Built-in help

VoltVerify™ User Guide

Compliance & Reliability Readiness Platform

Understand the application’s functions, choose the applicable NERC or compliance-framework readiness program, and create defensible compliance and reliability decision-support records without overstating results.

Application flowchart

How work moves through VoltVerify

Use enterprise mode for governed, tenant-owned work. Use conference mode for a short, privacy-first awareness assessment without sensitive evidence.

Getting started

Your first five minutes

  1. 1

    Sign in with your assigned account.

  2. 2

    Choose the applicable readiness program from the framework links.

  3. 3

    Confirm the organization and site shown on the page.

  4. 4

    Create an assessment from the correct published template version.

  5. 5

    Verify the assessment program, scope, and version before saving.

Important: VoltVerify™ provides self-assessment and decision support. It does not provide legal advice or guarantee compliance, cybersecurity, reliability, safety, or an audit outcome.

Role-based access

What each role is intended to do

RolePrimary responsibilities and access
Organization administratorMembers, organization settings, templates, conference programs, evidence, findings, controls, reports, crosswalks, and audit oversight.
Assessment managerAssessment program design, templates, assignments, reviewed findings, reporting, and conference programs.
AssessorAssessment responses, evidence, draft findings, prioritization, controls, and remediation updates.
Evidence contributorEvidence library and uploads only; no assessment or finding decision authority.
Remediation ownerAssigned findings, evidence, priorities, compensating controls, remediation, and retest support.
Executive viewerRead-only decision views, findings, controls, crosswalk, dashboards, and reports.
AuditorRead-only assessment artifacts, evidence metadata, findings, controls, crosswalk, reports, and audit history.
Platform administratorPlatform-level operations. Tenant access remains explicit and does not silently bypass organization boundaries.

Functions and features

Module reference

Dashboard

Open →

Role-aware readiness, evidence confidence, open/overdue findings, executive decisions, and maintenance windows.

C2M2 Profile

Open →

Review a separate DOE C2M2-aligned capability maturity profile by domain without changing readiness or evidence-adjusted scoring.

Assessments

Open →

Create a tenant/site assessment from a published template, autosave answers, follow applicability branches, and complete only when required responses are valid.

Evidence

Open →

Maintain tenant-isolated metadata and immutable file versions, freshness, sensitivity, scan state, integrity hashes, retention, and assessment/question links.

Findings

Open →

Generate deterministic draft findings or create them manually, then govern review, approval, assignment, remediation, retest, closure, or approved risk.

Priorities

Open →

Run the transparent four-input OT decision model and preserve each result, configuration version, rationale, and maintenance-window context.

Controls

Open →

Publish reusable compensating controls and govern proposed, active, reviewed, extended, expired, revoked, or completed attachments.

Crosswalk

Open →

Search and manage versioned, editable NERC CIP-to-NIST SP 800-82 reference mappings. Treat mappings as reviewed decision aids.

Reports

Open →

Create immutable signed assessment snapshots and export integrity-checked PDF, DOCX, CSV, or JSON versions.

Conference

Open →

Publish a privacy-first 24-question public assessment with local progress, immediate short results, optional contact consent, and automatic expiry.

Administration

Open →

Manage organizations, members, roles, sites, templates, retention, and governed administrative content.

