Vision Detection Systems
Substation Physical Security and NERC CIP-014: What Utilities Actually Have to Do
BLOG | UTILITY SECURITY

Substation Physical Security and NERC CIP-014: What Utilities Actually Have to Do

Physical attacks on the US grid hit a record in 2023, yet NERC CIP-014 covers only a narrow set of critical transmission substations. This guide explains the standard's scope in plain language, why most distribution substations fall outside it, and what proportionate protection looks like for the sites regulation never reaches.

BYVDS Editorial
PUBLISHEDAugust 2026
READ7 min
UTILITY
SUMMARY

Substation physical security is regulated by NERC CIP-014 at only a small set of critical transmission substations, while the vast majority of US substations, including nearly all distribution sites, fall outside the standard entirely. The threat is not waiting for regulation to catch up. DOE OE-417 filings recorded at least 175 physical attacks or threats against grid infrastructure in 2023, a record and roughly double the 2021 total, according to a Kansas Legislative Research Department analysis of the federal data. This guide explains what CIP-014 actually requires, which sites it leaves uncovered, and how utilities are protecting the rest. It is general information, not legal or compliance advice; scoping and compliance decisions belong with your NERC compliance team.

Which substations does NERC CIP-014 actually cover?

CIP-014 is NERC's physical security standard for the bulk power system, developed at FERC's direction after the 2013 rifle attack on the Metcalf transmission substation in California. Its premise is narrow by design: identify the transmission substations whose loss or damage could cause instability, uncontrolled separation, or cascading outages across the wider grid, then require verified security planning at those specific sites.

Scope is determined by a risk assessment, not a published list. Transmission owners periodically assess their stations against the standard's voltage and criticality criteria, and only the stations identified as critical carry obligations. In practice that is a small fraction of transmission substations nationally, and it excludes distribution substations altogether.

The practical takeaway is blunt. If you operate a distribution substation, or a transmission station that does not meet the criticality threshold, CIP-014 imposes no physical security requirements on that site. Whatever protection it gets is a business decision driven by outage risk, insurance exposure, and community impact rather than by compliance.

What does CIP-014 require at in-scope sites?

For the stations that do qualify, the standard lays out a sequence of obligations that, stripped of regulatory language, works roughly like this:

  1. Identify critical stations. Run a periodic risk assessment to determine which transmission substations, if damaged or destroyed, could cause widespread instability or cascading outages.
  2. Verify the assessment. Have an unaffiliated third party review the risk assessment so critical sites cannot be quietly assessed out of scope.
  3. Notify affected operators. Tell the relevant transmission operators when their primary control centers are tied to an identified station.
  4. Evaluate threats and vulnerabilities. For each identified site, assess the realistic attack scenarios, from gunfire outside the fence to forced entry.
  5. Build and implement a physical security plan. Document resiliency and security measures that address the evaluated threats, with timelines for executing them.
  6. Get an independent review. Have a qualified third party review both the threat evaluation and the security plan.

Deadlines, documentation expectations, and audit practices all carry detail this summary cannot, which is why the standing advice holds: treat this as orientation, and let your compliance team interpret the standard against your asset base.

Substation equipment behind perimeter fencing
Most distribution substations sit outside CIP-014's mandate

Why Moore County became the inflection point

In December 2022, gunfire damaged two Duke Energy substations in Moore County, North Carolina, cutting power to tens of thousands of customers, as reported by CBS News. The attack required no inside knowledge and no entry to either site. Rifle rounds fired at transformers from outside the perimeter were enough to take substantial load offline.

Moore County was the most visible incident in a much broader trend. Physical attacks on the grid rose 71% in 2022 compared with 2021, according to DOE data reported by CBS News, and as noted above, 2023 set a new record. The incidents that make national news are ballistic attacks, but the day-to-day reality at most substations is less dramatic and more frequent: cut fences, stripped grounding conductors, stolen copper, and vandalized equipment.

The regulatory response was immediate in one sense. FERC directed NERC to evaluate whether CIP-014's applicability criteria should be widened. What happened next defines the landscape utilities operate in today.

The gap NERC chose not to close

In April 2023, NERC delivered its FERC-directed evaluation and declined to recommend expanding CIP-014's applicability, as documented in the NERC filing and covered by Utility Dive. The standard's footprint stayed where it was. Distribution substations, and most transmission stations, remain outside mandatory physical security requirements by design.

That decision matters because the sites outside CIP-014 are precisely the ones absorbing most of the abuse. They are numerous, lightly staffed or unstaffed, often remote, and frequently protected by nothing more than chain-link fence and a padlock. They also hold what metal thieves want. The adjacent infrastructure numbers show the scale of that economy: AT&T reported more than 10,000 copper theft incidents against its network in 2025, with losses topping $80 million, per AT&T. That is telecom rather than electric infrastructure, but the criminal economics are identical, and substations concentrate copper in predictable, mapped, unattended locations. We cover the theft problem and its countermeasures in depth in our guide to copper theft prevention at substations; this article stays focused on the compliance picture and the proportionate-control question.

So the operating reality for a utility security manager is a two-tier estate: a handful of CIP-014 sites with mandated, audited security plans, and hundreds or thousands of substations where protection is discretionary but the threats are not.

