The Industry Organizations Collaboration Effort

The NATF and other industry organizations are working together to provide a streamlined, effective, and efficient industry-accepted approach for entities to assess supplier cyber security practices. The model, if applied widely, will reduce the burden on suppliers so their efforts with purchasers can be prioritized and entities can be provided with more information effectively and efficiently. The industry organizations collaboration effort is focused on improving cyber security, and assisting registered entities with compliance to regulatory requirements.

Each of the industry organizations and many individual entities are working on solutions for various stages of the supply chain cyber security risk assessment lifecycle. These solutions are brought together in this effort to provide a cohesive approach. This approach may change over time as it matures but staying cohesive will be key to maintaining streamlined effective and efficient cyber security.

This website provides information on the approach (also referred to as the “model”), projects/activities that have been accomplished, and projects/activities in progress, upcoming presentations, links and contact information, and recent news. 

Resources (View All)

NATF CIP-013 Implementation Guidance-Independent Assessments of Vendors (ERO Endorsed)

NATF CIP-013 Implementation Guidance-Supply Chain Risk Management Plans (ERO Endorsed)

NATF Industry Collaboration: Using Solution Providers for Third-Party Risk Management

Click "View All" above to access additional documents, presentations, supply-chain sites, and support products and services.

Supplier Sharing Calls

The intention of the Supplier Sharing Calls calls is to encourage conversation between suppliers and with the end-users of their products and services, provide a forum to share forefront security concerns and how to address them, and to discuss general security practices. These calls will be applicable to suppliers of all sizes and security maturity.

Upcoming Meetings and Activities

Expand all

Collapse all

Announcements  (View All)

January 13, 2026

NATF Supply Chain Criteria and Questionnaire Quickstart Guide Released

Since their creation over five years ago, the NATF Supply Chain Security Criteria and Energy Sector Supply Chain Risk Questionnaire have provided industry with ready-made tools that entities can use to evaluate their supplier’s security posture. These tools help entities conduct more thorough supplier risk assessments and assist entities in meeting their CIP-013 compliance obligations.

However, entities and suppliers that are not yet familiar with the criteria and questionnaire may be unsure how to start using these powerful tools. Therefore, the NATF Supply Chain Criteria and Questionnaire Quickstart Guide (Quickstart Guide) has been created to provide simple, step-by-step instruction in a brief and accessible format. The Quickstart Guide provides instructions for entities working to obtain information from suppliers, and for suppliers working to respond to requests for information from entities.

The Quickstart Guide has been posted on the NATF’s public Supply Chain Industry Coordination website alongside the existing criteria and questionnaire tools. 

Read More

October 10, 2025

Annual Supply Chain Criteria and Questionnaire Revision Process Underway

The annual revision process for the NATF Supply Chain Security Criteria (Criteria) and the Energy Sector Supply Chain Risk Questionnaire (Questionnaire) is now underway. As a reminder, the Criteria and Questionnaire are simple tools that entities can use when performing risk assessments on suppliers, and are intended to reduce the need for multiple, bespoke questionnaires or other data collection tools. The revision process, Criteria, and Questionnaire are posted on the NATF’s public Supply Chain Industry Coordination website. The process is open to industry, suppliers, regulators, and other stakeholders to provide the opportunity for input.

Input on the criteria and questionnaire can be submitted to supplychain@natf.net until close of business January 30, 2026, for consideration in the 2025 review cycle.

Both the Criteria and the Questionnaire are incorporated into the ERO Enterprise-endorsed implementation guidance documents for CIP-013 (available on the NERC website and the NATF public website):

These documents support using the Criteria and Questionnaire in a risk-based manner, where the entity determines which criteria or questions apply for procurement. The criteria and questionnaire are useful for supply chain risk management as well as ensuring potential threat vectors are identified via these industry-developed and adopted tools.

As the Criteria and Questionnaire are mechanisms to drive convergence on the information needed to conduct supplier risk assessments, it is important that the information you need to conduct risk analyses is included.

As a reminder: The Criteria and Questionnaire capture supplier information important to the energy sector for conducting risk assessments while keeping the amount of data received to a manageable level. The Criteria and Questionnaire are also verifiable via mappings to several industry frameworks. Note that while there is not a single security framework that addresses all criteria or questions, most can be verified by obtaining a combination of certifications and/or assessments. 

Read More