NERC CIP Background Checks: The 2026 Guide for Energy Employers [2026]

Founder & President, iprospectcheck
PBSA member since 2009 · 30+ years in employment screening

In This Article

    Loading...

Newsletter signup

NERC CIP Background Check

If your company is involved in the energy sector and touches the bulk electric system (BES), you’re required to conduct specialized NERC CIP background checks on certain employees, contractors, and vendors.

These checks help to protect the electrical grid and keep your company, employees, and the public safe.

In this guide, you’ll learn what NERC CIP background checks are, what they include, and how to stay compliant with laws and regulations.

What is a NERC CIP Background Check?

A NERC CIP background check is an investigation that the Federal Energy Regulatory Commission (FERC) requires you to conduct on certain employees, contractors, and vendors who have unescorted access to sensitive cyber data that touches the bulk electric system (BES).

The North American Electric Reliability Corporation (NERC) issued Critical Infrastructure Protection (CIP) standards that utility companies and others in the energy sector that touch the BES must follow.

These checks are designed to verify an individual’s safety, responsibility, trustworthiness, and qualifications.

Why You Should Screen Every Employee, Contractor, and Vendor with BES Access

NERC CIP-004 mandates NERC CIP background checks for employees, contractors, and third-party vendors with unescorted digital or physical access to critical cyber assets.

These are background investigations and personnel assessments designed to protect the electrical grid’s reliability and minimize insider risks to critical infrastructure.

Complying with NERC CIP mandates protects national security, as bad actors may target the bulk electrical system.

Following its requirements is mandatory. If you fail to implement a personnel risk assessment program that includes NERC CIP background checks, you could face civil penalties that could be in the millions of dollars per day per violation (for severe violations).

The North American Electric Reliability Corporation (NERC) and regional entities are tasked with enforcing NERC CIP under the Federal Energy Regulatory Commission’s (FERC) authority.

You should also conduct an in-depth background check on candidates to confirm they are who they claim to be. Candidate fraud and fake candidates have become a reality and are increasing.

For example, in our 2026 hiring survey report, 18.5% of employers reported they had either suspected or directly dealt with candidate fraud, and 22.9% agreed that they may have interviewed fake candidates or proxies at some point in time.

What a NERC CIP-Compliant Background Check Includes

Background Search Type NERC CIP Background Check Standard Background Check
Identity Verification Yes, enhanced Yes
National Criminal Records Search Yes Yes
Federal Criminal Records Search Yes Yes
7-year County Criminal Records Search Yes Yes
Motor Vehicle Records Check Yes No
OFAC-SDN Search Yes No
SAM Check Yes No
National Sex Offender Registry Search Yes Yes
Employment Verification Yes No
Education Verification Yes No
Global Terrorist Watchlist Search Yes Yes
Pre-employment Drug Test Yes No
Ongoing Drug Tests Yes No

Enhanced Identity Verification

Under NERC CIP-004, you are mandated to conduct enhanced identity verification on candidates who will have unescorted access to critical cyber systems.

This confirms the candidate’s legal identity by using validated, verified government-issued documents and biomarkers.

It also includes a Social Security Number (SSN) trace, which provides the following information:

  • Validity of the SSN
  • Date the number was issued by the Social Security Administration (SSA)
  • Names and aliases associated with the SSN (including maiden names)
  • Birthdate associated with the SSN
  • State in which the SSN was issued
  • Addresses associated with the SSN

Within the NERC CIP background check context, all covered employers must conduct in-depth identity verification on all employees, vendors, and contractors as required under the standards.

By contrast, our survey found that 31.8% of employers overall check government-issued IDs, which is the most common type of identity verification performed.

However, 5.1% of employers surveyed admitted that they don’t verify identity before they hire, and another 22.3% reported they were unsure about what their identity verification process covers.

Despite these statistics, 80.9% of surveyed employers believe that identity verification should be standard, and 67.5% believe it should apply to every position rather than just sensitive jobs.

7-Year Criminal Records Check

Covered employers within the energy sector whose work involves the bulk electrical system are required to conduct seven-year criminal records checks.

These checks include searches of local, state, and federal criminal records involving misdemeanor and felony convictions from the last seven years.

