The NERC CIP-014 physical security requirements obligate owners and operators of the most critical high-voltage transmission facilities in North America to identify those sites, evaluate the physical threats against them, build and implement a documented security plan, and have both the engineering analysis and the security plan independently reviewed by outside experts. The standard currently in force is CIP-014-3, effective June 16, 2022. Its purpose is narrow but consequential: prevent a physical attack on a single substation or control center from destabilizing an interconnection or triggering cascading outages.
Who Must Comply and Which Facilities Are Covered
CIP-014 applies to two registered entity types: Transmission Owners, which hold title to the equipment, and Transmission Operators, which run it day to day. The Transmission Owner carries the initial burden of identifying which of its facilities fall within scope.
Coverage turns on voltage and topology:
- Any transmission station or substation operating at 500 kV or higher is automatically in scope.
- Stations operating between 200 kV and 499 kV are in scope only if the station connects to three or more other transmission stations at 200 kV or above and its aggregate weighted value exceeds 3,000. The weighted value sums 700 per connected line at 200–299 kV and 1,300 per connected line at 300–499 kV.
The standard also covers the primary control center that can electronically operate an identified station. A monitoring-only center does not qualify; the control center must be able to cause a physical change, such as opening a breaker, at a critical station.1North American Electric Reliability Corporation. CIP-014-3 Physical Security
Nuclear Facility Exemption
Facilities inside a protected area under a security plan approved by the Nuclear Regulatory Commission or the Canadian Nuclear Safety Commission are exempt. Those sites already operate under separate physical security regimes that overlap with or exceed CIP-014.1North American Electric Reliability Corporation. CIP-014-3 Physical Security
The Six Requirements
R1: Risk Assessment
The Transmission Owner performs a transmission analysis to determine which of its qualifying stations and substations, if rendered inoperable or damaged by a physical attack, would cause instability, uncontrolled separation, or cascading outages within an interconnection. The analysis must include planned facilities expected to come online within 24 months. The Transmission Owner also identifies the primary control center that operationally controls each critical station.
The reassessment cycle depends on the last result. If the previous assessment identified one or more critical facilities, the next is due within 30 calendar months. If none were identified, the interval extends to 60 calendar months.1North American Electric Reliability Corporation. CIP-014-3 Physical Security
R2: Third-Party Verification of the Risk Assessment
Within 90 calendar days of completing R1, an unaffiliated third party must verify the risk assessment. The reviewer must be a registered Planning Coordinator, Transmission Planner, or Reliability Coordinator, or an organization with transmission planning or analysis experience. The point is to confirm the engineering behind the identification, not to evaluate physical security measures.1North American Electric Reliability Corporation. CIP-014-3 Physical Security
R3: Notifying the Control Center Operator
When the primary control center for a critical station belongs to a different entity, the Transmission Owner has seven calendar days after R2 verification to notify that Transmission Operator, and must include the date the verification was completed. Once notified, the Transmission Operator picks up its own obligations under R4 through R6 for that control center. The same seven-day window applies to notifying the operator if a facility later drops off the critical list.1North American Electric Reliability Corporation. CIP-014-3 Physical Security
R4: Threat and Vulnerability Evaluation
Both the Transmission Owner and any notified Transmission Operator must evaluate the specific physical threats and vulnerabilities facing each identified station, substation, and control center. The evaluation must consider:
- Unique site characteristics, including physical layout, geography, and structural features.
- Prior attacks at similar facilities, weighted by frequency, geographic proximity, and severity.
- Intelligence or threat warnings from law enforcement, the Electricity Sector Information Sharing and Analysis Center (ES-ISAC), NERC, and federal or Canadian government agencies.
A substation visible from a public highway presents a different threat profile than one behind dense terrain, and the evaluation must reflect that.1North American Electric Reliability Corporation. CIP-014-3 Physical Security
R5: Physical Security Plan
Within 120 calendar days after R2 verification, each Transmission Owner and notified Transmission Operator must develop and implement a documented physical security plan for every identified station, substation, and control center. The plan must include measures designed to deter, detect, delay, and respond to the specific threats found in the R4 evaluation. Typical measures include surveillance, motion detection, reinforced perimeter barriers, and access controls such as card readers or biometric scanners. Law enforcement contact and coordination information must be part of the plan.1North American Electric Reliability Corporation. CIP-014-3 Physical Security
Auditors scrutinize the link between R4 and R5 closely. Generic countermeasures untethered to identified vulnerabilities will not hold up. If the R4 evaluation flags a transformer bank within rifle range of a public road, the R5 plan needs to address that specific exposure.
R6: Independent Review of the Threat Evaluation and Security Plan
Within 90 calendar days of completing the R5 plan, an unaffiliated third party must review both the R4 evaluation and the R5 plan. The reviewer’s qualifications differ from R2 because the focus is physical security rather than transmission engineering. Acceptable reviewers include:
- An entity with electric industry physical security experience that has at least one staff member holding a Certified Protection Professional (CPP) or Physical Security Professional (PSP) certification.
- An entity approved by the ERO (NERC).
- A government agency with physical security expertise.
- An organization with demonstrated law enforcement, government, or military physical security expertise.
If the reviewer recommends changes, the entity has 60 calendar days to either implement the recommendation or document why it declined. Both the changes and any documented justifications become part of the compliance record. Entities must also have procedures such as nondisclosure agreements to protect sensitive information shared with reviewers.1North American Electric Reliability Corporation. CIP-014-3 Physical Security
The Compliance Clock
Each step starts the next, so slipping early compresses everything downstream:
- R1 risk assessment cycle: every 30 calendar months if critical facilities were previously identified; every 60 months if none were found.
- R2 third-party verification: within 90 calendar days after R1 is complete.
- R3 control center notification: within 7 calendar days after R2 is complete.
- R5 security plan development: within 120 calendar days after R2 is complete.
- R6 independent review: within 90 calendar days after the R5 plan is complete.
- Response to R6 recommendations: within 60 calendar days after the review.
Compliance documentation must be retained for at least three years. When a violation is found, records related to the noncompliance must be kept until mitigation is complete and approved, or for three years, whichever is longer.2North American Electric Reliability Corporation. Petition – CIP-014 Evidence Provision
Penalties for Noncompliance
Congress set the statutory ceiling for civil penalties under Part II of the Federal Power Act at $1 million per violation per day the violation continues.3Federal Energy Regulatory Commission. Civil Penalties NERC and the regional entities that enforce reliability standards have broad discretion in setting the actual amount. They weigh factors such as severity, duration, whether the entity self-reported, and prior compliance history.
Most penalties fall well below the ceiling. The per-day structure is what makes noncompliance expensive: even a moderate daily fine accumulates quickly when a gap persists for months, which physical security gaps often do. Missing an R1 assessment deadline, skipping a required third-party review, and operating without a documented security plan each constitutes a separate violation with its own clock. An entity behind on multiple requirements at once faces compounding exposure.