Your CIP compliance tool holds some of the most sensitive information your utility has: asset inventories with IP addresses, Electronic Security Perimeter diagrams, firewall rules, vulnerability assessment results and incident records. In CIP terms, much of it is BES Cyber System Information (BCSI).
Since January 1, 2024, CIP-011-3 and CIP-004-7 have allowed BCSI to be stored with third parties, including cloud providers, under the right controls. So should your compliance tool be SaaS or on-premises?
What the 2024 changes actually did
CIP-011-3 R1 now expects your information protection program to address BCSI in storage, in transit and in use, including when a vendor holds it. CIP-004-7 moved BCSI access management into a new R6, focused on provisioned access: who can obtain and use the BCSI, rather than where the server sits. Together, they created a compliant path for cloud storage.
What cloud storage of BCSI still requires
- Program work. Your CIP-011 program must describe how BCSI is protected with the provider: encryption, key management, provider personnel access, and what happens when the contract ends.
- Access management. CIP-004 R6 authorizations, verifications every 15 months and revocations apply to BCSI access provisioned in the tool.
- Vendor risk. The provider becomes a CIP-013 supply chain consideration if the tool relates to your BES Cyber Systems, and a target your security team must assess.
- Auditor questions. Expect to explain the provider’s controls, not just your own.
None of this is impossible. Large utilities do it. For a team of one or two, it is real work that doesn’t make the grid more reliable.
The on-premises case
An on-premises tool keeps BCSI inside the protections you already operate: your network, your access control and your backups. There is no third-party storage to describe in the CIP-011 program, no provider personnel access to assess, and the tool keeps working if the vendor has an outage.
The tradeoffs are real too: you need a server, someone to apply updates, and backups you test. Modern on-premises tools reduce this with guided installs, automatic database backups and one-step updates.
Questions to ask any vendor
- Where is our data stored, and who at your company can access it?
- Does the product make any outbound connections (telemetry, license checks, AI services)?
- How do we verify the integrity of your software before installing it (CIP-010 R1.6)?
- How will you notify us of incidents and vulnerabilities (CIP-013 R1.2)?
- Will you complete the NATF Energy Sector Supply Chain Risk Questionnaire?
- If you use AI, where does the model run, and can it change compliance dates or facts?
- What happens to our data, and our ability to use the tool, if your company disappears?
Our view
We built CIP Sentry on-premises because we think small and mid-size utilities shouldn’t have to take on extra CIP-011 and CIP-013 work just to organize their compliance program. But the right answer depends on your team, your IT capabilities and your risk appetite. Ask the questions above of every vendor, including us: our answers are in the Trust Center.

