NERC CIP
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Categorization and Governance
Identify and categorize Bulk Electric System (BES) Cyber Systems per CIP-002-5.1a as High Impact + Medium Impact + Low Impact based on functional criteria (Control Centers + Transmission Stations + Generation Resources + Special Protection Systems + Remedial Action Schemes + Restoration). Implement security management controls per CIP-003-8 including cyber security policies + governance + delegation of authority + low-impact cyber security plans + transient cyber asset and removable media controls. Review categorization at least every 15 months and following BES changes.
- BES Cyber System inventory + categorization
- CIP-002 R1/R2 evidence
- Cyber security policies
- Senior Manager designation
- 15-month review records
- Low-impact cyber security plan
- Transient cyber asset register
- Outdated categorization
- Missing policies
- No Senior Manager
- No transient asset register
Electronic Perimeters
Establish Electronic Security Perimeters (ESPs) per CIP-005-7 including identification of all external connections + Electronic Access Points (EAPs) + denial of communications by default + restrictions on inbound and outbound permitted communications + dial-up authentication + interactive remote access controls (encryption + multi-factor authentication + intermediate device with malicious code prevention) + vendor remote access management. Protect Real-Time Assessment and Real-Time Monitoring data between Control Centers per CIP-012-1 including identification of security protection + demarcation points + responsibilities.
- Network diagrams showing ESPs and EAPs
- Firewall rules with deny-by-default
- Interactive remote access architecture
- MFA deployment evidence
- Vendor remote access controls
- CIP-012 protection plan
- Demarcation point documentation
- No ESP diagrams
- Missing MFA
- No vendor remote access controls
- No CIP-012 plan
Incident and Recovery
Develop and maintain Cyber Security Incident response plan per CIP-008-6 including: process for identifying + classifying + responding to + reporting reportable Cyber Security Incidents within 1 hour to E-ISAC and DHS CISA per EOP-004 + lessons learned within 90 days + testing at least every 15 months + update plan within 60 days of plan testing. Develop and maintain BES Cyber System Recovery Plan per CIP-009-6 including: backup and restoration + recovery testing at least every 15 months + plan review + plan updates within 60 days of testing + Information Verification for backup media.
- CIP-008 incident response plan
- 1-hour E-ISAC notification capability
- 15-month testing records
- Lessons learned within 90 days
- CIP-009 recovery plan
- Backup and restoration testing
- Backup integrity verification
- No 1-hour reporting capability
- Skipped testing
- Missing lessons learned
- Untested backups
Information Protection
Implement information protection program per CIP-011-3 covering BES Cyber System Information (BCSI) including: identification methods to classify BCSI + protect and securely handle BCSI in physical and electronic formats + prevent unauthorized retrieval from a BES Cyber Asset + prevent unauthorized retrieval from disposed-of or released BES Cyber Asset (sanitization or destruction prior to disposal). Apply CIP-011 to high-impact and medium-impact BES Cyber Systems with external routable connectivity per CIP-011-3 effective 1 January 2024.
- BCSI classification methodology
- BCSI inventory
- Handling procedures (physical and electronic)
- Disposal/sanitization records
- Media destruction certificates
- Annual review of BCSI program
- No BCSI classification
- Missing handling procedures
- No disposal records
- Stale BCSI inventory
Personnel Security
Implement personnel and training controls per CIP-004-7 covering: cyber security awareness reinforcement at least quarterly + cyber security training prior to BES Cyber System access + 7-year personnel risk assessment (criminal history check) + reassessment every 7 years + access management (request + approval + revocation within 24 hours of termination + access to BES Cyber System Information (BCSI) tracking + quarterly access verification). Apply to Cyber Security Coordinator + workforce + contractors with BES Cyber System access.
- Quarterly awareness records
- Pre-access training records
- 7-year background check evidence
- 7-year reassessment records
- 24-hour termination process
- Quarterly access reviews
- BCSI access list
- Missing quarterly awareness
- No pre-access training
- Stale background checks
- Late terminations
Physical Security
Implement Physical Security Perimeters (PSPs) per CIP-006-6 with operational and procedural controls for protection + monitored physical access + 24-hour-a-day monitoring of access + access logging + alarming + visitor control + maintenance and testing of physical security mechanisms at least every 24 months. Conduct annual third-party verification of critical transmission station identification per CIP-014-3 R1/R2 + threat and vulnerability evaluation + develop and implement physical security plan + third-party review of threat evaluation. Coordinate with E-ISAC for sector threat intelligence.
- PSP boundaries documented
- Access control system
- 24-hour monitoring evidence
- Visitor logs
- Maintenance and testing records
- CIP-014 R1 inventory
- Third-party verification reports
- Physical security plan
- No PSP documentation
- No 24-hour monitoring
- Missing maintenance
- No CIP-014 third-party verification
Supply Chain Risk Management
Develop and implement supply chain cyber security risk management plan per CIP-013-2 (effective 1 October 2022) covering: identification and assessment of cyber security risks from vendor products and services + vendor security event notification + vendor personnel access termination notification + disclosure of vendor-known vulnerabilities + verify integrity and authenticity of software and patches + coordination of vendor remote access controls + coordination with vendors on Electronic Access Control and Monitoring Systems (EACMS). Review and approve plan at least every 15 months. Apply to high and medium impact BES Cyber Systems.
- CIP-013 supply chain risk management plan
- Vendor risk assessments
- Vendor notification clauses
- Software integrity verification (hashes + signatures)
- Vendor remote access controls
- EACMS coordination
- 15-month plan approval
- No supply chain plan
- Missing vendor clauses
- No software integrity
- No 15-month approval
System Security and Configuration
Implement system security management per CIP-007-6 including: ports and services management + security patch management (35-day evaluation + plan for mitigating actions) + malicious code prevention + security event monitoring + system access control (shared accounts + default accounts + interactive remote access password change + account lockout). Manage configuration change management per CIP-010-4 including: baseline configuration documentation + authorization for changes + monitoring for unauthorized changes + vulnerability assessment prior to deployment + annual paper-based and 36-month active vulnerability assessment + Transient Cyber Asset and Removable Media controls.
- Ports/services baseline
- 35-day patch evaluation evidence
- Malware prevention deployment
- Security event logs
- Baseline configurations
- Change authorization records
- Vulnerability assessment reports
- TCA/RM inventory and controls
- Patches over 35 days
- No baseline configs
- Missing vulnerability assessments
- No transient asset controls
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NERC CIP framework page.