North American Electric Reliability Corporation Critical Infrastructure Protection
NERC CIP is a set of mandatory cybersecurity rules designed to protect the electric grid infrastructure in North America. The standards require electric utilities and other responsible entities to secure the computer systems and assets that keep the bulk power system running reliably. They are enforced within the electric sector rather than being a voluntary framework that organizations can choose to adopt.
NERC CIP is a series of mandatory cybersecurity standards issued by the North American Electric Reliability Corporation to protect the Bulk Electric System (BES) from cyber and physical security risks. The standards impose obligations on responsible entities to identify and categorize BES Cyber Systems, defined as one or more BES Cyber Assets logically grouped to perform one or more reliability tasks, and to apply corresponding security controls based on impact categorization. Unlike voluntary frameworks such as ISO/IEC 27001 or the NIST Cybersecurity Framework, NERC CIP standards carry enforceable authority within their sector and jurisdiction and are subject to compliance monitoring and penalties for responsible entities. The specific standards, their numbering, applicability criteria, and control requirements are periodically revised; practitioners should verify obligations against the current official NERC CIP standards and the precise scope of entities and assets covered, which vary by impact rating and evolve over time. This entry describes the standards at a general level and does not address specific jurisdictional adoption details, enforcement practice, or the full enumeration of individual CIP requirements.
Why it matters
The bulk power system is foundational infrastructure: disruption to grid operations can cascade across regions, affecting other critical services, commerce, and public safety. NERC CIP exists because voluntary security practices were judged insufficient for assets whose failure carries systemic consequences. By making cybersecurity controls mandatory and enforceable within the electric sector, the standards establish a baseline that responsible entities cannot simply opt out of, unlike frameworks such as ISO/IEC 27001 or the NIST Cybersecurity Framework, which organizations adopt at their discretion.
For compliance and security professionals in the electric sector, NERC CIP matters because non-compliance is not merely a governance gap but a matter subject to compliance monitoring and potential penalties. The standards drive concrete operational obligations, from identifying and categorizing BES Cyber Systems to applying controls proportionate to an asset's impact rating. This risk-based structure means the depth of obligation varies with the criticality of the systems involved, so accurate identification and categorization of assets is a prerequisite to meeting the rest of the requirements.
Because the specific standards, numbering, applicability criteria, and control requirements are periodically revised, the practical significance of NERC CIP lies partly in staying current. Obligations that applied under one version of the standards may change, and the scope of covered entities and assets evolves over time. Practitioners should treat the current official NERC CIP standards as the authoritative reference and verify their obligations against them rather than relying on general summaries.
Who it's relevant to
Inside NERC CIP
Common questions
Answers to the questions practitioners most commonly ask about NERC CIP.

