field note
NERC CIP cameras: what CIP-006 actually requires
NERC CIP cameras monitor Physical Security Perimeters around BES Cyber Systems. CIP-006 requires restrict, monitor, alert, and log; it does not name cameras.
2026-08-21
NERC CIP cameras are the cameras a Responsible Entity uses to monitor Physical Security Perimeters around BES Cyber Systems, and sometimes to log physical access into those perimeters. NERC CIP does not require cameras by name. CIP-006, Physical Security of BES Cyber Systems, requires a documented physical security plan that restricts, monitors, alerts on, and logs physical access. Cameras are how most utilities implement the monitoring half. They fail that half when they go dark and nobody can prove they were watching.
That is the NERC security requirements problem in camera clothing. The NERC physical security standards that actually pull cameras are CIP-006, Physical Security of BES Cyber Systems, and, for certain transmission stations and substations, CIP-014. NERC security, for a camera fleet, is those two standards plus proof the plan ran. The program exists for power grid security: keep a compromise of BES Cyber Systems from becoming a reliability event on the Bulk Electric System. A camera fleet that is in the plan and not in the evidence is a monitoring control that is not operating.
What CIP-006 actually requires
The currently enforceable standard is CIP-006-6. FERC approved CIP-006-7.1 in March 2026; it is mandatory July 1, 2028, with the same camera-relevant language. The NERC CIP v5 family is still the program: High, Medium, and Low impact ratings under CIP-002, then the suite that follows. CIP-006-6 is that family with a later revision number.
The R1 table that pulls cameras in applies to High impact BES Cyber Systems and to Medium impact systems with external routable connectivity. NERC CIP compliance for those systems is a plan plus proof the plan ran.
| CIP-006-6 part | What it asks | Where cameras show up |
|---|---|---|
| R1 Parts 1.2 / 1.3 | Restrict unescorted physical access into each Physical Security Perimeter | Cameras are not the lock. NERC’s rationale allows a guard-monitored camera plus door release as one two-factor method |
| R1 Part 1.4 | Monitor for unauthorized access through a physical access point into a PSP | This is the usual camera job |
| R1 Part 1.5 | Issue an alarm or alert on detected unauthorized access, to the incident-response personnel, within 15 minutes of detection | A camera that records and is never watched does not satisfy this |
| R1 Parts 1.8 / 1.9 | Log authorized unescorted entry (individual, date, time) and retain those logs at least 90 calendar days | Footage inherits this clock only if video is the logging method |
| R2 | Escort visitors, log entry and exit, retain visitor logs 90 calendar days | Same inheritance rule |
| R3 | Maintain and test each Physical Access Control System and locally mounted hardware at each PSP at least once every 24 calendar months | Cameras at the perimeter are in this testing population |
Medium impact BES Cyber Systems without external routable connectivity get a lighter R1 Part 1.1: operational or procedural controls to restrict physical access. They do not pull in the monitor-alert-log chain the same way. Do not copy a High-impact camera program onto a Medium site that CIP-006 did not put in that column.
Where cameras land in the plan
A Physical Security Perimeter is the physical border around locations where BES Cyber Systems, or their associated electronic access control and monitoring systems, reside, and for which access is controlled. The camera on that door is a CIP-006 monitoring control. The camera on the parking lot is not, unless the plan put the lot inside the perimeter.
NERC’s technical rationale treats a guard-monitored remote camera plus a door release as an acceptable two-factor method. If that is how the plan works, the camera has to be available at the moment of entry.
Part 1.5 is a communication requirement: the people named in the Cyber Security Incident response plan receive the alert within 15 minutes of detection. Motion clips reviewed on Monday do not meet a clock that started Saturday night.
The 90-day clock on CIP-006 logs
The 90 calendar day retention in CIP-006 attaches to physical access logs and visitor logs. The word video appears nowhere in the requirement text. Monitoring a Physical Security Perimeter has no footage retention clock of its own.
If video recording is the method that logs authorized entry, that footage is the log and inherits 90 days. That is why 90 days is the common storage target for substation fleets. Citations and the folklore around the number are in video retention requirements. Compliance evidence that the process worked is a separate three calendar year clock.
