Get audit-ready for NERC CIP without downtime.
If vendors reach your substations, SCADA or any OT remotely, CIP-003-9 now applies to you. This page covers what changed, what is required, and how to get audit-ready.
Last updated:
CIP-005 requires all Interactive Remote Access to route through an Intermediate System, and requires you to determine and disable active vendor sessions (R2.4 / R2.5). Trout Access Gate is that Intermediate System, built for OT. It terminates every remote session in front of the machine. It enforces MFA even on PLCs and RTUs that cannot run it. It records the session and lets you cut a vendor's access instantly.
It runs on-premise with no cloud dependency. No BES traffic and no audit data leave your environment. Remote access does not depend on a vendor's cloud staying up, which matters when reliability is the point of the standard. The same appliance also delivers the internal network monitoring that CIP-015 (INSM) now requires.
NERC CIP has governed the grid since 2008, but enforcement scope just expanded. CIP-003-9 brings low-impact utilities into scope. Vendor remote access controls are now mandatory for every registered BES entity. CIP-015 requires internal network monitoring inside the perimeter, the direct response to Volt Typhoon. And CIP-002-8 reclassification may move entities from Low to Medium Impact, which triggers MFA, logging, and evidence retention requirements.
Per day, per violation
NERC's maximum fine authority. Self-reports get lighter treatment. Audit findings escalate.
CIP-003-9 in effect
Low-impact vendor remote access controls are now mandatory. Audits now check for them.
Registered BES entities
In North America, now subject to CIP. Munis, co-ops, and IPPs are in scope for the first time.
Legacy devices get MFA without firmware changes.
Access Gate connects beside your network. Legacy PLCs, HMIs, and RTU get MFA and monitoring without any device modification. This is how you solve CIP-007 for equipment that can't run agents.
An overlay defines your Electronic Security Perimeter.
Access Gate creates the ESP for CIP-005 without touching your network topology. No VLAN reconfiguration, no firewall rule sprawl, no maintenance windows.
Access Gate monitors east-west traffic for CIP-015.
Monitors traffic inside the ESP continuously. Exactly what CIP-015 requires. No separate monitoring platform needed.
Identify and classify all BES Cyber Systems and Cyber Assets
Agent-free asset discovery across IT, OT, and ICS. Finds every device on the network, including legacy PLCs and HMIs that can't run agents.
Vendor remote access controls; security policies; low-impact governance (CIP-003-9)
Proxy-based remote access with full session logging. Vendors connect through Access Gate, never directly to assets. Session kill-switch included.
Personnel risk assessment; security awareness; access management
Every session is tied to a named user. Role assignments, access history, and revocation are audit-ready out of the box.
Define and enforce ESPs; control interactive remote access; vendor session management
Access Gate is the CIP-005 Intermediate System for interactive remote access. It defines your ESP as an overlay without touching VLAN, and every vendor session is proxied, recorded, and terminable (R2.4/R2.5), on-premise with no cloud in the path.
Physical access controls for BES Cyber Systems
Outside scope for physical controls. Access Gate logs all logical access adjacent to physical access events.
Patch management; malware prevention; authentication enforcement; security event logging
MFA on all systems, including legacy OT that can't support it natively. Centralized event logging with tamper-evident audit trail.
Incident response processes; reporting timelines; plan testing
Real-time anomaly alerts with full event timeline. Does not replace the IR plan, but makes timeline reconstruction straightforward.
Baseline configurations; change detection; vulnerability assessments
Detects unauthorized configuration changes on network-visible assets. Baseline deltas are logged with timestamp and session attribution.
Vendor risk management; software integrity verification
Every vendor session is proxied, logged, time-limited, and revocable. Covers CIP-005 R2.4/R2.5 vendor session requirements.
Internal network security monitoring inside the ESP for high/medium impact systems
Continuous east-west traffic visibility inside the perimeter. This is exactly what CIP-015 requires.
Fully covered
Partially covered
Physical only
CIP-007 is the most violated NERC standard. The main finding: no MFA on legacy OT and bad event logging. Access Gate fixes both without touching OT devices.
Your next move depends on what kind of utility you are.
Municipal utilities
City-owned electric departments with substations and SCADA. Newly caught by CIP-003-9. Usually no dedicated OT security staff.
Highest urgencySuggested next step
Start with a focused CIP pilot. Get audit-ready evidence for CIP-002 and CIP-003, now that low-impact vendor remote access controls are in effect.
