Here is the honest situation. The NERC Critical Infrastructure Protection standards are mandatory, enforceable requirements for the North American bulk electric system. They run from categorizing BES Cyber Systems and setting security management controls through personnel, electronic and physical security, system security management, incident response, recovery, configuration and vulnerability management, information protection, communications between Control Centers, supply chain risk and physical protection of critical facilities. A responsible entity that runs its systems well but cannot show categorization, evidence retention or its incident reporting is exactly where responsible entities fall short in an audit.
This Kit removes the guesswork. It is the CIP standards written as adopt-ready controls you personalize in a weekend, with the evidence an auditor examines.
What you get, the moment you buy
Grounded in the NERC CIP standards, with BES Cyber System categorization, security management, personnel and training, electronic and physical security, system security, incident response, recovery, change and vulnerability management, information protection, Control Center communications and supply chain risk called out. Editable Word and Excel files.
What one control looks like
This is confirming applicability as a responsible entity, where scope begins. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. A CIP requirement you cannot evidence is a potential violation. This tells you what an auditor examines and where responsible entities fall short, for every standard.
- Categorization, evidence and supply chain built in. BES Cyber System categorization, compliance evidence retention and supply chain risk are written into the controls, the substance the CIP standards require.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. CIP aligns with NIST and ISO security, so this work feeds your wider operational technology security program.
Who buys this
Bulk electric system responsible entities and their compliance, security and operations leads. Whether it is a first alignment or an audit-readiness pass, you save weeks and walk in with categorization, security and evidence structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this an official NERC tool? No. It is an independent implementation toolkit grounded in the published CIP standards, to get your controls and evidence in order fast before an audit.
Does it cover BES Cyber System categorization? Yes. Categorizing systems by impact under CIP-002 is built as a control, and it drives the rest.
Does it cover supply chain risk? Yes. The CIP-013 supply chain cyber security risk management plan is built as a control.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com