CIP-014 does not mandate cameras
CIP-014-3 is the other NERC physical security standard that shows up in a camera conversation. It covers physical security of certain transmission stations and substations: a risk assessment and a documented plan whose measures the entity chooses. It never names cameras and sets no retention. If the plan says cameras cover a yard, those cameras have to work and the entity has to show that they did. If the plan uses fences, lighting, and patrols, CIP-014 does not invent a camera mandate.
Nuclear plants under NRC rules are a different regime. 10 CFR 73.55 names recorded video at protected-area perimeters. Do not import that language into a NERC CIP walkthrough.
When the camera is itself in scope
Most NERC CIP cameras are not BES Cyber Systems. A BES Cyber Asset is a Cyber Asset whose unavailability, degradation, or misuse would, within 15 minutes of its required operation, adversely impact BES reliability. A dark dome over a substation door is a failed monitoring control, not by itself a 15-minute reliability event. Classification still belongs to the entity’s CIP-002 process.
The NERC Glossary defines Physical Access Control Systems as Cyber Assets that control, alert, or log access to the Physical Security Perimeter, excluding locally mounted hardware such as motion sensors, locks, and badge readers. A camera on the fence is often that locally mounted hardware. The recorder that issues the Part 1.5 alert, or stores the Part 1.8 log, may be a PACS, and PACS associated with High impact systems, or Medium impact systems with external routable connectivity, appear in the CIP-006 tables as applicable systems of their own.
R3 still reaches the locally mounted devices: each PACS and the hardware at each PSP, tested at least once every 24 calendar months. A camera in the monitoring plan that has not been function-tested in two years is an R3 problem even when it is not a PACS.
Treat the devices as computers either way. Unique credentials, current firmware, valid certificates, and closed management are camera hardening. Ordinary outages, covered in why security cameras go offline, are CIP-006 control failures when the camera is in the plan.
CIP-013, supply chain risk management, applies to BES Cyber Systems and does not publish a camera brand list. Procurement for critical-infrastructure surveillance still has to survive NDAA Section 889 where those rules apply. Named manufacturers in that statute are a poor fit for a substation fleet. MentatNOC’s supported camera brands are Axis, Bosch, and Hanwha.
Proof the monitoring control operated
A Regional Entity audits the plan and whether the plan ran. The walkthrough shape is the same five gates as what auditors actually ask about camera systems. On a substation fleet the requests are specific.
- Show the inventory of cameras named in the CIP-006 or CIP-014 plan, and how you know it is complete. A spreadsheet of commissioning day is a hypothesis. The auditor can walk the PSP and compare.
- For these access points, show that monitoring was operating on a date in the audit period. Not a live view today. History. Outages are expected. Undetected outages are not.
- Show the 15-minute alert path actually fired. Configuration of an alert is design evidence. A dated alert that reached the named personnel is operating evidence.
- Show the 90 day access logs, and show they identify the individual and the time. If video is the log, that footage has to be retrievable for the clock the plan claimed.
- Show R3 testing inside 24 months for the devices at those PSPs. A sticker on a camera housing is not a dated test record.
Timestamps have to be trustworthy. A camera whose clock has drifted makes Part 1.8 logs and Part 1.5 alerts hard to correlate, which is the kind of gap a Regional Entity can spend the rest of the day on.
Doing this across 500 cameras
At one control house the plan is a binder and a known set of domes. Across a transmission and generation fleet the inventory drifts, the 24-month test window closes on devices nobody is watching, and a dark camera at a PSP door is filed as a facilities ticket instead of a CIP-006 monitoring failure. The 15-minute alert path is a configuration somebody set in 2019. The 90 day logs are in a recorder that overwrote itself on a retention setting the plan does not match.
MentatNOC keeps per-camera health and inventory current, records detections and repairs as they happen, and assembles a period into an evidence pack a Responsible Entity can hand to a Regional Entity. Staged firmware and credential work stay in the same trail. It monitors device health, not video. MentatNOC helps you prove your controls operated. It does not certify anyone, and no platform makes an organization CIP compliant on its own. The evidence shape is on compliance and proof, and a sample pack runs in the live platform demo.