CIP-003-9 and CIP-012-2 are in force. CIP-015 lands October 2028.

NERC CIP compliance, audit-ready, on your own servers.

CIP Sentry brings all 14 CIP standards, CIP-002 through CIP-015, into one secure workspace that runs inside your network. Change control that holds, deadlines that can’t slip, and evidence your auditors can trace.

  • Runs on your servers
  • No cloud, no vendor access
  • Optional private AI

Example Municipal Power

Compliance overview

Server onlineLocal AI · Standard

Standards in scope

14

CIP-002 → CIP-015

Due in 30 days

7

2 due this week

CMFs awaiting CAO

2

Oldest: 3 days

Overdue items

0

All clocks green

Compliance clocks

Next 90 days
  • CIP-007 R2.3Patch evaluation · EMS-APP-016 days
  • CIP-010 R2.1Baseline monitoring · North Substation11 days
  • CIP-004 R2.3Cyber security training · 3 people19 days
  • CIP-008 R2.1Incident response plan test41 days
  • CIP-003 R1.1Policy review · CIP Senior Manager64 days

Coverage by standard

Requirements with evidence
CIP-002
100%
CIP-003
96%
CIP-004
92%
CIP-005
100%
CIP-006
94%
CIP-007
88%
CIP-008
100%
CIP-009
97%
CIP-010
90%
CIP-011
100%
CIP-012
100%
CIP-013
95%
CIP-014
100%
CIP-015
62%
Illustration of the CIP Sentry interface with sample data.

Illustration with sample data from a fictional utility.

  • 14CIP standards in one workspace, CIP-002 to CIP-015
  • 20+recurring deadlines tracked from your own records
  • 51ready-made audit reports in PDF and Excel
  • 0bytes of compliance data sent to anyone's cloud

The problem

CIP compliance shouldn’t live in spreadsheets and inboxes.

Most small and mid-size utilities run their CIP program on shared drives, calendar reminders and a few people’s memory. It works until an audit notice arrives or someone leaves.

Clocks that live in someone’s head

35-day patch evaluations, 15-month reviews, 36-month tests, 24-hour revocations. One missed date is a possible violation.

Evidence scattered across drives

Screenshots in email, rosters in SharePoint, sign-offs on paper. Audit prep turns into a three-month scavenger hunt.

Changes nobody formally approved

CIP-010 baseline changes made in a hurry, documented later, or never tied to an authorization and a security-control test.

Tools that want your BCSI in the cloud

Most modern platforms are SaaS. Putting BES Cyber System Information there means more CIP-011 and CIP-004 R6 work, not less.

Why CIP Sentry

One secure command center for your whole CIP program.

Inside your perimeter

CIP Sentry runs on a server you control. Your compliance records, evidence and the optional AI stay on your network. No inbound connections, no vendor access, no cloud tenant.

Every requirement, every clock

All 14 standards, structured requirement by requirement. More than 20 recurring deadlines are calculated from your own records and surfaced before they are due.

Audit-ready by default

Evidence vault, audit trail, a requirement catalog auditors recognize and 51 ready-made reports in PDF and Excel. Your audit package already exists.

Change management · CIP-010

No baseline change without a signed authorization.

Every configuration change moves through a change management form (CMF): initiation, NERC impact assessment, authorization by the group’s CAO (Cyber Asset Owner, also called Change Authorizer Officer), implementation and verification. The baseline history updates itself and the signatures are on the record.

  • CAO authorization and completion attestations on every change
  • Per-asset baseline history with a one-click baseline report
  • Technical Feasibility Exceptions and CIP Exceptional Circumstances tracked to expiry
CMF-2026-041Awaiting CAO

Firmware update · RTU-RIV-07 (Riverside Generating Station)

  1. InitiatedM. Okafor · Sep 22
  2. NERC impact assessmentCIP-007 R1, R2 · CIP-010 R1.1
  3. CAO authorizationJ. Rivera · signature required
  4. Implemented & baseline updatedWithin 30 days of change
  5. VerifiedSecurity controls tested (R1.4)
CAO attestationI authorize this change to the baseline configuration.

Compliance clocks

Deadlines that can’t slip.

CIP Sentry computes periodic obligations from your own records: patch actions, log reviews, training, access reviews, plan tests and CIP Senior Manager approvals. Due-soon items surface in the app, as desktop notifications, and in your calendar.

  • 35-day, 15-month and 36-month clocks calculated, not typed in
  • Access revocation deadlines from the moment access should end
  • One click exports every deadline for 13 months to Outlook, Google or Apple Calendar
Reminders3 due soon
  • 07OCT
    Patch evaluationCIP-007 R2.3 · 35-day clock
  • 14OCT
    Log review sampleCIP-007 R4.4 · 15-day clock
  • 02NOV
    IR plan testCIP-008 R2.1 · 15-month clock
Add all deadlines to my calendar (.ics)

Audit Center

Your audit package already exists.

Evidence is stored against the requirement it proves. The audit trail shows who changed what and when. When the notice arrives, you pick reports; you don’t assemble binders.

