Last verified: September 2026

What NERC CIP-008 actually asks of your exercise program

What NERC CIP-008 asks of incident response testing, in the standard's own words. A mandatory test at least once every 15 calendar months, not annually; three acceptable methods, a tabletop exercise among them; which systems are in scope; what has to follow every test; why reporting is a separate duty; and where realistic exercises earn their place.

NERC CIP

If your organisation owns or operates high or medium impact BES Cyber Systems, you have probably heard that CIP-008 wants an annual tabletop.

It doesn't say annual. It says each Cyber Security Incident response plan must be tested at least once every 15 calendar months, and a test that slips past that is a violation from the first month late. It names three ways to run the test, and a tabletop exercise is one of them. And CIP-008 is neither guidance nor a voluntary standard. In the United States it is mandatory and enforceable, with civil penalties.

The standard also asks for more than the test. Each test is run against your plan, with departures from it written down. Within 90 days it is followed by lessons learned, a plan update, and notice to everyone with a role. That chain is where well-designed exercises earn their place, and the second half of this guide makes that case. The first half is what the standard says.

How to read this guide. NERC publishes its Reliability Standards free. Quoted passages are verbatim, attributed to the standard, requirement and part they come from. Everything else is our summary, in our own words. Where we cite NERC's audit worksheet or its technical rationale, we say so: both explain the standard, and neither is part of it. Enforceability and penalties are described for the United States. This guide doesn't cover how CIP-008 is enforced in Canada.

Mandatory, enforceable, and exact about penalties

CIP-008 is a Reliability Standard approved by the Federal Energy Regulatory Commission (FERC). In the United States, complying with it is not optional. The Federal Power Act says so directly: *"All users, owners and operators of the bulk-power system shall comply with reliability standards that take effect under this section."*¹ The same section defines those standards to include requirements for "cybersecurity protection"

  • Who enforces it. The Regional Entity serves as the Compliance Enforcement Authority for CIP-008, unless it owns, operates or controls the entity concerned.² NERC, as the Electric Reliability Organization, and FERC sit above it, and FERC can also order compliance and impose penalties directly.¹
  • How compliance is checked. Compliance audits, self-certification, spot checks, compliance investigations, self-reports and complaints.²
  • How long to keep the evidence. *"Each Responsible Entity shall retain evidence of each requirement in this standard for three calendar years."*²

**Violations can draw civil penalties: under the Federal Power Act, up to $1 million per violation per day, adjusted annually for inflation.**³ ⁴ The same Act requires any penalty to "bear a reasonable relation to the seriousness of the violation"

Be exact about where CIP-008 sits on that scale. NERC's sanction guidelines set a penalty's starting point from each requirement's risk rating, its Violation Risk Factor, and then adjust it for factors that include the entity's size and how long the violation ran.⁵ **Every CIP-008 requirement carries the lowest of the three ratings: Lower.**² If you have seen the statutory maximum presented as the price of a missed tabletop, that is the statute's outer limit attached to the requirements NERC rates lowest. The obligation is real. The headline arithmetic isn't.

Requirements at a glance

What CIP-008 asks Where Cycle Exercise or test?
A documented Cyber Security Incident response plan, including how you decide whether an incident is reportable CIP-008-6, R1² Kept current under R3 The plan the test is run against
Test each incident response plan CIP-008-6, R2, Part 2.1² At least once every 15 calendar months Yes. An actual Reportable Cyber Security Incident response, a paper drill or tabletop exercise, or an operational exercise, each of a Reportable Cyber Security Incident
Use the plan during the test, and document deviations from it CIP-008-6, R2, Part 2.2² Every test, and every qualifying incident response During the exercise
Document lessons learned, or their absence; update the plan; notify everyone with a role in it CIP-008-6, R3, Part 3.1² Within 90 calendar days of the test Follows the test
Update the plan, and notify, after a change to roles, response groups or technology that would affect it CIP-008-6, R3, Part 3.2² Within 60 calendar days of the change No
Notify E-ISAC and, in the United States, NCCIC CIP-008-6, R4² One hour after determining an incident is reportable; by the end of the next calendar day for an attempt to compromise; updates within 7 calendar days No. A separate obligation
Low impact systems: test the incident response plan CIP-003-9, Attachment 1, Section 4.5 At least once every 36 calendar months Yes, by the same three kinds of test
High impact recovery plans: an operational exercise CIP-009-6, R2, Part 2.3 At least once every 36 calendar months Yes: an operational exercise. A tabletop isn't one

Our summary; the requirement text is quoted in the sections below. CIP-008 rows apply to high and medium impact BES Cyber Systems and their associated Electronic Access Control or Monitoring Systems (EACMS). As of September 2026.

