NERC CIP Critical Infrastructure Protection
NERC CIP training for the people who have to produce the evidence. You work through the Critical Infrastructure Protection (CIP) standards as they apply to bulk electric system (BES) cyber assets, from categorization through to recovery plans.
Compliance and security are treated as two jobs that overlap. The course is honest about where a standard asks for paperwork and where it asks for a control that genuinely reduces risk.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- ICS and SCADA Security Essentials
- Class size
- Capped at 12 learners

What you will be able to do
- Categorize BES cyber systems as high, medium or low impact and document the reasoning
- Draw an electronic security perimeter and justify every access point in it
- Map each CIP requirement to a control you can actually evidence
- Assemble an evidence package an auditor can follow without a guided tour
- Write incident response and recovery plans that meet testing and reporting obligations
- Apply supply chain requirements to a real vendor contract and remote access path
- Identify a potential non compliance, self report it and build a mitigation plan
- Run an internal controls process that catches configuration drift between audits
Course outline
6 modules
- Registered entity functions and what each one owns
- Identifying BES cyber systems and their associated assets
- High, medium and low impact rating criteria
- Electronic security perimeters and their access points
- Physical security perimeters
- Getting scope wrong: the cost in both directions
What you need before you start
- ICS and SCADA Security Essentials, or equivalent control system experience
- Work at or with a registered entity, or a role that soon will
- Familiarity with your own asset base and network diagrams helps but is not required
- Roughly five hours a week outside class for the evidence exercises
Who this course is for
- Compliance and security staff at generation, transmission and distribution entities
- OT security engineers whose controls end up as audit evidence
- Internal auditors reviewing a CIP programme
- Consultants supporting utilities through audit cycles
- Managers accountable for a registered entity's compliance posture
Where this leads
Prepares you for
CISA
Awarded by ISACA
Audit thinking is the shared ground between this course and ISACA CISA, so the two reinforce each other in compliance roles. CISA is examined and issued by ISACA rather than by this academy, and carries its own experience requirement.
Questions about this course
More in industrial control systems and ot security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



