NERC CIP compliance in Texas is narrower than most oil and gas teams fear. Once it applies, it’s stricter than they expect. It binds only companies registered with NERC through Texas RE, usually because on-site generation or a high-voltage tie touches the bulk electric system. Registered sites have owed vendor remote access controls since April 1, 2026. Everyone else has homework too. For the wider picture, see our IT services for oil and gas companies.
NERC CIP compliance in Texas applies to oil and gas companies registered with NERC through Texas RE, typically because on-site generation or a high-voltage interconnection crosses bulk electric system thresholds. Registered sites must meet the CIP-002 through CIP-015 cybersecurity standards, and a single violation can cost up to $1,584,648 per day.
Most oil and gas companies that ask me about NERC CIP don’t have to comply with it. That’s the honest answer. It’s also where the harder conversation starts.
I’m the CTO at Uprite, and our engineers support producers, midstream operators and oilfield service firms from Houston to the Permian. The question comes up constantly. It usually shows up after a utility interconnection agreement, a cogeneration project or an insurance renewal, when someone reads the phrase critical infrastructure in a contract and assumes the whole company now answers to the grid regulator. Usually it doesn’t. Sometimes it does. And nobody noticed.
This guide covers who is actually in scope, what the CIP standards ask of your IT and OT teams, what changed in 2025 and 2026, and where to start if you sit somewhere in between. Let’s start with definitions. For the broader regulatory stack, including TSA pipeline directives, SEC incident disclosure and the Texas Data Privacy and Security Act, read our guide to oil and gas IT compliance in Texas.
What is NERC CIP compliance?
NERC CIP compliance means meeting the Critical Infrastructure Protection reliability standards that the North American Electric Reliability Corporation develops and FERC approves. They require registered owners and operators of the bulk electric system to categorize their cyber assets, protect and monitor them, respond to incidents, and keep evidence proving all of it.
The word that matters most there is registered. NERC CIP isn’t an industry certification you decide to chase. It’s a mandatory federal program that attaches to specific electrical functions, such as Generator Owner, Generator Operator or Transmission Owner. No function, no obligation. That distinction saves money.
Evidence is the other word worth underlining. Auditors don’t grade intentions. They grade dated records.
Does NERC CIP apply to Texas oil and gas companies?
Only if you perform a registered function on the bulk power system. Texas RE, the regional entity that oversees grid reliability in ERCOT, states that all bulk power system owners, operators and users in the ERCOT region must register with NERC and comply with the standards tied to their functions. Geography settles nothing. Being in Texas doesn’t exempt you. Being an oil company doesn’t pull you in.
So the real test is electrical. Here’s how it usually plays out.
| Your situation | Likely NERC status | What governs your IT security |
|---|---|---|
| Upstream producer buying all power from the grid or a co-op | Not registered | Customer contracts, cyber insurance and SEC rules if you’re public |
| Gas plant or refinery with behind-the-meter generation exporting 75 MVA or less | Often excluded under BES Exclusion E2 if backup power terms are met | Insurance requirements, plus API 1164 or IEC 62443 by choice |
| Site with a generator above 20 MVA, or above 75 MVA in total, connected at 100 kV or higher | Likely a Generator Owner and Generator Operator | NERC CIP, starting with CIP-002 categorization |
| Field solar or battery storage totaling 20 MVA or more at 60 kV or higher | Possible Category 2 registration since May 2026 | NERC standards for inverter-based resources |
| TSA-designated critical pipeline or LNG facility | A separate federal program | TSA Security Directive Pipeline-2021-02G |
| Company that owns a high-voltage substation or transmission line | Worth a registration review with Texas RE | Whatever function Texas RE assigns |
The thresholds that decide it
NERC’s bulk electric system definition includes generating resources connected at 100 kV or above with a gross individual nameplate rating above 20 MVA, or a plant aggregate above 75 MVA. Plenty of large processing and cogeneration sites clear those numbers without anyone in IT knowing it. Ask your electrical engineer.