It isn't annual: 15 calendar months, between tests

The requirement, verbatim. CIP-008-6, Requirement R2, Part 2.1:²

Test each Cyber Security Incident response plan(s) at least once every 15 calendar months:

  • By responding to an actual Reportable Cyber Security Incident;
  • With a paper drill or tabletop exercise of a Reportable Cyber Security Incident; or
  • With an operational exercise of a Reportable Cyber Security Incident.

Three things follow from the text.

  1. The interval runs between tests, not by calendar year. NERC grades a late test by the months "between tests of the plan(s)"
  2. Month 16 is already a violation. NERC's Violation Severity Levels for this part climb for each month a test is late. A test that lands in month 16 is a Lower-severity violation; month 17, Moderate; month 18, High; later than that, Severe.² The levels measure how serious a violation is. They are not a grace period.
  3. Each plan is tested. The requirement says "each … plan(s)".² If you run more than one incident response plan, each one needs its test. How you scope your plans is your decision.

NERC's audit worksheet reads it the same way. The worksheet guides auditors and isn't part of the standard, but on this point it is plain: *"The auditor should note that, while deviations from the incident response plan are permissible, deviations from the language of the Requirement (testing of the plan at least once every 15 calendar months, notification to the E-ISAC and NCCIC of applicable incidents, etc.), are not permissible."*⁸

So where does "annual" come from? One likely source is NERC's own technical rationale for CIP-008-6, which explains the standard but isn't part of it. Its closing section carries over text written for the earlier version, CIP-008-5, that speaks of exercising the plan annually.⁹ The standard is what binds, and it says 15 calendar months. Testing every year keeps you inside it. But "annual" read as once per calendar year can put a test in January one year and the next in December of the following year. That is nearly two years between tests, which CIP-008 grades at its most serious level.

Don't convert the interval. The standard says "calendar months", and nothing we found in NERC's text turns that into days or a date formula. Work to the words.

Three ways to test, and what the test has to be of

CIP-008 names tabletop exercises as one of three acceptable ways to test an incident response plan. The three are alternatives. The standard's own drafting convention says so: *"Throughout the standards, unless otherwise stated, bulleted items in the requirements and measures are items that are linked with an 'or,' and numbered items are items that are linked with an 'and.'"*²

Discussion-based exercises are expressly contemplated. The measures for Part 2.1, verbatim: *"Examples of evidence may include, but are not limited to, dated evidence of a lessons-learned report that includes a summary of the test or a compilation of notes, logs, and communication resulting from the test. Types of exercises may include discussion or operations based exercises."*²

Every method is of a Reportable Cyber Security Incident, and that is a defined term. NERC's Glossary, verbatim:¹⁰

Cyber Security Incident: A malicious act or suspicious event that:

  • For a high or medium impact BES Cyber System, compromises or attempts to compromise (1) an Electronic Security Perimeter, (2) a Physical Security Perimeter, or (3) an Electronic Access Control or Monitoring System; or
  • Disrupts or attempts to disrupt the operation of a BES Cyber System.

Reportable Cyber Security Incident: A Cyber Security Incident that compromised or disrupted:

  • A BES Cyber System that performs one or more reliability tasks of a functional entity;
  • An Electronic Security Perimeter of a high or medium impact BES Cyber System; or
  • An Electronic Access Control or Monitoring System of a high or medium impact BES Cyber System.

The exercise has to be of an incident like that. A scenario about corporate email, a website outage or a non-cyber operational emergency may be well worth running. On the definition's face, it isn't an exercise of a Reportable Cyber Security Incident.

What the standard doesn't set. It names three methods and no minimum duration, participant list, number of injects or pass mark.² The measures are examples of evidence, not criteria, and the standard says its measures *"should not be viewed as an all-inclusive list."*² If someone tells you a CIP-008 test must run four hours or include the executive team, ask where that is written.

Whether a particular exercise qualifies is your call first, and your Compliance Enforcement Authority's at audit.

A real incident can stand in for an exercise. Responding to an actual Reportable Cyber Security Incident is one of the three methods in its own right.² An attempt to compromise is not on that list.

