Who this is for: Utility NERC compliance officers, ISO/RTO operations engineers, demand response aggregators, DER operators, energy sector CISOs, NERC auditors, and anyone deploying AI systems that interact with bulk electric system (BES) operations.

Why this matters now. AI is increasingly embedded in grid operations: load forecasting, autonomous voltage regulation, demand response optimization, and frequency response. NERC CIP standards were written before AI entered the control room. This crosswalk maps existing CIP requirements to SWT3 procedures that produce cryptographic evidence an auditor can verify, closing the gap between traditional CIP compliance and AI governance.

PENALTY CONTEXT: NERC CIP violations carry penalties up to $1,000,000 per violation per day (Section 215(e) of the Federal Power Act). FERC has assessed penalties exceeding $10M in single enforcement actions. AI systems that make autonomous grid decisions without auditable evidence represent a material compliance risk.

Contents

1. Overview 2. The AI-in-Grid Landscape 3. CIP-to-Procedure Matrix 4. CIP-002: BES Cyber System Categorization 5. CIP-003: Security Management Controls 6. CIP-004: Personnel and Training 7. CIP-005: Electronic Security Perimeter 8. CIP-007: System Security Management 9. CIP-008: Incident Reporting and Response 10. CIP-009: Recovery Plans 11. CIP-010: Configuration Change Management 12. CIP-011: Information Protection 13. CIP-012: Control Center Communications 14. CIP-013: Supply Chain Risk Management 15. Reliability Standards (BAL, TOP, MOD, FAC) 16. Demand Response Procedures (ADR Namespace) 17. Energy Grid Profile 18. Quick Start 19. References

1. Overview

This crosswalk maps 13 NERC CIP standards (CIP-002 through CIP-014) plus 4 reliability standards (BAL-001, BAL-005, TOP-001, MOD-031, FAC-001) to existing SWT3 witness procedures. The mapping covers 45 procedure-to-requirement relationships across two categories:

SWT3 does not replace NERC CIP compliance programs. It adds a cryptographic evidence layer that proves AI systems operating within BES environments are governed, monitored, and auditable. Every witness anchor is independently verifiable and survives the full NERC audit retention period.

2. The AI-in-Grid Landscape

AI systems are entering grid operations across multiple domains:

Load Forecasting and Demand Response

Machine learning models predict electricity demand 1-72 hours ahead, enabling utilities and ISOs to optimize generation dispatch and activate demand response resources. FERC Order 2222 (effective 2023) opened wholesale markets to distributed energy resource aggregations, accelerating AI adoption for DER coordination.

Autonomous Voltage Regulation

Smart inverters and AI-controlled tap changers make sub-second voltage regulation decisions. IEEE 1547-2018 governs DER interconnection, but NERC has no specific AI provisions. The new ADR-VOLT.1 procedure witnesses autonomous voltage regulation actions with factor-level detail: deviation percentage, response type (tap change, capacitor bank, STATCOM, inverter droop), and response latency.

Frequency Response

Battery storage and fast-responding DERs increasingly provide primary frequency response under NERC BAL-001. AI systems decide when and how much to inject or absorb. ADR-GRID.1 witnesses grid signal correlation with signal type, response latency, and compliance ratio.

Cybersecurity Monitoring

AI-based intrusion detection and anomaly detection are deployed inside Electronic Security Perimeters (ESPs). CIP-005 and CIP-007 require logging and monitoring, but say nothing about the AI models making detection decisions. SWT3 witnesses these AI systems through AI-SEC.1, AI-LOG.1, and AI-DRIFT.1.

THE GAP: NERC CIP standards govern the infrastructure AI runs on. SWT3 witnesses the AI itself. Together they close the accountability loop: CIP proves the perimeter is secure, SWT3 proves the AI inside that perimeter is governed.

3. CIP-to-Procedure Matrix

Complete mapping of all 45 crosswalk relationships. CIP standards with multiple requirements map to multiple procedures.

