Energy sector compliance can feel like alphabet soup. NERC CIP, TSA Security Directives, CMMC and state rules all sound similar, but they apply to different organizations for different reasons. Mixing them up leads to wasted effort, or worse, missing an obligation you actually have.
This post explains in general terms how NERC CIP and TSA pipeline directives differ, who tends to be covered, and what contractors and smaller operators should ask. It is an overview, not legal advice. Your own obligations depend on your registration, contracts and regulators.
NERC CIP: The Bulk Electric System
NERC Critical Infrastructure Protection standards apply to entities that own or operate certain parts of the bulk electric system in North America. They cover areas such as identifying and categorizing systems, electronic and physical access controls, personnel training, incident reporting, system security management and recovery planning.
Applicability is not based on company size alone. It depends on whether an entity is registered for certain functions and which assets it operates, with requirements scaled to the impact the assets could have on reliability. Many small distribution utilities and cooperatives have little or no CIP-covered equipment, while others have a limited footprint. A registered entity should know its status from its regional compliance contacts.
TSA Security Directives: Pipelines
The Transportation Security Administration issued security directives for certain pipeline owners and operators. They have addressed topics such as reporting cybersecurity incidents, designating a cybersecurity coordinator, assessing vulnerabilities and implementing specific cybersecurity measures. The directives apply to operators the TSA has designated as critical, and the details have been updated over time, so operators should work from the current text provided to them.
The Key Differences
- Sector: NERC CIP concerns the electric grid. TSA directives concern designated pipeline and related operators.
- Authority: NERC standards are enforced through the electric reliability regulatory structure. TSA directives come from a federal agency.
- Approach: CIP is a long-established set of standards with formal audits. TSA directives have been issued in response to threats and have evolved, with performance-oriented requirements and reporting expectations.
- Scope: Both focus on operational systems, but each defines its covered assets differently.
A company can be touched by more than one framework. A utility with a gas operation or a contractor serving both pipelines and power plants may face different customer demands on different jobs.
Where Contractors and Vendors Fit
Even if you are not directly regulated, your customer may be. Operators are responsible for the security of their systems, including the access vendors have. As a result, vendors often see requirements flow down through contracts and questionnaires.
Common requests include:
- Background checks and training for personnel who access systems.
- Controls on remote access, such as multi-factor authentication and session logging.
- Rules for portable media and laptops brought on site.
- Prompt notification of security incidents.
- Evidence of patching and malware protection on devices connecting to the customer's environment.
- Return or destruction of sensitive information at contract end.
If you serve defense customers, CMMC is a separate matter based on contract requirements involving controlled unclassified information. It is not a substitute for, or a part of, the energy frameworks above.
Questions to Ask Your Customer
- Are we considered to have access to systems covered by your compliance program?
- Which of your policies apply to our staff and devices?
- What incident notification timeline do you expect from us?
- What evidence will you ask us for, and how often?
- Who is our point of contact for compliance questions?
Questions to Ask Yourself
- Which regulated customers do we serve, and what do our contracts say?
- Which of our people and laptops touch their environments?
- Do we have written procedures for access, incidents and device management that we could show an auditor or customer?
- Who owns compliance conversations internally?
A Practical Approach
Rather than building a separate program for each customer, many vendors build one solid baseline: multi-factor authentication, managed and encrypted devices, documented access procedures, incident response and training. Then they adapt to specific requirements. That baseline answers the large majority of questionnaire items.
Ironfield Cyber helps energy-sector contractors and small operators interpret what applies to them, document a baseline and prepare for customer reviews. If you have a questionnaire you do not know how to answer, we can help you work through it.