Cyber Security Policy
Policies covering six control areas: awareness, physical security, personnel & training, electronic access, incident response, and recovery plans — all present and current, or the file does not release.
GridProof assembles a documentation-complete, audit-ready CIP-003 compliance file — policies, Attachment 1 evidence, and the RSAW narrative — checked against every applicable NERC CIP requirement before a compliance specialist releases it.
A small utility's CIP-003 compliance file is only as strong as the evidence behind it. Miss a required policy element, skip a remote-access control, fail to document supply-chain risk management, or let a review date lapse — and a Regional Entity audit can result in a finding, a penalty up to $1.54M per day, or both.
Most utilities run this by hand, from memory, with a part-time IT lead improvising policy PDFs the night before an audit. The standard has not been read end-to-end since the last time it mattered. That is exactly where compliance gaps hide.
GridProof exists to close that gap with a single, exhaustive standard applied identically to every file.
We do not summarize the requirements and hope. Every file is scored against a versioned rule pack tied to the exact text of NERC CIP-003-9 and related standards. These are the provisions each file is held to.
Policies covering six control areas: awareness, physical security, personnel & training, electronic access, incident response, and recovery plans — all present and current, or the file does not release.
Evidence of policy implementation: signed acknowledgments, training records, access logs, incident reports, and review dates — verified against the policy inventory.
Documentation of multi-factor authentication, encryption, and access authorization for all low-impact remote-access connections.
Vendor risk assessment records, procurement language, and evidence of supply-chain controls for low-impact BES Cyber Systems.
A documented, tested incident response plan specific to low-impact assets, with evidence of annual review and tabletop exercises.
Recovery plans for low-impact BES Cyber Systems, including backup and restoration procedures, tested at least once per calendar year.
AI extracts and drafts. Deterministic rules — running as code, outside the model — decide what is complete. A human compliance specialist signs every release. That order is never reversed.
Upload your asset inventory, network diagram, vendor list, and existing policies. We return a free completeness read: which CIP-003 requirements and evidence items you already have, and which are missing.
As your authorized clerical agent, we collect and map your evidence to each CIP-003 requirement: policies, logs, training records, vendor assessments, incident reports, and recovery test results.
The RSAW narrative and policy documents are drafted from your validated data and the CIP-003 rule pack into field-locked templates — no legal opinions, no invented facts.
Every requirement is checked: policy existence, evidence dates, review cycles, access controls, supply-chain documentation. Any failure blocks release.
A NERC-experienced compliance specialist reviews the exception queue and signs the release. High-complexity or multi-entity files route to senior review first.
You receive the file: RSAW narrative, policy set, evidence binder, evidence log, and a 12-month compliance calendar — ready for your CIP Senior Manager to review and approve.
The deliverable is completeness itself — every requirement and evidence item accounted for or explicitly exception-coded. Nothing is left implicit.
The gates that decide completeness are code, not a model's opinion. A drafting error cannot slip past a requirement.
We prepare documentation and run evidence collection as your clerical agent. We never provide legal advice, make compliance attestations, or replace your CIP Senior Manager.
Simple, predictable, and aligned with a compliance standard — not a meter running.
Start with a free Compliance Gap Scan. Send your asset inventory and existing policies and we'll return a completeness read against every requirement of CIP-003-9.
Documentation-completeness service · not legal advice · your CIP Senior Manager approves every file.