Effective January 1, 2021, applicable NERC registered entities must comply with the expanded incident reporting requirements in revised Reliability Standard CIP-008-6. Reports must be submitted to the E-ISAC and, for those entities subject to the jurisdiction of the United States, the U.S. Department of Homeland Security Cybersecurity, and Infrastructure Agency (DHS CISA). Staff should work with their compliance departments on their entity’s specific requirements and obligations.

To report to the E-ISAC you may use, but are not limited to, the following reporting mechanisms:

• EOP-004 (hXXps://[.]pdf)

• E-ISAC Portal Bulletin

• Email to operations@eisac[.]com

• Call E-ISAC Watch Operations at 202-790-6000

• Copy of an OE-417 (hXXps://[.]pdf)

To report to DHS CISA - Submissions should be marked as CIP-008 reporting when submitted to CISA:

CISA Incident Reporting 

• (hXXps://us-cert.cisa[.]gov/forms/report) (a copy of this report may also be sent to the E-  ISAC to reduce duplication of efforts)

• (888)282-0870



The E-SIAC is providing this information for situational awareness.  If you have specific questions about the revised CIP-008-6 Reliability Standard applicability, or guidance, please contact NERC’s Compliance Assurance or your respective Regional Entity Compliance or Enforcement Staff.

If you have any questions about submitting a CIP-008-6 report to the E-ISAC, please contact operations@eisac[.]com or call 202-790-6000.





