PROTECT · Compliance · NERC CIP-013

Your utility clients will audit you. Be ready before they ask.

Media Express prepares Chicago-area suppliers to utilities — turbine manufacturers, control-system and equipment vendors, IT/OT integrators, communications vendors — for NERC CIP-013 supply chain cybersecurity questionnaires. Documentation, security posture pages, and vendor risk artifacts utility procurement teams look for.

⚜ Plain English · Quotable
NERC CIP (Critical Infrastructure Protection) is a set of mandatory cybersecurity standards for the U.S. and Canadian electric grid, issued by the North American Electric Reliability Corporation and enforced by FERC. CIP-013 is the standard about supply chain — and it's the one that makes utility customers ask you, the supplier, for security documentation, questionnaire responses, and evidence of your cybersecurity posture. Media Express prepares Chicago-area suppliers to Exelon, ComEd, and regional utilities for these requests, so you don't scramble when a 40-page questionnaire lands in your inbox.
⚡ Who This Applies To

If you sell to a utility — or through a distributor to one — you're in scope.

You are not directly regulated by NERC. Your utility customers are. Through CIP-013 supply-chain rules, they push cybersecurity requirements down to you via questionnaires, contract clauses, and audits. If your product touches the Bulk Electric System (BES), or supports operations that do, expect requests.

Rule of thumb: if a utility procurement officer or engineer buys from you, and CIP-013 is in the news at their company, you'll get a questionnaire.

⚡ What Utilities Are Enforcing

Three standards that hit suppliers hardest.

NERC has 14+ CIP standards. Most apply to the utility itself. As a supplier, you'll be pulled into three of them through your utility customer's due diligence.

CIP-013-2
Supply Chain Risk Management

The main standard that turns utility cybersecurity into your problem. Requires utilities to vet, question, and document vendor cybersecurity. Result: you get long questionnaires, security posture requests, and sometimes audits.

CIP-005-6
Electronic Security Perimeter

Rules for how utilities control network access to BES systems. If your product connects to their network — physically, wirelessly, or via cloud — you'll be asked how you support their access-control model.

CIP-011-3
BCSI Handling

Rules for handling BES Cyber System Information (BCSI) — the sensitive technical data about how the grid is built and operated. If your product or your engineers touch this data, utilities will ask how you protect it in storage and transit.

⚠️ If You Ignore It

The cost of not being ready.

Utilities are on the hook for millions in NERC fines if their supply chain risk management fails. That pressure flows downhill. Suppliers who can't answer questionnaires get replaced.

⚠️ Real Consequences

Suppliers unprepared for CIP-013 questionnaires face measurable losses over the next 24 months.

  • Utilities remove you from their approved vendor list — you stop getting purchase orders
  • New RFPs from utilities include CIP-013 questionnaires as a prerequisite — you can't even bid
  • Existing contracts add flow-down clauses at renewal that you're not ready to sign
  • Corrective action plans with deadlines — miss them and you're out
  • Cyber liability insurance premiums rise for uncertified utility suppliers
  • Competitors with better documentation take contracts you would have won
  • Recovering later costs 2-3× more than being proactive today
⚜ How We Help

The 5-step CIP-013 supplier readiness path.

A structured, phased approach with clear deliverables and fixed pricing. You always know what's next, what it costs, and when it's done.

1
Free Readiness Assessment (15 min)

Take our 15-question compliance quiz. Get an instant PDF report with your CIP-013 readiness score, exposure level, and top-priority gaps. This tells us what utility questionnaires will find weak in your current state.

2
Gap Analysis + Roadmap (2-3 weeks)

Fixed-price engagement. We compare your current cybersecurity posture and public-facing artifacts against typical utility CIP-013 questionnaires. You get a phased roadmap with timelines and costs, plus an OPSEC website audit to catch info leaks that hurt vendor risk scores.

3
Documentation + Security Posture Page (6-10 weeks)

Vendor questionnaire response framework covering typical utility questions. Public "Our Cybersecurity Posture" page on your website. Certifications page. Capability Statement adapted for utility procurement. All the artifacts a utility procurement team looks for — ready.

4
Technical Remediation (parallel)

Whatever technical gaps exist — MFA rollout, encryption, backup testing, endpoint controls, BCSI-handling procedures for engineers who touch utility data. We coordinate the work and verify each control is in place before the next questionnaire arrives.

