Explainer · NERC CIP
NERC CIP: thirteen standards and the calendar to 2029
The thirteen NERC CIP standards in one line each, the verified deadlines from 2026 to 2029, the penalties, and the overlaps with NIST CSF and ISO 27001.
By Sentrix · Published 2026-09-25
NERC's compliance registry counted approximately 1,636 U.S. entities subject to the CIP standards in April 2025, according to FERC's Order No. 907. Here is what each standard covers, then the calendar of approved versions to 2029, checked against the texts.
What the standards cover
Twelve cyber security standards and one physical security standard, according to the NERC Security Working Group's 2026 mapping, plus CIP-015, approved in 2025.
| Standard | Subject |
|---|---|
| CIP-002 | Categorization of cyber systems as high, medium or low impact |
| CIP-003 | Security management controls and plans for low impact |
| CIP-004 | Personnel, training, background checks, access management |
| CIP-005 | Electronic security perimeters and remote access |
| CIP-006 | Physical security of cyber systems |
| CIP-007 | System security, ports, patches, logs |
| CIP-008 | Incident reporting and response |
| CIP-009 | Recovery plans |
| CIP-010 | Configuration change management and vulnerability assessments |
| CIP-011 | Information protection |
| CIP-012 | Communications between control centers |
| CIP-013 | Supply chain risk management |
| CIP-014 | Physical security of critical substations and control centers |
| CIP-015 | Internal network security monitoring (INSM) |
What the calendar says
2026. NERC's 2026 CMEP Implementation Plan (February 2026) places the effective date of CIP-003-9 at April 1, 2026, under the "remote connectivity" risk element (vendor remote access for low impact, sections 6.1 to 6.3 of Attachment 1), and that of CIP-012-2 at July 1, 2026, for real-time data exchanged between control centers.
CIP-015-1. Order No. 907 (docket RM24-7-000, issued June 26, 2025, effective September 2, 2025) approves internal network security monitoring for high and medium impact systems with external routable connectivity, and directs NERC to extend it within twelve months to electronic (EACMS) and physical (PACS) access control systems outside the perimeter; NERC filed the CIP-015-2 petition on June 18, 2026, still pending. According to the IESO roadmap of July 10, 2026, the first compliance date for control centers is October 1, 2028.
Virtualization. Order No. 919 (docket RM24-8-000, issued March 19, 2026, effective May 26, 2026) approves eleven revised standards: CIP-002-7, 003-10, 004-8, 005-8, 006-7.1, 007-7.1, 008-7.1, 009-7.1, 010-5, 011-4.1 and 013-3, with four new definitions including Virtual Cyber Asset and Shared Cyber Infrastructure. The implementation plan cited by the order sets the effective date on the first day of the first calendar quarter twenty-four months after the order takes effect, which is July 1, 2028; early adoption is allowed by notifying the Regional Entity.
Low impact. On the same March 19, 2026, Order No. 918 (docket RM25-8-000) approves CIP-003-11, which adds, for low impact systems with external routable connectivity, authentication of remote users, protection of authentication information in transit and detection of malicious communications. Effective July 1, 2029 according to the IESO.
Physical security. FERC's order of September 10, 2026 (docket RD26-9-000) approves CIP-014-4 with an effective date of October 1, 2028; the initial risk assessment under Requirement R5 must be completed by that date.
Why it matters
The U.S. ceiling is $1,584,648 per violation per day (18 CFR 385.1602(d), amount set by Order 906 of January 2025). NERC's December 2025 inflation adjustment notice adds that the starting amounts of the penalty table, never indexed until now, rise by 15% a year in 2026, 2027 and 2028.
The useful signal is elsewhere. NERC's ORCP and CMEP Annual Report (February 11, 2026) states that 85% of noncompliance reported in 2025 was identified by the entities themselves, that CIP-010, CIP-007 and CIP-004 are the CIP standards most often involved, and that the leading root cause is "lack of or deficient policy/procedures". The same report notes that CIP files are treated as CEII and that NERC publishes neither CIP audit reports nor noncompliance filings: no list by name, and no exemption before the regional auditor.
Patches, configurations, access: three repetitive, dated requirements where the gap comes from a missing or poorly followed procedure, rarely from the technical control itself.
What we think at Sentrix
An entity subject to CIP is almost always subject to another framework too: NIST CSF for the board, ISO 27001 for a customer or an insurer, SP 800-53 for a federal contract. The mappings exist. NIST's white paper of September 29, 2021 publishes the CSF v1.1 to CIP mapping, with eight Subcategories for the single requirement CIP-010-2 R1. The NERC Security Working Group published in 2026, on NIST's OLIR program, the mapping of each CIP requirement to SP 800-53 r5.2.0, with a strength-of-relationship score. The ISA Global Cybersecurity Alliance concluded in 2024 that 95% of the technical controls in CIP can be verified through ISA/IEC 62443-3-3 or 4-2 certifications, and all of CIP-013-2 through 62443-4-1.
What we take from it:
- One piece of evidence, several frameworks. The list of evaluated patches under CIP-007 R2 or the vulnerability assessment under CIP-010 R3 also answers the CSF, control 8.8 of ISO 27001 and SI-2 of SP 800-53. Collected once, mapped to each.
- CIP-010 and CIP-015 describe a continuous exposure cycle: baseline configuration, change detection, assessment, internal monitoring. That is the scope of CTEM.
- Self-reports require dated traceability: who detected the gap, when, what mitigation, what closure. Without a timestamped file, a self-report is worth nothing.
- CIP-013 and vendor remote access are a third-party file: contracts, assessments, access logs.
The next step
Take the five dates on the calendar (April 1, 2026, July 1, 2026, July 1, 2028, October 1, 2028, July 1, 2029) and, for each new version, write down the requirement that changes and the evidence it will require. The blank lines are your work plan. To do it with us, contact us.
Sources
- FERC, Critical Infrastructure Protection Reliability Standard CIP-015-1-Cyber Security-Internal Network Security Monitoring (Order No. 907)
- FERC, Order No. 919; Virtualization Reliability Standards
- NERC, ORCP and CMEP Annual Report (February 11, 2026)
- NERC, 2026 ERO Enterprise CMEP Implementation Plan (February 2026)
Frequently asked questions
- Who do the NERC CIP standards apply to?
- Entities registered with NERC for a function on the North American bulk power system: transmission operators, generator owners, reliability coordinators, balancing authorities and others. FERC's Order No. 907 cites approximately 1,636 U.S. entities subject to the CIP standards on the April 2025 registry. In Canada, each province adopts the standards through its own regulator, with its own dates.
- Which CIP deadlines fall between 2026 and 2029?
- CIP-003-9 on April 1, 2026 and CIP-012-2 on July 1, 2026 according to NERC's 2026 CMEP Implementation Plan. The eleven standards revised for virtualization apply on July 1, 2028, twenty-four months after Order No. 919 took effect. CIP-014-4 takes effect on October 1, 2028. CIP-015-1 for control centers and CIP-003-11 follow, according to the IESO roadmap.
- What does a non-compliant entity risk under CIP?
- In the United States, the ceiling is $1,584,648 per violation per day under 18 CFR 385.1602(d). NERC's December 2025 notice also indexes the starting amounts of the penalty table for inflation from 2026. CIP files are treated as CEII and are not published by name, which changes nothing about the penalty or the burden of proof before the regional auditor.
Let's talk about your compliance program.
Last updated: 2026-09-25