There’s an escape hatch. Exclusion E2 removes behind-the-meter generation that serves your own load, as long as net capacity delivered to the grid stays at or under 75 MVA and your standby, backup and maintenance power comes from a balancing authority or a binding arrangement. Read those conditions closely. A new power contract or a change in how much you export can flip the answer without a single piece of equipment changing on site, so the review belongs on the calendar every time a power agreement gets renegotiated. Recheck it yearly.
The inverter-based resource change
The newer trap is solar and storage. Both use inverters. Under NERC’s revised registry criteria, owners of inverter-based resources totaling 20 MVA or more, connected at 60 kV or higher, fall into a new Category 2 and had to register and comply by May 15, 2026, according to Davis Wright Tremaine’s review of the NERC petition. Oilfield electrification projects that pair an array with batteries can reach that size faster than people expect. Check yours.
Why the Permian keeps raising the question
ERCOT’s December 2025 report on electric system constraints and needs counts about $23 billion of approved transmission projects in the Permian Basin area since 2014, including roughly 1,329 miles of new 765-kV lines. ERCOT says the buildout serves oil and gas loads alongside other large loads. That’s a lot of steel. More substations and more on-site generation in West Texas mean more operators will face a registration question they never had to answer before. Expect more registration reviews.

What IT requirements do the CIP standards set?
The CIP family runs from CIP-002 through CIP-015. How much of it lands on you depends on whether CIP-002 rates your systems high, medium or low impact. Most generation at an oil and gas site ends up low impact. That’s the lightest tier. It isn’t light.
- CIP-002 sorts your BES Cyber Systems into high, medium or low impact.
- CIP-003 sets security management policies and, for low impact assets, a 6-section security plan.
- CIP-004 covers personnel risk assessments, training and prompt access revocation.
- CIP-005 governs electronic security perimeters and interactive remote access.
- CIP-006 handles physical security for BES Cyber Systems.
- CIP-007 requires port and service control, patching, malware prevention, logging and password rules.
- CIP-008 defines incident response planning and reporting.
- CIP-009 requires recovery plans and tested backups.
- CIP-010 manages configuration baselines, change control and vulnerability assessments.
- CIP-011 protects BES Cyber System information wherever it’s stored.
- CIP-012 secures real-time data sent between control centers.
- CIP-013 addresses supply chain risk from vendors and products.
- CIP-014 protects critical transmission stations from physical attack.
- CIP-015 adds internal network security monitoring inside the perimeter.
Read that list as an IT person and most of it feels familiar. Asset inventory. Access control. Patching. Logging. Backups. Vendor risk. The difference is the proof, because NERC wants dated evidence for every requirement, kept long enough to survive an audit, and a missed interval counts as a violation even when the underlying control worked perfectly the whole time. Auditors check dates.
What changed in NERC CIP in 2025 and 2026?
Three changes matter for Texas operators right now. They land on very different timelines.
CIP-003-9 made vendor remote access a low impact requirement
Since April 1, 2026, CIP-003-9 has been enforceable, adding a Section 6 to the low impact security plan. If a vendor can reach a low impact BES Cyber System remotely, you now need documented methods to do 3 things.
- Determine when vendor electronic remote access is happening.
- Disable that access when you need to.
- Detect known or suspected malicious communications, inbound and outbound, during vendor sessions.
This is the one I’d fix first. Oil and gas sites run on vendors, from turbine manufacturers to controls integrators, and many of those relationships still rely on an always-on VPN account or a remote desktop tool somebody installed years ago. Vendors won’t fix it. That was never a good idea. Now it’s an enforceable finding.
CIP-015-1 moved monitoring inside the perimeter
FERC’s Order No. 907 approved CIP-015-1, effective September 2, 2025, with implementation phased in after that. It requires internal network security monitoring for high impact BES Cyber Systems and for medium impact systems with external routable connectivity. FERC also directed NERC to extend it to access control and physical access systems outside the perimeter within 12 months. Low impact sites aren’t covered today. Scope tends to grow. Watch it anyway.
