Dashboard
Program-wide
Coverage across every CIP standard and what needs attention now.
The platform
Eighteen modules that follow the structure of the standards themselves, connected by one set of assets, people and deadlines. Installed on your server, used from any browser on your network.
Illustration with sample data from a fictional utility.
Modules
Each module maps to the requirements it supports, so evidence lands in the right place the first time.
Program-wide
Coverage across every CIP standard and what needs attention now.
CIP-002 · CIP-010
Every Cyber Asset in or out of scope. Import from spreadsheets, Word, CSV and PDF.
CIP-002 · CIP-005 · CIP-006
Systems by impact rating with Attachment 1 criteria, plus facilities and perimeters.
CIP-006 · CIP-014
Perimeters, visitors, PACS testing, and transmission station risk assessments.
CIP-004
PRAs, training, access grants, revocations and privilege reviews.
CIP-010
Change management forms (CMFs) from initiation to authorization by the CAO (Cyber Asset Owner), with baseline history.
TFE · CEC
Technical Feasibility Exceptions and CIP Exceptional Circumstances, tracked to expiry.
CIP-007
Patch management on the 35-day clock and security event log review.
CIP-008
Response plans, the 1-hour reporting clock, tests and lessons learned.
CIP-009
Recovery plans with 15- and 36-month test clocks.
CIP-013
Risk management plan and a prequalified vendor list for procurement.
CIP-003
CIP Senior Manager-approved policies and the low impact plan.
CIP-012
Links between Control Centers and how their data is protected.
CIP-011
Your BCSI program and a register of where BCSI lives.
CIP-015
Your INSM program, built ahead of the 2028 enforcement date.
Any standard
Corrective action plans for compliance gaps, tracked to closure.
Audit readiness
CIP catalog, Evidence Vault, Audit Trail and 51 ready-made reports.
CIP-003 R3/R4
CIP Senior Manager, delegates and each group’s CAO (Cyber Asset Owner, also called Change Authorizer Officer), with designation history.
Compliance clocks
Every periodic obligation is computed from the last time it was done, not typed into a calendar by hand. The reminder bell counts overdue and due-soon items, re-checks every 15 minutes while CIP Sentry is open, and can raise a Windows notification once a day.
Change control
Change management forms carry each change from initiation through NERC impact assessment to authorization by the group’s CAO (Cyber Asset Owner, also called Change Authorizer Officer), then implementation and verification. The baseline history and the attestations stay with the asset.
Firmware update · RTU-RIV-07 (Riverside Generating Station)
Audit Center
The CIP Catalog, Evidence Vault, Audit Trail and Reports are in one place. When the audit notice arrives, choose from 51 ready-made reports or build your own, and export to PDF or Excel.
| Requirement | Evidence | Date |
|---|---|---|
| CIP-004 R2.3 | Training roster Q3 (PDF) | Sep 18 |
| CIP-007 R2.2 | Patch source review · EMS | Sep 14 |
| CIP-008 R2.1 | Tabletop exercise report | Aug 30 |
| CIP-010 R1.2 | CMF-2026-038 signed | Aug 27 |
| CIP-006 R3.1 | PACS test · North Sub | Aug 11 |
Optional add-on module
An optional module you can add to any CIP Sentry license, at purchase or later. It runs on your server or a machine on your network, and nothing is sent to the internet.
Here’s the recommended order. Each step opens the right page:
Include it in your first quote or add it later. The eighteen modules above work fully on their own.
Due dates, overdue items and report numbers always come from CIP Sentry’s records and rules. Numbers the AI can’t trace to your records are removed.
An open model runs where your data is. Choose Basic, Standard or Advanced to match your hardware.
Deployment & operations
Platform FAQ
One Windows computer that stays on, with Docker Desktop and Node.js. A guided script creates fresh random secrets, builds and starts everything, and prints the addresses people use. The first administrator is created with a one-time setup code that can only be read on the server.
Copy the new version over the old folder (your settings, certificates, uploads and backups are kept) and run the update script. It backs up the database first, builds, restarts, upgrades the database automatically and prints a health report. If a step fails, it stops and tells you where your backup is. Each release comes with SHA-256 hashes so you can verify it first.
No, the AI Assistant is an optional add-on module. If you add it, Basic mode runs on any computer. Standard mode (reading scans and photos, plain-English reports) needs a graphics card with about 8 GB of memory. Advanced mode uses a 24 GB card or a shared AI server on your network.
Yes. Asset lists import from spreadsheets, Word, CSV and text PDFs by matching their labels. With the optional AI Assistant module, CIP Sentry can also read photos, scans and spec sheets into the asset form for you to review.
Access is role-based per module (dashboard, cyber assets, change management, system security, mitigation, roles and seats and more). Changes are recorded in the audit trail.
Request a quote
Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.