NERC CIP compliance comes down to two things: running the right controls, and being able to prove it. Most utilities that stumble in an audit aren't missing a whole standard. They can't produce evidence for a control they were already running. This checklist walks the standards a power utility gets measured on, says plainly what each one asks for, and names the artifact an auditor will want to see.
Two things changed for 2026, and both are on this list. CIP-003-9 brought vendor remote access controls to low-impact systems on April 1, 2026, catching hundreds of munis and co-ops who assumed "low-impact" meant "no action required." And CIP-015 now requires internal network security monitoring inside the electronic security perimeter, the gap Volt Typhoon walked straight through.
Start where every audit starts: CIP-002
You can't protect what you haven't inventoried, and CIP-002 is where auditors begin because everything downstream depends on it. Build a complete list of BES Cyber Systems and categorize each by impact: high, medium, or low.
The hard part is the assets that can't tell you they exist: legacy PLCs, HMIs, and serial devices that won't run an agent and won't answer a scan cleanly. Miss those and the gap cascades into every control that follows.
- Do: inventory every device on the network, agent-free, including the equipment too old to instrument.
- Categorize each asset against the CIP-002 impact criteria, and keep the rationale. Auditors ask why something is low-impact.
- Evidence: a dated asset list with impact ratings and the method you used to discover each device.
Governance and vendor access: CIP-003 (and the CIP-003-9 change)
CIP-003 covers your security management controls: policies, a senior manager who owns them, and for low-impact sites, the governance that used to be light-touch. As of April 1, 2026, CIP-003-9 changed that. Low-impact BES Cyber Systems must now control and log vendor electronic remote access, and be able to cut a vendor session on demand.
If a vendor still VPNs or dials straight into a substation device, that's the finding. The fix is to put every vendor session through a broker that authenticates the person, records the session, and gives you a kill switch.
- Do: route all vendor access through a proxy, with no direct-to-asset connections.
- Evidence: vendor session records tied to named users, plus a documented procedure to disable access.
Least privilege and named access: CIP-004
CIP-004 is personnel: risk assessments, awareness training, and access management. On the network side, what an auditor tests is whether every session traces to a named individual, and whether you can show access being granted and revoked.
- Do: tie every session to a named user with a role, not a shared credential.
- Evidence: access history and revocation logs, audit-ready without a data-gathering scramble.
The electronic security perimeter: CIP-005
CIP-005 asks you to define electronic security perimeters and control interactive remote access across them. Classic CIP-005 means firewalls and jump hosts at every VLAN boundary, which is expensive to build and painful to change on a live grid.
An overlay network gives you the same enforced perimeter without re-architecting the underlay. Access Gate is the Intermediate System that Interactive Remote Access routes through: the ESP is defined in software, every vendor and remote session is proxied, recorded, and terminable mid-stream (R2.4/R2.5), and it runs on-premise with no cloud dependency, so nothing in the remote-access path leaves your environment. See the NERC CIP coverage matrix for the standard-by-standard mapping.
- Do: define ESPs and enforce them; proxy and monitor every interactive remote session.
- Evidence: ESP diagrams, interactive remote access logs, and session-termination capability.
Systems security and MFA on legacy OT: CIP-007
CIP-007 covers ports and services, patching, malware prevention, authentication, and security event logging. The recurring audit finding here is authentication: CIP-007 wants MFA, and a 15-year-old HMI can't do it natively.
You don't have to replace the device. Wrapping legacy OT at the network layer enforces multi-factor authentication in front of equipment that has no idea MFA exists, so the finding closes without touching firmware.
- Do: enforce MFA on every system, including OT that can't support it natively; centralize security event logging.
- Evidence: authentication enforcement records and a tamper-evident audit trail.
Detection and response: CIP-008 and CIP-009
CIP-008 is incident response: a documented plan, reporting timelines, and evidence you've tested it. CIP-009 is recovery: backup and restoration plans for BES Cyber Systems, tested on a schedule.
Tooling doesn't replace either plan, but it decides how fast you can reconstruct a timeline when something happens. Real-time anomaly alerts with a full event history turn "what happened and when" from a week of log archaeology into an afternoon.
- Do: keep IR and recovery plans current and tested. Untested plans are findings.
- Evidence: the plans, test records within the last cycle, and event timelines you can actually produce.
Configuration and supply chain: CIP-010 and CIP-013
CIP-010 is baseline configuration and change management: know the baseline, detect deviations. CIP-013 is supply-chain risk: vendor risk management and software integrity, and it leans on the same CIP-005 vendor-session controls (R2.4/R2.5) you built above.
- Do: detect unauthorized configuration changes on network-visible assets; keep vendor sessions proxied, logged, time-limited, and revocable.
- Evidence: baseline deltas with timestamps and session attribution; vendor session records.
The new one everyone's scrambling on: CIP-015 (INSM)
CIP-015-1 requires Internal Network Security Monitoring inside the electronic security perimeter for high- and medium-impact systems. FERC approved it in June 2025 as a direct answer to Volt Typhoon, where attackers lived inside the perimeter, undetected, for months. Perimeter defense says nothing about east-west traffic between two devices that both sit inside the ESP, and CIP-015 closes exactly that blind spot.
- Do: monitor east-west traffic inside the ESP; detect anomalies and retain the collected data.
- Evidence: sensor placement diagrams, anomaly logs, and a data-retention policy.
Here's how the monitoring obligations line up across the standards that carry them:
| Standard | Monitoring obligation | Applies to | Audit evidence |
|---|---|---|---|
| CIP-005-7 | ESP traffic inspection · dial-up access detection · IRA session recording with malicious code prevention | High + Medium impact BCS | Network/ESP diagrams · IRA session logs · IRP-capable jump host config |
| CIP-007-6 | Security event monitoring (R4) · alerting on detected events · 90-day log retention · review every 15 days | High + Medium impact BCS | SIEM correlation rules · retention attestation · weekly review log |
| CIP-010-4 | Baseline configuration change detection · paper + active vulnerability assessments (R3) | High + Medium impact BCS | Change-management tickets · authenticated scan reports · 35-day deviation log |
| CIP-015-1 | Internal NSM (INSM) of east-west traffic inside the ESP · anomaly detection + collected data retention | High impact (effective Oct 2028) · Medium impact w/ ERC (Oct 2029) | Sensor placement diagram · anomaly logs · data-retention policy |
| CIP-003-9 | Vendor electronic remote access detection + ability to disable (Sec 6, effective Apr 2026) | Low impact BCS only | Vendor session records · documented disable procedure |
Physical security: CIP-006
CIP-006 is physical access control for BES Cyber Systems: fences, locks, badge readers, cameras. It sits outside a network platform's scope, but logical access logs sitting next to physical access events make the correlation an auditor wants far easier to produce.
- Do: control and log physical access; correlate it with logical access where you can.
- Evidence: physical access logs aligned to the systems they protect.
How it fits with the frameworks you already run
If you also carry NIST 800-171, CMMC, or (for EU operations) NIS2, the controls overlap more than the paperwork suggests. Access control, logging, incident response, and network segmentation do double duty. Build the evidence once and map it across, rather than standing up a parallel program per framework.
Do this next
Run the checklist against your current state and flag every item where you lack documentation or haven't tested the control in the last 12 months. Those gaps are your audit risk. Fix them in dependency order. Start with CIP-002, because every other control depends on knowing what you're protecting, then CIP-003 and CIP-005 vendor access (now enforced at low-impact), then CIP-007 authentication and CIP-015 monitoring.
The NERC CIP coverage matrix maps all of this, covered, partial, and manual, so you can see where a platform closes the gap and where the work stays yours.