Proportionate protection for substations outside CIP-014

Nobody is going to build ballistic walls around every distribution substation, and no regulator expects it. The question for non-CIP sites is proportionality: what controls meaningfully reduce risk at a cost that scales across a large fleet?

CIP-014 critical transmission siteDistribution substation outside CIP-014
Regulatory driverMandatory NERC standard, subject to auditNone under CIP-014; internal risk management
Typical threat profileTargeted sabotage, coordinated attackGunfire, vandalism, copper theft, trespass
Common measures todayVerified security plan, hardened barriers, monitored detectionFencing, signage, sometimes little else
Fit for rapid-deploy monitored surveillanceStopgap during remediation constructionPrimary detection and deterrence layer

A layered approach for non-CIP sites typically stacks four elements:

  • Perimeter integrity and signage. Intact fencing, locked gates, and clear warning signage remove the easy-target signal and strengthen prosecution when incidents occur.
  • Detection with human verification. Cameras that feed 24/7 remote monitoring turn a passive record-it-later system into live detection, where a trained operator confirms what tripped the alert before anyone is dispatched. Verification is the difference between responding to a raccoon and responding to a crew with bolt cutters, and it means people, yours or your security partner's, handle verified incidents instead of chasing false alarms.
  • Vehicle intelligence at access points. License plate recognition on approach roads documents the vehicles casing or servicing a site, which matters because metal theft crews tend to revisit and to work multiple sites in a region.
  • A documented escalation path. Decide in advance who gets called for a verified intrusion at 2 a.m., what law enforcement needs, and how footage is preserved for prosecution.

Procurement teams at utilities and co-ops should also note hardware sourcing rules. Many utilities, especially those touching federal funding or critical infrastructure programs, require NDAA-compliant equipment and exclude cameras from FCC Covered List manufacturers such as Hikvision and Dahua. Our NDAA compliance overview explains what to check before standardizing on a platform.

The same playbook transfers across unstaffed infrastructure generally. The considerations mirror what we have written about water treatment facility security and cell tower copper theft: remote sites, no staff, valuable metal, and response times measured in tens of minutes unless detection is instant and verified.

Where rapid-deploy monitored surveillance fits

For non-CIP substations, rapid-deploy monitored surveillance has become the proportionate middle ground between a padlock and a permanent security build-out. Solar-powered mobile surveillance units need no trenching, no grid connection, and no construction permits in most jurisdictions, so a utility can put verified live detection on a vulnerable site in days and relocate units as the threat picture shifts across the fleet. Vision Detection Systems deploys these units for utility customers with 24/7 monitoring behind them, so an alert at an unstaffed substation becomes a verified incident report and a dispatch call rather than a discovery on the next maintenance visit.

The second use case is inside the CIP-014 program itself. Security plans at critical stations routinely trigger construction: perimeter walls, ballistic screening, hardened control houses, upgraded gates. That work takes months, and a substation mid-remediation is arguably at its most exposed, with breached perimeters, contractor laydown areas full of copper and equipment, and unfamiliar traffic normalizing on-site activity. Temporary monitored surveillance covers that window, protecting both the station and the contractor's materials until permanent systems are commissioned and the units move to the next site.

The bottom line for utility security teams

CIP-014 tells you what must be done at a small set of critical transmission substations. It says nothing about the rest of your fleet, and NERC's 2023 evaluation confirmed that will not change soon. With grid attacks at record levels and metal theft economics pulling crews toward unattended sites, the discretionary tier deserves a deliberate answer: layered, proportionate, verified detection, deployed where the risk is, movable when it shifts. Ask your NERC compliance team where the regulatory line sits in your territory, then decide, on the evidence, what the sites below that line are worth.

Frequently asked questions

What is NERC CIP-014 in plain language?

CIP-014 is NERC's physical security standard for the most critical transmission substations. It requires transmission owners to identify stations whose loss could cause widespread instability or cascading outages, evaluate threats at those sites, and implement a third-party-reviewed physical security plan.

Does NERC CIP-014 apply to distribution substations?

No. CIP-014 applies only to transmission substations identified as critical through the standard's risk assessment process. Distribution substations fall outside its scope, so their physical security is a utility business decision rather than a compliance requirement.

What happened in the Moore County substation attack?

In December 2022, gunfire damaged two Duke Energy substations in Moore County, North Carolina, cutting power to tens of thousands of customers. The attack pushed regulators to re-examine substation physical security nationwide.

How can utilities protect substations that fall outside CIP-014?

Layered, proportionate controls work best, such as intact perimeter fencing, lighting and signage, monitored camera systems with human verification, license plate recognition at access points, and a documented escalation path so verified incidents reach responders quickly.

Can mobile surveillance units be used during CIP-014 security upgrades?

Yes. Rapid-deploy monitored surveillance is commonly used as a stopgap while permanent measures like walls and barriers are under construction, covering both the substation and contractor equipment during the remediation period.

Cover the Substations Regulation Never Reaches

Solar-powered mobile surveillance units deploy in days without trenching or grid power, and 24/7 monitoring verifies intrusions so responders are dispatched to real events. Tell us about your substation fleet.