Common procedures

Complete the most important workflows

Start and complete an enterprise assessment
  1. Open Assessments and select the intended organization.
  2. Create an assessment using the correct site and published template version.
  3. Answer only from validated knowledge; use Unknown or Not Tested when appropriate.
  4. Add confidence, justification for Not Applicable, and non-sensitive assessor or management notes.
  5. Link current evidence, review the progress count, then complete the assessment when every applicable response is valid.
Manage evidence safely
  1. Confirm the organization, site, assessment, sensitivity, evidence date, freshness date, and retention requirement.
  2. Upload through the signed private-storage workflow; do not send OT evidence through conference mode or external AI tools.
  3. Wait for the configured malware scanner to mark the version Available.
  4. Verify the SHA-256 value when required and link the evidence to the exact assessment questions or findings.
  5. Use audited deletion requests instead of removing governed records directly.
Govern a finding through closure
  1. Create or generate a draft and confirm its requirement context, severity, confidence, evidence reviewed, and missing evidence.
  2. Move the finding through review and approval before assignment.
  3. Record the owner, due date, operational dependency, recommendation, and management response.
  4. Prioritize it using the four-input model and associate a maintenance window when applicable.
  5. Implement remediation or a time-bounded compensating control, retain validation evidence, move to Retest, and close only after supported verification.
Create a report version
  1. Open Reports and select the intended assessment.
  2. Choose Executive for risks, decisions, and roadmap content, or Technical for detailed responses, evidence context, mappings, controls, and retest guidance.
  3. Generate a new immutable version; do not overwrite an earlier decision record.
  4. Confirm the signing timestamp and SHA-256 prefix, then download the required format.
  5. Review all generated content with qualified compliance, legal, engineering, operational, and audit stakeholders before relying on it.
Publish a conference assessment
  1. Open Conference and create a draft from the reviewed 24-question starter.
  2. Choose a unique public slug, title, privacy notice, and a short retention period.
  3. Leave contact capture off unless there is an approved business purpose and consent process.
  4. Test the complete anonymous workflow and PDF before publishing.
  5. Pause the program when the event ends and ensure the daily retention task removes expired submissions.

Conference attendee guidance

Quick assessment boundaries

Appropriate

  • High-level Yes, Partially, No, or Unknown / Not Tested answers.
  • Browser-local progress before submission.
  • Immediate category indicators and suggested discussion areas.
  • Optional contact sharing only after explicit consent.

Do not enter

  • System names, IP addresses, diagrams, credentials, vulnerabilities, or evidence.
  • Personal information inside assessment answers.
  • Definitive compliance or audit conclusions.
  • Contact details unless you intend to consent to host retention.

Security and privacy

Safe operating practices

  • Always verify the selected organization before viewing or changing records.
  • Use the Evidence workflow—not notes or conference mode—for approved sensitive artifacts.
  • Never share signed download URLs, opaque conference result links, passwords, or secret values.
  • Treat Unknown and missing evidence as visible uncertainty; do not convert them to affirmative scores.
  • Use immutable versions and audit history instead of overwriting a prior decision record.
  • Report suspected exposure, incorrect tenant access, malware, or lost credentials immediately.

Troubleshooting

Common issues

Access denied

Confirm you are signed in, have an active membership in the intended organization, and hold the permission required for the module.

Assessment cannot complete

Look for unanswered applicable questions and Not Applicable responses without justification.

Evidence cannot download

Confirm the version finished upload, scanning marked it Available, storage is configured, and your role has evidence access.

Finding cannot move forward

Review the enforced lifecycle and complete the required review, approval, ownership, remediation, or retest information.

Report export fails integrity verification

Do not regenerate over the record. Notify an administrator; the stored snapshot, hash, or signing configuration may have changed.

Conference link is unavailable

The host may have paused it, or an individual result token may have expired under the program’s retention period.

IoT Manufacturer Activities and Supporting Capabilities

The final April 2026 NIST IR 8259 Rev. 1 covers nine manufacturer activities numbered 0–8: six primarily premarket and three postmarket. It revises IR 8259, not the six-capability IR 8259A baseline. The new 27-question assessment keeps manufacturer activity readiness separate from device technical readiness.

NIST IR 8259B (August 2021) covers four non-technical supporting capabilities: Documentation, Information and Query Reception, Information Dissemination, and Education and Awareness. Its 24-question assessment includes optional industrial/OT context. These are original readiness prompts, not mandatory NIST requirements.