Who it applies to

By function. CIP-008-6 applies to Balancing Authorities, Generator Operators, Generator Owners, Reliability Coordinators, Transmission Operators and Transmission Owners. It also applies to Distribution Providers, but only those that own certain protection or restoration systems: qualifying load-shedding systems of 300 MW or more, Remedial Action Schemes, certain Protection Systems and Cranking Paths.²

By system, and this is the part that decides it. Every CIP-008 requirement applies to **high impact and medium impact BES Cyber Systems, and their associated Electronic Access Control or Monitoring Systems.**² The standard exempts, verbatim, *"Responsible Entities that identify that they have no BES Cyber Systems categorized as high impact or medium impact according to the CIP-002 identification and categorization processes."*² The other exemptions include Cyber Assets at facilities regulated by the Canadian Nuclear Safety Commission, systems the US Nuclear Regulatory Commission regulates under a cyber security plan, and communication links between discrete Electronic Security Perimeters.²

Impact ratings come from CIP-002. CIP-002-5.1a's Attachment 1 sets the criteria. High impact covers, broadly, the control centres of Reliability Coordinators, and those of Balancing Authorities, Transmission Operators and Generator Operators above set thresholds. Medium impact covers, for example, large generating plants, high-voltage transmission stations and facilities critical to interconnection limits.¹¹ Categorisation is your CIP-002 process, and we don't reproduce the thresholds here.

Low impact systems fall under CIP-003 instead. CIP-003-9, in force since 1 April 2026, requires a cyber security plan for low impact BES Cyber Systems that includes an incident response section.⁶ ¹² Its testing line, verbatim. CIP-003-9, Attachment 1, Section 4.5:⁶

4.5 Testing the Cyber Security Incident response plan(s) at least once every 36 calendar months by: (1) responding to an actual Reportable Cyber Security Incident; (2) using a drill or tabletop exercise of a Reportable Cyber Security Incident; or (3) using an operational exercise of a Reportable Cyber Security Incident; and

Your systems What applies
High or medium impact BES Cyber Systems CIP-008-6. Test each plan at least once every 15 calendar months, then lessons learned, plan update and notification within 90 days. Notify E-ISAC and, in the US, NCCIC of reportable incidents and attempts
Low impact BES Cyber Systems CIP-003-9, Attachment 1, Section 4. Test at least once every 36 calendar months, and update the plan if needed within 180 days. Notify E-ISAC of reportable incidents⁶

Our summary. An entity can have both, and then both apply.

After the test: use the plan, record the deviations, learn within 90 days

CIP-008 doesn't stop at the test. CIP-008-6, Requirement R2, Part 2.2, verbatim:²

Use the Cyber Security Incident response plan(s) under Requirement R1 when responding to a Reportable Cyber Security Incident, responding to a Cyber Security Incident that attempted to compromise a system identified in the "Applicable Systems" column for this Part, or performing an exercise of a Reportable Cyber Security Incident. Document deviations from the plan(s) taken during the response to the incident or exercise.

And Requirement R3, Part 3.1, verbatim:²

No later than 90 calendar days after completion of a Cyber Security Incident response plan(s) test or actual Reportable Cyber Security Incident response:

3.1.1. Document any lessons learned or document the absence of any lessons learned;

3.1.2. Update the Cyber Security Incident response plan based on any documented lessons learned associated with the plan; and

3.1.3. Notify each person or group with a defined role in the Cyber Security Incident response plan of the updates to the Cyber Security Incident response plan based on any documented lessons learned.

Read together, these make a loop. You test, run the plan during the test, and write down where you left it. Then, within 90 calendar days, you record what you learned, change the plan and tell the people it affects. The loop is mandatory, and its clock is graded like the testing clock: NERC's severity levels for R3 climb past 90 days and again past 120.² Separately, a change to roles, response groups or technology that would affect the plan starts a 60-day clock to update it and notify (Part 3.2).²

The standard allows a test to find nothing. Documenting "the absence of any lessons learned" is a compliant outcome. The second half of this guide is about why a well-designed test rarely ends there.

Reporting is a separate obligation

CIP-008 carries two duties that are easy to blur: testing the plan (R2) and reporting incidents (R4). They have different triggers, different clocks and different recipients.

Requirement R4 requires notification to the Electricity Information Sharing and Analysis Center (E-ISAC) and, for entities subject to US jurisdiction, the National Cybersecurity and Communications Integration Center (NCCIC), "or their successors". The notification covers Reportable Cyber Security Incidents and Cyber Security Incidents that were attempts to compromise an applicable system, "unless prohibited by law".² The initial-notification timelines, verbatim, from Part 4.2:²

  • One hour after the determination of a Reportable Cyber Security Incident.
  • By the end of the next calendar day after determination that a Cyber Security Incident was an attempt to compromise a system identified in the "Applicable Systems" column for this Part.
  • The clocks start at determination, not at the incident. The determination is made under the documented process in your plan (Requirement R1, Part 1.2).²
  • What goes in the report, to the extent known: the functional impact, the attack vector used, and the level of intrusion achieved or attempted. Updates follow within 7 calendar days of new or changed information.²
  • From July 2028, CIP-008-7.1 names the Cybersecurity and Infrastructure Security Agency (CISA) in NCCIC's place.¹³

An exercise of your plan can run through its reporting process: who decides, on what information, and how fast.

