Free tool · 10 minutes

How ready are you for your next CIP audit?

26 questions based on the requirements auditors test most. Answer honestly, get a readiness score by area and a prioritized list of fixes. Your answers never leave this page.

01Governance & categorizationCIP-002 · CIP-003

Your CIP Senior Manager is named, and every change of CSM or delegate was documented within 30 days.

Cyber security policies were approved by the CIP Senior Manager within the last 15 calendar months.

Your BES Cyber System categorization was reviewed and approved within the last 15 calendar months, with the Attachment 1 criterion recorded for each system.

If you have low impact assets, your Attachment 1 plan covers all six sections, including vendor electronic remote access (Section 6, since April 2026).

02People & accessCIP-004

Everyone with authorized access completed training in the last 15 months and has a PRA within 7 years.

You can show quarterly verification that everyone with access has an authorization record.

For every termination in the last three years, you can show access removal within 24 hours, with timestamps.

03Perimeters & physical securityCIP-005 · CIP-006

Every permitted rule at every Electronic Access Point has a documented reason.

Interactive Remote Access uses an Intermediate System, encryption and MFA, and you can see and disable active vendor sessions.

Physical access logs and visitor logs are retained for at least 90 days, and PACS were tested within the last 24 months.

04System securityCIP-007

Patch sources are identified for all software and firmware, and every 35-day evaluation in the last three years is recorded.

Every applicable patch was applied, or a dated mitigation plan created or revised, within 35 days of evaluation, and mitigation plans closed on time.

For high impact systems, a sample of logged security events is reviewed at least every 15 days, with records.

Enabled ports and services are justified per asset, and default/generic accounts are inventoried.

05Change managementCIP-010

Every applicable Cyber Asset has a current baseline with all five required elements.

Every baseline change in the last three years was authorized before it was made, and the baseline was updated within 30 days.

You verify software integrity and authenticity (hashes or signatures) before installing updates.

A vulnerability assessment was performed within the last 15 months, with a dated action plan.

06Incident response & recoveryCIP-008 · CIP-009

The incident response plan was tested within the last 15 months, and lessons learned were documented within 90 days.

Your team knows who decides whether an incident is reportable, and how to notify the E-ISAC and CISA within 1 hour.

Recovery plans were tested within 15 months, and a sample of backups was restored successfully.

07Information protection & supply chainCIP-011 · CIP-012 · CIP-013

You know every location where BCSI is stored, including cloud tools and email, and who can access it.

Your supply chain risk management plan was approved within the last 15 months, and recent purchases show risk assessment.

If you operate a Control Center, your CIP-012 plan covers availability and link recovery (new in CIP-012-2, July 2026).

08Audit readinessProgram-wide

Evidence for each requirement can be produced within a day, without searching inboxes or personal drives.

More than one person could run the program if your compliance lead were unavailable for a month.

Request a quote

See CIP Sentry on your own terms.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.