When a candidate has a pending criminal charge or conviction, a criminal records search shows:

  • Offense date
  • Offense type
  • Offense severity (misdemeanor/felony)
  • Disposition
  • Disposition date
  • Sentence information (when available)

You can use this information to assess the potential risk a candidate could pose if hired.

Our survey found that 54.1% of employers reported that background checks reveal discrepancies between what candidates report and what the searches show very or somewhat often. Among the discrepancies, 17% involved omissions about the candidate’s criminal history.

Motor Vehicle Records

While a motor vehicle records (MVR) check isn’t required under the NERC CIP standards, it’s still recommended for positions involving driving.

An MVR check shows the following information about an applicant’s driving history and license:

  • Driver’s license number
  • Driver’s license class
  • Issuance and expiration dates
  • Full legal name
  • Registered address
  • Traffic citations
  • Major traffic crimes
  • Suspensions or revocations

With this information, you can better assess any risks the candidate could pose if hired and whether your insurance provider will insure them.

OFAC-SDN Search

NERC CIP doesn’t specifically require an OFAC-SDN search, but we strongly recommend it as a part of the required personnel risk assessment program you must implement.

The Office of Foreign Assets Control (OFAC) maintains a Specially Designated Nationals and Blocked Persons (SDN) list.

These are individuals deemed to pose a national security risk who have been sanctioned by the U.S. Department of the Treasury due to their activities.

If you hire or do business with someone named on the OFAC SDN list, your company could face serious penalties.

Additionally, someone named to the SDN list could pose a serious risk to the electrical system.

SAM Search

A Systems for Awards Management (SAM) search isn’t explicitly required by NERC CIP. However, you should conduct it if you’re a federal contractor.

SAM maintains the list of excluded entities and individuals. These are people and companies that are excluded from participating in federal contracts.

If you hire or do business with an excluded entity or individual, you could lose your ability to continue or secure federal contracts.

Debarred individuals and entities can’t contract with the federal government or be hired by any company that holds federal contracts.

National Criminal Records Search

A national criminal records search is a preliminary search conducted by a background check provider like iprospectcheck as part of the required seven-year criminal records search under NERC CIP.

When this search reveals a hit at the state, local, or federal levels, additional searches are conducted at the information’s source to verify the conviction records.

National Sex Offender Registry Search

NERC CIP doesn’t require a national sex offender registry search, but you should still conduct this check on all candidates to protect your employees and the public.

When an applicant is a registered sex offender, a sex offender registry check reveals:

  • Registered address
  • State in which the registrant is registered
  • Offense requiring registration
  • Names and aliases used by the registrant
  • Distinguishing characteristics (scars, tattoos, etc.)

Employment Verification

NERC CIP doesn’t require you to verify a candidate’s reported employment history.

However, many applicants lie about past employment on their resumes, which implicates their trustworthiness.

Employment verification shows the following information:

  • Names and locations of each employer
  • Employment dates with each employer
  • Titles and job duties

Our survey revealed that only 39% of companies consistently verify past employment for every hire. However, 40.3% reported they withdrew a job offer because of resume fraud or unverifiable credentials.

Verifying employment helps you assess whether a candidate can be trusted when working with sensitive cyber systems involved with the bulk electrical system.

Education Verification

Like employment verification, NERC CIP doesn’t explicitly require you to verify an applicant’s education.

However, education verification helps you assess a candidate’s trustworthiness by showing whether they have the education they’ve claimed and the qualifications necessary for the job.

Education verification reveals the following information:

  • Names/addresses of each institution attended
  • Enrollment dates
  • Any degrees conferred

Global Terrorist Watchlist Search

Conducting a global terrorist watchlist search on candidates isn’t required by NERC CIP, but it demonstrates you’ve conducted due diligence in your personnel risk assessments.

Global terrorist watchlist searches also help to protect the electrical grid from bad actors.

This search shows whether a candidate has engaged in or is suspected of engaging in serious offenses, including:

  • Terrorism
  • Narcotics trafficking
  • Major financial crimes
  • Is debarred or excluded
  • Serious international crimes
  • Major fraud
  • Has faced disciplinary action or sanctions

Anyone appearing on a global watchlist search will likely pose too great a risk to have access to critical cyber assets.

