PE-12: Emergency Lighting

PE-12 requires organizations to deploy automatic emergency lighting that activates during a power outage and covers all emergency exits and

Quick-reference card

FieldValue
Control IDPE-12
Control nameEmergency Lighting
FrameworkNIST SP 800-53 Revision 5
Control familyPhysical and Environmental Protection
BaselinesLOW MODERATE HIGH
RelevanceOrganization (First Party and Third Party)
Risk severityLow

What this control requires

PE-12 requires organizations to deploy automatic emergency lighting that activates during a power outage and covers all emergency exits and evacuation routes. This isn’t a general building-code checkbox. It’s a continuity requirement that applies specifically to facilities housing concentrations of information system resources, including data centers, server rooms, and mainframe environments.

In practice, this means your emergency lighting must operate without manual intervention. The system needs to detect a power disruption and engage backup illumination immediately, covering every path someone would use to leave the facility safely. Organizations that maintain NIST SP 800-53 controls across multiple facility types should document where PE-12 applies and confirm that each location meets the requirement independently.

The control also ties directly into your broader contingency planning. Your contingency plan should describe the emergency lighting provisions for each facility, and if those provisions fail entirely, you need a defined path to alternate processing sites. PE-12 doesn’t exist in isolation; it anchors the physical layer of your continuity strategy.

Why it matters

PE-12 sits in a category of controls that auditors can verify with a single walkthrough. Failure to maintain automatic emergency lighting introduces audit risk and may result in certification withdrawal or regulatory findings. Because baselines at all three levels (LOW, MODERATE, and HIGH) require PE-12, there’s no risk threshold that exempts an organization from this control.

The operational consequences extend beyond audit findings. When emergency lighting fails during an actual power disruption, personnel can’t safely navigate to exits or reach critical equipment for manual failover. Evacuation delays increase physical safety risk, and inability to access server rooms during an outage can extend system downtime well beyond what your recovery time objectives allow.

Where this breaks down most often is in maintenance. Organizations install compliant emergency lighting and then neglect periodic testing. Batteries degrade, fixtures fail, and exit signage burns out. By the time an actual outage occurs, the lighting system that passed its initial assessment no longer functions. This gap between installation and sustained compliance is exactly what auditors look for when reviewing PE family controls.

What attackers exploit

  • Disabled or degraded emergency lighting during a physical intrusion to reduce visibility for security personnel responding to unauthorized facility access
  • Power disruption as a precursor to physical breach, using intentional outages to create confusion and impair surveillance and access control systems
  • Targeting maintenance gaps in backup power systems, exploiting the window between battery failure and the next scheduled test cycle
  • Social engineering around facility evacuations, using false alarms or real outages to move personnel away from sensitive areas

How to implement

Most PE-12 failures don’t stem from missing equipment. They stem from missing maintenance schedules and unclear ownership of testing responsibilities.

For your organization

Start by inventorying every facility that houses information system resources covered by your authorization boundary. Data centers, server rooms, network closets, and any space containing system components all fall within scope. Map the emergency exits and evacuation routes for each facility and confirm that automatic emergency lighting covers every segment of those paths.

Deploy lighting systems that activate automatically when primary power fails. Battery-backed emergency fixtures and generator-powered systems both satisfy the requirement, but battery-backed units are more common for localized coverage. Confirm that each unit provides sufficient illumination duration. Most organizations target a minimum of 90 minutes, aligning with building codes and NFPA standards.

Specifically, you need to establish a documented testing schedule. Monthly functional tests, where you verify each fixture activates correctly, catch the most common failure mode: dead batteries. Annual full-duration tests confirm that backup power sustains illumination for the required period. Record every test result, including failures and corrective actions, because auditors will request this documentation.

Assign clear ownership for emergency lighting maintenance. In organizations where facilities management and IT security operate separately, PE-12 often falls into a gap between teams. Your business continuity plan should name the responsible party and define escalation procedures when fixtures fail testing.

But coverage alone isn’t sufficient without integration into your contingency planning. Your contingency plan should reference PE-12 provisions explicitly, describe what happens if emergency lighting fails entirely, and identify alternate processing sites as a fallback. This connection between physical controls and continuity planning is where auditors assess organizational maturity.

For your vendors

When assessing a vendor’s PE-12 compliance, your questionnaire should ask targeted questions rather than accepting a generic “yes, we have emergency lighting” response. Request documentation that specifies which facilities house your data and whether automatic emergency lighting covers the exits and evacuation routes in those specific locations.

