The platform

One secure workspace for your entire CIP program.

Eighteen modules that follow the structure of the standards themselves, connected by one set of assets, people and deadlines. Installed on your server, used from any browser on your network.

Example Municipal Power

Compliance overview

Server onlineLocal AI · Standard

Standards in scope

14

CIP-002 → CIP-015

Due in 30 days

7

2 due this week

CMFs awaiting CAO

2

Oldest: 3 days

Overdue items

0

All clocks green

Compliance clocks

Next 90 days
  • CIP-007 R2.3Patch evaluation · EMS-APP-016 days
  • CIP-010 R2.1Baseline monitoring · North Substation11 days
  • CIP-004 R2.3Cyber security training · 3 people19 days
  • CIP-008 R2.1Incident response plan test41 days
  • CIP-003 R1.1Policy review · CIP Senior Manager64 days

Coverage by standard

Requirements with evidence
CIP-002
100%
CIP-003
96%
CIP-004
92%
CIP-005
100%
CIP-006
94%
CIP-007
88%
CIP-008
100%
CIP-009
97%
CIP-010
90%
CIP-011
100%
CIP-012
100%
CIP-013
95%
CIP-014
100%
CIP-015
62%
Illustration of the CIP Sentry interface with sample data.

Illustration with sample data from a fictional utility.

Modules

Organized the way the standards are.

Each module maps to the requirements it supports, so evidence lands in the right place the first time.

Dashboard

Program-wide

Coverage across every CIP standard and what needs attention now.

Cyber Assets

CIP-002 · CIP-010

Every Cyber Asset in or out of scope. Import from spreadsheets, Word, CSV and PDF.

BES Cyber Systems

CIP-002 · CIP-005 · CIP-006

Systems by impact rating with Attachment 1 criteria, plus facilities and perimeters.

Physical Security

CIP-006 · CIP-014

Perimeters, visitors, PACS testing, and transmission station risk assessments.

Personnel & Access

CIP-004

PRAs, training, access grants, revocations and privilege reviews.

Change Management

CIP-010

Change management forms (CMFs) from initiation to authorization by the CAO (Cyber Asset Owner), with baseline history.

Exceptions

TFE · CEC

Technical Feasibility Exceptions and CIP Exceptional Circumstances, tracked to expiry.

System Security

CIP-007

Patch management on the 35-day clock and security event log review.

Incident Response

CIP-008

Response plans, the 1-hour reporting clock, tests and lessons learned.

Recovery Plans

CIP-009

Recovery plans with 15- and 36-month test clocks.

Supply Chain Risk

CIP-013

Risk management plan and a prequalified vendor list for procurement.

Policy & Low Impact

CIP-003

CIP Senior Manager-approved policies and the low impact plan.

Control Center Links

CIP-012

Links between Control Centers and how their data is protected.

Information Protection

CIP-011

Your BCSI program and a register of where BCSI lives.

Network Monitoring

CIP-015

Your INSM program, built ahead of the 2028 enforcement date.

Mitigation Plans

Any standard

Corrective action plans for compliance gaps, tracked to closure.

Audit Center

Audit readiness

CIP catalog, Evidence Vault, Audit Trail and 51 ready-made reports.

Roles & Seats

CIP-003 R3/R4

CIP Senior Manager, delegates and each group’s CAO (Cyber Asset Owner, also called Change Authorizer Officer), with designation history.

Compliance clocks

More than 20 recurring deadlines, calculated for you.

Every periodic obligation is computed from the last time it was done, not typed into a calendar by hand. The reminder bell counts overdue and due-soon items, re-checks every 15 minutes while CIP Sentry is open, and can raise a Windows notification once a day.

  • Training (15 months), PRAs (7 years), privilege reviews and access revocation deadlines
  • Patch actions (35 days), log reviews (15 days), baseline monitoring (35 days)
  • Plan tests, policy approvals, supply chain plan reviews and PACS testing
  • Low impact awareness, incident response tests and plan updates
  • Download every deadline for the next 13 months as a calendar file (.ics)
Reminders3 due soon
  • 07OCT
    Patch evaluationCIP-007 R2.3 · 35-day clock
  • 14OCT
    Log review sampleCIP-007 R4.4 · 15-day clock
  • 02NOV
    IR plan testCIP-008 R2.1 · 15-month clock
Add all deadlines to my calendar (.ics)

Change control

Authorization before change, every time.

Change management forms carry each change from initiation through NERC impact assessment to authorization by the group’s CAO (Cyber Asset Owner, also called Change Authorizer Officer), then implementation and verification. The baseline history and the attestations stay with the asset.

  • CAO authorization and completion attestations
  • Per-asset baseline reports with gaps flagged
  • Move, disposal, physical security and new-asset workflows
CMF-2026-041Awaiting CAO

Firmware update · RTU-RIV-07 (Riverside Generating Station)

  1. InitiatedM. Okafor · Sep 22
  2. NERC impact assessmentCIP-007 R1, R2 · CIP-010 R1.1
  3. CAO authorizationJ. Rivera · signature required
  4. Implemented & baseline updatedWithin 30 days of change
  5. VerifiedSecurity controls tested (R1.4)
CAO attestationI authorize this change to the baseline configuration.

Audit Center

Evidence stored against the requirement it proves.