CIP StandardRequirementSWT3 ProcedureCategoryCritical
CIP-002-7R1 - BES Cyber System categorizationAI-SAFE.1CATEGORIZATIONYes
CIP-002-7R1.3 - AI impact assessmentAI-DPIA.1IMPACTNo
CIP-002-7R2 - Categorization reviewAI-SAFE.2CATEGORIZATIONNo
CIP-003-9R1 - Cyber security policiesAI-GOV.1MANAGEMENTYes
CIP-003-9R1.2 - AI transparencyAI-TRANS.1AI_TRANSPARENCYNo
CIP-003-9R1.3 - AI explainabilityAI-EXPL.1AI_TRANSPARENCYNo
CIP-003-9R1.4 - AI fairnessAI-FAIR.1AI_FAIRNESSNo
CIP-003-9R2 - Senior manager authorityAI-GOV.2MANAGEMENTYes
CIP-003-9R3 - Delegate authorityAI-GOV.3MANAGEMENTNo
CIP-003-9R4 - Change controlAI-AUDIT.1MANAGEMENTNo
CIP-004-7R1 - Security awareness trainingAI-HITL.1PERSONNELYes
CIP-004-7R2 - Personnel risk assessmentAI-HITL.3PERSONNELYes
CIP-004-7R3 - Access authorizationAI-ACC.1PERSONNELYes
CIP-004-7R4 - Access revocationAI-REV.1PERSONNELYes
CIP-005-7R1 - Electronic Security PerimeterAI-SEC.1PERIMETERYes
CIP-005-7R2 - Remote access managementAI-SEC.2PERIMETERYes
CIP-005-7R3 - Vendor remote accessAI-ENV.1PERIMETERNo
CIP-007-6R1 - Logical portsAI-CYBER.1SYSTEM_SECURITYYes
CIP-007-6R2 - Patch managementAI-SUPPLY.1SYSTEM_SECURITYYes
CIP-007-6R3 - Malicious code preventionAI-SEC.3SYSTEM_SECURITYNo
CIP-007-6R4 - Security event monitoringAI-LOG.1SYSTEM_SECURITYYes
CIP-007-6R5 - System access controlAI-ID.1SYSTEM_SECURITYYes
CIP-008-6R1 - Incident response planAI-INCIDENT.1INCIDENT_RESPONSEYes
CIP-008-6R2 - Test response planAI-INCIDENT.2INCIDENT_RESPONSENo
CIP-008-6R3 - Retain incident recordsAI-AUDIT.1INCIDENT_RESPONSENo
CIP-009-6R1 - Recovery planAI-EMRG.1RECOVERYYes
CIP-009-6R2 - Test recovery planAI-ROBUST.1RECOVERYNo
CIP-009-6R3 - Maintain recovery planAI-RECOMM.1RECOVERYNo
CIP-010-4R1 - Baseline configurationAI-DRIFT.1CONFIGURATIONYes
CIP-010-4R1.6 - AI model lifecycleAI-LCM.1LIFECYCLENo
CIP-010-4R2 - Configuration monitoringAI-DRIFT.2CONFIGURATIONYes
CIP-010-4R3 - Vulnerability assessmentAI-PERF.1CONFIGURATIONYes
CIP-010-4R4 - Transient Cyber AssetsAI-MDL.1CONFIGURATIONNo
CIP-011-3R1 - Information protectionAI-DATA.1INFORMATIONYes
CIP-011-3R2 - Media sanitizationAI-DECOM.1INFORMATIONNo
CIP-012-1R1 - Control center commsAI-CHAIN.1COMMUNICATIONSYes
CIP-012-1R1.2 - Communication linksAI-TRUST.1COMMUNICATIONSNo
CIP-013-2R1 - Supply chain planAI-SUPPLY.1SUPPLY_CHAINYes
CIP-013-2R2 - Software integrityHBOM-SBOM.1SUPPLY_CHAINYes
CIP-013-2R3 - Software BOMAI-SBOM.1SUPPLY_CHAINNo
CIP-014-3R1 - Risk assessmentAI-HW.1PHYSICALYes
CIP-014-3R5 - Physical security planAI-SAFE.1PHYSICALYes
BAL-001-2Frequency responseADR-GRID.1RELIABILITYYes
BAL-005-1AGC and meteringADR-SETTLE.1RELIABILITYNo
TOP-001-5R1 - Operational dataADR-EVENT.1RELIABILITYYes
TOP-001-5R3 - Load sheddingADR-CURT.1RELIABILITYYes
MOD-031-3R1 - Demand data reportingADR-BASE.1RELIABILITYNo
FAC-001-3R1 - Facility connectionADR-CARBON.1RELIABILITYNo

4. CIP-002: BES Cyber System Categorization

CIP-002 requires entities to identify and categorize their BES Cyber Systems as high, medium, or low impact based on potential reliability impact. When AI systems participate in BES operations, they become part of the Cyber System categorization scope.