Order No. 919 opened the door to virtualization
In March 2026, FERC’s Order No. 919 approved 11 modified CIP standards that let entities virtualize in-scope systems securely. The order took effect May 26, 2026, and the revised standards themselves become effective April 1, 2028, according to Troutman Pepper Locke’s summary. That’s about 18 months out. Planning a virtualized control room or a server refresh? Design for the new definitions now rather than rebuilding in 2028.
How does NERC CIP compare with TSA pipeline rules and API 1164?
Oil and gas companies often face 2 or 3 of these at once, sometimes at the same site. They overlap far more than they conflict. That’s good news.
| Framework | Who it binds | Enforced by | What it asks of IT |
|---|---|---|---|
| NERC CIP | NERC-registered bulk electric system entities | NERC and Texas RE, with FERC oversight | Categorization, access control, patching, logging, incident response, vendor controls and dated evidence |
| TSA Security Directive Pipeline-2021-02G | Pipeline and LNG owners TSA has designated as critical | TSA | An approved implementation plan, an incident response plan and an annual assessment plan |
| API Standard 1164 | Pipeline control system operators who adopt it | Voluntary | Risk-based security for SCADA and control systems |
| IEC 62443 | Industrial automation owners and suppliers who adopt it | Voluntary, often written into contracts | Zone and conduit design plus security levels for OT |
TSA’s current directive, Security Directive Pipeline-2021-02G, took effect May 3, 2026 and expires May 2, 2027. It applies to owners and operators that TSA has designated as critical and notified. TSA tells you directly. Covered operators need a TSA-approved Cybersecurity Implementation Plan, an up-to-date Cybersecurity Incident Response Plan, and a Cybersecurity Assessment Plan with an annual update and an annual report on the previous year’s results. A midstream company with a critical pipeline and a registered generation site answers to both regimes. One control set can satisfy both. Two evidence trails are still required.

What does a low impact CIP program look like day to day?
Most oil and gas registrants will live in CIP-003. It’s the workhorse standard. The CIP-003-9 standard requires a CIP Senior Manager to approve your cyber security policies at least once every 15 calendar months, and then a security plan with 6 sections that covers every asset holding low impact systems. Here’s how each one turns into IT work.
- Cyber security awareness gets reinforced with staff at least once every 15 calendar months, with a dated record to prove it.
- Physical security controls limit who can reach the assets and locations holding low impact systems.
- Electronic access controls allow only necessary inbound and outbound routable traffic and authenticate any dial-up connection.
- An incident response plan has to be tested at least once every 36 calendar months and updated within 180 days of a test or a real incident, so the lessons learned actually land in the document.
- Transient cyber assets, meaning contractor laptops and USB drives, need malicious code checks before they touch the network.
- Vendor electronic remote access needs the 3 methods described above.
The same gaps show up again and again when we look at operational networks. A firewall rule base allows more than anyone can explain. A contractor laptop plugs straight into the control network. An incident plan exists on paper but has never been tested with the plant manager in the room. None of it is exotic. Every one is fixable. All of it needs a date, a name and a record.
A practical setup routes every vendor session through a single jump host with multifactor authentication, session recording and an off switch your own team controls, instead of a standing VPN account that stays open all year. Pair that with centralized logging and alerting from a managed security services provider, and Section 6 becomes a report you pull. Not a fire drill.
What does NERC CIP noncompliance cost?
The federal ceiling for a Federal Power Act civil penalty is $1,584,648 per violation, per day under FERC’s current inflation adjustment. Real penalties rarely get close. Many minor issues close with a mitigation plan instead of a fine. Don’t relax. A missed 15-month review is still a violation whether or not anything went wrong, and the finding stays on your compliance history where the next auditor will read it first and ask what else slipped.
