CIP-003-9 Enforceable April 1, 2026 — every file verified against the latest standard

The most defensible CIP-003 audit file a small utility can have.

GridProof assembles a documentation-complete, audit-ready CIP-003 compliance file — policies, Attachment 1 evidence, and the RSAW narrative — checked against every applicable NERC CIP requirement before a compliance specialist releases it.

Every applicable CIP-003 requirementSix low-impact control areas, gate-checkedAsset inventory · network diagram · vendor recordsSpecialist release on every file5-business-day SLA
Why files fail

A single missing evidence item can trigger a finding — and a penalty.

A small utility's CIP-003 compliance file is only as strong as the evidence behind it. Miss a required policy element, skip a remote-access control, fail to document supply-chain risk management, or let a review date lapse — and a Regional Entity audit can result in a finding, a penalty up to $1.54M per day, or both.

Most utilities run this by hand, from memory, with a part-time IT lead improvising policy PDFs the night before an audit. The standard has not been read end-to-end since the last time it mattered. That is exactly where compliance gaps hide.

GridProof exists to close that gap with a single, exhaustive standard applied identically to every file.

1 of 6
control areas with a missing evidence item is enough to trigger a finding
The benchmark

Measured against the letter of the NERC CIP standards — requirement by requirement.

We do not summarize the requirements and hope. Every file is scored against a versioned rule pack tied to the exact text of NERC CIP-003-9 and related standards. These are the provisions each file is held to.

CIP-003-9 R1

Cyber Security Policy

Policies covering six control areas: awareness, physical security, personnel & training, electronic access, incident response, and recovery plans — all present and current, or the file does not release.

CIP-003-9 R2

Attachment 1 Evidence

Evidence of policy implementation: signed acknowledgments, training records, access logs, incident reports, and review dates — verified against the policy inventory.

CIP-003-9 R3

Remote Access Controls

Documentation of multi-factor authentication, encryption, and access authorization for all low-impact remote-access connections.

CIP-003-9 R4

Supply Chain Risk Management

Vendor risk assessment records, procurement language, and evidence of supply-chain controls for low-impact BES Cyber Systems.

CIP-003-9 R5

Incident Response Plan

A documented, tested incident response plan specific to low-impact assets, with evidence of annual review and tabletop exercises.

CIP-003-9 R6

Recovery Plans

Recovery plans for low-impact BES Cyber Systems, including backup and restoration procedures, tested at least once per calendar year.

How a file is built

Intake to specialist release, with deterministic gates the AI cannot overrule.

AI extracts and drafts. Deterministic rules — running as code, outside the model — decide what is complete. A human compliance specialist signs every release. That order is never reversed.

01

Compliance Gap Scan

Upload your asset inventory, network diagram, vendor list, and existing policies. We return a free completeness read: which CIP-003 requirements and evidence items you already have, and which are missing.

02

Evidence collection & mapping

As your authorized clerical agent, we collect and map your evidence to each CIP-003 requirement: policies, logs, training records, vendor assessments, incident reports, and recovery test results.

03

Grounded drafting

The RSAW narrative and policy documents are drafted from your validated data and the CIP-003 rule pack into field-locked templates — no legal opinions, no invented facts.

04

Deterministic completeness gates

Every requirement is checked: policy existence, evidence dates, review cycles, access controls, supply-chain documentation. Any failure blocks release.

05

Specialist release

A NERC-experienced compliance specialist reviews the exception queue and signs the release. High-complexity or multi-entity files route to senior review first.

06

Delivery

You receive the file: RSAW narrative, policy set, evidence binder, evidence log, and a 12-month compliance calendar — ready for your CIP Senior Manager to review and approve.

The bar we hold

Rigor you can measure.

100%
Specialist-released
No file ships without a human signature.
5 days
Standard SLA
From complete intake to released file.
<1%
Critical-defect target
Tracked against a gold-standard file library.
6
Control areas covered
Every CIP-003 requirement, every applicable file.
Why GridProof

Built to be the most thorough option a small utility has.

Documentation-complete, by design

The deliverable is completeness itself — every requirement and evidence item accounted for or explicitly exception-coded. Nothing is left implicit.

Deterministic, not vibes

The gates that decide completeness are code, not a model's opinion. A drafting error cannot slip past a requirement.

In its lane, on purpose

We prepare documentation and run evidence collection as your clerical agent. We never provide legal advice, make compliance attestations, or replace your CIP Senior Manager.

Engagement

Flat fee, per released file. No hourly billing, ever.

Simple, predictable, and aligned with a compliance standard — not a meter running.

  • A free Compliance Gap Scan before you commit — see exactly what is missing.
  • One flat fee per released Audit-Ready Compliance File; disclosed pass-through evidence collection costs.
  • Optional fixed-fee senior review for multi-entity or complex asset configurations.
  • Optional Evidence Freshness Subscription for quarterly policy reviews and evidence updates.
FAQ

Questions, answered precisely.

Is GridProof a law firm?
No. GridProof, a service of Your Deputy, Obuke LLC, provides documentation-completeness services. It is not a law firm, does not provide legal advice, and does not represent you in any legal matter. Your CIP Senior Manager retains full accountability and must review and approve all deliverables.
Do you replace our CIP Senior Manager?
Never. GridProof prepares the documentation and evidence package. Your designated CIP Senior Manager reviews, approves, and attests to the file. We stay on the clerical side of the accountability line.
What makes a file 'complete'?
Completeness is defined by the NERC CIP standards: all six control areas covered, evidence mapped to each requirement, review dates current, and the RSAW narrative drafted. Deterministic gates enforce each one before release.
How fast is it?
The standard SLA is five business days from complete intake to a specialist-released file. The free Gap Scan is returned much sooner and tells you exactly what is still needed.
How are you priced?
A flat fee per released file, plus disclosed pass-through evidence collection costs. No hourly billing and no percentage of any penalty avoidance.

See what's missing before your next audit.

Start with a free Compliance Gap Scan. Send your asset inventory and existing policies and we'll return a completeness read against every requirement of CIP-003-9.

Documentation-completeness service · not legal advice · your CIP Senior Manager approves every file.