Solution
NERC compliance for utilities, co-ops and IBR operators
CIP cybersecurity, Operations and Planning reliability, and Inverter-Based Resource obligations on one platform, including Category 2 IBR, scoped to the functions you are registered for and the sites you operate. Evidence linked to the requirement it satisfies, owners and gaps tracked, and binder-ready when the regulator calls.
What changes for you
The evidence is ready before the audit is
Audit readiness stops being a scramble and becomes a state you can see at any point in the cycle.
Walk into your next audit with the binder built
Every applicable standard carries its evidence, owners, and dates linked back to the requirement, together with why it applies and which version was in force, exportable on demand instead of assembled the week before.
Catch stale evidence before an auditor does
Freshness tracking flags records that have aged out, so a stale review is surfaced early rather than found at the audit table.
See a CIP-002 change ripple through
When BES Cyber System categorization changes, the requirements it touches are re-flagged for review instead of quietly going out of date.
Move to new versions without losing your record
An approved version takes effect on its effective date. Evidence links and owners carry forward to the new requirements, and the prior version keeps its history.
The problem
NERC compliance is an evidence problem before it is an audit problem
Teams need to know which requirements apply, who owns each control, which evidence satisfies each requirement, when records go stale, and whether audit packages are ready before the next review. BizNerva is the structured system of record that holds all of that in one place.
- CIP standards cascade. CIP-002 critical-asset identification drives every other CIP requirement, and one change ripples through your evidence.
- Audit cycles demand a full evidence binder per applicable standard, with owners, dates, and a clean chain back to the requirement.
- IBR standards developed under FERC Order 901 phase in on dates that run from 2025 into 2029, and NERC keeps revising them, so the obligation set keeps changing.
- Category 2 registration brings non-BES IBR owners and operators into scope, and not every standard applies to every site in the same way.
- A stale review record is a finding waiting to happen. Evidence freshness matters more than evidence existence.
Operational depth
How BizNerva supports NERC compliance teams
- Map requirements to owners and evidence
- Assign several people per requirement as responsible, approver or informed
- Track evidence by CIP standard and requirement
- Determine applicability per site, including Category 2 IBR
- Monitor missing, stale, or insufficient evidence
- Track event deadlines in each facility time zone, with reminders and escalation
- Show phased requirements as upcoming until their compliance date
- Stage reviewed standard versions to take effect on their dates
- Flag requirements a new version changed for their owners to review
- Maintain audit-ready binders
- Give consultants and auditors structured access to the compliance record
- Prepare for internal reviews and external audits
Modules
What is included
NERC CIP coverage
CIP-002 through CIP-015 evidence tracking, including critical-asset identification, security management controls, personnel and training, electronic and physical security, incident reporting, recovery plans, supply-chain risk management, and Internal Network Security Monitoring (INSM). Tracked at requirement and part level.
IBR Reliability (FERC Order 901 + 909)
Inverter-Based Resource compliance for solar, wind, and battery-storage operators, tracked at the individual requirement: PRC-028-1 disturbance monitoring and reporting (R1 to R8), PRC-029-1 frequency and voltage ride-through (R1 to R4), PRC-030-1 unexpected IBR event mitigation (R1 to R4) and MOD-026-2 model verification (R1 to R7), each with its effective and phased compliance dates. PRC-029-1 R1 to R3 carry separate capability and performance portions, so the operation obligation shows as upcoming until PRC-028-1 disturbance monitoring is in place. PRC-024-3 IBR requirements are tracked through September 30, 2026, when IBR ride-through moves to PRC-029-1. A per-resource registry records nameplate capacity, point of interconnection and voltage.
Category 2 applicability, per site
For each site, each standard is determined Applicable, Not applicable, Needs input or Not yet applicable, with the reasons and a citation. A threshold check shows whether a point of interconnection reaches 20 MVA aggregate at 60 kV or above, as a hint only. Overrides require a written reason and are recorded.
Operations & Planning (O&P)
Reliability standards across the BAL, EOP, FAC, IRO, MOD, PRC, TOP and VAR families, scoped to the functions you are registered for. Fifteen standards, including EOP-005-3, FAC-001-4, FAC-002-4, IRO-010, TOP-003, MOD-032, VAR-001 and VAR-002, are tracked at the individual requirement; the rest, including EOP-004, EOP-006 and EOP-008, per standard. All with owners, evidence and review dates, alongside your CIP and IBR obligations rather than in a separate spreadsheet.
