Who this is for: Utility NERC compliance officers, ISO/RTO operations engineers, demand response aggregators, DER operators, energy sector CISOs, NERC auditors, and anyone deploying AI systems that interact with bulk electric system (BES) operations.
Why this matters now. AI is increasingly embedded in grid operations: load forecasting, autonomous voltage regulation, demand response optimization, and frequency response. NERC CIP standards were written before AI entered the control room. This crosswalk maps existing CIP requirements to SWT3 procedures that produce cryptographic evidence an auditor can verify, closing the gap between traditional CIP compliance and AI governance.
PENALTY CONTEXT: NERC CIP violations carry penalties up to $1,000,000 per violation per day (Section 215(e) of the Federal Power Act). FERC has assessed penalties exceeding $10M in single enforcement actions. AI systems that make autonomous grid decisions without auditable evidence represent a material compliance risk.
Contents
1. Overview 2. The AI-in-Grid Landscape 3. CIP-to-Procedure Matrix 4. CIP-002: BES Cyber System Categorization 5. CIP-003: Security Management Controls 6. CIP-004: Personnel and Training 7. CIP-005: Electronic Security Perimeter 8. CIP-007: System Security Management 9. CIP-008: Incident Reporting and Response 10. CIP-009: Recovery Plans 11. CIP-010: Configuration Change Management 12. CIP-011: Information Protection 13. CIP-012: Control Center Communications 14. CIP-013: Supply Chain Risk Management 15. Reliability Standards (BAL, TOP, MOD, FAC) 16. Demand Response Procedures (ADR Namespace) 17. Energy Grid Profile 18. Quick Start 19. References1. Overview
This crosswalk maps 13 NERC CIP standards (CIP-002 through CIP-014) plus 4 reliability standards (BAL-001, BAL-005, TOP-001, MOD-031, FAC-001) to existing SWT3 witness procedures. The mapping covers 45 procedure-to-requirement relationships across two categories:
- Cyber security controls (CIP-002 through CIP-014): Mapped to AI governance procedures (AI-SAFE, AI-GOV, AI-DRIFT, AI-INCIDENT, AI-SUPPLY, etc.) that produce witness anchors for AI system behavior in BES environments.
- Reliability standards (BAL, TOP, MOD, FAC): Mapped to demand response procedures (ADR namespace) that witness grid signal correlation, curtailment verification, settlement accuracy, and voltage regulation.
SWT3 does not replace NERC CIP compliance programs. It adds a cryptographic evidence layer that proves AI systems operating within BES environments are governed, monitored, and auditable. Every witness anchor is independently verifiable and survives the full NERC audit retention period.
2. The AI-in-Grid Landscape
AI systems are entering grid operations across multiple domains:
Load Forecasting and Demand Response
Machine learning models predict electricity demand 1-72 hours ahead, enabling utilities and ISOs to optimize generation dispatch and activate demand response resources. FERC Order 2222 (effective 2023) opened wholesale markets to distributed energy resource aggregations, accelerating AI adoption for DER coordination.
Autonomous Voltage Regulation
Smart inverters and AI-controlled tap changers make sub-second voltage regulation decisions. IEEE 1547-2018 governs DER interconnection, but NERC has no specific AI provisions. The new ADR-VOLT.1 procedure witnesses autonomous voltage regulation actions with factor-level detail: deviation percentage, response type (tap change, capacitor bank, STATCOM, inverter droop), and response latency.
Frequency Response
Battery storage and fast-responding DERs increasingly provide primary frequency response under NERC BAL-001. AI systems decide when and how much to inject or absorb. ADR-GRID.1 witnesses grid signal correlation with signal type, response latency, and compliance ratio.
Cybersecurity Monitoring
AI-based intrusion detection and anomaly detection are deployed inside Electronic Security Perimeters (ESPs). CIP-005 and CIP-007 require logging and monitoring, but say nothing about the AI models making detection decisions. SWT3 witnesses these AI systems through AI-SEC.1, AI-LOG.1, and AI-DRIFT.1.
