Regulatory compliance · Energy

NERC CIP Compliance Handbook 2026 by Kai London

CIP compliance fails on documentation far more often than on defence. This handbook works through the standards family the way a utility experiences it — categorise, protect, prove — with the evidence discipline that turns an audit into a routine week.

Available on Amazon. An independent practitioner guide — not affiliated with or endorsed by any regulator, regional entity or standards organisation.

What is inside

Asset categorisation

Identifying BES cyber systems and impact ratings — the decision every later obligation inherits.

Perimeters and access

Electronic and physical security perimeters, interactive remote access, and privileged account control in the control centre.

Configuration and change

Baselines, change management, vulnerability assessment and patch governance under operational constraints.

Personnel, training and supply chain

Risk assessment for staff and contractors, awareness obligations, and vendor requirements that survive procurement.

Incident reporting and recovery

Reportable events, response planning, and recovery testing for systems that hold the lights on.

Audit evidence discipline

Continuous evidence collection, self-reporting, and mitigation planning that reduces exposure rather than compounding it.

Who it is for: utility compliance managers and CIP senior managers, OT security leads in generation and transmission, control centre engineers, and internal auditors preparing for assessment.

NERC CIPIEC 62443NIST CSF 2.0
“

The audit does not test your defences. It tests your records of them.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.