Dashboard
Open →Role-aware readiness, evidence confidence, open/overdue findings, executive decisions, and maintenance windows.
Built-in help
Compliance & Reliability Readiness Platform
Understand the application’s functions, choose the applicable NERC or compliance-framework readiness program, and create defensible compliance and reliability decision-support records without overstating results.
Application flowchart
Use enterprise mode for governed, tenant-owned work. Use conference mode for a short, privacy-first awareness assessment without sensitive evidence.
Choose an organization, site, published template, and assessment owner.
Answer applicable questions, record confidence and notes, and save progress.
Link fresh, scanned evidence without placing sensitive details in notes.
Review findings, assign owners, approve decisions, and retain history.
Evaluate severity, outage need, safety impact, interim controls, and maintenance windows.
Attach compensating controls, implement work, retest, and close supported findings.
Review dashboards and generate signed executive or technical report versions.
Getting started
Sign in with your assigned account.
Choose the applicable readiness program from the framework links.
Confirm the organization and site shown on the page.
Create an assessment from the correct published template version.
Verify the assessment program, scope, and version before saving.
Role-based access
| Role | Primary responsibilities and access |
|---|---|
| Organization administrator | Members, organization settings, templates, conference programs, evidence, findings, controls, reports, crosswalks, and audit oversight. |
| Assessment manager | Assessment program design, templates, assignments, reviewed findings, reporting, and conference programs. |
| Assessor | Assessment responses, evidence, draft findings, prioritization, controls, and remediation updates. |
| Evidence contributor | Evidence library and uploads only; no assessment or finding decision authority. |
| Remediation owner | Assigned findings, evidence, priorities, compensating controls, remediation, and retest support. |
| Executive viewer | Read-only decision views, findings, controls, crosswalk, dashboards, and reports. |
| Auditor | Read-only assessment artifacts, evidence metadata, findings, controls, crosswalk, reports, and audit history. |
| Platform administrator | Platform-level operations. Tenant access remains explicit and does not silently bypass organization boundaries. |
Functions and features
Role-aware readiness, evidence confidence, open/overdue findings, executive decisions, and maintenance windows.
Review a separate DOE C2M2-aligned capability maturity profile by domain without changing readiness or evidence-adjusted scoring.
Create a tenant/site assessment from a published template, autosave answers, follow applicability branches, and complete only when required responses are valid.
Maintain tenant-isolated metadata and immutable file versions, freshness, sensitivity, scan state, integrity hashes, retention, and assessment/question links.
Generate deterministic draft findings or create them manually, then govern review, approval, assignment, remediation, retest, closure, or approved risk.
Run the transparent four-input OT decision model and preserve each result, configuration version, rationale, and maintenance-window context.
Publish reusable compensating controls and govern proposed, active, reviewed, extended, expired, revoked, or completed attachments.
Search and manage versioned, editable NERC CIP-to-NIST SP 800-82 reference mappings. Treat mappings as reviewed decision aids.
Create immutable signed assessment snapshots and export integrity-checked PDF, DOCX, CSV, or JSON versions.
Publish a privacy-first 24-question public assessment with local progress, immediate short results, optional contact consent, and automatic expiry.
Manage organizations, members, roles, sites, templates, retention, and governed administrative content.
Common procedures
Conference attendee guidance
Security and privacy
Troubleshooting
Confirm you are signed in, have an active membership in the intended organization, and hold the permission required for the module.
Look for unanswered applicable questions and Not Applicable responses without justification.
Confirm the version finished upload, scanning marked it Available, storage is configured, and your role has evidence access.
Review the enforced lifecycle and complete the required review, approval, ownership, remediation, or retest information.
Do not regenerate over the record. Notify an administrator; the stored snapshot, hash, or signing configuration may have changed.
The host may have paused it, or an individual result token may have expired under the program’s retention period.
The final April 2026 NIST IR 8259 Rev. 1 covers nine manufacturer activities numbered 0–8: six primarily premarket and three postmarket. It revises IR 8259, not the six-capability IR 8259A baseline. The new 27-question assessment keeps manufacturer activity readiness separate from device technical readiness.
NIST IR 8259B (August 2021) covers four non-technical supporting capabilities: Documentation, Information and Query Reception, Information Dissemination, and Education and Awareness. Its 24-question assessment includes optional industrial/OT context. These are original readiness prompts, not mandatory NIST requirements.
Define the same product consistently across assessments, including device and firmware, cloud services, applications, gateways, dependencies, supporting entities, lifecycle stage, support owner, support period, and expected deployment. For premarket products, identify planned versions and assumed environments. A site can represent product engineering or support. Distinguish a documented plan from demonstrated execution in notes, evidence, and confidence.
Use the same answer states, N/A justification, autosave, evidence links, draft findings, approval workflow, retest, and signed reports as the device assessment. Unknown / Not Tested means unverified, not confirmed absence. N/A is excluded from scoring. Each assessment retains its own template version, answers, scope, and score; no results are copied automatically.
In Crosswalks, an authorized manager can add the manufacturer pathway draft, review the proposed 8259A-to-Rev. 1 and 8259B-to-IEC topic comparisons, and publish a version. Published comparisons retain their informational warning. They do not change the original assessment responses or scores.
Informational / requires qualified validation. Proposed topic comparisons to IEC 62443-4-1:2018 do not establish clause coverage, equivalence, a security level, or certification. IEC 62443-4-2 concerns technical component requirements and needs separate evaluation. IEC 62443-2-4 applies to service providers when that role is in scope. Validate the applicable edition, licensed requirements, product boundary, and organizational role with qualified industrial/OT specialists. Crosswalks never change assessment answers or scores.