Standard versions and lifecycle
Each standard version is recorded with its FERC approval, effective and retirement dates. Approved future versions are staged and take effect on their effective date, for example TOP-003-7 on October 1, 2026. Evidence links and owners carry forward, and the prior version keeps its history. Scanner detection is automatic, but a change applies only after a BizNerva platform administrator approves reviewed requirement text, and requirements whose wording, interval or deadlines changed are flagged for their owners to review.
Roles, assignees and event deadlines
Assign several people to a requirement as responsible, approver or informed. Role templates set default assignees, job titles map people to roles automatically, and role training can be assigned. Event deadlines are computed from the event date and time in the time zone recorded for each facility. Clocks counted in hours or minutes require the event time and notify owners as soon as the event is logged; day-based clocks send reminders 30, 7 and 1 days ahead, with escalation when a deadline passes.
PRC-005 protection system component register
Register each Protection System component with its maximum maintenance interval. The interval drives the next maintenance-due date and review tasks on the same calendar as CIP cycles, so PRC-005 is scheduled per component rather than as one generic requirement. Bulk-load the register (and personnel rosters) from a spreadsheet with a saved column mapping.
CIP-004 & CIP-007 automation
A termination in a connected HRIS opens the CIP-004-7 R5.1 24-hour access-revocation clock automatically and produces the dated record. Register your patch sources once; the watch reminds you when each is due for a check on its cadence and runs the CIP-007-6 R2 35-day evaluation and action clocks once you open a cycle.
Audit-readiness scoring
Per-standard readiness score that surfaces gaps before your next NERC audit; requirements not yet in force are shown as upcoming, not counted as gaps. Evidence stays linked to the specific CIP or IBR requirement it satisfies, and the audit binder includes applicability determinations, standard version history, assignees and event deadlines.
Coverage
CIP requirement to BizNerva workflow
Every CIP standard maps to a structured evidence workflow. IBR standards under FERC Order 901 and Order 909 follow the same pattern.
| CIP standard | Example BizNerva workflow |
|---|---|
| CIP-002 | BES Cyber System identification evidence and periodic review tracking |
| CIP-003 | Security management controls, policy evidence, and approval records. CIP-003-9, CIP-003-10 and CIP-003-11 are recorded with their effective dates |
| CIP-004 | Personnel risk assessment, training, and access authorization evidence |
| CIP-005 | Electronic security perimeter records and access evidence |
| CIP-006 | Physical security plan evidence and access logs |
| CIP-007 | System security management tasks and evidence |
| CIP-008 | Incident response plan, testing, and incident evidence |
| CIP-009 | Recovery plan evidence and testing records |
| CIP-010 | Configuration / change evidence and vulnerability assessment tracking |
| CIP-011 | Information protection evidence |
| CIP-012 | Control Center communications evidence and review records (CIP-012-2, effective July 1, 2026) |
| CIP-013 | Supply-chain risk management records |
| CIP-014 | Physical security risk assessment and review evidence |
| CIP-015 | Internal Network Security Monitoring (INSM) evidence. Directed by FERC Order 887, approved as CIP-015-1 in FERC Order 907, effective October 1, 2028 for Control Centers, with other medium impact systems 24 months later |
Scoping
Start from what you are registered for
Tell us your registered functions and the applicable standard set is derived for you, then checked site by site, so you are not scoping a 500-requirement universe by hand. Where a fact that decides applicability is missing, we ask for it instead of guessing. CIP applicability is driven separately by your BES Cyber System categorization.
Coverage
Operations & Planning standards
Your O&P obligations live beside CIP and IBR in the same evidence vault, task list and audit binder. BAL-001-TRE, EOP-005, FAC-001, FAC-002, IRO-010, MOD-025, MOD-026, MOD-032, PRC-012, PRC-017, PRC-019, PRC-024, TOP-003, VAR-001 and VAR-002 are tracked at the individual requirement; the rest per standard, all with owners, linked evidence and review dates. CIP is additionally broken out to the individual requirement and part; IBR to the individual requirement.
