NERC CIP is the only OT cybersecurity regime in North America with real teeth: mandatory standards, scheduled audits, and civil penalties that can exceed a million dollars per violation per day. If you own or operate generation or transmission connected to the bulk electric system, some slice of CIP-002 through CIP-014 applies to you - and the size of that slice depends on how your SCADA and control systems are categorized. This guide walks the standards one by one, explains high, medium, and low impact categorization, describes the audit and enforcement machinery, gives honest timeline and cost ranges for building a program, and covers the questions smaller generators, renewables operators, and cloud SCADA buyers actually ask.
Explore the full security & certification article series - 60+ practitioner guides.
The regulatory driver is the Energy Policy Act of 2005, which made reliability standards for the bulk electric system (BES) mandatory and enforceable. FERC designated NERC as the Electric Reliability Organization, and NERC's Critical Infrastructure Protection (CIP) standards are the cyber and physical security subset. Unlike every voluntary framework in industrial security, CIP violations carry civil penalties - at the statutory maximum, more than one million dollars per violation per day - and compliance is verified by regional entities through scheduled audits, spot checks, and self-report obligations.
Who is in scope? Entities registered with NERC as users, owners, or operators of the BES: balancing authorities, reliability coordinators, transmission owners and operators, and generator owners and operators. As a rough guide, transmission at 100 kV and above and generation above registration thresholds - individual units above roughly 20 MVA, or plants above roughly 75 MVA, connected to the BES - bring an entity into the registry. Distribution utilities, municipal systems below thresholds, and behind-the-meter assets are generally outside CIP, though "generally" is doing work in that sentence: registration criteria have edge cases, so confirm with your regional entity rather than assuming.
The first and most consequential standard is CIP-002, which requires you to identify your BES cyber systems - the SCADA, EMS, control, and protection systems whose compromise within 15 minutes could affect reliable operation - and categorize them by impact:
Categorization determines which of the remaining standards apply and how heavily. High and medium impact systems carry the full program: electronic security perimeters, personnel risk assessments, configuration baselines, vulnerability assessments. Low impact systems get a much lighter regime under CIP-003. Getting categorization right - and documenting the engineering rationale - is the foundation the entire compliance program stands on, which is why auditors start there.
| Standard | Covers | What It Means for SCADA |
|---|---|---|
| CIP-002 | BES cyber system categorization | Identify and rank every control system by grid impact |
| CIP-003 | Security management controls | Policies, delegated authority, and the complete low-impact obligations |
| CIP-004 | Personnel and training | Background checks, training, and access revocation for anyone touching BES cyber systems |
| CIP-005 | Electronic security perimeters | Defined perimeters, controlled inbound/outbound access, intermediate systems for remote access |
| CIP-006 | Physical security of cyber systems | Physical access controls, monitoring, and logging for control system locations |
| CIP-007 | System security management | Ports and services, patching, malware prevention, security event monitoring, account management |
| CIP-008 | Incident reporting and response | IR plans, testing, and mandatory reporting of incidents and attempts |
| CIP-009 | Recovery plans | Backup, restoration procedures, and recovery testing for BES cyber systems |
| CIP-010 | Configuration change management | Baselines, change authorization, and vulnerability assessments |
| CIP-011 | Information protection | Protecting BES Cyber System Information (BCSI) in storage, transit, use, and disposal |
| CIP-012 | Control center communications | Protecting real-time data links between control centers |
| CIP-013 | Supply chain risk management | Vendor security requirements in procurement: notifications, remote access, software integrity |
| CIP-014 | Physical security of key substations | Risk assessment and protection of the most critical transmission stations |
Also on the horizon: FERC has directed internal network security monitoring (INSM) for certain CIP environments, and the resulting CIP-015 standard is in the implementation pipeline - meaning east-west traffic visibility inside the perimeter is coming to the compliance floor. Cloud-relevant revisions matter too: CIP-004-7 and CIP-011-3, effective January 1, 2024, explicitly accommodate BCSI in cloud services with proper access and encryption controls.
Most generators - including the vast majority of solar, wind, and battery plants that register at all - land in the low impact tier, governed by CIP-003's Attachment 1. The obligations are lighter but real: cyber security awareness reinforcement, physical access controls, electronic access controls (permit only necessary inbound and outbound communications at the asset boundary), cyber security incident response plans with periodic testing, controls for transient cyber assets and removable media (the contractor laptop problem), and - in recent revisions - vendor electronic remote access management. There are no formal electronic security perimeter documentation requirements or patch-tracking obligations at low impact, but auditors do expect you to demonstrate the access controls you claim.
Note the architectural implication: an outbound-only communication model - where nothing at the site accepts inbound connections and telemetry leaves through a controlled, encrypted path - is about the cleanest possible story for low-impact electronic access controls. It is also simply good engineering, as we argue in our secure SCADA for OT networks guide.
Six regional entities audit registered entities on multi-year cycles - commonly every three to six years depending on registration functions and risk profile - supplemented by spot checks and self-certifications. The compliance culture is evidence-driven: policies, dated records, access lists, training logs, and change tickets, all mapped to requirement language. Entities are expected to self-report violations they discover; self-reports with strong mitigation are treated far more gently than audit findings.
