WATCHUR6 // NERC CIP // AUDIT READINESS

NERC CIP isn't a framework you adopt.
It's a standard you're held to.

If you own or operate the bulk electric system, NERC CIP is mandatory — with penalties up to $1 million per violation, per day. The usual problem isn't refusing to comply; it's partial compliance: visible controls done, but categorization, access, and evidence gaps an auditor finds. We close that gap.

Book a NERC CIP Strategy Call
NERC CIP MANDATORY UNDER FERC HIGH / MED / LOW IMPACT VETERAN-LED

// WHY NERC CIP, WHY NOW

No discretion. Just the standard, and the audit.

$1M / DAY

Penalties with teeth

Violations are assessed per-violation, per-day — up to $1 million per day for the most serious high-impact failures. FERC holds the penalty authority.

MANDATORY

Not a framework you adapt

Unlike voluntary standards, NERC CIP is a prescriptive set of requirements you must meet to operate the bulk electric system. Compliance is enforced, not optional.

PARTIAL

The most common failure

The usual audit finding isn't willful non-compliance — it's partial compliance: visible controls handled, but gaps in categorization, access, and evidence.

// IMPLEMENTED ISN'T THE SAME AS EVIDENCED

We've handled the major CIP requirements, so we're compliant.
NERC CIP grades you on what you can prove, not what you've done.

The most common condition in a CIP engagement isn't refusal to comply — it's partial compliance. You've addressed the visible controls and genuinely believe you're meeting the standard, but gaps remain in asset categorization, access management, or evidence collection that become findings in a formal audit. NERC CIP is unusually demanding about documentation: it's not enough to implement a control — you must prove, with retained evidence, that it operated as required across the whole audit period. Strong operational security with missing cyber asset inventories and change records is exactly what turns into per-day penalties.

// WHERE EVERY CIP PROGRAM STARTS

One decision scopes everything that follows.

NERC CIP spans thirteen standards as of 2026, but they all hang off a single classification. CIP-002 categorization — High, Medium, or Low impact — determines which requirements apply to each system and how rigorous they are. Get it wrong and every control downstream inherits the error.

CIP-002 Categorization High / Medium / Low impact · the foundation of all compliance

Where every program begins: under CIP-002 you identify your BES Cyber Systems and classify each as High, Medium, or Low impact. That rating drives which requirements apply and how stringent they are across every other standard. Categorize accurately and the program scopes itself sensibly; miscategorize and you either over-build or, worse, under-protect systems an auditor will flag. The three control areas below are what your categorization scopes.

// CIP-003 / 004 / 007

Security Management & Access

Security management controls, personnel and training, access management, and system security hardening.

// CIP-005 / 006

Electronic & Physical Perimeters

Electronic security perimeters around BES cyber systems, and physical security of the assets themselves.

// CIP-008 / 009 / 010 / 013

Response, Recovery & Supply Chain

Incident reporting, recovery planning, configuration change management, and supply-chain risk.

Categorization — not the controls — is what an auditor scrutinizes first.

NERC CIP · MANDATORY UNDER FERC 13 Standards · ACTIVE AS OF 2026 CIP-002 · CATEGORIZATION FIRST

// THE PATH

From categorization to a clean audit.

How a utility builds a defensible CIP posture and keeps it. The amber stages are the regulator-facing moments — the NERC and Regional Entity audit, and the continuous compliance the program expects between reviews.

Scope

Identify BES Assets

WK 1–4

Categorize

CIP-002 Impact Rating

WK 3–6

Implement

Controls by Impact

MO 2–8

Evidence

Inventories & Records

ONGOING

Audit

NERC / Regional Entity

ON CYCLE

Sustain

Continuous Compliance

ONGOING

Amber stages are the regulator-facing moments — the audit conducted by NERC and your Regional Entity through the Compliance Monitoring and Enforcement Program, and the continuous compliance expected between audits. Everything before exists to make the review routine.

// IS THIS YOU?

Three signs NERC CIP is on you.

// 01 // BES OPERATOR

You own or operate the grid

You run generation, transmission at 100 kV+, or control centers — so NERC CIP is mandatory, and the only question is which of your assets are in scope.

// 02 // LOW-IMPACT, NEW BURDEN

You're a co-op or municipal utility

You've operated under lighter oversight, but CIP-003-9's supply-chain rules for low-impact systems became enforceable in April 2026. The burden just moved to you.

// 03 // EVIDENCE GAPS

You can't prove it on demand

Your controls are in place but your inventories, baselines, and access records aren't audit-ready. That's the gap that becomes findings.

// WHAT WE DO

The categorization, the controls, and the evidence.

// Phase 01 · Scope

Asset ID & CIP-002 Categorization

We identify your BES Cyber Systems and build a defensible CIP-002 categorization — the foundation that scopes the entire program and the first thing an auditor scrutinizes.

