Blog & guides

Practical NERC CIP know-how.

Written for the people who actually run CIP programs: specific, current and free of vendor fluff.

CIP-011BCSIbuying guide

BCSI in the cloud or on-premises? Choosing a CIP compliance tool after CIP-011-3

CIP-011-3 and CIP-004-7 made cloud storage of BES Cyber System Information possible. That doesn't make it free. How to weigh SaaS and on-premises CIP compliance tools.

· 6 min readRead
CIP-003low impactvendor access

CIP-003-9 vendor remote access: a practical guide for low impact sites

Since April 1, 2026, CIP-003-9 Attachment 1 Section 6 requires low impact entities to determine, disable and monitor vendor electronic remote access. Here is how to build a plan that holds up in an audit.

· 7 min readRead
auditevidenceRSAW

NERC CIP audit preparation: a 90-day plan

Your Regional Entity's audit notice gives you about 90 days. A week-by-week plan to prepare evidence, close gaps, brief your subject matter experts and answer the RSAW and RFIs with confidence.

· 8 min readRead
regulatoryCIP-015virtualization

NERC CIP changes 2026–2030: the timeline every small utility needs

CIP-003-9 and CIP-012-2 are in force, the virtualization package arrives July 2028, CIP-015 INSM starts October 2028 and CIP-003-11 lands in 2029. A dated roadmap and what to do now.

· 6 min readRead
CIP-007patchingaudit

The CIP-007 35-day patch cycle: a workflow that survives audits

CIP-007-6 R2 is the most-violated area of the most-violated CIP standard. A step-by-step patch evaluation and mitigation workflow, the evidence to keep, and the mistakes auditors find.

· 7 min readRead

Subscribe via RSS

Request a quote

See CIP Sentry on your own terms.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.