Define the same product consistently across assessments, including device and firmware, cloud services, applications, gateways, dependencies, supporting entities, lifecycle stage, support owner, support period, and expected deployment. For premarket products, identify planned versions and assumed environments. A site can represent product engineering or support. Distinguish a documented plan from demonstrated execution in notes, evidence, and confidence.

Use the same answer states, N/A justification, autosave, evidence links, draft findings, approval workflow, retest, and signed reports as the device assessment. Unknown / Not Tested means unverified, not confirmed absence. N/A is excluded from scoring. Each assessment retains its own template version, answers, scope, and score; no results are copied automatically.

In Crosswalks, an authorized manager can add the manufacturer pathway draft, review the proposed 8259A-to-Rev. 1 and 8259B-to-IEC topic comparisons, and publish a version. Published comparisons retain their informational warning. They do not change the original assessment responses or scores.

Informational / requires qualified validation. Proposed topic comparisons to IEC 62443-4-1:2018 do not establish clause coverage, equivalence, a security level, or certification. IEC 62443-4-2 concerns technical component requirements and needs separate evaluation. IEC 62443-2-4 applies to service providers when that role is in scope. Validate the applicable edition, licensed requirements, product boundary, and organizational role with qualified industrial/OT specialists. Crosswalks never change assessment answers or scores.

NIST IR 8259 Rev. 1 — Manufacturer Activities

Activity 0 — Prioritize Cybersecurity and Maintain Cybersecurity Posture; Activity 1 — Identify Expected Customers and Define Expected Use Cases; Activity 2 — Research Customer Cybersecurity Needs and Goals; Activity 3 — Determine Appropriate Means to Support Customer Needs and Goals; Activity 4 — Define IoT Product Cybersecurity Capabilities; Activity 5 — Plan for Adequate Support of Customer Needs and Goals; Activity 6 — Ongoing Support through the Lifecycle and End of Life; Activity 7 — Define Approaches for Communicating to Customers; Activity 8 — Decide What to Communicate and How

This assessment is a cybersecurity readiness and decision-support tool based on NIST IR 8259 Rev. 1, April 2026. These original prompts interpret risk-based manufacturer guidance, not universal mandatory requirements. Evaluate applicability for the product, its components and supporting entities, expected customers, deployment environment, lifecycle, and applicable regulatory or contractual requirements. Scores describe the assessed manufacturer activities or supporting capabilities only; they do not establish device technical readiness. VoltVerify does not provide certification or guarantee compliance with NIST guidance. Informational / requires qualified validation. Proposed topic comparisons to IEC 62443-4-1:2018 do not establish clause coverage, equivalence, a security level, or certification. IEC 62443-4-2 concerns technical component requirements and needs separate evaluation. IEC 62443-2-4 applies to service providers when that role is in scope. Validate the applicable edition, licensed requirements, product boundary, and organizational role with qualified industrial/OT specialists. Crosswalks never change assessment answers or scores.

NIST IR 8259 Rev. 1, April 2026
NIST IR 8259B — Manufacturer Supporting Capabilities

Documentation; Information and Query Reception; Information Dissemination; Education and Awareness

This assessment is a cybersecurity readiness and decision-support tool based on NIST IR 8259B, August 2021. These original prompts interpret risk-based manufacturer guidance, not universal mandatory requirements. Evaluate applicability for the product, its components and supporting entities, expected customers, deployment environment, lifecycle, and applicable regulatory or contractual requirements. Scores describe the assessed manufacturer activities or supporting capabilities only; they do not establish device technical readiness. VoltVerify does not provide certification or guarantee compliance with NIST guidance. Informational / requires qualified validation. Proposed topic comparisons to IEC 62443-4-1:2018 do not establish clause coverage, equivalence, a security level, or certification. IEC 62443-4-2 concerns technical component requirements and needs separate evaluation. IEC 62443-2-4 applies to service providers when that role is in scope. Validate the applicable edition, licensed requirements, product boundary, and organizational role with qualified industrial/OT specialists. Crosswalks never change assessment answers or scores.