  • Requirement catalog, Evidence Vault, Audit Trail and Reports in one place
  • 51 ready-made reports plus a report builder, in PDF and Excel
  • Mitigation plans tracked to closure across any standard
Evidence VaultAudit-ready
RequirementEvidenceDate
CIP-004 R2.3Training roster Q3 (PDF)Sep 18
CIP-007 R2.2Patch source review · EMSSep 14
CIP-008 R2.1Tabletop exercise reportAug 30
CIP-010 R1.2CMF-2026-038 signedAug 27
CIP-006 R3.1PACS test · North SubAug 11
PDFExcel51 ready-made reports

Optional add-on · AI Assistant

An optional AI Assistant, on your own hardware.

Add the AI Assistant module to guide your team through each process, import existing asset records on day one and build reports from plain-English requests. Mock audits and audit response preparation are coming soon. It never decides a compliance fact.

  • Optional module: include it at purchase or add it later
  • Runs locally. Nothing is sent to the internet
  • Dates and numbers always come from your records; your team approves every draft
See what the AI Assistant does
CIP AdvisorAI Assistant
I’m the new admin. Walk me through setting up CIP Sentry.

Here’s the recommended order. Each step opens the right page:

  1. Access controlAdd accounts for your teamGo
  2. Roles & SeatsCIP Senior Manager and each group’s CAOGo
  3. PoliciesCIP-003 R1, approved by the CIP Senior ManagerGo
  4. Facilities & perimetersESPs and PSPsGo
  5. Import assetsUpload the documents you already haveGo

Coverage

All 14 CIP standards. One workspace.

From BES Cyber System categorization to internal network security monitoring. Each standard has its own module and a free, plain-English guide.

Deployment

Everything stays inside your perimeter.

One server on your network runs the whole platform. The database and API aren’t reachable from the network, connections use TLS from a certificate authority you control, and the optional AI model runs on the same hardware.

  • Guided install on a Windows server with Docker
  • Nightly database backups and an automatic backup before every update
  • A diagnostics tool that explains any problem in plain English
  • No inbound internet connection, no telemetry, no vendor remote access
  • Every update backs up the database first and ends with a health report
CIP Sentry deployment architectureUsers' browsers and the desktop app connect over HTTPS to one CIP Sentry server inside the utility network. The server runs the web app, the API, a PostgreSQL database and an optional add-on AI model that runs locally. Nothing connects to the internet.YOUR UTILITY NETWORKWeb browsersYour compliance teamDesktop appWindows, on the serverCalendar & email.ics files, your SMTPHTTPSCIP Sentry serverOne computer you controlWeb app · port 2443TLS with your own certificate authorityAPI · compliance clocks · reportsBound to this computer onlyPostgreSQL databaseNightly backups · 30 days keptAI Assistant (optional)Add-on. Local model via Ollama.Nothing is sent to the internet.Internet / cloudNot required.No inbound connections.

Trust Center

Built for your CIP-013 vendor review.

You have to assess every vendor that touches your BES Cyber Systems. We publish the answers before you ask.

Visit the Trust Center
  • Software integritySHA-256 hashes published for every release so you can verify it before installing (CIP-010 R1.6, CIP-013 R1.2.5)
  • Vulnerability disclosureA public disclosure policy, security.txt and customer advisories (R1.2.4)
  • Incident notificationA written commitment and a named security contact (R1.2.1, R1.2.2)
  • No vendor remote accessOn-premises by design. Support happens only in customer-initiated sessions (R1.2.3, R1.2.6)

Questions

Straight answers.

Is CIP Sentry cloud software?

No. CIP Sentry is installed on a server inside your network, and people use it in their browser or the Windows desktop app. It needs no internet connection to work, and we have no standing access to your system.

Which NERC CIP standards does it cover?

All 14: CIP-002 through CIP-015, including CIP-003 low impact programs, CIP-012 control center communications, CIP-014 transmission station security and CIP-015 internal network security monitoring (built ahead of its October 2028 enforcement date). See the standards guides.

Is the AI required? Does it send our data anywhere?

No, and no. The AI Assistant is an optional add-on module you can include at purchase or add later. It runs on your own hardware through a local model, and it never decides a compliance fact: due dates, overdue items and report numbers always come from CIP Sentry’s own records and rules.

Is CIP Sentry certified by NERC?

NERC does not certify software, and no tool can make you compliant by itself. CIP Sentry is built requirement by requirement from the official standards so your program, evidence and deadlines are organized the way auditors expect.

How is CIP Sentry priced?

By quote, sized to your registered functions, impact levels and number of sites. Small low-impact-only entities pay much less than multi-site medium-impact programs. Request a quote.

How does CIP Sentry support our CIP-013 review of you as a vendor?

Our Trust Center answers the CIP-013 R1.2 vendor items up front: incident notification, vulnerability disclosure, software integrity verification and remote access (there is none). We complete the NATF Energy Sector Supply Chain Risk Questionnaire on request.

Request a quote

See CIP Sentry on your own terms.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.