What Does NERC CIP-013 Require?
CIP-013 requires applicable entities to manage cyber risk introduced through vendors, products, software, and remote access. The standard defines the process. Operators still need evidence when trusted activity creates a security question.
What CIP-013 requires.
CIP-013-2 is the mandatory and enforceable baseline. Build the supply chain risk plan, use it, and keep it current.
Vendor incidents
- Vendor incident notification
- Incident response coordination
Vendor access
- Access termination
- Vendor-initiated remote access
Product risk
- Vulnerability disclosure
- Software integrity and authenticity
R2: implement the plan. R3: review and approve it at least once every 15 calendar months.
Read CIP-013-2Vendor risk becomes an investigation problem.
Access controls tell you who is allowed in. Evidence tells you what happened after the connection was made.
See it
Can you observe vendor and third-party activity across the network segments you monitor?
Scope it
What systems, destinations, protocols, and access paths were involved?
Investigate it
Was the behavior expected, suspicious, or malicious, and what evidence supports that conclusion?
Authorization establishes permission. It does not establish behavior.
NERC CIP-015CIP-013 questions, answered.
What is NERC CIP-013?
CIP-013 is NERC's Cyber Security - Supply Chain Risk Management standard. It requires applicable Responsible Entities to develop, implement, review, and approve supply chain cyber security risk management plans.
What version of CIP-013 is enforceable?
NERC currently lists CIP-013-2 as mandatory and subject to enforcement. CIP-013-3 is subject to future enforcement.
Does CIP-013 address vendor remote access?
Yes. R1.2.6 requires the supply chain risk management process to address coordination of controls for vendor-initiated remote access.
Does CIP-013 require network monitoring?
CIP-013 is a supply chain risk management standard, not a general network-monitoring requirement. Network evidence can still support investigation of vendor access, third-party activity, and supply chain incidents.
Educational guidance only. Confirm applicability and implementation requirements with current NERC, FERC, Regional Entity, legal, engineering, and compliance guidance.
Where CrunchAtlas fits.
CrunchAtlas supports the evidence and investigation side of supply chain risk. Passive network telemetry shows what vendor or third-party activity did, then carries suspicious behavior into an investigated case.
Network Detection and Response
Passively surface vendor and third-party activity across monitored IT and OT networks.
Explore NDRAlert Investigation
Turn suspicious activity into an evidence-backed case with scope and next steps.
Explore Alert InvestigationHost and Network Forensics
Reconstruct what happened when the question arrives after the event.
Explore ForensicsIncident Reporting
Document findings, evidence, affected systems, and recommended actions.
Explore Incident ReportingPower and Energy
See CrunchAtlas across connected, segmented, and fully air-gapped electric environments.
Explore Power & EnergyTrusted access still needs evidence.
See what vendor and third-party activity actually did, then investigate what doesn't fit.
Coverage depends on deployment scope, available telemetry, and the systems being monitored.