“Low impact” isn't low effort
Policies, awareness, physical and electronic access controls, incident response, transient assets and now vendor remote access.
For low impact entities
For many entities CIP-003 is the entire CIP program. It became harder on April 1, 2026, when CIP-003-9 added vendor electronic remote access controls, and CIP-003-11 adds more in 2029. CIP Sentry turns Attachment 1 into a program you can run and prove.
Low impact requirements are where most registered entities live, and where the newest obligations are landing. A structured, evidence-first plan is the difference between a smooth audit and a scramble.
Policies, awareness, physical and electronic access controls, incident response, transient assets and now vendor remote access.
OEM modems, cellular gateways and integrator VPNs at remote sites are easy to miss.
A 36-month incident response test and a 15-month policy approval don't feel urgent until they're late.
How CIP Sentry helps
Build and maintain the plan for all six sections, with evidence attached to each.
Document how vendor electronic remote access is determined, disabled and monitored for malicious communications.
15-month policy approval and awareness, 36-month incident response tests and 180-day plan updates.
Keep your plan structured so the 2029 changes are an update, not a rewrite.
For assets containing low impact BES Cyber Systems with vendor electronic remote access, you need methods to determine when vendors have access, to disable it, and to detect known or suspected malicious communications for both inbound and outbound traffic.
Yes. Quotes are sized to scope. A low-impact-only program is priced well below a multi-site medium impact deployment.
Request a quote
Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.