Services
All services
Where you stand
Security Assessment Security Gap Analysis Physical Security Compliance
Build the program
Resilience as a Service Training & Drills Business Continuity Multi-Site Programs Integrated Security Program
Specific exposures
Executive & Creator Event Security & Safety Food Safety & Defense AlertMedia
Industries
All industries Nonprofits & Faith Property Management Corporate & Campus Critical Infrastructure Healthcare
Grants
Nonprofit Security Grants Port Security Grants
Resources
WorldSafe Certified Blog Guides Glossary Physical Security vs Cybersecurity Building a Security Culture Creator Exposure Ebook Info Accessibility Check Wes Subscribe
Company
About Get Your Risk Score
Physical security compliance

Compliance that survives
the audit.

NERC CIP-014, TSA pipeline security, and state utility oversight turn on the same requirement. An independent party has to examine your physical security and write down what it found. WorldSafe performs that review and produces the record.

Request a compliance review
Standard
CIP-014-3
six requirements for transmission owners
Independence
Two requirements
call for an unaffiliated third party
Cadence
30 months
between risk assessments
Why independence is written into the rule

Regulators stopped accepting self-assessment.

CIP-014 requires an unaffiliated third party at two separate points. The standard defines unaffiliated precisely. The reviewer cannot be an entity that controls, is controlled by, or sits under common control with the registered entity. An internal security team cannot satisfy it. Neither can a corporate sibling.

The reviewer produces written findings. The entity then modifies its evaluation and plan to match each recommendation, or documents why it did not. That record is the evidence an auditor examines.

WorldSafe works as the outside party. A practitioner evaluates the facility, writes the findings, and hands over documentation organized the way audits request it.

Scope

Frameworks we work under.

Physical security obligations for regulated infrastructure, and the evidence each one expects.

NERC CIP-014

Transmission stations, substations, and primary control centers

Unaffiliated third-party review

The R6 review of your threat evaluation and security plan

TSA pipeline security

Criticality assessment and physical measures at critical facilities

Evidence packages

Dated documentation, assembled the way auditors request it

Annual plan review

Scheduled review and testing so the plan stays current

State and local oversight

Public utility commission expectations layered on federal rules

CIP-014-3

The six requirements.

What the standard asks of transmission owners and operators, in order.

R1
Risk assessment

Identify transmission stations and substations that, if rendered inoperable, could cause instability, uncontrolled separation, or cascading failure.

R2
Third-party verification

An unaffiliated third party verifies the R1 risk assessment. The verifier needs transmission planning or analysis experience.

R3
Notification

Notify the transmission operator that controls the primary control center for each identified facility.

R4
Threat and vulnerability evaluation

Evaluate the potential threats and vulnerabilities to each identified facility, accounting for prior history, intelligence, and site conditions.

R5
Physical security plan

Develop and implement a documented plan that addresses what the evaluation found, with resiliency measures and law enforcement coordination.

R6
Third-party review

An unaffiliated third party with appropriate experience reviews the R4 evaluation and the R5 plan, and issues written findings.

WorldSafe performs the R6 review and supports R4 and R5 development. R2 verification sits with a registered planning coordinator, transmission planner, reliability coordinator, or an entity with transmission planning experience, so WorldSafe does not perform it. Being clear about that boundary matters more than winning the whole scope.

Evaluate → Plan → Review

How WorldSafe runs a compliance engagement.

Three phases, each producing a document that stands on its own.

1
Evaluate

A practitioner walks the facility and evaluates threats and vulnerabilities against site conditions, prior incidents, and current intelligence. The output is a written evaluation.

2
Plan

WorldSafe develops the physical security plan, or reviews the plan you already have, and maps every measure back to a specific finding.

3
Review

WorldSafe issues written findings as the unaffiliated reviewer. You modify the plan or document your reasoning. Both outcomes leave an audit trail.

Beyond the grid

Pipelines, ports, and other regulated facilities.

TSA pipeline security guidelines ask operators to identify critical facilities and apply physical security measures at each one. Port facilities carry their own federal requirements. The pattern repeats across regulated infrastructure. Identify what is critical, evaluate what threatens it, document the measures, and keep the record current.

Criticality first

The assessment starts by deciding which facilities carry consequence.

Measures mapped to findings

Every control traces to a documented threat or vulnerability.

Records that stay current

Plans get reviewed and tested on a schedule, not after an audit notice.

Port facility operators can also review Port Security Grant Program support.

Common questions.

Scope, independence, cadence, and what gets delivered.

Which physical security regulations apply to my facilities?

NERC CIP-014 applies to transmission owners and transmission operators with qualifying transmission stations, substations, and primary control centers. TSA pipeline security guidelines apply to critical pipeline facilities. State public utility commissions add their own expectations. WorldSafe identifies which apply before any work begins.

What does CIP-014 require an unaffiliated third party to do?

Two requirements. Requirement R2 has an unaffiliated third party verify the R1 risk assessment. Requirement R6 has an unaffiliated third party review the R4 threat and vulnerability evaluation and the R5 physical security plan. Unaffiliated means the reviewer cannot be a corporate affiliate of the entity.

Can WorldSafe perform the R2 verification?

No. R2 verification calls for a registered planning coordinator, transmission planner, reliability coordinator, or an entity with transmission planning or analysis experience. WorldSafe performs the R6 review and supports the R4 evaluation and R5 plan development, which is where physical security expertise applies.

How often does CIP-014 require a risk assessment?

Every 30 calendar months for entities that have completed a prior risk assessment, and every 60 calendar months for entities performing an initial assessment.

What happens to the reviewer's recommendations?

The transmission owner or operator either modifies the evaluation and security plan consistent with each recommendation, or documents the reasons for not doing so. Both paths produce evidence an auditor will ask to see.

What does WorldSafe deliver?

A written evaluation of threats and vulnerabilities, a physical security plan or a review of the existing plan, written findings with recommendations, and a documentation package organized the way auditors request it.

Independent review,
documented properly.

Talk to WorldSafe about a CIP-014 review or a compliance assessment for your facilities.

Book a consultation

[email protected] · +877-831-SAFE