THE GAP: NERC CIP standards govern the infrastructure AI runs on. SWT3 witnesses the AI itself. Together they close the accountability loop: CIP proves the perimeter is secure, SWT3 proves the AI inside that perimeter is governed.
3. CIP-to-Procedure Matrix
Complete mapping of all 45 crosswalk relationships. CIP standards with multiple requirements map to multiple procedures.
| CIP Standard | Requirement | SWT3 Procedure | Category | Critical |
|---|---|---|---|---|
| CIP-002-7 | R1 - BES Cyber System categorization | AI-SAFE.1 | CATEGORIZATION | Yes |
| CIP-002-7 | R1.3 - AI impact assessment | AI-DPIA.1 | IMPACT | No |
| CIP-002-7 | R2 - Categorization review | AI-SAFE.2 | CATEGORIZATION | No |
| CIP-003-9 | R1 - Cyber security policies | AI-GOV.1 | MANAGEMENT | Yes |
| CIP-003-9 | R1.2 - AI transparency | AI-TRANS.1 | AI_TRANSPARENCY | No |
| CIP-003-9 | R1.3 - AI explainability | AI-EXPL.1 | AI_TRANSPARENCY | No |
| CIP-003-9 | R1.4 - AI fairness | AI-FAIR.1 | AI_FAIRNESS | No |
| CIP-003-9 | R2 - Senior manager authority | AI-GOV.2 | MANAGEMENT | Yes |
| CIP-003-9 | R3 - Delegate authority | AI-GOV.3 | MANAGEMENT | No |
| CIP-003-9 | R4 - Change control | AI-AUDIT.1 | MANAGEMENT | No |
| CIP-004-7 | R1 - Security awareness training | AI-HITL.1 | PERSONNEL | Yes |
| CIP-004-7 | R2 - Personnel risk assessment | AI-HITL.3 | PERSONNEL | Yes |
| CIP-004-7 | R3 - Access authorization | AI-ACC.1 | PERSONNEL | Yes |
| CIP-004-7 | R4 - Access revocation | AI-REV.1 | PERSONNEL | Yes |
| CIP-005-7 | R1 - Electronic Security Perimeter | AI-SEC.1 | PERIMETER | Yes |
| CIP-005-7 | R2 - Remote access management | AI-SEC.2 | PERIMETER | Yes |
| CIP-005-7 | R3 - Vendor remote access | AI-ENV.1 | PERIMETER | No |
| CIP-007-6 | R1 - Logical ports | AI-CYBER.1 | SYSTEM_SECURITY | Yes |
| CIP-007-6 | R2 - Patch management | AI-SUPPLY.1 | SYSTEM_SECURITY | Yes |
| CIP-007-6 | R3 - Malicious code prevention | AI-SEC.3 | SYSTEM_SECURITY | No |
| CIP-007-6 | R4 - Security event monitoring | AI-LOG.1 | SYSTEM_SECURITY | Yes |
| CIP-007-6 | R5 - System access control | AI-ID.1 | SYSTEM_SECURITY | Yes |
| CIP-008-6 | R1 - Incident response plan | AI-INCIDENT.1 | INCIDENT_RESPONSE | Yes |
| CIP-008-6 | R2 - Test response plan | AI-INCIDENT.2 | INCIDENT_RESPONSE | No |
| CIP-008-6 | R3 - Retain incident records | AI-AUDIT.1 | INCIDENT_RESPONSE | No |
| CIP-009-6 | R1 - Recovery plan | AI-EMRG.1 | RECOVERY | Yes |
| CIP-009-6 | R2 - Test recovery plan | AI-ROBUST.1 | RECOVERY | No |
| CIP-009-6 | R3 - Maintain recovery plan | AI-RECOMM.1 | RECOVERY | No |
| CIP-010-4 | R1 - Baseline configuration | AI-DRIFT.1 | CONFIGURATION | Yes |
| CIP-010-4 | R1.6 - AI model lifecycle | AI-LCM.1 | LIFECYCLE | No |
| CIP-010-4 | R2 - Configuration monitoring | AI-DRIFT.2 | CONFIGURATION | Yes |
| CIP-010-4 | R3 - Vulnerability assessment | AI-PERF.1 | CONFIGURATION | Yes |
| CIP-010-4 | R4 - Transient Cyber Assets | AI-MDL.1 | CONFIGURATION | No |
| CIP-011-3 | R1 - Information protection | AI-DATA.1 | INFORMATION | Yes |
| CIP-011-3 | R2 - Media sanitization | AI-DECOM.1 | INFORMATION | No |
| CIP-012-1 | R1 - Control center comms | AI-CHAIN.1 | COMMUNICATIONS | Yes |
| CIP-012-1 | R1.2 - Communication links | AI-TRUST.1 | COMMUNICATIONS | No |
