← Back

KNOWLEDGE HUB

NERC CIP: the regulation that protects North America's power grid

The mandatory standards governing cybersecurity for the US and Canadian bulk electric system — and how they relate to technical standards like IEC 62443.

What it is

NERC CIP (Critical Infrastructure Protection) is a set of mandatory — not voluntary — standards governing cybersecurity for the Bulk Electric System of the United States and Canada. It's administered by NERC under FERC's regulatory authority.

Unlike 62443, which is a technical standard applicable to any industry in any country, NERC CIP is a specific legal obligation for the North American power sector, with real audits and real fines for non-compliance.

Why it matters

If an entity operates generation, transmission, or certain distribution assets that qualify as part of the Bulk Electric System, CIP isn't optional. And even outside North America, CIP is widely used as a de facto reference across much of the global electric sector, including Latin America.

How it's structured

  • CIP-002: identification and categorization of BES Cyber Systems (High, Medium, Low impact) — everything else depends on this classification.
  • CIP-003 through CIP-011: specific controls — personnel management, electronic security perimeter, physical security, vulnerability management, recovery plans, configuration change management.
  • CIP-013 and CIP-014: supply chain security and physical security of critical facilities.

Best practices

  • Invest the necessary time in CIP-002 categorization — a misclassified asset carries errors into every other standard.
  • Use a technical framework like IEC 62443 for the architectural 'how', and CIP for the mandatory regulatory 'what' — they're not competitors, they're complementary.
  • Document compliance evidence from day one of the control, don't reconstruct it right before the audit.

Common mistakes

  • Underestimating how much real work it takes to keep compliance evidence current between audits.
  • Treating CIP as a security ceiling ('we're compliant, so we're secure') instead of a regulatory floor.
  • Not involving Legal and Operations from the program's design stage — CIP fails when it's treated as an IT/OT-only project.

References

  • NERC CIP Standards (nerc.com)
  • CIP-002-5.1a — BES Cyber System Categorization
  • CIP-013-2 — Supply Chain Risk Management