Pre-Employment Drug Test

You aren’t required to conduct pre-employment drug tests under NERC CIP standards.

However, people who abuse drugs may pose a higher risk of accidents and other problems when working with critical cyber systems.

It’s a good idea to conduct five- or 10-panel drug tests to check for a candidate’s recent use of illicit substances.

Ongoing Drug Testing

Ongoing drug testing isn’t required, but it’s a good idea to ensure your employees are safe and pose minimal risk.

You should conduct random drug tests, reasonable suspicion tests, and post-accident drug tests as both a deterrent to illegal substance use and a safety measure to reduce risk.

Know Before You Hire

What are NERC CIP 004 Audits?

Audits occur at least every three years and are conducted by a regional entity.

In addition to scheduled audits, regional entities also conduct spot checks on utilities and contractors for NERC, with FERC having final authority over penalties for violations.

For NERC CIP 004, auditors will ask to review your written personnel risk assessment policy and compare it with your completed PRA records with dates, access-grant timestamps, quarterly access review logs, and 24-hour revocation logs.

They’ll also want to see your training completion logs that demonstrate all personnel completed training before being granted unescorted access, except in the case of designated emergencies.

You must revoke unescorted access within 24 hours of an employee’s, contractor’s, or vendor’s termination or role change, including remote and electronic access.

What Happens When You Fail a NERC CIP 004 Audit?

When violations are found, NERC scores them by multiplying the violation risk factor by its severity level to determine the base penalty range.

A severe violation can result in a penalty of up to $1.5 million per violation per day.

A review of the FERC Civil Penalty Actions list reveals civil fines of up to the seven-figure to eight-figure range plus multi-million-dollar disgorgements.

CIP-004 violations were among the three top categories of violations reported in 2025.

The most common CIP-004 findings included employers:

  • Granting access to employees before completing the personnel risk assessments
  • Failing to renew PRAs within seven years
  • Failing to revoke access within 24 hours of termination or role change
  • Incomplete or missing documentation

You can also face non-monetary consequences, including being publicly posted on the NERC Notices of Penalty List, facing a mandatory mitigation plan, and undergoing follow-up spot checks.

If you self-report violations voluntarily and implement a mitigation plan, you can reduce the penalty significantly.

Under NERC Sanctions Guidelines 3.3.8, NERC and/or the regional entity can reduce your monetary penalty when you self-report early, within a reasonable time after discovery, and before the violation is discovered by an auditor.

Important Laws & Regulations

Federal Laws and Regulations

NERC CIP 004

NERC CIP 004 includes the personnel and safety training mandates that all companies involved with the bulk electric system must follow for their sensitive cyber systems.

It includes several requirements:

  • Establishment, documentation, and implementation of a security awareness program – You must provide awareness reinforcement at least quarterly through posters, memos, emails, brochures, etc.
  • Establishment, documentation, and implementation of a cybersecurity training program for individuals who will have unescorted access to sensitive cyber systems – Employees, vendors, and contractors who will have unescorted physical or digital access must complete training before you can grant access authority (other than in designated emergencies), and you must provide additional training annually. Document all training.
  • Development and implementation of a personnel risk assessment (PRA) program – You must complete an individual’s personnel risk assessment before granting them authorized unescorted access to cyber assets.
  • The PRA program must include (at a minimum) a thorough identity verification process and a 7-year criminal background check in every jurisdiction in which the individual has lived for six or more months during the past 7 years.
  • All PRAs must be completed again within seven years or for cause.
  • All PRA results must be documented and retained for each person with unescorted access.
  • The employer must maintain lists of each person who has authorized, unescorted access to critical cyber systems, including their specific digital and physical access rights. This includes lists of vendors and contractors who have unescorted access rights.
  • The employer must revoke an individual’s access rights within 24 hours of termination for cause or within seven days for a change in role that no longer requires unescorted access. The employer must maintain documentation of the revocation.
  • The employer must provide lists and documentation of all requirements as noted above upon request by NERC or a regional entity.

Fair Credit Reporting Act

The Fair Credit Reporting Act (FCRA) protects consumers’ privacy in the information that consumer reporting agencies (CRAs) collect, retain, and report to third parties, including employers.

