Compliance & Certifications • Power Sector

Power & Utility SCADA Compliance:
NERC CIP Explained

Merobix Engineering • • 12 min read

NERC CIP is the only OT cybersecurity regime in North America with real teeth: mandatory standards, scheduled audits, and civil penalties that can exceed a million dollars per violation per day. If you own or operate generation or transmission connected to the bulk electric system, some slice of CIP-002 through CIP-014 applies to you - and the size of that slice depends on how your SCADA and control systems are categorized. This guide walks the standards one by one, explains high, medium, and low impact categorization, describes the audit and enforcement machinery, gives honest timeline and cost ranges for building a program, and covers the questions smaller generators, renewables operators, and cloud SCADA buyers actually ask.

Back to Blog

Explore the full security & certification article series - 60+ practitioner guides.

13CIP Standards: CIP-002 to CIP-014
3Impact Levels: High / Medium / Low
$1M+Max Penalty Per Violation Per Day

What NERC CIP Is and Why It Binds

The regulatory driver is the Energy Policy Act of 2005, which made reliability standards for the bulk electric system (BES) mandatory and enforceable. FERC designated NERC as the Electric Reliability Organization, and NERC's Critical Infrastructure Protection (CIP) standards are the cyber and physical security subset. Unlike every voluntary framework in industrial security, CIP violations carry civil penalties - at the statutory maximum, more than one million dollars per violation per day - and compliance is verified by regional entities through scheduled audits, spot checks, and self-report obligations.

Who is in scope? Entities registered with NERC as users, owners, or operators of the BES: balancing authorities, reliability coordinators, transmission owners and operators, and generator owners and operators. As a rough guide, transmission at 100 kV and above and generation above registration thresholds - individual units above roughly 20 MVA, or plants above roughly 75 MVA, connected to the BES - bring an entity into the registry. Distribution utilities, municipal systems below thresholds, and behind-the-meter assets are generally outside CIP, though "generally" is doing work in that sentence: registration criteria have edge cases, so confirm with your regional entity rather than assuming.

CIP-002: Categorization Decides Everything

The first and most consequential standard is CIP-002, which requires you to identify your BES cyber systems - the SCADA, EMS, control, and protection systems whose compromise within 15 minutes could affect reliable operation - and categorize them by impact:

Categorization determines which of the remaining standards apply and how heavily. High and medium impact systems carry the full program: electronic security perimeters, personnel risk assessments, configuration baselines, vulnerability assessments. Low impact systems get a much lighter regime under CIP-003. Getting categorization right - and documenting the engineering rationale - is the foundation the entire compliance program stands on, which is why auditors start there.

The Standards at a Glance

Standard Covers What It Means for SCADA
CIP-002BES cyber system categorizationIdentify and rank every control system by grid impact
CIP-003Security management controlsPolicies, delegated authority, and the complete low-impact obligations
CIP-004Personnel and trainingBackground checks, training, and access revocation for anyone touching BES cyber systems
CIP-005Electronic security perimetersDefined perimeters, controlled inbound/outbound access, intermediate systems for remote access
CIP-006Physical security of cyber systemsPhysical access controls, monitoring, and logging for control system locations
CIP-007System security managementPorts and services, patching, malware prevention, security event monitoring, account management
CIP-008Incident reporting and responseIR plans, testing, and mandatory reporting of incidents and attempts
CIP-009Recovery plansBackup, restoration procedures, and recovery testing for BES cyber systems
CIP-010Configuration change managementBaselines, change authorization, and vulnerability assessments
CIP-011Information protectionProtecting BES Cyber System Information (BCSI) in storage, transit, use, and disposal
CIP-012Control center communicationsProtecting real-time data links between control centers
CIP-013Supply chain risk managementVendor security requirements in procurement: notifications, remote access, software integrity
CIP-014Physical security of key substationsRisk assessment and protection of the most critical transmission stations

Also on the horizon: FERC has directed internal network security monitoring (INSM) for certain CIP environments, and the resulting CIP-015 standard is in the implementation pipeline - meaning east-west traffic visibility inside the perimeter is coming to the compliance floor. Cloud-relevant revisions matter too: CIP-004-7 and CIP-011-3, effective January 1, 2024, explicitly accommodate BCSI in cloud services with proper access and encryption controls.