| O&P standard | Example BizNerva workflow |
|---|---|
| PRC-005 | Protection system maintenance evidence and review cycles |
| PRC-012 / PRC-017 | Remedial Action Scheme review, maintenance and testing records |
| PRC-019 | Generator voltage control and protection coordination records |
| PRC-024 | Generator frequency and voltage protection setting (no-trip region) evidence. PRC-024-4, effective October 1, 2026, no longer covers IBR |
| PRC-025 | Generator relay loadability setting records |
| MOD-025 | Real and reactive power capability verification records |
| MOD-026 | Model verification records under MOD-026-2, which replaced MOD-026-1 and MOD-027-1 on April 1, 2026 |
| MOD-032 | Power system modeling data submission records |
| VAR-001 / VAR-002 | Voltage and reactive control, and generator voltage schedule evidence |
| EOP-004 | Event reporting obligations and submitted-report evidence |
| EOP-005 | EOP-005-3 R1 to R16: restoration plan, blackstart testing and training records, including the 24-hour notice of a Blackstart Resource capability change |
| EOP-006 | System restoration coordination plan evidence |
| EOP-008 | Loss of control center functionality plan evidence and testing |
| FAC-001 / FAC-002 | FAC-001-4 R1 to R4 and FAC-002-4 R1 to R6: facility interconnection requirements and interconnection study documentation, per requirement |
| TOP-001 / TOP-002 / TOP-003 | Operating procedure, planning and data specification evidence |
| IRO-001, 002, 008, 010, 014, 017 | Reliability coordination procedure, data and outage coordination evidence |
| BAL-001 / BAL-001-TRE / BAL-002 / BAL-003 / BAL-005 | Balancing performance procedure and reporting evidence |
In development
What we are building next
These are not available yet. They are listed so you can judge the direction before you commit, and so early customers can shape the order we build them in.
Requirement-level breakout of the remaining O&P standards
BAL-001-TRE, EOP-005-3, FAC-001-4, FAC-002-4, IRO-010, TOP-003, MOD-025, MOD-026, MOD-032, PRC-012, PRC-017, PRC-019, PRC-024, VAR-001 and VAR-002 are already decomposed to their individual requirements. The remaining O&P standards, including the EOP-004, EOP-006 and EOP-008 reporting and plan standards, are being broken out to the same requirement-by-requirement level, so all of O&P is tracked the way CIP is today.
Automatic patch-feed ingestion for the CIP-007 evaluation cycle
Pull newly published patches from a registered vendor advisory feed and open the CIP-007-6 R2 evaluation cycle automatically. Today the patch-source register tracks your sources, reminds you when each is due for a check on its cadence, and runs the 35-day evaluation and action clocks once you open a cycle.
Trust posture
Built for conservative compliance environments
BizNerva is designed for evidence management, workflow control, audit preparation, and advisor collaboration. AI assistance supports review and gap detection. The core system of record stays structured, permissioned, evidence-linked, and exportable. Standard version changes are reviewed by a person before they apply.
Audience
Who this is for
Best fit for
- Registered utilities managing NERC CIP evidence
- Co-ops and smaller registered entities without large compliance teams
- Solar, wind, and battery operators preparing for IBR reliability obligations
- Category 2 non-BES IBR owners and operators newly registered with NERC
- NERC consultants and advisory firms running client programs on one platform
- Compliance teams that need structured evidence before the next audit cycle
Not a replacement for
- Legal counsel
- Real-time system operations and dispatch
- GADS performance and availability reporting
- Engineering studies
- OT security tooling
- Managed security operations
Platform
Built on the BizNerva platform
Evidence vault, task ownership, readiness scoring, gap detection, exportable audit binders, and partner access apply to CIP, O&P and IBR workflows where traceability, evidence freshness, and audit readiness matter most. See the full platform layer.
FAQ
NERC compliance questions we get asked
- Which NERC standards does BizNerva cover?
- BizNerva covers NERC CIP-002 through CIP-015, Operations and Planning standards across the BAL, EOP, FAC, IRO, MOD, PRC, TOP and VAR families, and the Inverter-Based Resource standards developed under FERC Order 901, including those FERC approved in Order 909. CIP is tracked at the individual requirement and part; IBR is tracked at the requirement level (PRC-028-1 R1 to R8, PRC-029-1 R1 to R4, PRC-030-1 R1 to R4 and MOD-026-2 R1 to R7). For O&P, a set of standards is tracked at the individual requirement and the rest per standard, all with owners, linked evidence and review dates.