This law prohibits CRAs from reporting certain information older than seven years for jobs paying less than $75,000 annually:

  • Arrests that didn’t result in convictions
  • Paid tax liens
  • Debt collection accounts
  • Civil lawsuits and judgments
  • Chapter 13 bankruptcies (Chapter 7 bankruptcies can be reported for 10 years)

The FCRA doesn’t prohibit CRAs from reporting conviction records. The seven-year rule also doesn’t apply to positions that pay more than $75,000.

You must comply with the FCRA’s notice and consent rules by disclosing that you perform background checks on a standalone form and obtaining the candidate’s written consent before initiating a search.

If you learn information from a background check that makes you want to decline employment, you must complete the adverse action steps before making a final decision.

Title VII of the Civil Rights Act of 1964

Title VII is a leading federal law that prohibits workplace discrimination based on an applicant’s or employee’s protected characteristics.

Under guidance from the Equal Employment Opportunity Commission (EEOC), you should individually assess criminal convictions you learn about from background checks as they relate to the job for which you’re considering an applicant before basing a decision not to hire them on that information.

Fair Chance to Compete for Jobs Act

The Fair Chance to Compete for Jobs Act (FCA) applies to federal agencies and companies that seek or hold federal contracts.

This federal fair chance hiring law prohibits federal contractors and agencies from asking about criminal history before making a conditional employment offer.

If a company inquires earlier in the hiring process, federal agencies can’t contract with them.

State Laws

State laws vary widely. Many state and local jurisdictions have passed ban-the-box laws that control when in the hiring process you can inquire about criminal history information.

A few states have enacted marijuana drug testing rules that restrict testing for inactive metabolites of THC, except when required by other laws.

Consult legal counsel to understand your local and state legal obligations where your company operates.

Know Before You Hire

How to Run a Compliant NERC CIP Background Check

1. Design and Implement a Compliant Security Awareness Program

Your company must have a compliant security awareness program that complies with NERC CIP 004 and reinforce it at least quarterly, through direct messages, indirect messages, and management enforcement.

You can display posters, send email reminders, provide computer-based training, hold meetings, and use other methods to ensure your team is aware of the need for security and understands and uses sound security practices.

2. Design and Implement a Compliant Cybersecurity Training Program

You must also build a compliant cybersecurity training program that satisfies NERC CIP requirements.

All personnel must complete training before receiving authorization for unescorted access.

You must hold and review training at least once per year.

3. Build and Implement a Documented Personnel Risk Assessment Policy

Every employee, vendor, and contractor who will have unescorted access (physical or digital) to your critical cyber assets related to the bulk electrical system must undergo an in-depth personal risk assessment before they can be hired or assigned to the role.

At a minimum, your PRA should include an enhanced identity verification that includes a search of the individual’s SSN and address history, plus a seven-year criminal records search in every jurisdiction in which the candidate has lived within the last seven years.

Auditors will ask for your documented policy.

NERC CIP doesn’t provide a list of disqualifying crimes and leaves the authority to you to determine which types of convictions pose a risk to your organization.

You should assess any convictions carefully in light of the risks they could pose if an applicant were hired and granted unescorted access.

Include information about how your hiring teams should adjudicate conviction records.

Also provide information about other searches you perform and your reasoning.

4. Train HR and Hiring Teams on NERC CIP-Specific Rules

Your hiring managers should be trained to understand how to perform NERC CIP checks and when they are required.

This includes checks for anyone who will have digital or unescorted physical access to BES cyber systems rather than basing them on job titles.

Make sure they understand that there is an emergency exception in designated emergencies and that everyone with unescorted access must undergo a re-check every seven years.

5. Provide Compliant Disclosures and Obtain Authorization from the Candidate

Provide disclosure to applicants that you conduct background checks on a standalone form.

Obtain their written consent before initiating a search.

Our study found that even though disclosure and consent forms are required under the FCRA, just 47.3% of employers had reviewed them within the past year, and 12.6% failed to use these forms.

Disclosure and consent violations can expose you to significant liability under the FCRA.

6. Time Background Checks Correctly

Before you grant authorized digital or physical unescorted access, you must complete and document the personnel risk assessment.