NIST IR 8259B, August 2021

NIST IR 8259A IoT Device Cybersecurity Assessments

Evaluate foundational technical capabilities for a specific connected device. The May 2020 baseline covers Device Identification, Device Configuration, Data Protection, Logical Access to Interfaces, Software Update, Cybersecurity State Awareness. The 39 prompts are original readiness interpretations, not 39 mandatory NIST requirements. No later Device Security catalog category is included.

Start from the NIST IR 8259A program page, select a site and published template, and record manufacturer, product/model, firmware, hardware, deployment, network zone, owner/operator, connectivity, interfaces, operational impact, and scope notes. This works for chargers, inverters, storage systems, sensors, gateways, and controllers without prescribing a protocol.

Choose Implemented, Partially Implemented, Not Implemented, Not Applicable, or Unknown / Not Tested. Unknown means the capability has not been verified; Not Implemented is a confirmed absence. N/A always needs a rationale based on risk and deployment context. Enter confidence and assessor/management notes; answers autosave, and you can resume from Assessments.

Use the Evidence repository to upload or link manuals, architecture, SBOMs, configurations, logs, certificates, signing documentation, inventories, scans, and test results. Follow safe testing and data-handling practices. Uploads are optional; question examples are alternatives. Unavailable or quarantined evidence does not count as available evidence.

Generate draft findings for partial or absent capabilities and investigations for unknown answers. Enable evidence-only investigations if needed. Review condition, risk, product/firmware, evidence missing, severity, operational consequences, recommendations, owner, due date, and retest requirement. The existing review, approval, assignment, remediation, retest, and closure workflow applies.

Readiness Score: implemented = 100, partial = 50, not implemented = 0, unknown/not tested and unanswered = 0 pending verification. Unknown is uncertainty, not a confirmed absence. N/A is excluded. Questions are weighted equally in the baseline. Evidence confidence: fresh available evidence = 100, stale available evidence = 70, otherwise assessor HIGH = 100, MEDIUM = 70, LOW = 40, unset = 10 for answered questions; unanswered = 0. Evidence-adjusted readiness = readiness × evidence confidence / 100. No applicable questions means no readiness conclusion (displayed as N/A).

Administrators can install the published 1.0 baseline, export JSON, import a renamed clone, create and edit a draft, publish it, or retire a template. Assessments retain their exact version. Crosswalks are separately versioned; proposed mappings require qualified validation and do not alter responses.

This assessment is a cybersecurity readiness and decision-support tool. NIST IR 8259A provides a baseline of generally applicable IoT device cybersecurity capabilities and does not mandate implementation of every capability for every device or environment. Applicability and implementation should be evaluated based on the device, deployment architecture, operating environment, threat model, organizational risk, and applicable regulatory or contractual requirements. VoltVerify does not provide certification or guarantee compliance with NIST guidance.

Open IoT device security program

Glossary

Terms used in the portal

Readiness
Weighted indicator derived from applicable assessment answers; not a compliance determination.
Evidence confidence
Indicator reflecting available/fresh linked evidence and recorded assessor confidence.
Evidence-adjusted readiness
Readiness multiplied by evidence confidence to expose unsupported affirmative answers.
Finding
A governed gap record with context, evidence, severity, ownership, recommendation, and lifecycle history.
Compensating control
A time-bounded, reviewed measure used while the preferred remediation is constrained or pending.
Maintenance window
Approved operational period that may constrain or enable remediation work.
Published version
Immutable reviewed content used to preserve the exact basis of an assessment or decision.
Tenant
An organization boundary. Tenant-owned records must never be accessed through another organization context.

Need additional help?

Contact your organization administrator for membership, role, template, retention, evidence-storage, scanner, or content questions. For VoltVerify or VoltBreach assistance, contact us directly. For suspected security or privacy incidents, follow your organization’s incident-response process immediately.