VoltVerify™NERC CIP Readiness & Gap Assessment Platform

Built-in help

VoltVerify™ User Guide

NERC CIP Readiness & Gap Assessment Platform

Understand the application’s functions, choose the right workflow, and create defensible NERC CIP / OT decision-support records without overstating compliance.

Application flowchart

How work moves through VoltVerify

Use enterprise mode for governed, tenant-owned work. Use conference mode for a short, privacy-first awareness assessment without sensitive evidence.

Getting started

Your first five minutes

  1. 1

    Sign in with your assigned account.

  2. 2

    Confirm the organization shown on the page.

  3. 3

    Start from the Dashboard’s role-specific attention items.

  4. 4

    Open only the module needed for your current task.

  5. 5

    Verify organization, site, assessment, and version before saving.

Important: VoltVerify™ provides self-assessment and decision support. It does not provide legal advice or guarantee compliance, cybersecurity, reliability, safety, or an audit outcome.

Role-based access

What each role is intended to do

RolePrimary responsibilities and access
Organization administratorMembers, organization settings, templates, conference programs, evidence, findings, controls, reports, crosswalks, and audit oversight.
Assessment managerAssessment program design, templates, assignments, reviewed findings, reporting, and conference programs.
AssessorAssessment responses, evidence, draft findings, prioritization, controls, and remediation updates.
Evidence contributorEvidence library and uploads only; no assessment or finding decision authority.
Remediation ownerAssigned findings, evidence, priorities, compensating controls, remediation, and retest support.
Executive viewerRead-only decision views, findings, controls, crosswalk, dashboards, and reports.
AuditorRead-only assessment artifacts, evidence metadata, findings, controls, crosswalk, reports, and audit history.
Platform administratorPlatform-level operations. Tenant access remains explicit and does not silently bypass organization boundaries.

Functions and features

Module reference

Dashboard

Open →

Role-aware readiness, evidence confidence, open/overdue findings, executive decisions, and maintenance windows.

Assessments

Open →

Create a tenant/site assessment from a published template, autosave answers, follow applicability branches, and complete only when required responses are valid.

Evidence

Open →

Maintain tenant-isolated metadata and immutable file versions, freshness, sensitivity, scan state, integrity hashes, retention, and assessment/question links.

Findings

Open →

Generate deterministic draft findings or create them manually, then govern review, approval, assignment, remediation, retest, closure, or approved risk.

Priorities

Open →

Run the transparent four-input OT decision model and preserve each result, configuration version, rationale, and maintenance-window context.

Controls

Open →

Publish reusable compensating controls and govern proposed, active, reviewed, extended, expired, revoked, or completed attachments.

Crosswalk

Open →

Search and manage versioned, editable NERC CIP-to-NIST SP 800-82 reference mappings. Treat mappings as reviewed decision aids.

Reports

Open →

Create immutable signed assessment snapshots and export integrity-checked PDF, DOCX, CSV, or JSON versions.

Conference

Open →

Publish a privacy-first 24-question public assessment with local progress, immediate short results, optional contact consent, and automatic expiry.

Administration

Open →

Manage organizations, members, roles, sites, templates, retention, and governed administrative content.

