Sia RegAI / Frameworks / NERC CIP
Framework · Utilities & energy
NERC CIP standards reference.
A concise topic index for the Critical Infrastructure Protection Reliability Standards. Use the current effective versions and implementation plans in the official NERC standards library before deciding applicability.
Page boundary: this page is the standards reference. For asset inventory, applicability, evidence collection, control ownership and audit-pack workflow, use the separate implementation guide.
The standards, by purpose
- CIP-002 — BES Cyber System categorisation (high, medium, low).
- CIP-003 — security management controls.
- CIP-004 — personnel and training.
- CIP-005 — electronic security perimeters.
- CIP-006 — physical security of BES Cyber Systems.
- CIP-007 — system security management.
- CIP-008 — incident reporting and response planning.
- CIP-009 — recovery plans.
- CIP-010 — configuration change management and vulnerability assessments.
- CIP-011 — information protection.
- CIP-013 — supply chain risk management.
- CIP-014 — physical security (substations, control centres).
From reference to implementation
For a utility preparing for a CIP audit, the five-phase Sia RegAI workflow:
- BES Cyber System categorisation — CIP-002 R1 ratings, with rationale documented.
- Requirement mapping — every CIP-003-to-014 requirement mapped to applicable assets at each impact level.
- Evidence inventory — collected, dated, and tied back to specific requirements and assets.
- Policy drafting — CIP-required documentation generated in your house template, version-controlled.
- Audit-pack assembly — Reliability Standard Audit Worksheets (RSAWs) populated, evidence cross-linked, narrative drafted.
Common audit findings
- CIP-007 patch-management evidence missing for some applicable assets between scheduled assessment dates.
- CIP-004 access reviews completed but the evidence record can't prove the review covered all required identifiers.
- CIP-010 baseline-deviation logs lack the rationale the auditor expects for low-significance changes.
- CIP-013 supply-chain procurement language updated but legacy contracts not re-papered within the agreed phase-in.
Where Sia RegAI may fit
For a scoped implementation, define the applicable NERC standards, FERC orders, regional-entity materials and controlled asset register. Sia RegAI can then support structuring, candidate mapping and draft evidence narratives for human review.
Primary sources
Related guides
- NERC CIP compliance with AI — from CIP-002 asset inventory to audit-ready evidence
- Regulatory change management software — a buyer's guide