Free · NERC CIP 2026

NERC CIP Compliance Assessment Tool

Evaluate your BES Cyber System compliance posture across all applicable NERC CIP standards — tailored to your environment's impact level. Receive a personalized compliance gap report with recommendations.

~15 minutes
Up to 65 questions
PDF report emailed
CIP-002 through CIP-015

Step 1 — Select Your BES Cyber System Impact Level

NERC CIP requirements differ based on the impact categorization of your BES Cyber Systems. Select the highest impact level that applies to your environment. This determines which CIP standards and requirements are included in your assessment.

🟢
Low Impact

BES Cyber Systems whose compromise would not directly affect BES reliability at a significant level. Minimal CIP requirements apply.

Applies: CIP-002, CIP-003
CIP-002 CIP-003
🟡
Medium Impact

BES Cyber Systems with moderate potential for adverse BES impact. Most CIP standards apply. Typical for transmission substations and generation facilities.

Applies: CIP-002 through CIP-013
CIP-002 CIP-003 CIP-004 CIP-005 CIP-006 CIP-007 CIP-008 CIP-009 CIP-010 CIP-011 CIP-013
🔴
High Impact

BES Cyber Systems with the highest potential impact on BES reliability. All CIP standards apply. Typical for Control Centers and major transmission facilities.

Applies: All CIP standards (CIP-002 – CIP-015)
CIP-002 CIP-003 CIP-004 CIP-005 CIP-006 CIP-007 CIP-008 CIP-009 CIP-010 CIP-011 CIP-012 CIP-013 CIP-014 CIP-015
Standards Covered

NERC CIP-002 through CIP-015

Questions are tailored to your selected impact level.