| CIP-013-2 | R1 - Supply chain plan | AI-SUPPLY.1 | SUPPLY_CHAIN | Yes |
| CIP-013-2 | R2 - Software integrity | HBOM-SBOM.1 | SUPPLY_CHAIN | Yes |
| CIP-013-2 | R3 - Software BOM | AI-SBOM.1 | SUPPLY_CHAIN | No |
| CIP-014-3 | R1 - Risk assessment | AI-HW.1 | PHYSICAL | Yes |
| CIP-014-3 | R5 - Physical security plan | AI-SAFE.1 | PHYSICAL | Yes |
| BAL-001-2 | Frequency response | ADR-GRID.1 | RELIABILITY | Yes |
| BAL-005-1 | AGC and metering | ADR-SETTLE.1 | RELIABILITY | No |
| TOP-001-5 | R1 - Operational data | ADR-EVENT.1 | RELIABILITY | Yes |
| TOP-001-5 | R3 - Load shedding | ADR-CURT.1 | RELIABILITY | Yes |
| MOD-031-3 | R1 - Demand data reporting | ADR-BASE.1 | RELIABILITY | No |
| FAC-001-3 | R1 - Facility connection | ADR-CARBON.1 | RELIABILITY | No |
4. CIP-002: BES Cyber System Categorization
CIP-002 requires entities to identify and categorize their BES Cyber Systems as high, medium, or low impact based on potential reliability impact. When AI systems participate in BES operations, they become part of the Cyber System categorization scope.
Maps to CIP-002-7 R1
factor_a = safety_level (1-5 classification scale), factor_b = validation_method (1=automated, 2=human, 3=dual), factor_c = constraint_count. Each witness anchor records the safety classification of an AI system affecting BES reliability, producing evidence that the system has been categorized per CIP-002.
Maps to CIP-002-7 R1.3
Data protection and reliability impact assessments for AI systems affecting BES operations. The anchor captures the scope of AI influence on grid reliability.
5. CIP-003: Security Management Controls
CIP-003 requires documented cyber security policies and a designated senior manager. For AI systems, this extends to governance policies covering model deployment, transparency, and fairness in grid decisions.
Maps to CIP-003-9 R1
Witnesses the existence and enforcement of AI governance policies within the CIP program. factor_a = policy_version, factor_b = enforcement_level. Every AI system operating in BES scope should have a governance anchor proving it operates under a documented policy.
Maps to CIP-003-9 R1.2/R1.3/R1.4
Three complementary procedures that extend CIP-003 into AI-specific governance: transparency (is the AI's role disclosed?), explainability (can its decisions be understood?), and fairness (are grid dispatch decisions non-discriminatory across service territories?).
6. CIP-004: Personnel and Training
CIP-004 governs personnel risk assessment, training, and access management. For AI systems, this includes oversight of who trains, deploys, and monitors AI models with BES access.
Maps to CIP-004-7 R1 through R4
Four procedures covering the personnel lifecycle: AI-HITL.1 witnesses human oversight of AI decisions (R1 training), AI-HITL.3 captures reviewer identity per decision (R2 risk assessment), AI-ACC.1 witnesses access control events (R3 authorization), and AI-REV.1 records access revocation (R4 termination). Together they produce a complete chain of personnel-to-AI accountability.
7. CIP-005: Electronic Security Perimeter
CIP-005 defines the electronic boundary around BES Cyber Systems. AI systems operating inside or across ESPs must be monitored at boundary crossings.
