Quick-reference card
| Field | Value |
|---|---|
| Control ID | PE-21 |
| Control Name | Electromagnetic Pulse Protection |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Physical and Environmental Protection |
| Baselines | — |
| Relevance | Organization (First Party and Third Party) |
| Risk Severity | Low |
What PE-21 requires
PE-21 requires your organization to deploy protective measures that shield systems and components from electromagnetic pulse (EMP) damage. Most physical security controls focus on keeping people out, but this control addresses an invisible threat that can disable or destroy electronic equipment without physical contact.
An EMP is a short burst of electromagnetic energy spread across a range of frequencies. These bursts can originate from natural sources, such as solar storms and geomagnetic disturbances, or from man-made sources, including high-altitude electromagnetic pulse (HEMP) weapons. Regardless of origin, the result is the same: unshielded electronic systems face disruption ranging from temporary malfunction to permanent hardware failure.
To satisfy this control, you must identify which systems require EMP protection and then implement appropriate countermeasures. Those countermeasures include shielding (such as Faraday cages), surge suppressors, ferro-resonant transformers, and earth grounding. The control is especially significant for organizations operating systems that support U.S. critical infrastructure, where an EMP event could cascade into widespread service outages. Understanding the full NIST SP 800-53 framework helps you place this control in context.
Why it matters
Failure to maintain PE-21 introduces audit risk and may result in certification withdrawal or regulatory findings during federal assessments. Because no baseline assigns PE-21 by default, many organizations overlook it entirely. That gap becomes a liability when an assessor determines your systems fall within critical infrastructure scope or when your risk assessment identifies EMP as a credible threat.
The consequences extend beyond compliance. EMP events can destroy power supplies, network switches, storage arrays, and embedded control systems in a single burst. Unlike software-based attacks that leave hardware intact, EMP damage is physical. Recovery timelines for hardware destroyed by EMP are measured in weeks or months, not hours. Organizations without protective measures face extended downtime, significant capital expenditure to replace damaged equipment, and potential data loss if storage media is corrupted beyond recovery.
Building a broader NIST compliance program ensures this control doesn’t fall through the cracks when your environment warrants it.
What threat vectors PE-21 addresses
- Solar storms and geomagnetic disturbances that induce currents in long conductors, damaging transformers and connected equipment. The 1989 geomagnetic storm that collapsed Quebec’s power grid demonstrated how natural EMP events can disable infrastructure across an entire region.
- High-altitude electromagnetic pulse weapons capable of disabling electronics across a wide geographic area through a single detonation above the atmosphere
- Intentional electromagnetic interference devices that target specific facilities or systems at close range, potentially disrupting data center operations without any physical breach
- Cascading power grid failures triggered by EMP events that propagate through interconnected infrastructure, extending the blast radius of damage far beyond the initial point of impact
How to implement
PE-21 applies at the organizational level, but implementation looks different depending on whether you’re hardening your own environment or evaluating a vendor’s readiness.
For your organization
Start with a risk assessment to determine which systems and facilities warrant EMP protection. Not every asset needs shielding. Focus on systems that support critical operations, store irreplaceable data, or connect to infrastructure where disruption would cause cascading failures. Your assessment should document the specific EMP threat sources relevant to your geographic location and operational context, whether that’s proximity to critical power infrastructure, military installations, or regions with elevated geomagnetic storm risk.
Once you’ve identified in-scope systems, implement protective measures in layers:
- Shielding. Install Faraday cages or shielded enclosures around critical server rooms and data centers. Ensure all cable entry points use waveguide penetrations or filtered connectors that prevent EMP energy from entering the enclosure.
- Surge suppression. Deploy transient voltage surge suppressors (TVSS) on power lines, data lines, and telecommunications circuits entering protected spaces. Select suppressors rated for the energy levels associated with EMP threats, not just standard lightning protection.
- Ferro-resonant transformers. Use constant-voltage transformers on power feeds to critical systems. These transformers regulate voltage output and absorb transient energy spikes that surge suppressors alone may not fully attenuate.
- Earth grounding. Establish a single-point ground system for protected facilities. All shielding, surge suppressors, and equipment grounds should converge at one grounding point to prevent ground loops that could channel EMP energy into protected equipment.
