Free Β· NERC CIP-002

NERC CIP-002 Assessment Tool

You need to know what you have before you can protect it. This assessment evaluates your BES Cyber System identification, categorization, and impact rating practices across all CIP-002-5.1a requirements β€” because an accurate asset inventory is the foundation every other CIP standard depends on.

~10 minutes
All R1, R2, R3 requirements
PDF report emailed
Attachment 1 criteria mapped

Step 1 β€” Select Your BES Cyber System Impact Level

CIP-002 requirements differ based on the impact categorization of your BES Cyber Systems. Select the highest level that applies to your environment. This determines which Attachment 1 criteria and sub-requirements are assessed.

🟒
Low Impact

BES Cyber Systems not meeting High or Medium thresholds. No discrete asset-by-asset identification required β€” but cyber security plan obligations under CIP-003 apply.

CIP-002 Attachment 1 Part 3
General scopingCIP-003 linkage
🟑
Medium Impact

BES Cyber Systems meeting Attachment 1 Part 2 criteria. Full discrete identification, CIP Senior Manager approval, and 60-day update obligations apply.

Attachment 1 Parts 2.1–2.9 + R2 + R3
R1 Part 2R2R3General
πŸ”΄
High Impact

BES Cyber Systems meeting Attachment 1 Part 1 criteria. All R1, R2, R3 requirements apply, including 6-year stability assessments and strictest identification obligations.

Attachment 1 Parts 1.1–1.6 + 2.1–2.9 + R2 + R3
R1 Parts 1 & 2R2R3General
Requirements Covered

CIP-002-5.1a β€” All Requirements

Questions are tailored to your selected impact level.

R1 / Attachment 1 Parts 1 & 2
Identify and categorize High and Medium Impact BES Cyber Systems using all applicable Attachment 1 criteria
MediumHigh
R2 β€” Annual Review
CIP Senior Manager review and approval of BES Cyber System lists at least every 15 calendar months
MediumHigh
R3 β€” 60-Day Updates
Update BES Cyber System lists within 60 days of any change to assets, facilities, or categorization
MediumHigh
Low Impact Obligations
CIP-003 cyber security plan requirements for Low Impact BES Cyber Systems (no discrete ID required)
Low
General Scoping & Asset Management
BES definition application, 35-day rule, inventory practices, documentation quality, internal audits
LowMediumHigh