Overview
The CIP standards are the cyber and physical security part of NERC's reliability standards. They start with categorizing BES Cyber Systems as high, medium, or low impact, then set requirements that scale with that rating. Scope follows the rating. Topics include security management controls, personnel and training, electronic security perimeters, physical security, system security, incident response, recovery, configuration change management, information protection, communications between control centres, supply chain risk, and physical security of key transmission sites. A newer standard, CIP-015, adds internal network security monitoring.
Canada adopts these standards province by province. NERC says its standards are mandatory and enforceable in British Columbia, Alberta, Saskatchewan, Manitoba, Ontario, Quebec, New Brunswick, and Nova Scotia, sometimes with changes to fit local regimes. In Ontario the IESO sets enforcement dates under the market rules, its Market Assessment and Compliance Division enforces them, and the Ontario Energy Board can stay or revoke a standard. Alberta's AESO adopts Alberta reliability standards with AUC approval, including Alberta-only CIP supplements, and the Market Surveillance Administrator enforces them. BC's BCUC adopts standards after review by BC Hydro and uses WECC as its administrator. Quebec's Régie de l'énergie adopts standards filed by Hydro-Québec as reliability coordinator, sets their dates, and uses NPCC to monitor compliance. NERC also holds a memorandum of understanding with the Canada Energy Regulator.
Versions keep moving. On NERC's US schedule, CIP-003-9 (low impact controls) became enforceable on April 1, 2026 and CIP-012-2 on July 1, 2026. A set of revised CIP-002 to CIP-013 versions is due on July 1, 2028, CIP-015-1 on October 1, 2028, and CIP-003-11 and CIP-015-2 in 2029. Provincial dates can lag or differ. Check the regulator's list.
Who it applies to in Canada
Registered owners and operators of the bulk electric system, such as transmission owners and operators, generator owners and operators, balancing authorities, and reliability coordinators. Requirements scale with the impact rating of each BES Cyber System.
Canada's grid is tied into the North American interconnections, and 8 provinces make NERC standards mandatory through their own laws. Each province decides adoption, effective dates, and enforcement, so Canadian utilities follow provincial versions that can differ from US dates.
Controls at a glance
The CIP family has 14 active standards, CIP-002 to CIP-015, each with numbered requirements scaled by impact rating.
CIP-002, BES Cyber System categorization
- Identify BES Cyber Systems
- Rate each as high, medium, or low impact
- Review and approve the list periodically
CIP-003, Security management controls
- Documented cyber security policies approved by a senior manager
- Named CIP senior manager and delegations
- Low impact plans for access, malware, and incident response
CIP-004, Personnel and training
- Security awareness program
- Role-based cyber security training
- Personnel risk assessments before access
- Timely access revocation
CIP-005, Electronic security perimeters
- Define electronic security perimeters
- Control inbound and outbound access
- Multi-factor authentication for interactive remote access
CIP-006, Physical security of BES Cyber Systems
- Physical security plan
- Control and log physical access
- Visitor control program
CIP-007, System security management
- Ports and services management
- Security patch management
- Malicious code prevention
- Security event monitoring and account management
CIP-008, Incident reporting and response planning
- Cyber security incident response plan
- Test the plan regularly
- Report reportable incidents and attempts
CIP-009, Recovery plans
- Recovery plans for BES Cyber Systems
- Backup and restoration processes
- Test and update recovery plans
CIP-010, Configuration change management and vulnerability assessments
- Baseline configurations
- Authorize and document changes
- Periodic vulnerability assessments
- Control transient cyber assets and removable media
CIP-011, Information protection
- Identify BES Cyber System information
- Protect it in storage, transit, and use
- Secure reuse and disposal of assets
CIP-012, Communications between control centres
- Protect real-time assessment and monitoring data
- Cover confidentiality and integrity of the data
- Document the protection plan
CIP-013, Supply chain risk management
- Supply chain cyber security risk management plan
- Vendor incident notification and coordination
- Verify software integrity and authenticity
- Coordinate vendor remote access controls
CIP-014, Physical security of transmission
- Risk assessment of transmission stations and substations
- Third-party verification of the assessment
- Threat and vulnerability evaluation
- Physical security plan for identified sites
CIP-015, Internal network security monitoring
- Monitor network traffic inside the perimeter
- Detect anomalous activity
- Keep monitoring data for analysis
Certification and assessment
Registered entities show compliance through audits, spot checks, self-certifications, and self-reports under each province's compliance monitoring program. There's no certification. Violations can lead to penalties set by the provincial authority, and the amounts and procedures differ from one province to the next.
Dates to know
- 2026-04-01
- CIP-003-9 becomes enforceable on NERC's US schedule
- 2026-07-01
- CIP-012-2 becomes enforceable on NERC's US schedule
- 2028-07-01
- Revised CIP-002 to CIP-013 versions scheduled to take effect in the US
- 2028-10-01
- CIP-015-1 internal network security monitoring scheduled to take effect in the US
Resources
Official texts and free tools for NERC CIP. Links open the publisher’s site.
- CIP Reliability Standards, North American Electric Reliability Corporation (NERC)
- North American key players, with federal and provincial summaries, North American Electric Reliability Corporation (NERC)
- Ontario enforcement dates for NERC reliability standards and NPCC criteria, Independent Electricity System Operator (IESO)
- Alberta reliability standards, Alberta Electric System Operator (AESO)
- Normes de fiabilité (reliability standards), Régie de l'énergie du Québec
Need help? Browse the directory or read the guides.
References
- CIP Reliability Standards, North American Electric Reliability Corporation (NERC)
- North American key players, North American Electric Reliability Corporation (NERC)
- Ontario, US comparator, standard-making and enforcement functions, North American Electric Reliability Corporation (NERC)
- Alberta, US comparator, standard-making and enforcement functions, North American Electric Reliability Corporation (NERC)
- Québec, US comparator, standard-making and enforcement functions, North American Electric Reliability Corporation (NERC)
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.