Media Express prepares Chicago-area suppliers to utilities — turbine manufacturers, control-system and equipment vendors, IT/OT integrators, communications vendors — for NERC CIP-013 supply chain cybersecurity questionnaires. Documentation, security posture pages, and vendor risk artifacts utility procurement teams look for.
You are not directly regulated by NERC. Your utility customers are. Through CIP-013 supply-chain rules, they push cybersecurity requirements down to you via questionnaires, contract clauses, and audits. If your product touches the Bulk Electric System (BES), or supports operations that do, expect requests.
Rule of thumb: if a utility procurement officer or engineer buys from you, and CIP-013 is in the news at their company, you'll get a questionnaire.
NERC has 14+ CIP standards. Most apply to the utility itself. As a supplier, you'll be pulled into three of them through your utility customer's due diligence.
The main standard that turns utility cybersecurity into your problem. Requires utilities to vet, question, and document vendor cybersecurity. Result: you get long questionnaires, security posture requests, and sometimes audits.
Rules for how utilities control network access to BES systems. If your product connects to their network — physically, wirelessly, or via cloud — you'll be asked how you support their access-control model.
Rules for handling BES Cyber System Information (BCSI) — the sensitive technical data about how the grid is built and operated. If your product or your engineers touch this data, utilities will ask how you protect it in storage and transit.
Utilities are on the hook for millions in NERC fines if their supply chain risk management fails. That pressure flows downhill. Suppliers who can't answer questionnaires get replaced.
A structured, phased approach with clear deliverables and fixed pricing. You always know what's next, what it costs, and when it's done.
Take our 15-question compliance quiz. Get an instant PDF report with your CIP-013 readiness score, exposure level, and top-priority gaps. This tells us what utility questionnaires will find weak in your current state.
Fixed-price engagement. We compare your current cybersecurity posture and public-facing artifacts against typical utility CIP-013 questionnaires. You get a phased roadmap with timelines and costs, plus an OPSEC website audit to catch info leaks that hurt vendor risk scores.
Vendor questionnaire response framework covering typical utility questions. Public "Our Cybersecurity Posture" page on your website. Certifications page. Capability Statement adapted for utility procurement. All the artifacts a utility procurement team looks for — ready.
Whatever technical gaps exist — MFA rollout, encryption, backup testing, endpoint controls, BCSI-handling procedures for engineers who touch utility data. We coordinate the work and verify each control is in place before the next questionnaire arrives.
When new questionnaires arrive from utility customers, we help you respond consistently, quickly, and with evidence. Managed retainer includes response templates, artifact repository, and quarterly refresh of your posture page as CIP standards evolve.
Supplier readiness for CIP-013 is much lighter than full CMMC — you're not signing up to be audited by NERC. You just need to answer utility questionnaires well and keep your documented posture current.
Prices depend on your company size, existing security posture, and how many utility clients you serve. Assessment results give you an accurate quote.
Above are typical Illinois market rates. Media Express pricing is more accessible — we build once and reuse across clients, so you don't pay for someone else's discovery work. Contact us for a personalized quote based on your exact situation.
⚜ Free Consultation →You are not directly regulated by NERC — but your utility customers are. Through CIP-013, they must vet and question their suppliers. So you don't sign a NERC document, but you receive questionnaires, must document your posture, and may be audited by your utility client. In practice, being ready for CIP-013 flow-down is required to keep supplying utilities.
The NERC standard specifically about supply chain cybersecurity. It requires utilities to develop and implement a supply chain cybersecurity risk management plan — which they enforce by sending you vendor questionnaires, requiring documentation, and sometimes auditing you.
6-12 weeks if you already have baseline cybersecurity. 3-6 months if you're starting from scratch and need to build documentation, posture pages, and remediate technical gaps.
Starter package (questionnaire response ready): $6-12k. Full alignment: $20-60k phased. Ongoing retainer: $1.5-6k/mo. See our pricing tiers above.
Suppliers are not formally certified. Certification is for the utility itself. What suppliers need is documented cybersecurity posture, questionnaire response frameworks, and evidence artifacts that satisfy your utility customer's CIP-013 due diligence.
Utilities are audited by Regional Entities (ReliabilityFirst, MRO, SERC, WECC, NPCC, TRE) on behalf of NERC. Regional Entities do not audit suppliers directly. But your utility customer can — and increasingly does — audit you on-site or remotely as part of CIP-013 due diligence.
Utilities remove you from their approved vendor list. New RFPs include CIP-013 prerequisites you can't meet. Existing contracts add flow-down clauses at renewal. Cyber insurance rates rise. Competitors take your contracts.
NERC CIP references several related terms and other frameworks. If you want to go deeper on any of them, our wiki covers each in plain English.
Take the free 15-question Compliance Readiness Assessment. Instant PDF report with your CIP-013 exposure, readiness score, and top-priority actions. No sales pitch.