AI-SAFE.1 -- Safety Classification

Maps to CIP-002-7 R1

factor_a = safety_level (1-5 classification scale), factor_b = validation_method (1=automated, 2=human, 3=dual), factor_c = constraint_count. Each witness anchor records the safety classification of an AI system affecting BES reliability, producing evidence that the system has been categorized per CIP-002.

Assessor note: Query the SWT3 ledger for all AI-SAFE.1 anchors. Each represents a classification decision. Verify that every AI system in the BES Cyber System inventory has a corresponding anchor. Cross-reference factor_a values against the entity's impact categorization criteria.
AI-DPIA.1 -- Impact Assessment

Maps to CIP-002-7 R1.3

Data protection and reliability impact assessments for AI systems affecting BES operations. The anchor captures the scope of AI influence on grid reliability.

Assessor note: DPIA anchors demonstrate that the entity evaluated AI impact on BES reliability before deployment, addressing the "categorization" requirement from an AI-specific angle.

5. CIP-003: Security Management Controls

CIP-003 requires documented cyber security policies and a designated senior manager. For AI systems, this extends to governance policies covering model deployment, transparency, and fairness in grid decisions.

AI-GOV.1 -- Governance Policy

Maps to CIP-003-9 R1

Witnesses the existence and enforcement of AI governance policies within the CIP program. factor_a = policy_version, factor_b = enforcement_level. Every AI system operating in BES scope should have a governance anchor proving it operates under a documented policy.

AI-TRANS.1, AI-EXPL.1, AI-FAIR.1

Maps to CIP-003-9 R1.2/R1.3/R1.4

Three complementary procedures that extend CIP-003 into AI-specific governance: transparency (is the AI's role disclosed?), explainability (can its decisions be understood?), and fairness (are grid dispatch decisions non-discriminatory across service territories?).

Assessor note: FERC has increasing interest in algorithmic fairness in wholesale market participation. AI-FAIR.1 anchors for dispatch and curtailment AI provide evidence of non-discriminatory operation.

6. CIP-004: Personnel and Training

CIP-004 governs personnel risk assessment, training, and access management. For AI systems, this includes oversight of who trains, deploys, and monitors AI models with BES access.

AI-HITL.1 / AI-HITL.3 / AI-ACC.1 / AI-REV.1

Maps to CIP-004-7 R1 through R4

Four procedures covering the personnel lifecycle: AI-HITL.1 witnesses human oversight of AI decisions (R1 training), AI-HITL.3 captures reviewer identity per decision (R2 risk assessment), AI-ACC.1 witnesses access control events (R3 authorization), and AI-REV.1 records access revocation (R4 termination). Together they produce a complete chain of personnel-to-AI accountability.

Assessor note: CIP-004-7 R4 requires access revocation within 24 hours. AI-REV.1 anchors include timestamps. Query for any revocation gap exceeding 24h as a potential violation.

7. CIP-005: Electronic Security Perimeter

CIP-005 defines the electronic boundary around BES Cyber Systems. AI systems operating inside or across ESPs must be monitored at boundary crossings.

AI-SEC.1 / AI-SEC.2 / AI-ENV.1

Maps to CIP-005-7 R1 through R3

AI-SEC.1 witnesses adversarial threat detection at ESP boundaries. AI-SEC.2 witnesses input validation for remote AI access. AI-ENV.1 attests the runtime environment, proving AI model execution stays within the defined ESP.

8. CIP-007: System Security Management

CIP-007 covers ports, patching, malware prevention, monitoring, and access control. Five requirements map to five SWT3 procedures.

