CIP-002 · BES Cyber System Categorization

CIP-002: categorize every BES Cyber System, then keep the list true.

CIP-002 is where every CIP program starts. It decides which of your systems are high, medium or low impact, and therefore which of the other thirteen standards apply to them.

Enforceable nowCIP-002-5.1a (effective December 27, 2016)
Next versionCIP-002-8 (July 1, 2028) with the virtualization package
Applies toBAs, DPs with qualifying UFLS/UVLS/RAS/protection systems, GOs, GOPs, RCs, TOs and TOPs

Requirements at a glance

R1

Identify and categorize

Consider each asset type (Control Centers, transmission stations and substations, generation resources, special protection systems and more) and identify each high impact and medium impact BES Cyber System using the Attachment 1 criteria. Identify each asset that contains a low impact BES Cyber System (a list of the systems themselves is not required).

R2

Review and approve every 15 months

Review the R1 identifications at least once every 15 calendar months and update them if needed, even if nothing changed. Have the CIP Senior Manager or delegate approve the R1 identifications at the same interval.

Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.

Recurring deadlines

ObligationIntervalRequirementIn CIP Sentry
Review BES Cyber System identifications and update as needed15 calendar monthsCIP-002-5.1a R2.1Auto-tracked
CIP Senior Manager (or delegate) approval of the identifications15 calendar monthsCIP-002-5.1a R2.2

Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines

Why CIP-002 matters more than any other standard

Every other CIP standard scopes its requirements by impact rating. Get CIP-002 wrong and the error flows everywhere: systems that should have had electronic access controls don’t, or you spend money protecting things that were never in scope. Auditors know this, so the categorization methodology is often the first thing they read.

How categorization works

  1. List your BES assets. Work through the asset types in R1: Control Centers and backup Control Centers, transmission stations and substations, generation resources, systems and facilities critical to system restoration (Blackstart Resources and Cranking Paths), Special Protection Systems, and qualifying distribution protective systems.
  2. Find the BES Cyber Systems at each asset. A BES Cyber System is one or more BES Cyber Assets grouped to perform a reliability task. A BES Cyber Asset is a Cyber Asset whose loss would affect the BES within 15 minutes.
  3. Apply Attachment 1 from the top down. Criteria 1.1–1.4 set high impact (mostly large Control Centers). Criteria 2.1–2.13 set medium impact (for example generation at or above 1,500 MW at a single site, transmission stations above the weighted-value threshold, and certain Control Centers). Everything else at a BES asset is low impact.
  4. Document the reasoning. Record which criterion applied and the numbers behind it, such as net real power capability or aggregate weighted value.

Common audit findings

  • No evidence of the “boring” review. The 15-month review happened in someone’s head. Keep a dated record even when nothing changed.
  • Stale capability numbers. Generation capacity or line counts changed after an uprate or a new interconnection, but the categorization didn’t.
  • Planned changes missed. New assets that go live between reviews must be categorized when they become subject to the standard, not at the next review.
  • Grouping without rationale. How BES Cyber Assets are grouped into systems is your choice, but it should be deliberate and documented.

Preparing for CIP-002-8 and virtualization (2028)

FERC’s March 2026 orders approved the virtualization package (CIP-002-7 and its companions) and CIP-002-8. From July 1, 2028, new glossary terms such as Cyber System, Virtual Cyber Asset and Shared Cyber Infrastructure change how you describe what you own, and the Control Center definition and criterion 2.12 change. Entities with virtualized servers, hypervisors or shared storage should start mapping them now.

Evidence auditors typically ask for

  • Your documented categorization methodology and the asset list it was applied to
  • Dated lists of high and medium impact BES Cyber Systems and of assets containing low impact systems
  • Attachment 1 criteria worksheets showing why each asset landed where it did (for example 2.1 generation capacity, 2.5 transmission weighted value)
  • Signed and dated CIP Senior Manager approvals no more than 15 calendar months apart
  • Records of reviews showing what was checked, including reviews where nothing changed

How CIP Sentry helps with CIP-002

Attachment 1 built in

Each BES Cyber System records the impact rating and the Attachment 1 criterion that set it, so the reason for every rating travels with the system.

Inventory first

Cyber Assets are tracked in or out of CIP scope, so the path from asset to BES Cyber System to impact rating is always visible.

15-month review clock

The annual categorization review and approval show up as a compliance clock long before they are due, with the approval recorded against the CIP Senior Manager's seat.

Audit-ready lists

Generate dated high, medium and low impact lists and categorization reports in PDF or Excel on demand.

CIP-002 FAQ

Do we need to list every low impact BES Cyber System?

No. CIP-002-5.1a R1.3 requires you to identify each asset that contains a low impact BES Cyber System. An inventory of the individual low impact systems or Cyber Assets is not required, though many entities keep one anyway to support CIP-003.

What happens with CIP-002-8?

FERC approved CIP-002-8 in March 2026. It revises the Control Center definition and Attachment 1 criterion 2.12 and takes effect with the virtualization package on July 1, 2028. Plan a re-categorization review before then.

Does a 'no change' review still count?

Yes, but only if you can prove it happened. Keep dated evidence of what you reviewed and the CIP Senior Manager's approval even when the lists did not change.

Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

Related standards

Request a quote

Run CIP-002 without the spreadsheet.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.