NERC CIP software with BES cyber asset inventory as a live control, not a quarterly spreadsheet.
BES cyber system categorisation, electronic and physical access control evidence, configuration and change management, personnel & training records, incident response and recovery — all mapped to CIP-002 through CIP-014 with signed, hash-chained audit trail. On-premises for OT segmentation, cloud for corporate boundary.
You're shopping for NERC CIP software because the next Regional Entity audit is scheduled and your CIP-010 baselines live in three different tools.
BES cyber asset inventory drifts between spreadsheets and reality
CIP-010 configuration baselines get compared to production once a quarter
CIP-004 access review is a per-person email chain, not a report
TFEs (Technical Feasibility Exceptions) live in a shared drive folder
Evidence for an audit is a two-month project every three years
Incident response tabletops don't produce CIP-008-compliant records
NERC CIP controls that survive a Regional Entity audit.
BES cyber system inventory (CIP-002)
High / Medium / Low impact categorisation with BES cyber asset, BES cyber system and associated systems tracked live. Categorisation review workflow with signed approval.
Electronic + physical access (CIP-005/006)
ESP and PSP asset inventory, access request / review / revoke workflow, interactive remote access session logging, and physical access log ingestion — all evidenced by control.
Configuration change management (CIP-010)
Baseline configuration per BES cyber asset, change authorisation workflow with security impact analysis, and 35-day monitoring for unauthorised change. Baseline compare runs on schedule, not on request.
Personnel & training (CIP-004)
PRA (Personnel Risk Assessment) tracking, CIP training completion, access authorisation matrix and 15-month access review — all live, all evidenced.
Incident response + recovery (CIP-008/009)
Incident response plan execution, reportable Cyber Security Incident workflow with 1-hour E-ISAC / DOE notification clock, recovery plan test records and lessons-learned.
TFE workflow
Technical Feasibility Exception lifecycle — justification, compensating measures, approval, expiry — with automatic re-review when the underlying standard revises.
What changes when NERC CIP is one system.
- Regional Entity audit prep drops from months to weeks
- CIP-010 baseline drift surfaces in days, not at the next audit cycle
- CIP-004 15-month access reviews run on schedule and produce evidence
- TFEs stop expiring silently
- Reportable Cyber Security Incidents hit the 1-hour clock, every time
- One evidence base serves NERC CIP, NIST 800-53 and IEC 62443
Every NERC CIP standard your Regional Entity will ask about.
CIP-002 (BES Cyber System Categorisation)
High / Medium / Low impact rating with cyber asset, cyber system and associated system tracking. Categorisation review with signed approval.
CIP-003 through CIP-007
Security management controls, personnel & training, electronic security perimeters, physical security, systems security management — evidenced through platform behaviour.
CIP-008 (Incident Reporting)
Reportable Cyber Security Incident and attempted-compromise workflow with 1-hour E-ISAC / DOE notification clock, evidence preservation and post-incident review.
CIP-009 (Recovery Plans)
Recovery plan authoring, exercise scheduling, execution evidence and lessons-learned tracked live.
CIP-010 (Configuration Change Mgmt)
Baseline configurations, authorised change workflow with security impact analysis, and 35-day unauthorised-change monitoring.
CIP-011 / CIP-013 / CIP-014
Information protection, supply chain risk management and physical security of critical facilities modeled natively.
NERC CIP software, answered.
What is NERC CIP software?
NERC CIP software is the system that inventories BES cyber assets, enforces and evidences CIP-002 through CIP-014 controls (categorisation, access, configuration, incident response, recovery, information protection, supply chain, physical security) and produces the signed audit trail a Regional Entity auditor accepts as evidence.
Does V5 cover the whole CIP standard set?
Yes. CIP-002 through CIP-014 are all mapped to platform controls with live evidence. The platform is not itself an auditor — the Regional Entity (WECC, RF, SERC, MRO, NPCC, Texas RE) still audits — but audit prep collapses because the evidence is already produced.
Cloud or on-premises?
Both. V5 Ultimate On-Premises is preferred for OT-segmented boundaries where BES cyber system data must not traverse the corporate network to a multi-tenant SaaS. Cloud is used for corporate-side registration, PRA, training and vendor management.
How does TFE tracking work?
Technical Feasibility Exceptions carry a justification, compensating measures, approval chain, expiry and required re-review. When the underlying CIP standard revises, affected TFEs surface automatically for re-assessment — they don't quietly go stale in a shared drive.
Does V5 also cover NIST 800-53 and IEC 62443?
Yes. The evidence base for NERC CIP largely subsumes NIST SP 800-53 low/moderate baseline and IEC 62443-2-1 requirements for operators. Utilities running CIP, RMF and IEC-based OT programs reuse one control set.
How long does implementation take?
Most utilities stand up BES cyber asset inventory and CIP-004 access review within 30–45 days. Full CIP-010 baseline coverage across High and Medium impact assets typically takes 12–20 weeks depending on OT footprint.
Turn Regional Entity audits into a report extract — not another six-month evidence-collection sprint.
Free trial. On-prem evaluation available. No sales gate.