Maps to CIP-005-7 R1 through R3
AI-SEC.1 witnesses adversarial threat detection at ESP boundaries. AI-SEC.2 witnesses input validation for remote AI access. AI-ENV.1 attests the runtime environment, proving AI model execution stays within the defined ESP.
8. CIP-007: System Security Management
CIP-007 covers ports, patching, malware prevention, monitoring, and access control. Five requirements map to five SWT3 procedures.
Maps to CIP-007-6 R1 through R5
Each CIP-007 requirement has a direct procedure mapping: port control (AI-CYBER.1), patch management (AI-SUPPLY.1), malicious code prevention (AI-SEC.3), security event monitoring (AI-LOG.1), and system access control with unique identifiers (AI-ID.1). The AI-LOG.1 procedure is particularly important: it witnesses the AI system that monitors security events, creating an evidence chain for the monitor itself.
9. CIP-008: Incident Reporting and Response
Maps to CIP-008-6 R1 through R3
AI-INCIDENT.1 witnesses the incident response lifecycle (R1 plan execution), AI-INCIDENT.2 records response plan testing (R2, at least every 15 months), and AI-AUDIT.1 provides the audit trail for incident records (R3, 3-year retention). SWT3 anchors are immutable and timestamped, satisfying the evidence integrity requirement.
10. CIP-009: Recovery Plans
Maps to CIP-009-6 R1 through R3
AI-EMRG.1 witnesses emergency override lifecycle events (R1 recovery plan), AI-ROBUST.1 witnesses robustness and recovery testing (R2), and AI-RECOMM.1 witnesses re-commissioning after recovery (R3 plan maintenance). The lifecycle chain capability links these anchors into a complete recovery narrative.
11. CIP-010: Configuration Change Management
CIP-010 is where AI governance meets CIP most directly. AI model updates are configuration changes. Drift detection is configuration monitoring. Vulnerability assessments apply to AI models.
Maps to CIP-010-4 R1 and R2
AI-DRIFT.1 establishes and monitors the AI model baseline configuration (R1). AI-DRIFT.2 detects consequence-mapped drift with threshold responses (R2, monitoring at least every 35 days). Every model weight change, hyperparameter update, or retraining event produces an anchor that proves the change was detected and recorded.
Maps to CIP-010-4 R1.6
AI model lifecycle management within the CIP configuration change process. Every model promotion, rollback, or retirement is witnessed as a configuration change.
12. CIP-011: Information Protection
Maps to CIP-011-3 R1 and R2
AI-DATA.1 witnesses data governance for AI training data that includes BES Cyber System Information (BCSI). AI-DECOM.1 witnesses AI system decommissioning and model artifact disposal, mapping to CIP-011's media sanitization requirement.
13. CIP-012: Control Center Communications
Maps to CIP-012-1 R1
AI-CHAIN.1 witnesses the multi-agent audit trail when AI systems communicate between control centers. AI-TRUST.1 verifies trust between communicating AI systems. CIP-012 requires protection of real-time assessment and monitoring data; SWT3 proves the AI systems handling that data are governed.
14. CIP-013: Supply Chain Risk Management
Maps to CIP-013-2 R1 through R3
Three procedures covering the AI supply chain: AI-SUPPLY.1 witnesses supply chain risk assessment (R1 plan), HBOM-SBOM.1 verifies software integrity from vendors (R2 verification), and AI-SBOM.1 records the software bill of materials for AI components (R3). Together they address both the NERC CIP supply chain requirements and the EO 14028 SBOM mandate.
15. Reliability Standards (BAL, TOP, MOD, FAC)
Beyond the CIP cyber security standards, NERC reliability standards govern the physics of the grid. AI systems participating in frequency response, load management, and settlement need witness evidence too.
| Standard | Requirement | Procedure | What It Witnesses |
|---|---|---|---|
| BAL-001-2 | Frequency response | ADR-GRID.1 | Grid signal type, response latency, compliance ratio |
| BAL-005-1 | AGC and metering | ADR-SETTLE.1 | Energy settled (kWh), price (USD/MWh), event count |
| TOP-001-5 R1 | Operational data exchange | ADR-EVENT.1 | Event phase, committed curtailment (kW) |
| TOP-001-5 R3 | Load shedding | ADR-CURT.1 | Actual vs committed reduction, compliance ratio |
| MOD-031-3 R1 | Demand data reporting | ADR-BASE.1 | Baseline consumption (kW), method, confidence |
| FAC-001-3 R1 | Facility connection | ADR-CARBON.1 | Credit type (REC, offset, EAC), quantity (MWh) |
16. Demand Response Procedures (ADR Namespace)
The ADR namespace contains 7 procedures purpose-built for energy sector witnessing. Each produces a SWT3 anchor with factor-level detail matching the physical quantities grid operators measure.