The bigger cost is operational. A generation site that can’t prove control over vendor access is also a site where an attacker could borrow that same access. The fine matters less. Our post on whether a Colonial Pipeline-style cyberattack could disrupt your business shows how fast an IT incident becomes an operations shutdown.

Where should a Texas oil and gas IT team start?
Start with scope, not tools. Buying monitoring software before you know whether you’re registered is backward. Scope comes first.
- List every site with on-site generation, battery storage or a high-voltage interconnection, including nameplate ratings and interconnection voltage.
- Check the NERC Compliance Registry, or ask Texas RE registration staff, whether any of those sites already carries a registered function.
- Map where your business network ends and your control systems begin, including every remote access path.
- Put vendor remote access behind one controlled, logged and interruptible path.
- Build an evidence calendar for every recurring interval, from 15-month reviews to 36-month incident plan tests.
- Run a tabletop exercise with operations, IT and your key vendors in the same room.
Not registered? Steps 3 through 6 are still worth doing. Attackers don’t check registration. These steps line up with TSA expectations, insurer questionnaires and the cybersecurity essentials Houston oil and gas companies need. Our guide to OT and IT security for Texas manufacturers covers the network segmentation side in more depth, and it applies just as well to a gas plant or a compressor station.
How does Uprite help with NERC CIP?
Let’s be clear about our role. Uprite isn’t a NERC auditor, and we don’t certify anyone. Texas RE handles the audits. What we do is run the IT and security operations that produce the evidence. We keep you ready.
Uprite has supported Texas businesses since 1999, and our 42-person team handles the monitoring, patching, access control, backup and incident response work that CIP-003 and the TSA directives both expect from an operator. We did similar work for a Texas oil and gas company whose aging infrastructure and slow support had become an operational risk, which you can read about in our oil and gas IT modernization case study. For a structured look at your own gaps, start with a compliance and regulatory assessment.
Questions Texas Oil and Gas Teams Ask About NERC CIP
Is ERCOT exempt from NERC CIP because it isn’t tied into the other grids?
No, ERCOT isn’t exempt from NERC reliability standards. Texas RE enforces them across the ERCOT region, and every bulk power system owner, operator or user there must register for its functions. ERCOT’s limited links to other grids matter for federal rate regulation, not for reliability standards.
Does a gas processing plant with cogeneration have to register with NERC?
It depends on generator size, connection voltage and how much power the plant exports. A unit above 20 MVA, or site generation above 75 MVA, connected at 100 kV or higher usually meets the bulk electric system definition. Behind-the-meter units can be excluded when net export stays at or below 75 MVA and backup service terms are met. Texas RE makes the final call.
What’s the difference between low, medium and high impact BES Cyber Systems?
CIP-002 rates each BES Cyber System by how much harm its loss could do to the grid. High impact covers the largest control centers, medium impact covers significant generation and transmission, and low impact covers the rest of what’s in scope. Most oil and gas generation lands in low impact, which puts CIP-003 at the center of the program.
How large can NERC CIP penalties get?
The federal cap is $1,584,648 per violation, per day. Actual penalties are usually far lower and scale with risk, duration and compliance history. Minor documentation gaps often close with a mitigation plan instead of a fine.
Can a managed IT provider handle CIP-003-9 vendor remote access controls?
Yes, a managed IT provider can run the technical controls, but your company stays the responsible entity. The provider can operate the jump host, multifactor authentication, logging and alerting, then hand you the evidence. Your CIP Senior Manager still approves the policies, and your name is on the registration.
Do TSA pipeline security directives replace NERC CIP for midstream companies?
Neither program replaces the other. TSA directives cover pipeline and LNG facilities that TSA designates as critical, while NERC CIP covers registered bulk electric system functions. A midstream company subject to both keeps separate plans and evidence, even when one set of controls satisfies both.
Not sure whether a generator, substation or solar project puts your company in NERC scope? Talk with our team, and we’ll help you map the answer and the IT controls that go with it.
Speak to an IT Expert