What Low Impact Actually Requires

Most generators - including the vast majority of solar, wind, and battery plants that register at all - land in the low impact tier, governed by CIP-003's Attachment 1. The obligations are lighter but real: cyber security awareness reinforcement, physical access controls, electronic access controls (permit only necessary inbound and outbound communications at the asset boundary), cyber security incident response plans with periodic testing, controls for transient cyber assets and removable media (the contractor laptop problem), and - in recent revisions - vendor electronic remote access management. There are no formal electronic security perimeter documentation requirements or patch-tracking obligations at low impact, but auditors do expect you to demonstrate the access controls you claim.

Note the architectural implication: an outbound-only communication model - where nothing at the site accepts inbound connections and telemetry leaves through a controlled, encrypted path - is about the cleanest possible story for low-impact electronic access controls. It is also simply good engineering, as we argue in our secure SCADA for OT networks guide.

Audits, Enforcement, and Penalties

Six regional entities audit registered entities on multi-year cycles - commonly every three to six years depending on registration functions and risk profile - supplemented by spot checks and self-certifications. The compliance culture is evidence-driven: policies, dated records, access lists, training logs, and change tickets, all mapped to requirement language. Entities are expected to self-report violations they discover; self-reports with strong mitigation are treated far more gently than audit findings.

Penalties scale with risk and duration. Most findings settle well below the statutory maximum, but the record shows the ceiling is real - settlements in the millions, and one widely reported 2019 settlement reached ten million dollars across a large violation history. The quieter cost is remediation under a mitigation plan on an auditor's timeline, plus heightened scrutiny for years afterward. Budget-wise, honest ranges: standing up a credible low-impact program is typically a several-week to few-month effort largely in documentation and access-control cleanup; medium and high impact programs are 12 to 24 month builds with dedicated compliance staff, and ongoing costs (evidence maintenance, patch tracking, training, audits) that commonly run into hundreds of thousands of dollars per year for larger entities. These vary enormously with fleet size and starting posture.

The Compliance Process, Step by Step

  1. Confirm registration and functions with your regional entity; map which standards attach to each function.
  2. Run CIP-002 categorization across all assets, with documented rationale, and have it reviewed - miscategorization poisons everything downstream.
  3. Gap-assess against the applicable requirements, honestly. Third-party mock audits are worth their fee here.
  4. Build the program: policies and delegations (CIP-003), personnel and training workflow (CIP-004), network architecture and access controls (CIP-005/007), incident response and recovery plans (CIP-008/009), change management (CIP-010), information protection (CIP-011), and supply-chain procurement language (CIP-013).
  5. Operationalize evidence. Every control needs a record it produces automatically - access logs, training completions, change tickets, alarm and event histories. Evidence that requires heroics before an audit is evidence that will fail one.
  6. Exercise and self-assess annually, self-report honestly when you find gaps, and track standard revisions - CIP moves continuously.

Cloud SCADA and NERC CIP: What Fits Where

Can a cloud SCADA platform live inside a CIP program? The honest answer is: it depends on the asset class. For high and medium impact BES cyber systems, the perimeter-oriented standards still make cloud-hosted control genuinely hard to fit, and most entities keep those systems on-premise (NERC's cloud workstreams are actively evolving this). But a large share of real-world power-sector SCADA sits outside that boundary: distribution utilities, municipal systems, behind-the-meter generation, small renewables below registration thresholds, and low-impact monitoring contexts - where cloud platforms are both permissible and often the stronger security choice, because MFA, audit trails, patching, and monitored delivery arrive as platform defaults rather than staffing problems.

This is the segment Merobix serves. The platform's architecture reads like a CIP control catalog even where CIP does not bind: outbound-only gateway (electronic access control by construction), TOTP and FIDO2 MFA with roles, session revocation, and access audit chains (CIP-004-style personnel evidence), signed telemetry envelopes with replay detection, encryption of sensitive data with TLS everywhere (CIP-011-style information protection), runtime threat detection with SIEM delivery, and backup validation with controlled restore tooling (CIP-009-style recovery). For vendor-risk diligence of the CIP-013 flavor, Merobix runs a SOC 2 readiness program, maps its controls to IEC 62443, and is building release assurance with signed build provenance so software integrity is verifiable - framed as roadmap, because that work is in progress. Architecture details are on the security page; the deployment trade-offs are covered in our cloud vs on-premise comparison, and you can evaluate the evidence trail yourself in a demo.