AI-CYBER.1 / AI-SUPPLY.1 / AI-SEC.3 / AI-LOG.1 / AI-ID.1

Maps to CIP-007-6 R1 through R5

Each CIP-007 requirement has a direct procedure mapping: port control (AI-CYBER.1), patch management (AI-SUPPLY.1), malicious code prevention (AI-SEC.3), security event monitoring (AI-LOG.1), and system access control with unique identifiers (AI-ID.1). The AI-LOG.1 procedure is particularly important: it witnesses the AI system that monitors security events, creating an evidence chain for the monitor itself.

Assessor note: CIP-007-6 R2 requires patch evaluation within 35 days. AI-SUPPLY.1 anchors with timestamps provide evidence of patch assessment timing. Cross-reference against vulnerability scan dates.

9. CIP-008: Incident Reporting and Response

AI-INCIDENT.1 / AI-INCIDENT.2 / AI-AUDIT.1

Maps to CIP-008-6 R1 through R3

AI-INCIDENT.1 witnesses the incident response lifecycle (R1 plan execution), AI-INCIDENT.2 records response plan testing (R2, at least every 15 months), and AI-AUDIT.1 provides the audit trail for incident records (R3, 3-year retention). SWT3 anchors are immutable and timestamped, satisfying the evidence integrity requirement.

10. CIP-009: Recovery Plans

AI-EMRG.1 / AI-ROBUST.1 / AI-RECOMM.1

Maps to CIP-009-6 R1 through R3

AI-EMRG.1 witnesses emergency override lifecycle events (R1 recovery plan), AI-ROBUST.1 witnesses robustness and recovery testing (R2), and AI-RECOMM.1 witnesses re-commissioning after recovery (R3 plan maintenance). The lifecycle chain capability links these anchors into a complete recovery narrative.

11. CIP-010: Configuration Change Management

CIP-010 is where AI governance meets CIP most directly. AI model updates are configuration changes. Drift detection is configuration monitoring. Vulnerability assessments apply to AI models.

AI-DRIFT.1 / AI-DRIFT.2

Maps to CIP-010-4 R1 and R2

AI-DRIFT.1 establishes and monitors the AI model baseline configuration (R1). AI-DRIFT.2 detects consequence-mapped drift with threshold responses (R2, monitoring at least every 35 days). Every model weight change, hyperparameter update, or retraining event produces an anchor that proves the change was detected and recorded.

Assessor note: This is the strongest CIP-to-SWT3 mapping. CIP-010 R1 requires baseline configurations. AI-DRIFT.1 produces cryptographic baselines for AI models. Ask for the DRIFT.1 anchor history and verify it covers all AI systems in the BES Cyber System inventory.
AI-LCM.1

Maps to CIP-010-4 R1.6

AI model lifecycle management within the CIP configuration change process. Every model promotion, rollback, or retirement is witnessed as a configuration change.

12. CIP-011: Information Protection

AI-DATA.1 / AI-DECOM.1

Maps to CIP-011-3 R1 and R2

AI-DATA.1 witnesses data governance for AI training data that includes BES Cyber System Information (BCSI). AI-DECOM.1 witnesses AI system decommissioning and model artifact disposal, mapping to CIP-011's media sanitization requirement.

13. CIP-012: Control Center Communications

AI-CHAIN.1 / AI-TRUST.1

Maps to CIP-012-1 R1

AI-CHAIN.1 witnesses the multi-agent audit trail when AI systems communicate between control centers. AI-TRUST.1 verifies trust between communicating AI systems. CIP-012 requires protection of real-time assessment and monitoring data; SWT3 proves the AI systems handling that data are governed.

14. CIP-013: Supply Chain Risk Management

AI-SUPPLY.1 / HBOM-SBOM.1 / AI-SBOM.1

Maps to CIP-013-2 R1 through R3

Three procedures covering the AI supply chain: AI-SUPPLY.1 witnesses supply chain risk assessment (R1 plan), HBOM-SBOM.1 verifies software integrity from vendors (R2 verification), and AI-SBOM.1 records the software bill of materials for AI components (R3). Together they address both the NERC CIP supply chain requirements and the EO 14028 SBOM mandate.

Assessor note: CIP-013 is the newest CIP standard and the most relevant to AI supply chain risks. Ask for HBOM-SBOM.1 anchors covering AI model dependencies (PyTorch, TensorFlow, ONNX runtimes) and cross-reference with vulnerability scan results.

