Requirements at a glance
Configuration change management
Develop a baseline for each applicable Cyber Asset (OS/firmware, commercial and open-source software, custom software, logical ports and security patches). Authorize and document changes that deviate from the baseline, update the baseline within 30 days, determine and verify affected security controls, test changes in a test environment for high impact systems where required, and verify software identity and integrity before a baseline change when the method is available (R1.6).
Configuration monitoring
For high impact BES Cyber Systems, monitor at least once every 35 calendar days for changes to the baseline, and document and investigate detected unauthorized changes.
Vulnerability assessments
Perform a paper or active vulnerability assessment at least once every 15 calendar months, an active assessment in a test or production environment every 36 months for high impact systems, assess new Cyber Assets before adding them to production, and document the results with an action plan.
Transient cyber assets and removable media
Implement plans for transient cyber assets and removable media, whether managed by you or by a third party, covering authorization, software vulnerability mitigation, malicious code mitigation and detection of unauthorized use (Attachment 1).
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
Recurring deadlines
| Obligation | Interval | Requirement | In CIP Sentry |
|---|---|---|---|
| Update the baseline after an authorized change | 30 calendar days | CIP-010-4 R1.3 | |
| Monitor for changes to the baseline (high impact) | 35 calendar days | CIP-010-4 R2.1 | Auto-tracked |
| Paper or active vulnerability assessment | 15 calendar months | CIP-010-4 R3.1 | |
| Active vulnerability assessment (high impact) | 36 calendar months | CIP-010-4 R3.2 |
Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines
Authorization comes first
The core rule of CIP-010 is simple: authorize the change before you make it, document it, update the baseline within 30 days and verify the security controls it could affect. The most common finding is the reverse order: a technician fixes something urgently, and the paperwork arrives weeks later. A change process that is faster to follow than to skip is the real control.
Software integrity (R1.6)
Before installing an update, verify that it came from the real vendor and wasn’t altered. Use the vendor’s published hashes or code signatures, and keep the evidence with the change record. This is also why utilities ask their software vendors for signed installers and published hashes under CIP-013. CIP Sentry publishes SHA-256 hashes for every one of its own releases.
Vulnerability assessments with follow-through
A 15-month assessment that produces findings but no dated action plan will not survive an audit. Record each finding, decide what you will do, and track the plan to completion, ideally in the same place as your mitigation plans.
Evidence auditors typically ask for
- A baseline for each applicable Cyber Asset with all five required elements
- Change records showing authorization before the change, the baseline update within 30 days, and security control verification
- Test environment records for high impact changes where required
- Software integrity and authenticity verification before baseline changes (hashes, signatures, vendor confirmations)
- 35-day monitoring records and investigation of any unauthorized change
- Vulnerability assessment reports, results and dated action plans
- Transient cyber asset and removable media plans and usage records
How CIP Sentry helps with CIP-010
Change Management (CMF)
Every change moves from initiation through NERC impact assessment to authorization by the CAO (Cyber Asset Owner, also called Change Authorizer Officer), then implementation and verification, with attestations on the record.
Baseline history per asset
Baselines and their full history live with each Cyber Asset. The CIP Cyber Asset Baseline report prints one or two pages per asset, with gaps flagged.
35-day monitoring clock
Baseline monitoring for high impact systems is scheduled per system, and vulnerability assessment findings are tracked to closure as mitigation plans.
Exceptions tracked
Technical Feasibility Exceptions and CIP Exceptional Circumstances are recorded with expiry dates, never forgotten in a folder.
CIP-010 FAQ
What is in a CIP-010 baseline?
R1.1 lists five elements: operating system or firmware, commercially available or open-source software intentionally installed, custom software, logical network accessible ports, and applied security patches.
What does R1.6 require?
Before a change that deviates from the baseline, verify the identity of the software source and the integrity of the software, when the method to do so is available from the software source. It applies to high impact and medium impact BES Cyber Systems. Vendor-published hashes or code signatures are the usual method.
Is CIP-010 often violated?
Yes. With CIP-007 and CIP-004 it is one of the three most-violated CIP standards. Changes made before authorization and baselines updated late are the classic findings.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