What to Look For in a SCADA Vendor for Power and Utilities

Key takeaway: CIP compliance is decided at categorization and won on evidence. Get CIP-002 right with documented rationale, build controls that generate their own records, and choose vendors whose architecture makes your electronic access story simple. And if your assets sit outside CIP scope today - distribution, small renewables, behind-the-meter - build to CIP-grade controls anyway: the regulatory floor for the power sector only moves in one direction.

Utilities that operate both generation and water assets face overlapping regimes - the AWIA requirements for water utility SCADA follow a similar risk-assessment logic, and substations speaking DNP3 can layer on DNP3 Secure Authentication for command integrity.

Frequently Asked Questions

Who has to comply with NERC CIP?

Entities registered with NERC as users, owners, or operators of the Bulk Electric System (BES) - generally facilities operating at 100 kV and above and generation above registration thresholds (individual units above roughly 20 MVA or plants above roughly 75 MVA connected to the BES, with nuances). That includes balancing authorities, transmission owners and operators, generator owners and operators, and reliability coordinators. Distribution utilities and behind-the-meter or small distributed generation generally fall outside CIP scope, though state rules and good practice still apply. Registration criteria have edge cases, especially for aggregated renewable portfolios, so confirm your status with your regional entity rather than assuming.

What are high, medium, and low impact BES cyber systems?

CIP-002 requires every registered entity to categorize its BES cyber systems by the impact their compromise would have on the grid. High impact covers large control centers; medium impact covers large generation facilities (generally 1,500 MW and above in a single interconnection), major transmission facilities, and certain control centers; everything else that qualifies as a BES cyber system is low impact. The category determines which requirements apply: high and medium systems face the full weight of the standards (electronic security perimeters, personnel screening, configuration change management, and more), while low impact systems have a lighter set under CIP-003 covering security awareness, physical and electronic access controls, incident response, and transient cyber assets.

What happens if you violate NERC CIP?

NERC CIP is mandatory and enforceable under the Energy Policy Act of 2005, with civil penalties that can reach over one million dollars per violation per day at the statutory maximum. In practice most findings are settled for far less, scaled by risk and duration, but seven- and eight-figure settlements have occurred for extensive violation histories. Regional entities audit registered entities on multi-year cycles (commonly every three to six years depending on registration and risk), and entities are expected to self-report violations they discover. Beyond fines, a poor compliance record brings increased audit scrutiny and mandated mitigation plans, so the operational cost of weak programs compounds.

Can cloud SCADA be used under NERC CIP?

Increasingly yes, with care about scope. Revised standards effective January 1, 2024 (CIP-004-7 and CIP-011-3) explicitly accommodate BES Cyber System Information stored in the cloud with appropriate access and encryption controls, and NERC has active work underway on broader cloud use. For high and medium impact BES cyber systems themselves, the perimeter-based standards still make cloud-hosted control difficult to fit. Where cloud SCADA fits cleanly today: low impact contexts, distribution-level and behind-the-meter assets outside CIP scope, market and analytics data, and monitoring alongside a compliant control system. Verify with your regional entity, and demand strong isolation, encryption, and audit evidence from any cloud vendor regardless.

Does NERC CIP apply to solar, wind, and battery projects?

It depends on size and connection. Renewable plants that meet BES registration criteria - generally plants above roughly 75 MVA aggregate connected at 100 kV or above - register as generator owners and operators and must comply, typically as low impact unless very large. Many distributed solar, small wind, and behind-the-meter battery projects fall below thresholds and are out of CIP scope entirely. Two cautions: portfolios of smaller sites can approach thresholds in aggregate as rules evolve, and inverter-based resources are receiving growing reliability and security attention from NERC, so the compliance floor for renewables is more likely to rise than fall. Design new SCADA deployments to CIP-grade controls from day one.

Sources & Further Reading

Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.

CIP-Grade Controls Without the CIP-Grade Staffing

Outbound-only access, MFA, audit chains, and SIEM delivery as platform defaults - see where Merobix fits your generation and distribution assets.

Request a Demo → See Our Security Architecture
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →