CIP-013 · Supply Chain Risk Management

CIP-013: manage the risk that arrives with every vendor.

CIP-013 requires a supply chain cyber security risk management plan for procuring BES Cyber Systems and their EACMS and PACS, covering vendor incident notification, vulnerability disclosure, software integrity and remote access, approved every 15 months.

Enforceable nowCIP-013-2 (effective October 1, 2022)
Next versionCIP-013-3 (July 1, 2028); CIP-013-4 in development after FERC Order No. 912
Applies toHigh impact and medium impact BES Cyber Systems and their associated EACMS and PACS

Requirements at a glance

R1

Supply chain risk management plan

Develop plan(s) with processes used in planning the procurement of applicable systems to identify and assess cyber security risks from vendor products and services, and from transitions between vendors (R1.1).

R1.2

Six vendor processes

The plan must include processes for: (1) vendor notification of vendor-identified incidents, (2) coordination of responses to vendor-identified incidents, (3) vendor notification when remote or onsite access should no longer be granted to vendor representatives, (4) disclosure by vendors of known vulnerabilities, (5) verification of software integrity and authenticity of software and patches provided by the vendor, and (6) coordination of controls for vendor-initiated remote access.

R2

Implement the plan

Implement the plan(s). Contract terms are not required to change, and implementation does not require renegotiating or abrogating existing contracts.

R3

Review and approve every 15 months

Review and obtain CIP Senior Manager or delegate approval of the plan(s) at least once every 15 calendar months.

Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.

Recurring deadlines

ObligationIntervalRequirementIn CIP Sentry
Review and approve the supply chain risk management plan15 calendar monthsCIP-013-2 R3Auto-tracked

Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines

Turning the plan into a routine

A CIP-013 plan fails in practice when it lives only in a policy document. Build the vendor processes into procurement: a risk questionnaire before purchase, contract terms (or documented alternatives) for the six R1.2 items, and a record of how risks were identified and addressed for each purchase.

Industry tools you can reuse

  • NATF Supply Chain Security Criteria and Energy Sector Supply Chain Risk Questionnaire (version 7.0, May 2026) give you a common set of questions that many vendors have already answered.
  • EEI Model Procurement Contract Language (version 4.0, June 2026) provides clauses aligned to the R1.2 processes.
  • Independent assessments shared across utilities can reduce duplicate questionnaires for widely used vendors.

Software integrity in practice

R1.2.5 and CIP-010 R1.6 work together. Your plan asks vendors to provide a way to verify software (signed installers, published hashes), and your change process records that you used it. Choosing vendors who publish this by default makes both standards easier.

Evidence auditors typically ask for

  • The supply chain cyber security risk management plan(s) addressing R1.1 and each R1.2 process
  • Procurement records showing risk identification and assessment for applicable purchases
  • Vendor questionnaires or assessments (many entities use the NATF Energy Sector Supply Chain Risk Questionnaire)
  • Contract language or other vendor commitments covering the R1.2 processes (often based on EEI model language)
  • CIP Senior Manager or delegate approvals no more than 15 months apart

How CIP Sentry helps with CIP-013

Supply Chain Risk module

Keep your supply chain risk management plan and a prequalified vendor list for procurement in one place.

15-month approval clock

The CIP Senior Manager approval of the plan is tracked like every other periodic obligation.

Integrity checks recorded

Software integrity verification from CIP-010 R1.6 is recorded on each change, supporting your R1.2.5 process.

A vendor that answers first

CIP Sentry's own Trust Center answers the R1.2 questions about us before you ask, and we complete the NATF questionnaire on request.

CIP-013 FAQ

Does CIP-013 apply to low impact systems?

CIP-013-2 applies to high and medium impact BES Cyber Systems and their associated EACMS and PACS. Low impact vendor remote access is addressed separately in CIP-003-9 Attachment 1 Section 6.

Do we have to rewrite existing contracts?

No. CIP-013 applies to procurement going forward, and R2 notes that implementation does not require renegotiating existing contracts. New procurements should reflect your plan.

What is coming next?

CIP-013-3 takes effect with the virtualization package on July 1, 2028. In September 2025 FERC Order No. 912 directed further supply chain improvements, which NERC is developing as CIP-013-4 (Project 2025-06). Expect more rigorous vendor risk assessment.

Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

Related standards

Request a quote

Run CIP-013 without the spreadsheet.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.