5
Ongoing Questionnaire Support

When new questionnaires arrive from utility customers, we help you respond consistently, quickly, and with evidence. Managed retainer includes response templates, artifact repository, and quarterly refresh of your posture page as CIP standards evolve.

💰 What It Costs

Fixed pricing at every phase. No open-ended consulting.

Supplier readiness for CIP-013 is much lighter than full CMMC — you're not signing up to be audited by NERC. You just need to answer utility questionnaires well and keep your documented posture current.

Questionnaire Ready
Starter Package
$6,000 – $12,000
One-time, delivered in 4-6 weeks
  • Vendor questionnaire response framework
  • Security posture page on your website
  • Baseline cybersecurity policies
  • Capability Statement (utility-adapted)
  • Trust posture + certifications page
  • Response templates for future questionnaires
Ongoing Retainer
Managed Readiness
$1,500 – $6,000/mo
Recurring, month-to-month
  • Response support for incoming questionnaires
  • Quarterly posture page refresh
  • CIP standard update alerts
  • Documentation maintenance
  • Website + trust posture upkeep
  • Compliance-ready hosting included
  • Priority support during audit prep

Prices depend on your company size, existing security posture, and how many utility clients you serve. Assessment results give you an accurate quote.

Above are typical Illinois market rates. Media Express pricing is more accessible — we build once and reuse across clients, so you don't pay for someone else's discovery work. Contact us for a personalized quote based on your exact situation.

⚜ Free Consultation →
❓ Common Questions

FAQ.

Does NERC CIP apply to me if I only supply parts to a utility?

You are not directly regulated by NERC — but your utility customers are. Through CIP-013, they must vet and question their suppliers. So you don't sign a NERC document, but you receive questionnaires, must document your posture, and may be audited by your utility client. In practice, being ready for CIP-013 flow-down is required to keep supplying utilities.

What is CIP-013?

The NERC standard specifically about supply chain cybersecurity. It requires utilities to develop and implement a supply chain cybersecurity risk management plan — which they enforce by sending you vendor questionnaires, requiring documentation, and sometimes auditing you.

How long does NERC CIP supplier readiness take?

6-12 weeks if you already have baseline cybersecurity. 3-6 months if you're starting from scratch and need to build documentation, posture pages, and remediate technical gaps.

How much does readiness cost?

Starter package (questionnaire response ready): $6-12k. Full alignment: $20-60k phased. Ongoing retainer: $1.5-6k/mo. See our pricing tiers above.

Do I need to be NERC CIP certified?

Suppliers are not formally certified. Certification is for the utility itself. What suppliers need is documented cybersecurity posture, questionnaire response frameworks, and evidence artifacts that satisfy your utility customer's CIP-013 due diligence.

Who audits my utility customer — and can they audit me?

Utilities are audited by Regional Entities (ReliabilityFirst, MRO, SERC, WECC, NPCC, TRE) on behalf of NERC. Regional Entities do not audit suppliers directly. But your utility customer can — and increasingly does — audit you on-site or remotely as part of CIP-013 due diligence.

What happens if I ignore CIP-013 questionnaires?

Utilities remove you from their approved vendor list. New RFPs include CIP-013 prerequisites you can't meet. Existing contracts add flow-down clauses at renewal. Cyber insurance rates rise. Competitors take your contracts.

📚 Related Terms

Also worth understanding.

NERC CIP references several related terms and other frameworks. If you want to go deeper on any of them, our wiki covers each in plain English.

Ready to see where you stand?

Take the free 15-question Compliance Readiness Assessment. Instant PDF report with your CIP-013 exposure, readiness score, and top-priority actions. No sales pitch.

Media Express LLC · Chicago IL · Est. 1995 · Independent · 31+ years
Media Express LLC prepares suppliers to utilities and Bulk Electric System operators for NERC CIP-013 supply chain cybersecurity requirements. Media Express is not a NERC Regional Entity, does not perform official NERC audits, and does not certify entities registered with NERC. Formal NERC audits of registered entities are conducted by Regional Entities (ReliabilityFirst, MRO, SERC, WECC, NPCC, TRE) under NERC delegation.