric System Assets”

Talk to the GuardsArm team about how these services apply to your environment.