What Does NERC CIP-013 Require?

CIP-013 requires applicable entities to manage cyber risk introduced through vendors, products, software, and remote access. The standard defines the process. Operators still need evidence when trusted activity creates a security question.

What CIP-013 requires.

CIP-013-2 is the mandatory and enforceable baseline. Build the supply chain risk plan, use it, and keep it current.

CIP-013-2 Enforceable baseline
15 months Plan review cycle
3 years Evidence retention
01

Vendor incidents

  • Vendor incident notification
  • Incident response coordination
02

Vendor access

  • Access termination
  • Vendor-initiated remote access
03

Product risk

  • Vulnerability disclosure
  • Software integrity and authenticity

R2: implement the plan.   R3: review and approve it at least once every 15 calendar months.

Read CIP-013-2

Vendor risk becomes an investigation problem.

Access controls tell you who is allowed in. Evidence tells you what happened after the connection was made.

01

See it

Can you observe vendor and third-party activity across the network segments you monitor?

02

Scope it

What systems, destinations, protocols, and access paths were involved?

03

Investigate it

Was the behavior expected, suspicious, or malicious, and what evidence supports that conclusion?

Authorization establishes permission. It does not establish behavior.

NERC CIP-015

CIP-013 questions, answered.

What is NERC CIP-013?

CIP-013 is NERC's Cyber Security - Supply Chain Risk Management standard. It requires applicable Responsible Entities to develop, implement, review, and approve supply chain cyber security risk management plans.

What version of CIP-013 is enforceable?

NERC currently lists CIP-013-2 as mandatory and subject to enforcement. CIP-013-3 is subject to future enforcement.

Does CIP-013 address vendor remote access?

Yes. R1.2.6 requires the supply chain risk management process to address coordination of controls for vendor-initiated remote access.

Does CIP-013 require network monitoring?

CIP-013 is a supply chain risk management standard, not a general network-monitoring requirement. Network evidence can still support investigation of vendor access, third-party activity, and supply chain incidents.

Educational guidance only. Confirm applicability and implementation requirements with current NERC, FERC, Regional Entity, legal, engineering, and compliance guidance.

Trusted access still needs evidence.

See what vendor and third-party activity actually did, then investigate what doesn't fit.

Coverage depends on deployment scope, available telemetry, and the systems being monitored.