Dashboard
Open →Role-aware readiness, evidence confidence, open/overdue findings, executive decisions, and maintenance windows.
Built-in help
NERC CIP Readiness & Gap Assessment Platform
Understand the application’s functions, choose the right workflow, and create defensible NERC CIP / OT decision-support records without overstating compliance.
Application flowchart
Use enterprise mode for governed, tenant-owned work. Use conference mode for a short, privacy-first awareness assessment without sensitive evidence.
Choose an organization, site, published template, and assessment owner.
Answer applicable questions, record confidence and notes, and save progress.
Link fresh, scanned evidence without placing sensitive details in notes.
Review findings, assign owners, approve decisions, and retain history.
Evaluate severity, outage need, safety impact, interim controls, and maintenance windows.
Attach compensating controls, implement work, retest, and close supported findings.
Review dashboards and generate signed executive or technical report versions.
Getting started
Sign in with your assigned account.
Confirm the organization shown on the page.
Start from the Dashboard’s role-specific attention items.
Open only the module needed for your current task.
Verify organization, site, assessment, and version before saving.
Role-based access
| Role | Primary responsibilities and access |
|---|---|
| Organization administrator | Members, organization settings, templates, conference programs, evidence, findings, controls, reports, crosswalks, and audit oversight. |
| Assessment manager | Assessment program design, templates, assignments, reviewed findings, reporting, and conference programs. |
| Assessor | Assessment responses, evidence, draft findings, prioritization, controls, and remediation updates. |
| Evidence contributor | Evidence library and uploads only; no assessment or finding decision authority. |
| Remediation owner | Assigned findings, evidence, priorities, compensating controls, remediation, and retest support. |
| Executive viewer | Read-only decision views, findings, controls, crosswalk, dashboards, and reports. |
| Auditor | Read-only assessment artifacts, evidence metadata, findings, controls, crosswalk, reports, and audit history. |
| Platform administrator | Platform-level operations. Tenant access remains explicit and does not silently bypass organization boundaries. |
Functions and features
Role-aware readiness, evidence confidence, open/overdue findings, executive decisions, and maintenance windows.
Create a tenant/site assessment from a published template, autosave answers, follow applicability branches, and complete only when required responses are valid.
Maintain tenant-isolated metadata and immutable file versions, freshness, sensitivity, scan state, integrity hashes, retention, and assessment/question links.
Generate deterministic draft findings or create them manually, then govern review, approval, assignment, remediation, retest, closure, or approved risk.
Run the transparent four-input OT decision model and preserve each result, configuration version, rationale, and maintenance-window context.
Publish reusable compensating controls and govern proposed, active, reviewed, extended, expired, revoked, or completed attachments.
Search and manage versioned, editable NERC CIP-to-NIST SP 800-82 reference mappings. Treat mappings as reviewed decision aids.
Create immutable signed assessment snapshots and export integrity-checked PDF, DOCX, CSV, or JSON versions.
Publish a privacy-first 24-question public assessment with local progress, immediate short results, optional contact consent, and automatic expiry.
Manage organizations, members, roles, sites, templates, retention, and governed administrative content.
Common procedures
Conference attendee guidance
Security and privacy
Troubleshooting
Confirm you are signed in, have an active membership in the intended organization, and hold the permission required for the module.
Look for unanswered applicable questions and Not Applicable responses without justification.
Confirm the version finished upload, scanning marked it Available, storage is configured, and your role has evidence access.
Review the enforced lifecycle and complete the required review, approval, ownership, remediation, or retest information.
Do not regenerate over the record. Notify an administrator; the stored snapshot, hash, or signing configuration may have changed.
The host may have paused it, or an individual result token may have expired under the program’s retention period.
Glossary
Contact your organization administrator for membership, role, template, retention, evidence-storage, scanner, or content questions. For suspected security or privacy incidents, follow your organization’s incident-response process immediately.