September 11, 2026

CIP-008 doesn't say annual. It says 15 calendar months.

CIP-008 requires each incident response plan to be tested at least once every 15 calendar months, not annually. Month 16 is already a violation, and a once-a-calendar-year schedule can put nearly two years between tests.

"An annual tabletop" is the usual shorthand for CIP-008's incident response test. The standard is more exact than that, and the difference cuts the wrong way for anyone who takes the shorthand literally.

For high and medium impact BES Cyber Systems, CIP-008-6, Requirement R2, Part 2.1, reads:¹

Test each Cyber Security Incident response plan(s) at least once every 15 calendar months:

  • By responding to an actual Reportable Cyber Security Incident;
  • With a paper drill or tabletop exercise of a Reportable Cyber Security Incident; or
  • With an operational exercise of a Reportable Cyber Security Incident.

The interval runs between tests, not by calendar year. NERC grades a late test by the months "between tests of the plan(s)".¹

Month 16 is already a violation. The severity level rises for each month a test is late: Lower in month 16, Moderate in month 17, High in month 18, Severe after that.¹ Those levels grade how serious a violation is. They aren't a grace period.

Here's where the shorthand bites. Testing every twelve months keeps you inside the requirement. "Once a year", read as once per calendar year, doesn't. It allows a test in January one year and the next in December of the following year. That's nearly two years between tests, which CIP-008 grades at its most serious level.

So where does "annual" come from? One likely source is NERC's own technical rationale for CIP-008-6, which explains the standard but isn't part of it. Its closing section carries over text written for the earlier version, CIP-008-5, that speaks of exercising the plan annually.² The standard is what binds, and it says 15 calendar months.

None of this makes the obligation softer. In the United States, CIP-008 is mandatory. The Federal Power Act is direct about it: *"All users, owners and operators of the bulk-power system shall comply with reliability standards that take effect under this section."*³ Violations can draw civil penalties.³ The mandate is real. The "annual" isn't.

Nor does the clock move with the next version. CIP-008-7.1, which takes effect on 1 July 2028, keeps the same testing requirement.⁴

The three methods and what the test has to be of, which systems are in scope, the 36-month cycle for low impact systems, the 90-day loop that follows every test, and why reporting is a separate duty are all in one place: What NERC CIP-008 actually asks of your exercise program.


Standards references current as of September 2026. Quoted passages are verbatim from the sources noted. This piece has not been reviewed or endorsed by NERC. It is scheduled for re-verification by March 2027.

¹ NERC Reliability Standard CIP-008-6, Cyber Security — Incident Reporting and Response Planning, the version subject to enforcement in the United States. Requirement text is quoted verbatim. Used for the Violation Severity Levels.

² NERC's Technical Rationale and Justification for CIP-008-6 (January 2019). Explanatory, and not part of the standard. Its final section carries over the rationale written for CIP-008-5.

³ Federal Power Act §215, 16 U.S.C. §824o, Electric reliability, from the Office of the Law Revision Counsel. Quoted verbatim.

⁴ NERC Reliability Standard CIP-008-7.1, approved and subject to future enforcement.

READINESS STARTS BEFORE THE CRISIS.

Put your team to the test.

Build your first scenario and turn preparation into measurable progress.

Explore pricing →Request a demo →