  • BES asset identification and inventory
  • CIP-002 High / Medium / Low categorization
  • Applicability and scope documentation

// Phase 02 · Implement

Controls Across the Standards

We close the control gaps across the CIP standards that apply to your impact levels — security management, perimeters, system hardening, incident response, recovery, and supply chain.

  • Access, perimeter, and system security controls
  • Incident response and recovery planning
  • Supply-chain risk (incl. CIP-003-9 low-impact)

// Phase 03 · Prove

Evidence & Audit Readiness

We build the inventories, baselines, access reviews, and change records that turn implemented controls into provable ones — and prepare you for the NERC and Regional Entity audit.

  • Cyber asset inventories and configuration baselines
  • Access review and change-record evidence
  • NERC / Regional Entity audit preparation

// PER VIOLATION, PER DAY

With penalties measured in dollars per day, "we think we're compliant" is the most expensive sentence in the room.

Book a NERC CIP Strategy Call

// FREQUENTLY ASKED

The NERC CIP questions utilities keep asking.

Who actually has to comply with NERC CIP?

NERC CIP is mandatory for entities that own or operate the Bulk Electric System (BES) in North America — not a voluntary framework you can opt out of if it applies. The BES generally includes generation above certain capacity thresholds, transmission facilities at 100 kV and above, and the control centers operating them. If you own or operate that infrastructure, compliance is legally required, enforced by NERC under authority delegated by FERC in the U.S. and equivalent regulators in Canada, through six Regional Entities.

There's an important boundary: distribution-only utilities below the BES threshold are generally not subject to mandatory CIP compliance, though many adopt the standards voluntarily as a baseline. So the practical first question isn't how to comply, but precisely which of your assets are in scope — because miscategorizing what counts as a BES Cyber System is one of the most consequential mistakes you can make.

Why does everything start with CIP-002 categorization?

Because CIP-002 (BES Cyber System Categorization) determines the scope and rigor of everything else — it's the foundation of the entire program. Under CIP-002 you identify your BES Cyber Systems and classify them as High, Medium, or Low impact, and that rating drives which requirements across the other standards apply and how stringent they are. High and Medium impact systems face the most demanding controls — layered access management, physical security, personnel training — while Low impact systems carry a lighter but real and growing set of obligations.

Get categorization wrong and every downstream decision inherits the error: you over-invest in controls for systems that don't need them, or — far more dangerously — under-protect systems you misclassified as lower impact and end up with serious audit findings. That's why categorization is where we start. An accurate, defensible, well-documented categorization both scopes your work sensibly and is the thing an auditor scrutinizes first.

We addressed the major requirements. Doesn't that mean we're compliant?

Not necessarily — this is the single most common trap in NERC CIP. The condition assessors encounter most often isn't willful non-compliance but partial compliance: an organization has addressed the visible requirements and genuinely believes it's meeting the standard, while gaps remain in asset categorization, access management, or evidence collection that would produce findings in a formal audit.

NERC CIP is unusually demanding about documentation — it's not enough to have implemented a control; you must prove, with retained evidence, that it operated as required throughout the audit period. Many utilities have strong operational security but can't produce the cyber asset inventories, configuration baselines, access reviews, and change records an auditor expects, and that evidentiary gap is what turns into penalties. Because penalties are assessed per-violation, per-day and can reach up to $1 million per day for the most serious violations, the distance between feeling compliant and being demonstrably compliant is expensive. We focus on closing exactly that gap.

What changed for low-impact utilities in 2026?

The most significant recent change for smaller operators is CIP-003-9, the Supply Chain Low-Impact Revisions, which became enforceable on April 1, 2026. Historically, low-impact BES cyber systems had comparatively light oversight, and many municipally owned utilities and rural cooperatives operated comfortably in that tier. CIP-003-9 changes that by extending specific supply-chain risk requirements down to low-impact assets — reflecting that attackers increasingly target the supply chain, and that low-impact doesn't mean no-impact.

For a smaller utility this can be a jarring shift: requirements and an evidentiary burden that previously seemed to belong only to larger High and Medium impact operators now apply to you, and the timeline isn't generous. If your utility has low-impact BES cyber systems and hasn't worked through what CIP-003-9 requires of your vendor and supply-chain practices, that's live exposure now, not a future planning item. We help low-impact operators interpret the requirements realistically for their size and build the supply-chain controls and documentation the standard now expects.

// THE NEXT MOVE

Find the gaps before the Regional Entity does.

Book a 30-minute NERC CIP strategy call with a WatchUr6 advisor. Bring what BES assets you operate, your current impact categorization, and when your next audit falls. You'll walk away knowing your scope, your categorization and evidence gaps, and a realistic path to a defensible, audit-ready program — whether you hire us or not.

Book a NERC CIP Strategy Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED