NERC CIP-014, TSA pipeline security, and state utility oversight turn on the same requirement. An independent party has to examine your physical security and write down what it found. WorldSafe performs that review and produces the record.
Request a compliance reviewCIP-014 requires an unaffiliated third party at two separate points. The standard defines unaffiliated precisely. The reviewer cannot be an entity that controls, is controlled by, or sits under common control with the registered entity. An internal security team cannot satisfy it. Neither can a corporate sibling.
The reviewer produces written findings. The entity then modifies its evaluation and plan to match each recommendation, or documents why it did not. That record is the evidence an auditor examines.
WorldSafe works as the outside party. A practitioner evaluates the facility, writes the findings, and hands over documentation organized the way audits request it.
Physical security obligations for regulated infrastructure, and the evidence each one expects.
Transmission stations, substations, and primary control centers
The R6 review of your threat evaluation and security plan
Criticality assessment and physical measures at critical facilities
Dated documentation, assembled the way auditors request it
Scheduled review and testing so the plan stays current
Public utility commission expectations layered on federal rules
What the standard asks of transmission owners and operators, in order.
Identify transmission stations and substations that, if rendered inoperable, could cause instability, uncontrolled separation, or cascading failure.
An unaffiliated third party verifies the R1 risk assessment. The verifier needs transmission planning or analysis experience.
Notify the transmission operator that controls the primary control center for each identified facility.
Evaluate the potential threats and vulnerabilities to each identified facility, accounting for prior history, intelligence, and site conditions.
Develop and implement a documented plan that addresses what the evaluation found, with resiliency measures and law enforcement coordination.
An unaffiliated third party with appropriate experience reviews the R4 evaluation and the R5 plan, and issues written findings.
WorldSafe performs the R6 review and supports R4 and R5 development. R2 verification sits with a registered planning coordinator, transmission planner, reliability coordinator, or an entity with transmission planning experience, so WorldSafe does not perform it. Being clear about that boundary matters more than winning the whole scope.
Three phases, each producing a document that stands on its own.
A practitioner walks the facility and evaluates threats and vulnerabilities against site conditions, prior incidents, and current intelligence. The output is a written evaluation.
WorldSafe develops the physical security plan, or reviews the plan you already have, and maps every measure back to a specific finding.
WorldSafe issues written findings as the unaffiliated reviewer. You modify the plan or document your reasoning. Both outcomes leave an audit trail.
TSA pipeline security guidelines ask operators to identify critical facilities and apply physical security measures at each one. Port facilities carry their own federal requirements. The pattern repeats across regulated infrastructure. Identify what is critical, evaluate what threatens it, document the measures, and keep the record current.
The assessment starts by deciding which facilities carry consequence.
Every control traces to a documented threat or vulnerability.
Plans get reviewed and tested on a schedule, not after an audit notice.
Port facility operators can also review Port Security Grant Program support.
Scope, independence, cadence, and what gets delivered.
NERC CIP-014 applies to transmission owners and transmission operators with qualifying transmission stations, substations, and primary control centers. TSA pipeline security guidelines apply to critical pipeline facilities. State public utility commissions add their own expectations. WorldSafe identifies which apply before any work begins.
Two requirements. Requirement R2 has an unaffiliated third party verify the R1 risk assessment. Requirement R6 has an unaffiliated third party review the R4 threat and vulnerability evaluation and the R5 physical security plan. Unaffiliated means the reviewer cannot be a corporate affiliate of the entity.
No. R2 verification calls for a registered planning coordinator, transmission planner, reliability coordinator, or an entity with transmission planning or analysis experience. WorldSafe performs the R6 review and supports the R4 evaluation and R5 plan development, which is where physical security expertise applies.
Every 30 calendar months for entities that have completed a prior risk assessment, and every 60 calendar months for entities performing an initial assessment.
The transmission owner or operator either modifies the evaluation and security plan consistent with each recommendation, or documents the reasons for not doing so. Both paths produce evidence an auditor will ask to see.
A written evaluation of threats and vulnerabilities, a physical security plan or a review of the existing plan, written findings with recommendations, and a documentation package organized the way auditors request it.
Talk to WorldSafe about a CIP-014 review or a compliance assessment for your facilities.
Book a consultation[email protected] · +877-831-SAFE