Penalties scale with risk and duration. Most findings settle well below the statutory maximum, but the record shows the ceiling is real - settlements in the millions, and one widely reported 2019 settlement reached ten million dollars across a large violation history. The quieter cost is remediation under a mitigation plan on an auditor's timeline, plus heightened scrutiny for years afterward. Budget-wise, honest ranges: standing up a credible low-impact program is typically a several-week to few-month effort largely in documentation and access-control cleanup; medium and high impact programs are 12 to 24 month builds with dedicated compliance staff, and ongoing costs (evidence maintenance, patch tracking, training, audits) that commonly run into hundreds of thousands of dollars per year for larger entities. These vary enormously with fleet size and starting posture.
Can a cloud SCADA platform live inside a CIP program? The honest answer is: it depends on the asset class. For high and medium impact BES cyber systems, the perimeter-oriented standards still make cloud-hosted control genuinely hard to fit, and most entities keep those systems on-premise (NERC's cloud workstreams are actively evolving this). But a large share of real-world power-sector SCADA sits outside that boundary: distribution utilities, municipal systems, behind-the-meter generation, small renewables below registration thresholds, and low-impact monitoring contexts - where cloud platforms are both permissible and often the stronger security choice, because MFA, audit trails, patching, and monitored delivery arrive as platform defaults rather than staffing problems.
This is the segment Merobix serves. The platform's architecture reads like a CIP control catalog even where CIP does not bind: outbound-only gateway (electronic access control by construction), TOTP and FIDO2 MFA with roles, session revocation, and access audit chains (CIP-004-style personnel evidence), signed telemetry envelopes with replay detection, encryption of sensitive data with TLS everywhere (CIP-011-style information protection), runtime threat detection with SIEM delivery, and backup validation with controlled restore tooling (CIP-009-style recovery). For vendor-risk diligence of the CIP-013 flavor, Merobix runs a SOC 2 readiness program, maps its controls to IEC 62443, and is building release assurance with signed build provenance so software integrity is verifiable - framed as roadmap, because that work is in progress. Architecture details are on the security page; the deployment trade-offs are covered in our cloud vs on-premise comparison, and you can evaluate the evidence trail yourself in a demo.
Key takeaway: CIP compliance is decided at categorization and won on evidence. Get CIP-002 right with documented rationale, build controls that generate their own records, and choose vendors whose architecture makes your electronic access story simple. And if your assets sit outside CIP scope today - distribution, small renewables, behind-the-meter - build to CIP-grade controls anyway: the regulatory floor for the power sector only moves in one direction.
Utilities that operate both generation and water assets face overlapping regimes - the AWIA requirements for water utility SCADA follow a similar risk-assessment logic, and substations speaking DNP3 can layer on DNP3 Secure Authentication for command integrity.
Entities registered with NERC as users, owners, or operators of the Bulk Electric System (BES) - generally facilities operating at 100 kV and above and generation above registration thresholds (individual units above roughly 20 MVA or plants above roughly 75 MVA connected to the BES, with nuances). That includes balancing authorities, transmission owners and operators, generator owners and operators, and reliability coordinators. Distribution utilities and behind-the-meter or small distributed generation generally fall outside CIP scope, though state rules and good practice still apply. Registration criteria have edge cases, especially for aggregated renewable portfolios, so confirm your status with your regional entity rather than assuming.
CIP-002 requires every registered entity to categorize its BES cyber systems by the impact their compromise would have on the grid. High impact covers large control centers; medium impact covers large generation facilities (generally 1,500 MW and above in a single interconnection), major transmission facilities, and certain control centers; everything else that qualifies as a BES cyber system is low impact. The category determines which requirements apply: high and medium systems face the full weight of the standards (electronic security perimeters, personnel screening, configuration change management, and more), while low impact systems have a lighter set under CIP-003 covering security awareness, physical and electronic access controls, incident response, and transient cyber assets.
NERC CIP is mandatory and enforceable under the Energy Policy Act of 2005, with civil penalties that can reach over one million dollars per violation per day at the statutory maximum. In practice most findings are settled for far less, scaled by risk and duration, but seven- and eight-figure settlements have occurred for extensive violation histories. Regional entities audit registered entities on multi-year cycles (commonly every three to six years depending on registration and risk), and entities are expected to self-report violations they discover. Beyond fines, a poor compliance record brings increased audit scrutiny and mandated mitigation plans, so the operational cost of weak programs compounds.
Increasingly yes, with care about scope. Revised standards effective January 1, 2024 (CIP-004-7 and CIP-011-3) explicitly accommodate BES Cyber System Information stored in the cloud with appropriate access and encryption controls, and NERC has active work underway on broader cloud use. For high and medium impact BES cyber systems themselves, the perimeter-based standards still make cloud-hosted control difficult to fit. Where cloud SCADA fits cleanly today: low impact contexts, distribution-level and behind-the-meter assets outside CIP scope, market and analytics data, and monitoring alongside a compliant control system. Verify with your regional entity, and demand strong isolation, encryption, and audit evidence from any cloud vendor regardless.
It depends on size and connection. Renewable plants that meet BES registration criteria - generally plants above roughly 75 MVA aggregate connected at 100 kV or above - register as generator owners and operators and must comply, typically as low impact unless very large. Many distributed solar, small wind, and behind-the-meter battery projects fall below thresholds and are out of CIP scope entirely. Two cautions: portfolios of smaller sites can approach thresholds in aggregate as rules evolve, and inverter-based resources are receiving growing reliability and security attention from NERC, so the compliance floor for renewables is more likely to rise than fall. Design new SCADA deployments to CIP-grade controls from day one.
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
Outbound-only access, MFA, audit chains, and SIEM delivery as platform defaults - see where Merobix fits your generation and distribution assets.