Free tool
Your CIP compliance calendar, dated.
Enter when you last completed each recurring obligation. We calculate the next due date, flag anything overdue, and give you a calendar file for Outlook, Google or Apple Calendar. Nothing leaves your browser.
| Include | Obligation | Interval | Last completed | Next due | Status |
|---|---|---|---|---|---|
| CIP-002-5.1a R2Review BES Cyber System categorization and CIP Senior Manager approval | 15 calendar months | — | |||
| CIP-003-9 R1.1CIP Senior Manager approval of high/medium impact policies | 15 calendar months | — | |||
| CIP-003-9 R1.2CIP Senior Manager approval of low impact policies | 15 calendar months | — | |||
| CIP-003-9 Att. 1 Sec. 1Low impact security awareness reinforcement | 15 calendar months | — | |||
| CIP-003-9 Att. 1 Sec. 4.5Test the low impact incident response plan | 36 calendar months | — | |||
| CIP-004-7 R1.1Security awareness reinforcement | Each calendar quarter | — | |||
| CIP-004-7 R2.3Cyber security training (per person) | 15 calendar months | — | |||
| CIP-004-7 R4.2Verify active access has authorization records | Each calendar quarter | — | |||
| CIP-004-7 R4.3Verify electronic access privileges are correct and necessary | 15 calendar months | — | |||
| CIP-004-7 R3.5Personnel risk assessment (per person) | 84 calendar months | — | |||
| CIP-006-6 R3.1PACS maintenance and testing | 24 calendar months | — | |||
| CIP-007-6 R2.2Evaluate security patches from each source | 35 calendar days | — | |||
| CIP-007-6 R4.4Review a sample of logged security events (high impact) | 15 calendar days | — | |||
| CIP-007-6 R5.6Change passwords (where technically feasible) | 15 calendar months | — | |||
| CIP-008-6 R2.1Test the Cyber Security Incident response plan | 15 calendar months | — | |||
| CIP-009-6 R2.1Test each recovery plan | 15 calendar months | — | |||
| CIP-009-6 R2.2Test a representative sample of backup information | 15 calendar months | — | |||
| CIP-009-6 R2.3Operational exercise of the recovery plan (high impact) | 36 calendar months | — | |||
| CIP-010-4 R2.1Monitor for baseline changes (high impact) | 35 calendar days | — | |||
| CIP-010-4 R3.1Paper or active vulnerability assessment | 15 calendar months | — | |||
| CIP-010-4 R3.2Active vulnerability assessment (high impact) | 36 calendar months | — | |||
| CIP-013-2 R3Review and approve the supply chain risk management plan | 15 calendar months | — |
“Calendar months” are calculated conservatively as due by the last day of the Nth month after the month you last performed the task (for example, done in March 2026 with a 15-month interval → due by June 30, 2027). Some entities use shorter internal targets; follow your own documented procedures. Quarterly items are due by the end of the next calendar quarter. Event-driven deadlines (24-hour revocation, 1-hour incident reporting, 30/60/90-day updates) are not calendar-based and aren't listed here; CIP Sentry tracks those too.
Why a calendar isn't enough on its own
A calendar tells you when something is due. It doesn’t prove you did it, who approved it, or which evidence goes with it, and it doesn’t recalculate when work is finished early or late. That is the gap CIP Sentry fills: every clock is recalculated from your records the moment a task is completed, and the evidence is stored against the requirement.
Request a quote
Stop maintaining the calendar by hand.
Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.