Common procedures

Complete the most important workflows

Start and complete an enterprise assessment
  1. Open Assessments and select the intended organization.
  2. Create an assessment using the correct site and published template version.
  3. Answer only from validated knowledge; use Unknown or Not Tested when appropriate.
  4. Add confidence, justification for Not Applicable, and non-sensitive assessor or management notes.
  5. Link current evidence, review the progress count, then complete the assessment when every applicable response is valid.
Manage evidence safely
  1. Confirm the organization, site, assessment, sensitivity, evidence date, freshness date, and retention requirement.
  2. Upload through the signed private-storage workflow; do not send OT evidence through conference mode or external AI tools.
  3. Wait for the configured malware scanner to mark the version Available.
  4. Verify the SHA-256 value when required and link the evidence to the exact assessment questions or findings.
  5. Use audited deletion requests instead of removing governed records directly.
Govern a finding through closure
  1. Create or generate a draft and confirm its requirement context, severity, confidence, evidence reviewed, and missing evidence.
  2. Move the finding through review and approval before assignment.
  3. Record the owner, due date, operational dependency, recommendation, and management response.
  4. Prioritize it using the four-input model and associate a maintenance window when applicable.
  5. Implement remediation or a time-bounded compensating control, retain validation evidence, move to Retest, and close only after supported verification.
Create a report version
  1. Open Reports and select the intended assessment.
  2. Choose Executive for risks, decisions, and roadmap content, or Technical for detailed responses, evidence context, mappings, controls, and retest guidance.
  3. Generate a new immutable version; do not overwrite an earlier decision record.
  4. Confirm the signing timestamp and SHA-256 prefix, then download the required format.
  5. Review all generated content with qualified compliance, legal, engineering, operational, and audit stakeholders before relying on it.
Publish a conference assessment
  1. Open Conference and create a draft from the reviewed 24-question starter.
  2. Choose a unique public slug, title, privacy notice, and a short retention period.
  3. Leave contact capture off unless there is an approved business purpose and consent process.
  4. Test the complete anonymous workflow and PDF before publishing.
  5. Pause the program when the event ends and ensure the daily retention task removes expired submissions.

Conference attendee guidance

Quick assessment boundaries

Appropriate

  • High-level Yes, Partially, No, or Unknown / Not Tested answers.
  • Browser-local progress before submission.
  • Immediate category indicators and suggested discussion areas.
  • Optional contact sharing only after explicit consent.

Do not enter

  • System names, IP addresses, diagrams, credentials, vulnerabilities, or evidence.
  • Personal information inside assessment answers.
  • Definitive compliance or audit conclusions.
  • Contact details unless you intend to consent to host retention.

Security and privacy

Safe operating practices

  • Always verify the selected organization before viewing or changing records.
  • Use the Evidence workflow—not notes or conference mode—for approved sensitive artifacts.
  • Never share signed download URLs, opaque conference result links, passwords, or secret values.
  • Treat Unknown and missing evidence as visible uncertainty; do not convert them to affirmative scores.
  • Use immutable versions and audit history instead of overwriting a prior decision record.
  • Report suspected exposure, incorrect tenant access, malware, or lost credentials immediately.

Troubleshooting

Common issues

Access denied

Confirm you are signed in, have an active membership in the intended organization, and hold the permission required for the module.

Assessment cannot complete

Look for unanswered applicable questions and Not Applicable responses without justification.

Evidence cannot download

Confirm the version finished upload, scanning marked it Available, storage is configured, and your role has evidence access.

Finding cannot move forward

Review the enforced lifecycle and complete the required review, approval, ownership, remediation, or retest information.

Report export fails integrity verification

Do not regenerate over the record. Notify an administrator; the stored snapshot, hash, or signing configuration may have changed.

Conference link is unavailable

The host may have paused it, or an individual result token may have expired under the program’s retention period.

Glossary

Terms used in the portal

Readiness
Weighted indicator derived from applicable assessment answers; not a compliance determination.
Evidence confidence
Indicator reflecting available/fresh linked evidence and recorded assessor confidence.
Evidence-adjusted readiness
Readiness multiplied by evidence confidence to expose unsupported affirmative answers.
Finding
A governed gap record with context, evidence, severity, ownership, recommendation, and lifecycle history.
Compensating control
A time-bounded, reviewed measure used while the preferred remediation is constrained or pending.
Maintenance window
Approved operational period that may constrain or enable remediation work.
Published version
Immutable reviewed content used to preserve the exact basis of an assessment or decision.
Tenant
An organization boundary. Tenant-owned records must never be accessed through another organization context.

Need additional help?

Contact your organization administrator for membership, role, template, retention, evidence-storage, scanner, or content questions. For suspected security or privacy incidents, follow your organization’s incident-response process immediately.