Ask for the vendor’s emergency lighting test records from the past 12 months. You’re looking for evidence of both monthly functional tests and annual duration tests. A vendor that can’t produce test records likely isn’t maintaining the system consistently. Gaps in testing documentation are a reliable red flag for broader physical security control weaknesses.

Request the vendor’s contingency plan sections that describe emergency lighting provisions. The plan should name specific facility locations, describe the type of emergency lighting deployed, and outline the failover process if lighting systems fail. Vendors operating from ISO 27001-certified facilities should be able to map their supporting utilities controls to PE-12 requirements.

Where this gets more complex is with vendors using colocation or shared data center facilities. In these cases, the colocation provider typically owns the emergency lighting infrastructure. Your vendor should be able to demonstrate that the colo provider maintains PE-12-equivalent controls and that the vendor has verified this through their own assessment or audit review. Don’t accept “our colo handles it” without supporting evidence.

Verify that the vendor’s facilities have been assessed within the last authorization cycle and that PE-12 was evaluated as part of that assessment. If the vendor holds a FedRAMP or StateRAMP authorization, PE-12 is already in scope at all baselines. For vendors without federal authorization, request their most recent third-party assessment report and confirm emergency lighting was tested, not just documented.

Evidence examples

Evidence typeExample artifact
Policy documentationPhysical and environmental protection policy defining emergency lighting requirements, maintenance responsibilities, and testing frequency
Implementation proceduresEmergency lighting procedures specifying installation standards, fixture types, battery replacement schedules, and escalation for failed units
Facility coverage recordsEmergency lighting floor plans showing fixture locations mapped to emergency exits and evacuation routes
Test recordsMonthly functional test logs and annual duration test results documenting pass/fail status, dates, and corrective actions taken
Contingency plan referencesContingency plan sections describing emergency lighting provisions per facility and alternate processing site procedures
System security planSystem security plan documenting PE-12 implementation status, responsible parties, and facility scope

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20227.11 Supporting utilitiesPartial

ISO 27001 Section 7.11 covers supporting utilities broadly, including power supply continuity, which partially overlaps with PE-12’s emergency lighting requirements. PE-12 is more specific in requiring automatic activation and coverage of exits and evacuation routes. Organizations mapping between frameworks should note that satisfying 7.11 alone may not fully address PE-12’s scope, and additional documentation of lighting-specific provisions is typically needed. Related physical protection requirements under ISO 27001 Section 7.5 address broader threats to facility security.

  • CP-02 — Contingency Plan: PE-12 requires that emergency lighting provisions are described in the organization’s contingency plan, making CP-02 the planning counterpart to PE-12’s physical implementation.
  • CP-07 — Alternate Processing Site: When emergency lighting fails entirely at a primary facility, CP-07 defines the fallback to alternate processing sites where power and lighting infrastructure can sustain operations.

Frequently asked questions

What is NIST SP 800-53 PE-12?

PE-12 is the NIST SP 800-53 control that requires organizations to employ and maintain automatic emergency lighting covering emergency exits and evacuation routes within facilities housing information systems. The control applies at all three baselines (LOW, MODERATE, and HIGH), making it a universal requirement for any system operating under the NIST framework. Automatic activation during a power outage or disruption is the defining characteristic; manual or portable lighting doesn’t satisfy the requirement.

What happens if PE-12 is not implemented?

Failure to implement PE-12 results in a documented control deficiency during authorization assessments, which can delay or prevent an authority to operate. Auditors verify that automatic emergency lighting covers emergency exits and evacuation routes, and a gap in either coverage or maintenance records constitutes a finding. Beyond audit consequences, the absence of emergency lighting during a power disruption creates physical safety hazards for personnel and can extend system downtime by preventing safe access to critical infrastructure.

How do you audit PE-12?

Auditors assess PE-12 by physically inspecting facilities to confirm that automatic emergency lighting is installed along all evacuation routes and at every emergency exit. They review emergency lighting test records to verify that monthly functional tests and annual duration tests are being conducted and documented. They also examine the contingency plan for references to emergency lighting provisions and confirm that the system security plan accurately reflects PE-12 implementation status, responsible parties, and facility scope.

How often should emergency lighting be tested?

Most organizations conduct monthly functional tests to verify that each emergency lighting fixture activates correctly, combined with annual full-duration tests to confirm that backup power sustains illumination for the required period. These testing intervals align with NFPA standards and are consistent with what auditors expect when reviewing emergency lighting test records during a PE-12 assessment. Every test should be documented with dates, pass or fail outcomes, and any corrective actions taken for failed units.

Experience superior visibility and a simpler approach to cyber risk management