home / frameworks / nerc-cip

// Canadian sector regulators

NERC Critical Infrastructure Protection (CIP) Reliability Standards

NERC's cyber and physical security standards for the bulk electric system, from asset categorization to supply chain risk and network monitoring. They're mandatory in 8 Canadian provinces, each of which adopts and enforces them through its own regulator.

North America (mandatory in 8 Canadian provinces through provincial law)

Overview

The CIP standards are the cyber and physical security part of NERC's reliability standards. They start with categorizing BES Cyber Systems as high, medium, or low impact, then set requirements that scale with that rating. Scope follows the rating. Topics include security management controls, personnel and training, electronic security perimeters, physical security, system security, incident response, recovery, configuration change management, information protection, communications between control centres, supply chain risk, and physical security of key transmission sites. A newer standard, CIP-015, adds internal network security monitoring.

Canada adopts these standards province by province. NERC says its standards are mandatory and enforceable in British Columbia, Alberta, Saskatchewan, Manitoba, Ontario, Quebec, New Brunswick, and Nova Scotia, sometimes with changes to fit local regimes. In Ontario the IESO sets enforcement dates under the market rules, its Market Assessment and Compliance Division enforces them, and the Ontario Energy Board can stay or revoke a standard. Alberta's AESO adopts Alberta reliability standards with AUC approval, including Alberta-only CIP supplements, and the Market Surveillance Administrator enforces them. BC's BCUC adopts standards after review by BC Hydro and uses WECC as its administrator. Quebec's Régie de l'énergie adopts standards filed by Hydro-Québec as reliability coordinator, sets their dates, and uses NPCC to monitor compliance. NERC also holds a memorandum of understanding with the Canada Energy Regulator.

Versions keep moving. On NERC's US schedule, CIP-003-9 (low impact controls) became enforceable on April 1, 2026 and CIP-012-2 on July 1, 2026. A set of revised CIP-002 to CIP-013 versions is due on July 1, 2028, CIP-015-1 on October 1, 2028, and CIP-003-11 and CIP-015-2 in 2029. Provincial dates can lag or differ. Check the regulator's list.

Who it applies to in Canada

Registered owners and operators of the bulk electric system, such as transmission owners and operators, generator owners and operators, balancing authorities, and reliability coordinators. Requirements scale with the impact rating of each BES Cyber System.

Canada's grid is tied into the North American interconnections, and 8 provinces make NERC standards mandatory through their own laws. Each province decides adoption, effective dates, and enforcement, so Canadian utilities follow provincial versions that can differ from US dates.

Controls at a glance

The CIP family has 14 active standards, CIP-002 to CIP-015, each with numbered requirements scaled by impact rating.

CIP-002, BES Cyber System categorization

  • Identify BES Cyber Systems
  • Rate each as high, medium, or low impact
  • Review and approve the list periodically

CIP-003, Security management controls

  • Documented cyber security policies approved by a senior manager
  • Named CIP senior manager and delegations
  • Low impact plans for access, malware, and incident response

CIP-004, Personnel and training

  • Security awareness program
  • Role-based cyber security training
  • Personnel risk assessments before access
  • Timely access revocation

CIP-005, Electronic security perimeters

  • Define electronic security perimeters
  • Control inbound and outbound access
  • Multi-factor authentication for interactive remote access

CIP-006, Physical security of BES Cyber Systems

  • Physical security plan
  • Control and log physical access
  • Visitor control program

CIP-007, System security management

  • Ports and services management
  • Security patch management
  • Malicious code prevention
  • Security event monitoring and account management

CIP-008, Incident reporting and response planning

  • Cyber security incident response plan
  • Test the plan regularly
  • Report reportable incidents and attempts

CIP-009, Recovery plans

  • Recovery plans for BES Cyber Systems
  • Backup and restoration processes
  • Test and update recovery plans

CIP-010, Configuration change management and vulnerability assessments

  • Baseline configurations
  • Authorize and document changes
  • Periodic vulnerability assessments
  • Control transient cyber assets and removable media

CIP-011, Information protection

  • Identify BES Cyber System information
  • Protect it in storage, transit, and use
  • Secure reuse and disposal of assets

CIP-012, Communications between control centres

  • Protect real-time assessment and monitoring data
  • Cover confidentiality and integrity of the data
  • Document the protection plan

CIP-013, Supply chain risk management

  • Supply chain cyber security risk management plan
  • Vendor incident notification and coordination
  • Verify software integrity and authenticity
  • Coordinate vendor remote access controls

CIP-014, Physical security of transmission

  • Risk assessment of transmission stations and substations
  • Third-party verification of the assessment
  • Threat and vulnerability evaluation
  • Physical security plan for identified sites

CIP-015, Internal network security monitoring

  • Monitor network traffic inside the perimeter
  • Detect anomalous activity
  • Keep monitoring data for analysis

Certification and assessment

Registered entities show compliance through audits, spot checks, self-certifications, and self-reports under each province's compliance monitoring program. There's no certification. Violations can lead to penalties set by the provincial authority, and the amounts and procedures differ from one province to the next.

Dates to know

2026-04-01
CIP-003-9 becomes enforceable on NERC's US schedule
2026-07-01
CIP-012-2 becomes enforceable on NERC's US schedule
2028-07-01
Revised CIP-002 to CIP-013 versions scheduled to take effect in the US
2028-10-01
CIP-015-1 internal network security monitoring scheduled to take effect in the US

Resources

Official texts and free tools for NERC CIP. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. CIP Reliability Standards, North American Electric Reliability Corporation (NERC)
  2. North American key players, North American Electric Reliability Corporation (NERC)
  3. Ontario, US comparator, standard-making and enforcement functions, North American Electric Reliability Corporation (NERC)
  4. Alberta, US comparator, standard-making and enforcement functions, North American Electric Reliability Corporation (NERC)
  5. Québec, US comparator, standard-making and enforcement functions, North American Electric Reliability Corporation (NERC)