The recovery boundary: CIP-009

Recovery plans are a different standard, CIP-009, with their own tests. One of them marks the edge of what any tabletop can do. CIP-009-6, Requirement R2, Part 2.3, which applies to high impact BES Cyber Systems, verbatim:⁷

Test each of the recovery plans referenced in Requirement R1 at least once every 36 calendar months through an operational exercise of the recovery plans in an environment representative of the production environment. An actual recovery response may substitute for an operational exercise.

A tabletop tests your plan and your people. It doesn't prove your systems come back. NERC's own structure draws that line: discussion-based testing is a named method for the incident response plan, and a separate operational exercise is required to prove recovery for high impact systems.

Which version applies

  • **CIP-008-6 is the version in force in the United States, effective 1 January 2021.**¹² ¹⁴ FERC approved it in June 2019, and it took effect on the first day of the first calendar quarter 18 months later.¹⁴
  • **Its successor, CIP-008-7.1, takes effect on 1 July 2028 and keeps the same testing requirement.**¹³ ¹² FERC approved it on 19 March 2026, and CIP-008-6 goes inactive on 30 June 2028.¹² It adds Shared Cyber Infrastructure to the systems in scope and to the two definitions above, names CISA in NCCIC's place, and adds one exemption.¹³ ¹⁰ Parts 2.1, 2.2 and 3.1 are unchanged, and so is every timeline.¹³
  • As of September 2026, every US entity is on CIP-008-6. Early adoption of the new version can't begin before 1 January 2027.¹⁵
  • Your 15-month clock doesn't reset at the changeover. The implementation plan has entities keep to the periodic timeframes of their last performance under the version being retired.¹⁵
  • **There are no regional variances and no interpretations of CIP-008-6.**² Regional Entities enforce the standard. They don't vary it.

Where the standard leaves room

Naming these is more useful than smoothing them over.

  • What a test must include. The standard sets no minimum scope, duration, participant list or inject count. The measures give examples of evidence, not criteria.²
  • How a calendar month is counted. Nothing in the NERC text we reviewed defines it.
  • How plans are scoped. "Each plan" is tested, but how many plans you have, and what each covers, is yours to decide.
  • Regional audit practice. CIP-008-6 has no regional variances. Whether audit practice differs from one Regional Entity to another isn't something we have seen documented, so we claim nothing either way.
  • Canada, and enforcement history. This guide covers US enforceability only. It doesn't cover past CIP-008 enforcement actions or the amounts involved.

Why exercise well, not just on time

Everything above is what CIP-008 requires. This section is about doing it well.

CIP-008 mandates an outcome: an incident response plan that is tested on a clock and gets better after each test. The standard says what has to happen after a test, not how good the test must be. That is left to you. Realistic, adaptive exercises are one of the most direct ways to make each test worth running, and to generate the learning and records the rest of the chain depends on.

Run the incident the standard means. The test has to be of a Reportable Cyber Security Incident. A realistic scenario, built around the compromise or disruption of the systems your plan protects, tests the plan CIP-008 is about. A generic IT outage doesn't.

Find out where people leave the plan. Part 2.2 asks you to document deviations. A scripted walk-through tends to follow the plan, because the script does. An exercise that adapts to the crew's decisions surfaces where people actually depart from it. Capturing decisions as they happen means those deviations are recorded, not reconstructed a week later. That is designed to support the record Part 2.2 asks for.

Give the 90-day loop something to work on. Part 3.1 lets you document that there were no lessons learned, and that is a legitimate outcome. But a scenario the crew has seen before, run to the same script, has little left to teach. Injects that respond to what the crew decides make each test likelier to find something worth fixing. The lessons learned, the plan update and the notification in Part 3.1 exist for exactly that.

Generate the kind of record NERC lists. The measures give "a lessons-learned report that includes a summary of the test or a compilation of notes, logs, and communication resulting from the test" as examples of evidence.² Decision capture and a structured debrief help generate records like those NERC gives as examples.

Put the reportability call under pressure. The one-hour clock starts at determination, and determination is a judgement made on incomplete information. An exercise can rehearse that call: who makes it, on what, and how fast.

Ask more of the plan than a walk-through does, within a tabletop's limits. A paper drill or tabletop is a named, legitimate way to test the plan. An adaptive exercise pushes the same plan harder, because the situation keeps responding to the people in the room. It is still a test of plans and people.