Document each protective measure, its location, the systems it protects, and its maintenance schedule. A common mistake is installing protective hardware and never testing or maintaining it. Surge suppressors degrade over time, and grounding connections corrode. Include EMP protection verification in your regular maintenance cycles.
Review the NIST 800-53 compliance checklist to track PE-21 alongside your other physical and environmental controls.
For your vendors
When your vendors operate systems that process or store your data, their EMP resilience becomes your concern. Evaluate vendor readiness by requesting specific evidence and asking targeted questions.
Questionnaire questions to include:
- Do you maintain an EMP risk assessment for facilities housing our data?
- What shielding, surge suppression, and grounding measures protect systems processing our information?
- How frequently do you test and maintain EMP protective measures?
- Are your data center facilities certified to any EMP protection standard (such as MIL-STD-188-125)?
Evidence to request:
- EMP risk assessment documentation
- Facility shielding specifications and test results
- Surge suppressor inventory with maintenance records
- Business continuity plans that address EMP scenarios
Red flags during vendor assessment:
- The vendor has no EMP risk assessment and considers the threat irrelevant without documented justification
- Surge suppressors are installed but have no maintenance or testing records
- Grounding systems are shared across multiple buildings with no single-point ground architecture
- The vendor cannot identify which systems are in scope for EMP protection
Use a standardized NIST 800-53 questionnaire template to structure your vendor assessments consistently.
Understanding third-party risk requirements under NIST 800-53 will help you scope these evaluations correctly.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Policy | Physical and environmental protection policy with EMP-specific provisions |
| Risk assessment | EMP threat and vulnerability assessment identifying in-scope systems |
| Shielding documentation | Faraday cage installation specifications and shielding effectiveness test results |
| Surge suppressor inventory | List of TVSS devices by location, rating, installation date, and last test date |
| Grounding records | Single-point ground system diagrams and resistance measurement logs |
| Maintenance records | Scheduled maintenance logs for all EMP protective measures |
| System security plan | SSP sections documenting EMP countermeasures and their coverage |
Cross-framework mapping
No cross-framework mappings are currently configured for PE-21.
Related controls
- PE-18 Location of System Components. PE-18 addresses where you place systems to reduce environmental and physical risk. Siting decisions directly affect EMP exposure levels, making PE-18 a natural complement to the shielding and grounding measures required by PE-21.
- PE-19 Information Leakage. PE-19 focuses on preventing unintentional electromagnetic emissions that could expose sensitive data. While PE-21 protects systems from incoming EMP energy, PE-19 addresses the reverse vector, making the two controls part of a unified electromagnetic risk strategy.
Frequently asked questions
What is NIST SP 800-53 PE-21
PE-21 is a physical and environmental protection control in the NIST SP 800-53 framework that requires organizations to employ protective measures against electromagnetic pulse damage to systems and system components. Those measures include shielding, surge suppressors, ferro-resonant transformers, and earth grounding. The control is particularly relevant for organizations operating critical infrastructure systems where an EMP event could cause widespread disruption.
What happens if PE-21 is not implemented
Organizations that fail to implement PE-21 when it’s applicable face audit findings, potential certification issues, and unmitigated risk to electronic systems from EMP events. Without shielding and surge suppression, a single EMP burst from a solar storm or man-made source can destroy servers, network equipment, and storage devices. Recovery from that level of hardware damage typically requires weeks of procurement, provisioning, and reconfiguration.
How do you audit PE-21
Auditors verify PE-21 by reviewing EMP risk assessments, inspecting shielding installations, and examining maintenance records for surge suppressors, ferro-resonant transformers, and earth grounding systems. They confirm that your organization has identified which systems require protection and has documented the specific countermeasures deployed at each location. Physical inspection of Faraday cage integrity and grounding resistance measurements may also be part of the assessment. Expect auditors to look for evidence that protective measures are tested on a defined schedule and that any deficiencies found during testing are tracked through remediation.
What protective measures satisfy PE-21
Four primary categories of protective measures satisfy PE-21. Shielding, such as Faraday cages and shielded enclosures, blocks EMP energy from reaching equipment. Surge suppressors on power and data lines absorb transient voltage spikes. Ferro-resonant transformers regulate voltage and dampen energy surges on power feeds. Earth grounding through a single-point ground system provides a safe discharge path for induced currents. Effective implementation layers all four measures based on the results of an EMP-specific risk assessment.