Rural electric cooperatives
Member-owned co-ops on aging distribution infrastructure. CIP-003-9 compliance is new territory. Tight budgets.
High urgencySuggested next step
Talk to NRECA about recommended vendor solutions. Request a pilot scoped to CIP-003 vendor access controls.
IPPs & generation operators
Independent power producers with 20MW+ generation. Already in CIP scope, but CIP-015 INSM and CIP-005 vendor access revisions create new gaps.
High urgencySuggested next step
Map your existing controls against CIP-015 INSM. Access Gate fills the east-west monitoring gap.
Transmission owners & operators
Medium and high-impact BES. CIP-015 INSM is mandatory now. Complex multi-site environments where agent-based tools don't work.
StrategicSuggested next step
Evaluate the overlay architecture for multi-site ESP definition. No change management across substations.
Get audit-ready evidence in three phases.
First, full asset inventory (CIP-002). Then ESP and vendor access controls (CIP-003, CIP-005). Finally, MFA and INSM activation (CIP-007, CIP-015). Evidence packages delivered.
Reach audit-ready without touching devices.
Agent-free. No firmware changes, no device modifications, no downtime. Works in CIP environments where change management approval takes six months.
Self-reporting lowers penalties.
Self-reported violations with a corrective action plan get lower penalties. Violations discovered in audit are aggravating factors. NERC fined Exelon $1.8M in one action.
Operating water or wastewater systems too?
Many electric utility operators also run water and wastewater infrastructure. New York imposes a parallel set of OT cybersecurity regulations under DEC and DOH, with a January 1, 2027 compliance deadline. See our NY State EFC SECURE & DEC/DOH compliance guide for the parallel water-sector requirements, the 12-step EFC checklist, and NIST CSF 2.0 mapping.
For the full reference architecture behind CIP-005 remote access, CIP-007 system security, and CIP-010 change management, see the Zero Trust for Utility OT whitepaper. It covers commissioning and brownfield deployment timelines, the four-pillar coverage map, and the NERC CIP + CCCS matrix by control family.
CIP-002 starts with identifying and categorising your BES Cyber Systems, which is a risk assessment before it is a compliance exercise. If you are starting from a blank sheet, our walkthrough on how to perform a risk assessment on your OT environment covers asset discovery, consequence rating, and how to scope the assessment without active scans that a relay or an RTU will not survive.
Common questions about NERC CIP and Access Gate.
CIP-003-9 now in effect
CIP-003-9 extends vendor remote access controls to low-impact BES Cyber Systems, effective April 1, 2026. Before this, low-impact sites had minimal oversight. Now every entity must document and control vendor electronic remote access. This catches hundreds of munis and co-ops who assumed 'low-impact' meant 'no action required.'
Yes. CIP-005 requires all Interactive Remote Access to BES Cyber Systems to pass through an Intermediate System that enforces encryption and multi-factor authentication. Entities must also be able to determine and disable active vendor remote access sessions (R2.4/R2.5). Access Gate is an Intermediate System built for OT. It brokers and records every remote session in front of the machine, enforces MFA even on legacy PLCs and RTUs, and ends a vendor session on demand. It runs on premise with no cloud dependency, so nothing in the remote access path relies on an external service.
CIP-015-1 requires Internal Network Security Monitoring inside the Electronic Security Perimeter for high- and medium-impact BES systems. FERC Order 907 approved it in June 2025 as a direct response to Volt Typhoon, where attackers lived inside the perimeter undetected for months. Access Gate's overlay network provides exactly this visibility.
CIP-007 requires authentication enforcement on all systems, but legacy PLCs and HMIs can't support MFA natively. Access Gate wraps these devices at the network layer, enforcing multi-factor authentication without modifying device firmware. The audit finding goes away without touching the OT equipment.
Access Gate is installed in a day. The CIP pilot then delivers audit-ready evidence in three phases. First, a full BES Cyber Asset inventory (CIP-002). Then ESP definition and vendor remote access controls (CIP-003, CIP-005). Finally, MFA enforcement and INSM activation (CIP-007, CIP-015).
NERC can fine up to $1 million per day, per violation. Self-reported violations with a corrective action plan get significantly lower penalties than violations discovered in audit. NERC fined Exelon entities $1.8M in a single enforcement action.