New in v0.7.4
Witnesses AI-driven voltage regulation actions. factor_a = voltage deviation from nominal (x100, e.g., 250 = 2.50%), factor_b = response action (1=tap change, 2=capacitor bank, 3=STATCOM, 4=inverter droop, 5=load transfer), factor_c = response time in milliseconds. Maps to IEEE 1547-2018 Sec. 6, NERC FAC-001-3 R4, and EU SOGL Art. 18.
Frequency Response Evidence
Witnesses the correlation between grid operator signals and AI-driven responses. factor_a = signal type (1=emergency, 2=economic, 3=capacity, 4=frequency regulation, 5=voltage support), factor_b = response latency (ms). NERC BAL-001 requires frequency response; this procedure proves the AI responded correctly.
Load Reduction Evidence
Witnesses actual vs committed load reduction during demand response events. factor_a = actual reduction (kW), factor_b = committed reduction (kW), factor_c = compliance ratio (x1000, must exceed 950 for PASS). This is settlement-grade evidence.
17. Energy Grid Profile
SWT3 ships with a pre-built energy-grid profile that bundles all 7 ADR procedures plus 10 NERC CIP-mapped AI procedures into a single configuration.
$ swt3 init --profile energy-grid
# Or with full expansion:
$ swt3 init --profile energy-grid --expand
The profile sets clearing level 2 (Sensitive), requires agent identity and signing, and configures 30-minute trust mesh freshness windows aligned with grid operational cycles. It includes:
- ADR-BASE.1 through ADR-VOLT.1 (7 procedures) -- demand response lifecycle
- AI-SAFE.1, AI-GOV.1, AI-DRIFT.1/2, AI-EMRG.1, AI-INCIDENT.1, AI-CHAIN.1, AI-SUPPLY.1, AI-HITL.1 (10 procedures) -- NERC CIP AI governance
18. Quick Start
Python
from swt3_ai import Witness
witness = Witness(
agent_id="grid-optimizer-v2",
signing_key="your-signing-key",
clearing_level=2 # Sensitive (grid reliability data)
)
# Wrap your AI client
client = witness.wrap(openai_client)
# Witness a voltage regulation decision
witness.record_raw("ADR-VOLT.1",
factor_a=250, # 2.50% deviation
factor_b=1, # Tap change
factor_c=150 # 150ms response
)
# Witness a demand response event
witness.record_raw("ADR-EVENT.1",
factor_a=2, # Curtailment start
factor_b=5000 # 5000 kW committed
)
# Flush to clearing house
witness.flush()
TypeScript
import { Witness } from '@tenova/swt3-ai';
const witness = new Witness({
agentId: 'grid-optimizer-v2',
signingKey: process.env.SWT3_SIGNING_KEY,
clearingLevel: 2
});
// Witness voltage regulation
witness.recordRaw('ADR-VOLT.1', {
factorA: 250, // 2.50% deviation
factorB: 1, // Tap change
factorC: 150 // 150ms response
});
await witness.flush();
19. References
- NERC Reliability Standards Library
- NERC CIP Standards (CIP-002 through CIP-014)
- FERC Order 2222 -- Participation of Distributed Energy Resources in Wholesale Markets
- IEEE 1547-2018 -- Standard for Interconnection of Distributed Energy Resources
- SWT3 Protocol Specification v2.0.0
- SWT3 Demand Response Guide (ADR Namespace)
- CISA AI-in-OT Crosswalk -- complementary guide for OT environments
- UCT Registry -- full procedure catalog (277 procedures, 80 frameworks)