Compliance with CIP-008 is the whole standard: every plan tested on time, used and learned from, reports made, evidence kept. Exercising well is one of the most direct ways to make the test, and the learning that must follow it, worth the time it takes.

What Crewcible produces that maps to it

Crewcible is built for the exercise itself: designing it, running it, and capturing what came out of it. Crewcible exercises are discussion-based. They are designed to support your CIP-008 response-plan testing. A discussion-based exercise pressure-tests the plan and the people; it doesn't prove your systems recover — that's what operational testing is for.

Within a program that takes the whole CIP-008 loop seriously, three outputs line up.

Scenarios that put your incident response plan under pressure. Global Library scenarios are ready to run and can be launched in minutes. A scenario built for your own environment takes hours, not weeks. That makes it practical to exercise the incident your plan exists for, a compromise of the systems it protects, rather than the one that is easiest to stage.

Exercises that follow your people, not a script. AI-suggested injects respond to what the crew actually decides, so the exercise tests judgement as the situation moves. The facilitator decides what gets released and when. AI enabled, human led.

A record you can learn from inside 90 days. Crewcible captures decisions and reasoning per participant and per inject as the exercise runs. After-action output and an improvement plan come out of the exercise, rather than being reconstructed afterwards. That output is designed to support the lessons-learned and plan-update work Part 3.1 asks for, and it helps generate the kind of record the measures give as examples. What you conclude from it, what you change, and what you keep as evidence stays your call.

Crewcible is built by experts who have supported crisis situations and exercises in the world's largest organizations.

For ready-to-run starting points, browse the Global Library.


Standards references current as of September 2026. Quoted passages are verbatim from the sources noted. Everything else on this page is our summary. This page has not been reviewed or endorsed by NERC. This guide is scheduled for re-verification by March 2027.

¹ Federal Power Act §215, 16 U.S.C. §824o, Electric reliability, from the Office of the Law Revision Counsel. Quoted verbatim.

² NERC Reliability Standard CIP-008-6, Cyber Security — Incident Reporting and Response Planning, the version subject to enforcement in the United States. Used for the requirements, measures, applicability, exemptions, drafting conventions, compliance section, Violation Risk Factors and Violation Severity Levels. Requirement and measure text is quoted verbatim.

³ Federal Power Act §316A, 16 U.S.C. §825o-1, Enforcement of certain provisions, which sets the statutory maximum civil penalty.

⁴ FERC's civil monetary penalty rules, 18 CFR §385.1601–1602, official annual edition, which adjust the statutory maximum for inflation at least once a year. The current adjusted amount is published by FERC.

⁵ NERC Rules of Procedure, Appendix 4B, Sanction Guidelines (effective 19 January 2021). Used for how a penalty's starting point is set and adjusted.

⁶ NERC Reliability Standard CIP-003-9, Security Management Controls, including Attachment 1. Section 4.5 is quoted verbatim. It carries over unchanged into the approved successor versions CIP-003-10 and CIP-003-11.

⁷ NERC Reliability Standard CIP-009-6, Recovery Plans for BES Cyber Systems. Part 2.3 is quoted verbatim.

⁸ NERC's Reliability Standard Audit Worksheet for CIP-008-6 (revision dated 17 January 2019). It guides auditors and says of itself that it should not be treated as a substitute for the standard or as additional requirements. Quoted verbatim.

⁹ NERC's Technical Rationale and Justification for CIP-008-6 (January 2019). Explanatory, and not part of the standard. Its final section carries over the rationale written for CIP-008-5.

¹⁰ NERC's Glossary of Terms Used in NERC Reliability Standards. The current definitions, in force since 1 January 2021, are quoted verbatim. The glossary also lists the revised definitions that take effect with CIP-008-7.1.

¹¹ NERC Reliability Standard CIP-002-5.1a, BES Cyber System Categorization, Attachment 1, Impact Rating Criteria. Summarised only.

¹² NERC's standard records, for status and dates: CIP-008-6, CIP-008-7.1 and CIP-003-9.

¹³ NERC Reliability Standard CIP-008-7.1, approved and subject to future enforcement. Compared with CIP-008-6 for what changes and what doesn't.

¹⁴ NERC, Implementation Plan for CIP-008-6 (January 2019). Used for how the effective date is set.

¹⁵ NERC, Implementation Plan for the revised CIP standards (April 2024), which covers CIP-008-7. Used for early adoption and for how periodic requirements carry over. The earliest early-adoption date is our calculation from its terms and FERC's order.

READINESS STARTS BEFORE THE CRISIS.

Put your team to the test.

Build your first scenario and turn preparation into measurable progress.

Explore pricing →Request a demo →