Activity 0 — Prioritize Cybersecurity and Maintain Cybersecurity Posture; Activity 1 — Identify Expected Customers and Define Expected Use Cases; Activity 2 — Research Customer Cybersecurity Needs and Goals; Activity 3 — Determine Appropriate Means to Support Customer Needs and Goals; Activity 4 — Define IoT Product Cybersecurity Capabilities; Activity 5 — Plan for Adequate Support of Customer Needs and Goals; Activity 6 — Ongoing Support through the Lifecycle and End of Life; Activity 7 — Define Approaches for Communicating to Customers; Activity 8 — Decide What to Communicate and How
This assessment is a cybersecurity readiness and decision-support tool based on NIST IR 8259 Rev. 1, April 2026. These original prompts interpret risk-based manufacturer guidance, not universal mandatory requirements. Evaluate applicability for the product, its components and supporting entities, expected customers, deployment environment, lifecycle, and applicable regulatory or contractual requirements. Scores describe the assessed manufacturer activities or supporting capabilities only; they do not establish device technical readiness. VoltVerify does not provide certification or guarantee compliance with NIST guidance. Informational / requires qualified validation. Proposed topic comparisons to IEC 62443-4-1:2018 do not establish clause coverage, equivalence, a security level, or certification. IEC 62443-4-2 concerns technical component requirements and needs separate evaluation. IEC 62443-2-4 applies to service providers when that role is in scope. Validate the applicable edition, licensed requirements, product boundary, and organizational role with qualified industrial/OT specialists. Crosswalks never change assessment answers or scores.
NIST IR 8259 Rev. 1, April 2026Documentation; Information and Query Reception; Information Dissemination; Education and Awareness
This assessment is a cybersecurity readiness and decision-support tool based on NIST IR 8259B, August 2021. These original prompts interpret risk-based manufacturer guidance, not universal mandatory requirements. Evaluate applicability for the product, its components and supporting entities, expected customers, deployment environment, lifecycle, and applicable regulatory or contractual requirements. Scores describe the assessed manufacturer activities or supporting capabilities only; they do not establish device technical readiness. VoltVerify does not provide certification or guarantee compliance with NIST guidance. Informational / requires qualified validation. Proposed topic comparisons to IEC 62443-4-1:2018 do not establish clause coverage, equivalence, a security level, or certification. IEC 62443-4-2 concerns technical component requirements and needs separate evaluation. IEC 62443-2-4 applies to service providers when that role is in scope. Validate the applicable edition, licensed requirements, product boundary, and organizational role with qualified industrial/OT specialists. Crosswalks never change assessment answers or scores.
NIST IR 8259B, August 2021Evaluate foundational technical capabilities for a specific connected device. The May 2020 baseline covers Device Identification, Device Configuration, Data Protection, Logical Access to Interfaces, Software Update, Cybersecurity State Awareness. The 39 prompts are original readiness interpretations, not 39 mandatory NIST requirements. No later Device Security catalog category is included.
Start from the NIST IR 8259A program page, select a site and published template, and record manufacturer, product/model, firmware, hardware, deployment, network zone, owner/operator, connectivity, interfaces, operational impact, and scope notes. This works for chargers, inverters, storage systems, sensors, gateways, and controllers without prescribing a protocol.
Choose Implemented, Partially Implemented, Not Implemented, Not Applicable, or Unknown / Not Tested. Unknown means the capability has not been verified; Not Implemented is a confirmed absence. N/A always needs a rationale based on risk and deployment context. Enter confidence and assessor/management notes; answers autosave, and you can resume from Assessments.
Use the Evidence repository to upload or link manuals, architecture, SBOMs, configurations, logs, certificates, signing documentation, inventories, scans, and test results. Follow safe testing and data-handling practices. Uploads are optional; question examples are alternatives. Unavailable or quarantined evidence does not count as available evidence.
Generate draft findings for partial or absent capabilities and investigations for unknown answers. Enable evidence-only investigations if needed. Review condition, risk, product/firmware, evidence missing, severity, operational consequences, recommendations, owner, due date, and retest requirement. The existing review, approval, assignment, remediation, retest, and closure workflow applies.
Readiness Score: implemented = 100, partial = 50, not implemented = 0, unknown/not tested and unanswered = 0 pending verification. Unknown is uncertainty, not a confirmed absence. N/A is excluded. Questions are weighted equally in the baseline. Evidence confidence: fresh available evidence = 100, stale available evidence = 70, otherwise assessor HIGH = 100, MEDIUM = 70, LOW = 40, unset = 10 for answered questions; unanswered = 0. Evidence-adjusted readiness = readiness × evidence confidence / 100. No applicable questions means no readiness conclusion (displayed as N/A).
Administrators can install the published 1.0 baseline, export JSON, import a renamed clone, create and edit a draft, publish it, or retire a template. Assessments retain their exact version. Crosswalks are separately versioned; proposed mappings require qualified validation and do not alter responses.
This assessment is a cybersecurity readiness and decision-support tool. NIST IR 8259A provides a baseline of generally applicable IoT device cybersecurity capabilities and does not mandate implementation of every capability for every device or environment. Applicability and implementation should be evaluated based on the device, deployment architecture, operating environment, threat model, organizational risk, and applicable regulatory or contractual requirements. VoltVerify does not provide certification or guarantee compliance with NIST guidance.
Open IoT device security programGlossary
Contact your organization administrator for membership, role, template, retention, evidence-storage, scanner, or content questions. For VoltVerify or VoltBreach assistance, contact us directly. For suspected security or privacy incidents, follow your organization’s incident-response process immediately.