Clocks that live in someone’s head
35-day patch evaluations, 15-month reviews, 36-month tests, 24-hour revocations. One missed date is a possible violation.
CIP-003-9 and CIP-012-2 are in force. CIP-015 lands October 2028.
CIP Sentry brings all 14 CIP standards, CIP-002 through CIP-015, into one secure workspace that runs inside your network. Change control that holds, deadlines that can’t slip, and evidence your auditors can trace.

Illustration with sample data from a fictional utility.
The problem
Most small and mid-size utilities run their CIP program on shared drives, calendar reminders and a few people’s memory. It works until an audit notice arrives or someone leaves.
35-day patch evaluations, 15-month reviews, 36-month tests, 24-hour revocations. One missed date is a possible violation.
Screenshots in email, rosters in SharePoint, sign-offs on paper. Audit prep turns into a three-month scavenger hunt.
CIP-010 baseline changes made in a hurry, documented later, or never tied to an authorization and a security-control test.
Most modern platforms are SaaS. Putting BES Cyber System Information there means more CIP-011 and CIP-004 R6 work, not less.
Why CIP Sentry
CIP Sentry runs on a server you control. Your compliance records, evidence and the optional AI stay on your network. No inbound connections, no vendor access, no cloud tenant.
All 14 standards, structured requirement by requirement. More than 20 recurring deadlines are calculated from your own records and surfaced before they are due.
Evidence vault, audit trail, a requirement catalog auditors recognize and 51 ready-made reports in PDF and Excel. Your audit package already exists.
Change management · CIP-010
Every configuration change moves through a change management form (CMF): initiation, NERC impact assessment, authorization by the group’s CAO (Cyber Asset Owner, also called Change Authorizer Officer), implementation and verification. The baseline history updates itself and the signatures are on the record.
Firmware update · RTU-RIV-07 (Riverside Generating Station)
Compliance clocks
CIP Sentry computes periodic obligations from your own records: patch actions, log reviews, training, access reviews, plan tests and CIP Senior Manager approvals. Due-soon items surface in the app, as desktop notifications, and in your calendar.
Audit Center
Evidence is stored against the requirement it proves. The audit trail shows who changed what and when. When the notice arrives, you pick reports; you don’t assemble binders.
| Requirement | Evidence | Date |
|---|---|---|
| CIP-004 R2.3 | Training roster Q3 (PDF) | Sep 18 |
| CIP-007 R2.2 | Patch source review · EMS | Sep 14 |
| CIP-008 R2.1 | Tabletop exercise report | Aug 30 |
| CIP-010 R1.2 | CMF-2026-038 signed | Aug 27 |
| CIP-006 R3.1 | PACS test · North Sub | Aug 11 |
Optional add-on · AI Assistant
Add the AI Assistant module to guide your team through each process, import existing asset records on day one and build reports from plain-English requests. Mock audits and audit response preparation are coming soon. It never decides a compliance fact.
Here’s the recommended order. Each step opens the right page:
Coverage
From BES Cyber System categorization to internal network security monitoring. Each standard has its own module and a free, plain-English guide.
Deployment
One server on your network runs the whole platform. The database and API aren’t reachable from the network, connections use TLS from a certificate authority you control, and the optional AI model runs on the same hardware.
Built for
Municipal and state utilities that need government-grade procurement and on-premises control.
Distribution and G&T co-ops running CIP with one or two people.
IPPs and newly registered inverter-based resources starting CIP-003 from zero.
TOs, TOPs and control centers with medium impact systems, CIP-012 and CIP-014.
Trust Center
You have to assess every vendor that touches your BES Cyber Systems. We publish the answers before you ask.
Visit the Trust CenterQuestions
No. CIP Sentry is installed on a server inside your network, and people use it in their browser or the Windows desktop app. It needs no internet connection to work, and we have no standing access to your system.
All 14: CIP-002 through CIP-015, including CIP-003 low impact programs, CIP-012 control center communications, CIP-014 transmission station security and CIP-015 internal network security monitoring (built ahead of its October 2028 enforcement date). See the standards guides.
No, and no. The AI Assistant is an optional add-on module you can include at purchase or add later. It runs on your own hardware through a local model, and it never decides a compliance fact: due dates, overdue items and report numbers always come from CIP Sentry’s own records and rules.
NERC does not certify software, and no tool can make you compliant by itself. CIP Sentry is built requirement by requirement from the official standards so your program, evidence and deadlines are organized the way auditors expect.
By quote, sized to your registered functions, impact levels and number of sites. Small low-impact-only entities pay much less than multi-site medium-impact programs. Request a quote.
Our Trust Center answers the CIP-013 R1.2 vendor items up front: incident notification, vulnerability disclosure, software integrity verification and remote access (there is none). We complete the NATF Energy Sector Supply Chain Risk Questionnaire on request.
Request a quote
Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.