Skip to main content
Image coming soon

NERC CIP Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
NERC CIP · Critical Infrastructure Protection · Evidence & Implementation Kit
Meet the NERC CIP standards, without decoding the requirements yourself.
Every standard handed to you as an adopt-ready control, from BES Cyber System categorization and electronic and physical security through system security and recovery to supply chain and reporting, with the evidence an auditor examines.
CIP-ready in a weekend, not a quarter.

Here is the honest situation. The NERC Critical Infrastructure Protection standards are mandatory, enforceable requirements for the North American bulk electric system. They run from categorizing BES Cyber Systems and setting security management controls through personnel, electronic and physical security, system security management, incident response, recovery, configuration and vulnerability management, information protection, communications between Control Centers, supply chain risk and physical protection of critical facilities. A responsible entity that runs its systems well but cannot show categorization, evidence retention or its incident reporting is exactly where responsible entities fall short in an audit.

This Kit removes the guesswork. It is the CIP standards written as adopt-ready controls you personalize in a weekend, with the evidence an auditor examines.

What you get, the moment you buy

18
Standards as adopt-ready controls. Every standard, from categorization and security management through system security to supply chain and reporting, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what an auditor examines, plus where responsible entities fall short, so you close the gap first.
1
CIP Control Matrix, pre-built. Every CIP standard in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each standard and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the NERC CIP standards, with BES Cyber System categorization, security management, personnel and training, electronic and physical security, system security, incident response, recovery, change and vulnerability management, information protection, Control Center communications and supply chain risk called out. Editable Word and Excel files.

Categorization drives everything, and evidence is audited
Under CIP-002 your BES Cyber System impact rating sets which requirements apply, and NERC audits turn on retained, dated evidence for each one. Get the categorization or the evidence retention wrong and the whole program is exposed to penalties. This Kit builds categorization and evidence into controls with what an auditor asks for.

What one control looks like

This is confirming applicability as a responsible entity, where scope begins. All 18 are built to this depth.

CIP-1 Confirm applicability as a responsible entity SCOPE
Put this control in place

Determine and document how the NERC Critical Infrastructure Protection standards apply to [your organization name] as a responsible entity for the bulk electric system, identifying its functional registrations and in-scope assets, so scope is clear and the organization can evidence its applicability assessment.

Standard note.

The NERC CIP standards are mandatory, enforceable reliability standards for responsible entities on the North American bulk electric system.

Evidence an auditor examines
  • An applicability assessment against NERC CIP
  • Functional registrations identified
  • Records of the determination
Common finding they raise: A responsible entity does not assess how NERC CIP applies to it.

Why this is not another template pack

  • The evidence is the point. A CIP requirement you cannot evidence is a potential violation. This tells you what an auditor examines and where responsible entities fall short, for every standard.
  • Categorization, evidence and supply chain built in. BES Cyber System categorization, compliance evidence retention and supply chain risk are written into the controls, the substance the CIP standards require.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. CIP aligns with NIST and ISO security, so this work feeds your wider operational technology security program.

Who buys this

Bulk electric system responsible entities and their compliance, security and operations leads. Whether it is a first alignment or an audit-readiness pass, you save weeks and walk in with categorization, security and evidence structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 18 standards
✓  A completed CIP control matrix
✓  The evidence an auditor examines
✓  Your categorization, access and system security in place
✓  A readiness percentage and a fix list
✓  The recovery, supply chain and reporting gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this an official NERC tool? No. It is an independent implementation toolkit grounded in the published CIP standards, to get your controls and evidence in order fast before an audit.

Does it cover BES Cyber System categorization? Yes. Categorizing systems by impact under CIP-002 is built as a control, and it drives the rest.

Does it cover supply chain risk? Yes. The CIP-013 supply chain cyber security risk management plan is built as a control.

What if it is not for me? A 30-day money-back guarantee.

Do not enter a CIP audit with requirements you cannot show.
Every CIP standard is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be CIP-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com