15. Reliability Standards (BAL, TOP, MOD, FAC)

Beyond the CIP cyber security standards, NERC reliability standards govern the physics of the grid. AI systems participating in frequency response, load management, and settlement need witness evidence too.

StandardRequirementProcedureWhat It Witnesses
BAL-001-2Frequency responseADR-GRID.1Grid signal type, response latency, compliance ratio
BAL-005-1AGC and meteringADR-SETTLE.1Energy settled (kWh), price (USD/MWh), event count
TOP-001-5 R1Operational data exchangeADR-EVENT.1Event phase, committed curtailment (kW)
TOP-001-5 R3Load sheddingADR-CURT.1Actual vs committed reduction, compliance ratio
MOD-031-3 R1Demand data reportingADR-BASE.1Baseline consumption (kW), method, confidence
FAC-001-3 R1Facility connectionADR-CARBON.1Credit type (REC, offset, EAC), quantity (MWh)

16. Demand Response Procedures (ADR Namespace)

The ADR namespace contains 7 procedures purpose-built for energy sector witnessing. Each produces a SWT3 anchor with factor-level detail matching the physical quantities grid operators measure.

ADR-VOLT.1 -- Autonomous Voltage Regulation Witnessing

New in v0.7.4

Witnesses AI-driven voltage regulation actions. factor_a = voltage deviation from nominal (x100, e.g., 250 = 2.50%), factor_b = response action (1=tap change, 2=capacitor bank, 3=STATCOM, 4=inverter droop, 5=load transfer), factor_c = response time in milliseconds. Maps to IEEE 1547-2018 Sec. 6, NERC FAC-001-3 R4, and EU SOGL Art. 18.

Assessor note: This is the only procedure in any compliance framework that witnesses autonomous voltage regulation decisions at the factor level. Query for factor_c values exceeding IEEE 1547 response time limits as potential compliance issues.
ADR-GRID.1 -- Grid Signal Correlation

Frequency Response Evidence

Witnesses the correlation between grid operator signals and AI-driven responses. factor_a = signal type (1=emergency, 2=economic, 3=capacity, 4=frequency regulation, 5=voltage support), factor_b = response latency (ms). NERC BAL-001 requires frequency response; this procedure proves the AI responded correctly.

ADR-CURT.1 -- Curtailment Verification

Load Reduction Evidence

Witnesses actual vs committed load reduction during demand response events. factor_a = actual reduction (kW), factor_b = committed reduction (kW), factor_c = compliance ratio (x1000, must exceed 950 for PASS). This is settlement-grade evidence.

17. Energy Grid Profile

SWT3 ships with a pre-built energy-grid profile that bundles all 7 ADR procedures plus 10 NERC CIP-mapped AI procedures into a single configuration.

$ swt3 init --profile energy-grid

# Or with full expansion:
$ swt3 init --profile energy-grid --expand

The profile sets clearing level 2 (Sensitive), requires agent identity and signing, and configures 30-minute trust mesh freshness windows aligned with grid operational cycles. It includes:

18. Quick Start

Python

from swt3_ai import Witness

witness = Witness(
    agent_id="grid-optimizer-v2",
    signing_key="your-signing-key",
    clearing_level=2  # Sensitive (grid reliability data)
)

# Wrap your AI client
client = witness.wrap(openai_client)

# Witness a voltage regulation decision
witness.record_raw("ADR-VOLT.1",
    factor_a=250,   # 2.50% deviation
    factor_b=1,     # Tap change
    factor_c=150    # 150ms response
)

# Witness a demand response event
witness.record_raw("ADR-EVENT.1",
    factor_a=2,     # Curtailment start
    factor_b=5000   # 5000 kW committed
)

# Flush to clearing house
witness.flush()

TypeScript

import { Witness } from '@tenova/swt3-ai';

const witness = new Witness({
  agentId: 'grid-optimizer-v2',
  signingKey: process.env.SWT3_SIGNING_KEY,
  clearingLevel: 2
});

// Witness voltage regulation
witness.recordRaw('ADR-VOLT.1', {
  factorA: 250,   // 2.50% deviation
  factorB: 1,     // Tap change
  factorC: 150    // 150ms response
});

await witness.flush();

19. References