Your sequencing should match local and federal fair chance hiring laws that apply to you.

In our survey, 34.8% of employers completed screens after the interview but before making an offer. Another 16.5% wait until after making a conditional employment offer.

7. Choose a Reliable, NERC CIP-Experienced Screening Provider

The background check provider you choose must understand the CIP-004 minimum requirements and build packages that scale with the position and access level.

Your provider should be reliable, trustworthy, accurate, and legally compliant.

When you’re searching for a screening provider, you want to choose a company based on accuracy rather than price alone. Our survey supported this and found that 35.5% of employers chose based on accuracy vs. only 18.1% who did so based on price.

Additionally, 83.8% of employers reported that US-based support is very or somewhat important, with 46.5% reporting they would pay more for it.

At iprospectcheck, we stay current with all relevant local, state, and federal laws and regulations and quickly return accurate, in-depth reports to our clients.

As an experienced background check provider, we can help you maintain compliance and offer 100% US-based support.

8. Schedule Recurring Re-Evaluations

Use a tracking system to make sure you reassess each staff member with unescorted access at least every seven years or for cause.

Build your system into your compliance calendar to avoid missing deadlines.

9. Maintain Audit-Ready Documentation

Retain records of all completed PRAs, your screening awareness and training programs, and revocation of access lists.

Include documentation of each individual who has been granted unescorted physical or digital access to critical BES cyber systems.

Regional entities will ask for these records. Incomplete records are a common finding and can result in significant fines.

10. Follow the Adverse Action Process When Necessary

If you learn negative information about a candidate from a background check and want to deny employment, you must complete the adverse action steps and state-law requirements before making a final decision:

  • Send a pre-adverse action notice that includes a copy of the report that contains the concerning information, and the current CFPB-approved version of the “Summary of Your Rights Under the FCRA.
  • Give the candidate a reasonable time (usually, five business days) to respond with evidence of the information’s inaccuracy or that they have been rehabilitated.
  • Send a final adverse action notice and include a copy of the applicant’s rights under the FCRA and state law if you ultimately decide not to hire them based on the background check report.

As a company that NERC CIP covers, you must have a documented adverse action process and be ready to demonstrate compliance to auditors.

Our survey found that while 72.9% of US employers reported they’re confident that their hiring process follows the law, only 40.4% have a documented adverse action process, and 43.7% are unsure if they have a process at all.

Trust iprospectcheck as Your Reliable NERC CIP Background Check Provider

NERC CIP background checks help you meet your legal and regulatory obligations and protect the public from electric grid attacks and emergencies.

This allows your company to serve as a good steward of the electrical system and the nation’s security interests.

At iprospectcheck, we’re an experienced background check provider delivering compliant background checks, so you can pass audits and keep the grid secure.

Contact us today to learn more about our background checks and receive a free quote: (888) 509-1979.

FAQs

How far back does a NERC CIP background check go?

NERC CIP background checks must include at least seven years of criminal history.

Post-hire checks must also be conducted at least every seven years.

Does NERC CIP require a credit check?

No, NERC CIP doesn’t require a credit check.

How long does a NERC CIP background check take?

In most cases, background check reports come back within a few hours to a few days.

However, in local court jurisdictions that require hand searches of records, the process can take a week or more.

Do contractors and vendors need a NERC CIP background check?

Yes, any personnel, including contractors, employees, and vendors, who have unescorted access to critical cyber systems tied to the bulk electrical system must undergo NERC CIP background checks.

Know Before You Hire

About the Author
matthew rodgers

Matthew J. Rodgers

Matthew J. Rodgers is a highly accomplished business executive with over 30 years of experience providing strategic vision and leadership to companies ranging from the fortune 500 to iprospectcheck, a company which he co-founded over a decade ago. Matthew is a valued consultant who is dedicated to helping companies create and implement efficient, cost effective and compliant employment screening programs. Matt has been a member of the Professional Background Screeners Association since 2009 . When not focused on iprospectcheck, he can be found spending time with his family, fly fishing, or occasionally running the wild rivers of the American west. A lifetime member of American Whitewater, Matt is passionate about protecting and restoring America’s whitewater rivers.

iprospectcheck logo