The CIP Catalog, Evidence Vault, Audit Trail and Reports are in one place. When the audit notice arrives, choose from 51 ready-made reports or build your own, and export to PDF or Excel.

  • Requirement catalog auditors recognize
  • Full audit trail of changes
  • Report builder with saved reports
Evidence VaultAudit-ready
RequirementEvidenceDate
CIP-004 R2.3Training roster Q3 (PDF)Sep 18
CIP-007 R2.2Patch source review · EMSSep 14
CIP-008 R2.1Tabletop exercise reportAug 30
CIP-010 R1.2CMF-2026-038 signedAug 27
CIP-006 R3.1PACS test · North SubAug 11
PDFExcel51 ready-made reports

Optional add-on module

AI Assistant

An optional module you can add to any CIP Sentry license, at purchase or later. It runs on your server or a machine on your network, and nothing is sent to the internet.

CIP AdvisorAI Assistant
I’m the new admin. Walk me through setting up CIP Sentry.

Here’s the recommended order. Each step opens the right page:

  1. Access controlAdd accounts for your teamGo
  2. Roles & SeatsCIP Senior Manager and each group’s CAOGo
  3. PoliciesCIP-003 R1, approved by the CIP Senior ManagerGo
  4. Facilities & perimetersESPs and PSPsGo
  5. Import assetsUpload the documents you already haveGo
Import a documentLocal AI
asset-sheet_HMI-NSUB-02.pdfRead by the AI on your server
  • Asset nameHMI-NSUB-02✓
  • OS / firmwareWindows 10 IoT LTSC✓
  • Ports & services2 listed✓
  • ESPESP-NSUB✓
  • Guided setup and help chatAsk CIP questions in plain English, or say you’re new and get a guided tour: accounts, roles, policies, facilities, systems, people, then assets, in the right order, each one a click away.
  • Asset import on day oneStart from the documents you already have. The assistant reads spreadsheets, Word files, PDFs, scans and photos into asset records and fills in baseline fields for you to review.
  • Reports in plain EnglishDescribe the report you need. The assistant builds it from your records, summarizes it and answers follow-up questions about it.
  • Mock auditComing soonRehearse before the auditors arrive. Run a practice audit across your program and get a list of gaps and weak or missing evidence to fix first.
  • Audit response preparationComing soonDraft answers to auditor questions and data requests from your own records and evidence, ready for your subject matter experts to review, edit and approve.

Optional module

Include it in your first quote or add it later. The eighteen modules above work fully on their own.

Never decides a fact

Due dates, overdue items and report numbers always come from CIP Sentry’s records and rules. Numbers the AI can’t trace to your records are removed.

Local by design

An open model runs where your data is. Choose Basic, Standard or Advanced to match your hardware.

Everything the AI Assistant does

Deployment & operations

Simple to run. Hard to break.

CIP Sentry deployment architectureUsers' browsers and the desktop app connect over HTTPS to one CIP Sentry server inside the utility network. The server runs the web app, the compliance clocks and reports, a secure database and an optional add-on AI model that runs locally. Nothing connects to the internet. It can also run in your own cloud, or on your company intranet as a web application.YOUR UTILITY NETWORKWeb browsersYour compliance teamDesktop appWindows, on the serverCalendar & emailAlerts via your emailHTTPSCIP Sentry serverOne computer you controlWeb appEncrypted connections you controlCompliance clocks · reportsNot reachable from the networkSecure databaseNightly backups · 30 days keptAI Assistant (optional)Add-on. Runs on this server.Nothing is sent to the internet.Internet / cloudNot required.No inbound connections.Can also run in your owncloud, or on your companyintranet as a web application.
  • One serverA Windows computer on your network. People connect in a web browser or use the desktop app.
  • Encrypted connectionsEvery connection inside your network is encrypted, with certificates your IT team controls.
  • Backups built inNightly database backups kept 30 days, plus a backup before every update.
  • Guided updatesThe update script backs up the database first, upgrades it automatically and prints a health report.
  • Plain-English diagnosticsA read-only diagnostics tool checks every component and tells you exactly what to fix.
  • Role-based accessPermissions per module, a one-time setup code for the first administrator, and an audit trail.

Platform FAQ

Practical questions

What does it take to install?

One Windows computer that stays on. A guided installer sets everything up, creates unique security keys for your installation and shows the address your team uses. The first administrator is created with a one-time setup code that can only be read on the server.

How do updates work?

Copy the new version over the old folder (your settings, certificates, uploads and backups are kept) and run the update script. It backs up the database first, builds, restarts, upgrades the database automatically and prints a health report. If a step fails, it stops and tells you where your backup is. Each release comes with SHA-256 hashes so you can verify it first.

Is the AI required? What hardware does it need?

No, the AI Assistant is an optional add-on module. If you add it, Basic mode runs on any computer. Standard mode (reading scans and photos, plain-English reports) needs a graphics card with about 8 GB of memory. Advanced mode uses a 24 GB card or a shared AI server on your network.

Can we import what we already have?

Yes. Asset lists import from spreadsheets, Word, CSV and text PDFs by matching their labels. With the optional AI Assistant module, CIP Sentry can also read photos, scans and spec sheets into the asset form for you to review.

Who can see what?

Access is role-based per module (dashboard, cyber assets, change management, system security, mitigation, roles and seats and more). Changes are recorded in the audit trail.

Request a quote

See CIP Sentry on your own terms.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.