Requirements at a glance
Identify and categorize
Consider each asset type (Control Centers, transmission stations and substations, generation resources, special protection systems and more) and identify each high impact and medium impact BES Cyber System using the Attachment 1 criteria. Identify each asset that contains a low impact BES Cyber System (a list of the systems themselves is not required).
Review and approve every 15 months
Review the R1 identifications at least once every 15 calendar months and update them if needed, even if nothing changed. Have the CIP Senior Manager or delegate approve the R1 identifications at the same interval.
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
Recurring deadlines
| Obligation | Interval | Requirement | In CIP Sentry |
|---|---|---|---|
| Review BES Cyber System identifications and update as needed | 15 calendar months | CIP-002-5.1a R2.1 | Auto-tracked |
| CIP Senior Manager (or delegate) approval of the identifications | 15 calendar months | CIP-002-5.1a R2.2 |
Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines
Why CIP-002 matters more than any other standard
Every other CIP standard scopes its requirements by impact rating. Get CIP-002 wrong and the error flows everywhere: systems that should have had electronic access controls don’t, or you spend money protecting things that were never in scope. Auditors know this, so the categorization methodology is often the first thing they read.
How categorization works
- List your BES assets. Work through the asset types in R1: Control Centers and backup Control Centers, transmission stations and substations, generation resources, systems and facilities critical to system restoration (Blackstart Resources and Cranking Paths), Special Protection Systems, and qualifying distribution protective systems.
- Find the BES Cyber Systems at each asset. A BES Cyber System is one or more BES Cyber Assets grouped to perform a reliability task. A BES Cyber Asset is a Cyber Asset whose loss would affect the BES within 15 minutes.
- Apply Attachment 1 from the top down. Criteria 1.1–1.4 set high impact (mostly large Control Centers). Criteria 2.1–2.13 set medium impact (for example generation at or above 1,500 MW at a single site, transmission stations above the weighted-value threshold, and certain Control Centers). Everything else at a BES asset is low impact.
- Document the reasoning. Record which criterion applied and the numbers behind it, such as net real power capability or aggregate weighted value.
Common audit findings
- No evidence of the “boring” review. The 15-month review happened in someone’s head. Keep a dated record even when nothing changed.
- Stale capability numbers. Generation capacity or line counts changed after an uprate or a new interconnection, but the categorization didn’t.
- Planned changes missed. New assets that go live between reviews must be categorized when they become subject to the standard, not at the next review.
- Grouping without rationale. How BES Cyber Assets are grouped into systems is your choice, but it should be deliberate and documented.
Preparing for CIP-002-8 and virtualization (2028)
FERC’s March 2026 orders approved the virtualization package (CIP-002-7 and its companions) and CIP-002-8. From July 1, 2028, new glossary terms such as Cyber System, Virtual Cyber Asset and Shared Cyber Infrastructure change how you describe what you own, and the Control Center definition and criterion 2.12 change. Entities with virtualized servers, hypervisors or shared storage should start mapping them now.
Evidence auditors typically ask for
- Your documented categorization methodology and the asset list it was applied to
- Dated lists of high and medium impact BES Cyber Systems and of assets containing low impact systems
- Attachment 1 criteria worksheets showing why each asset landed where it did (for example 2.1 generation capacity, 2.5 transmission weighted value)
- Signed and dated CIP Senior Manager approvals no more than 15 calendar months apart
- Records of reviews showing what was checked, including reviews where nothing changed
How CIP Sentry helps with CIP-002
Attachment 1 built in
Each BES Cyber System records the impact rating and the Attachment 1 criterion that set it, so the reason for every rating travels with the system.
Inventory first
Cyber Assets are tracked in or out of CIP scope, so the path from asset to BES Cyber System to impact rating is always visible.
15-month review clock
The annual categorization review and approval show up as a compliance clock long before they are due, with the approval recorded against the CIP Senior Manager's seat.
Audit-ready lists
Generate dated high, medium and low impact lists and categorization reports in PDF or Excel on demand.
CIP-002 FAQ
Do we need to list every low impact BES Cyber System?
No. CIP-002-5.1a R1.3 requires you to identify each asset that contains a low impact BES Cyber System. An inventory of the individual low impact systems or Cyber Assets is not required, though many entities keep one anyway to support CIP-003.
What happens with CIP-002-8?
FERC approved CIP-002-8 in March 2026. It revises the Control Center definition and Attachment 1 criterion 2.12 and takes effect with the virtualization package on July 1, 2028. Plan a re-categorization review before then.
Does a 'no change' review still count?
Yes, but only if you can prove it happened. Keep dated evidence of what you reviewed and the CIP Senior Manager's approval even when the lists did not change.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

