Requirements at a glance
Documented cyber security policies
Policies approved by the CIP Senior Manager at least once every 15 calendar months. R1.1 covers the topics for high and medium impact systems (personnel and training, perimeters, physical security, system security, incident response, recovery, configuration change management, information protection, CIP Exceptional Circumstances). R1.2 covers low impact topics, including vendor electronic remote access in CIP-003-9.
Low impact cyber security plan(s)
For assets with low impact BES Cyber Systems, implement documented plans covering the Attachment 1 sections: security awareness, physical security controls, electronic access controls, Cyber Security Incident response, transient cyber asset and removable media malicious code mitigation, and vendor electronic remote access security controls.
Identify a CIP Senior Manager
Name a single CIP Senior Manager and document any change within 30 calendar days.
Delegation of authority
Document the process by which the CIP Senior Manager delegates authority, with delegate names, the actions delegated, and dates. Changes to delegates are documented within 30 days.
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
Recurring deadlines
| Obligation | Interval | Requirement | In CIP Sentry |
|---|---|---|---|
| CIP Senior Manager approval of high/medium impact policies | 15 calendar months | CIP-003-9 R1.1 | Auto-tracked |
| CIP Senior Manager approval of low impact policies | 15 calendar months | CIP-003-9 R1.2 | Auto-tracked |
| Low impact security awareness reinforcement | 15 calendar months | CIP-003-9 Att. 1 Sec. 1 | Auto-tracked |
| Test the low impact Cyber Security Incident response plan | 36 calendar months | CIP-003-9 Att. 1 Sec. 4.5 | Auto-tracked |
| Update the low impact incident response plan after a test or actual incident | 180 calendar days | CIP-003-9 Att. 1 Sec. 4.6 | Auto-tracked |
| Document a change of CIP Senior Manager or delegate | 30 calendar days | CIP-003-9 R3, R4 |
Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines
Governance that auditors test first
CIP-003 is short, but auditors lean on it because it proves accountability. They will look for a single named CIP Senior Manager, dated approvals, and delegations that match what people actually signed. A policy approved 16 months after the last one is a violation even if nothing else changed.
The low impact plan, section by section
If your entity has only low impact BES Cyber Systems, CIP-003-9 R2 and Attachment 1 are your CIP program. Each section needs a documented plan and evidence that you implemented it:
- Cyber security awareness. Reinforce good practices at least once every 15 calendar months.
- Physical security controls. Control physical access to the asset or the locations of the low impact systems, and to any electronic access control devices.
- Electronic access controls. Permit only necessary inbound and outbound routable communication and authenticate dial-up access.
- Cyber Security Incident response. Identify, classify and respond to incidents, report reportable incidents to the E-ISAC, test the plan every 36 months, and update it within 180 days.
- Transient cyber assets and removable media. Mitigate the risk of malicious code on laptops and USB media, whether you or a vendor manage them.
- Vendor electronic remote access (new in CIP-003-9). Determine when vendors have remote access, be able to disable it, and detect known or suspected malicious communications for both inbound and outbound traffic.
Getting Section 6 right
Section 6 caught many small utilities and generators off guard in April 2026. Start with an honest inventory of every way a vendor can reach a low impact system: OEM remote support modems, cellular gateways at solar and wind sites, integrator VPNs and vendor-managed firewalls. Then document how each path is identified, switched off on demand, and monitored. Keep the evidence (session logs, firewall rules, alerts) where it can be pulled for an audit.
Evidence auditors typically ask for
- Current policies with CIP Senior Manager approval dates no more than 15 months apart
- A dated CIP Senior Manager designation and delegation records with the specific authority delegated
- Your low impact plan(s) mapped to each Attachment 1 section, per asset or asset group
- Security awareness materials and proof of distribution
- Diagrams and configurations showing how inbound and outbound electronic access to low impact systems is permitted only where necessary
- Vendor remote access controls: how you determine, disable and detect vendor electronic remote access (Section 6)
- Incident response plan tests and post-test updates, and transient cyber asset procedures
How CIP Sentry helps with CIP-003
Policy approvals on a clock
Policy & Low Impact tracks R1.1 and R1.2 policies separately and puts each 15-month CIP Senior Manager approval on the dashboard before it is due.
Low Impact Plan workspace
Build the R2 plan section by section against Attachment 1, including Section 6 vendor electronic remote access, with the tests and updates on their own 36-month and 180-day clocks.
Roles & Seats
Record the CIP Senior Manager, delegates and each group's CAO (Cyber Asset Owner, also called Change Authorizer Officer) against real people, with a designation history that shows who held authority on any date.
Built for low-impact-only entities
Newly registered generator owners and small distribution providers can run their whole CIP program from CIP Sentry without paying for high impact complexity.
CIP-003 FAQ
What changed in CIP-003-9?
CIP-003-9 added Attachment 1 Section 6, vendor electronic remote access security controls for low impact BES Cyber Systems: a method to determine vendor electronic remote access, a method to disable it, and a method to detect known or suspected malicious communications. It became enforceable on April 1, 2026.
What will CIP-003-11 require?
FERC approved CIP-003-11 in Order No. 918 (March 2026). It adds further low impact controls aimed at coordinated attacks on many low impact sites. It becomes effective July 1, 2029, after CIP-003-10 (the virtualization version) takes effect July 1, 2028.
Can the CIP Senior Manager delegate policy approval?
No. The R1 policy approvals must be made by the CIP Senior Manager. Other approvals under the standards can be delegated through the documented R4 process.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

