Under active development Content is continuously updated and improved · Last updated Feb 18, 2026, 2:55 AM UTC

CIP-013-2 R1CIP-013-2 R1

>Control Description

Each Responsible Entity shall develop one or more documented supply chain cyber security risk management plan(s) for high and medium impact BES Cyber Systems and their associated Electronic Access Control or Monitoring Systems (EACMS) and Physical Access Control Systems (PACS). The plan(s) shall include: [Violation Risk Factor: Medium] [Time Horizon: Operations Planning]

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.