- Does BizNerva cover NERC O&P standards or only CIP?
- Both. Operations and Planning standards are tracked alongside CIP in the same evidence vault, task list and audit binder, so a registered entity does not run its O&P program in a separate spreadsheet. CIP is decomposed to requirement and part level. For O&P, BAL-001-TRE, EOP-005-3, FAC-001-4, FAC-002-4, IRO-010, MOD-025, MOD-026, MOD-032, PRC-012, PRC-017, PRC-019, PRC-024, TOP-003, VAR-001 and VAR-002 are decomposed to their individual requirements. The remaining standards, including EOP-004, EOP-006, EOP-008, TOP-002 and PRC-025, are tracked per standard, with further requirement-level breakout in development. PRC-005 maintenance is scheduled per component through the protection-system component register, whose maximum-interval dates drive review tasks on the same calendar as CIP.
- How does BizNerva decide which NERC standards apply to us?
- Applicability is derived from the functions the entity is registered for, covering Generator Owner, Generator Operator, Transmission Owner, Transmission Operator, Balancing Authority, Reliability Coordinator and Distribution Provider, and then evaluated per site against the conditions of each standard. CIP applicability is driven separately by BES Cyber System categorization, so a change to categorization re-flags the requirements it affects for review. When a fact that decides applicability is missing, the standard is marked Needs input and you are asked for that fact rather than being given a guess.
- Does BizNerva handle Category 2 non-BES inverter-based resources?
- Yes. For each site, each standard is determined Applicable, Not applicable, Needs input or Not yet applicable, with the reasons and a citation. Not yet applicable is used for standards NERC lists for Category 2 as Requires Modification or In Development, such as EOP-005: they are tracked but not yet applied. From the resources you record, BizNerva shows whether a point of interconnection meets the Category 2 registration threshold of 20 MVA aggregate nameplate capacity at 60 kV or above. That check is a hint only; it never sets your facility classification. You can override a determination, but an override requires a written reason and is recorded.
- What happens when NERC revises a standard?
- Each standard version is recorded with its FERC approval and its effective and retirement dates. An approved future version is staged and takes effect on its effective date; TOP-003-7, for example, is staged to replace TOP-003-6.1 on October 1, 2026. When the new version takes effect, the prior version is marked superseded, its evidence links and assigned owners carry forward to the new requirements, and the superseded record keeps its status and history. Retirement is handled the same way. Detection is automatic, application is not: version changes found by the regulatory scanner are reviewed and approved by a BizNerva platform administrator before they apply, and a version whose requirement text has not been reviewed is recorded for reference only and is not applied to your requirements. When a new version changes a requirement you own, such as its wording, review interval or event deadlines, that requirement is flagged for review with the before and after, and the flag stays until someone reviews it. Upcoming version dates appear as alerts ahead of time.
- How does BizNerva show requirements that are phased in later?
- A requirement whose compliance date has not arrived is shown as upcoming with that date, and it does not count as a gap in readiness until it applies. PRC-029-1 R1 to R3 are split into a capability (design) portion and a performance (operation) portion: the capability portion applies on the effective date for BES IBRs and on the later of January 1, 2027 or the effective date for Category 2 non-BES IBRs, and the performance portion stays upcoming until the facility records that its PRC-028-1 disturbance monitoring equipment is established. CIP-015-1 is phased the same way: Control Centers and backup Control Centers on October 1, 2028, and other medium impact BES Cyber Systems with External Routable Connectivity 24 months later.
- How are event deadlines such as PRC-028, PRC-030, VAR-002 and EOP-005 tracked?
- When you record an event, BizNerva computes the deadlines those standards start from the event date and time, in the time zone recorded for that facility. Each facility carries its own time zone, and an event cannot be logged at a facility with no time zone recorded, so a deadline is never computed from a guessed zone. For clocks counted in hours or minutes, such as the 30-minute VAR-002-4.1 R3 and R4 notifications, the time of the event is required and the owners are notified as soon as the event is logged. For day-based clocks, the people assigned to the requirement are reminded 30, 7 and 1 days before each deadline, and a deadline that passes without completion is escalated to the approvers and organization administrators.
- Does BizNerva do NERC GADS reporting?
- No. BizNerva does not produce GADS performance or availability submissions, and it does not connect to plant historian, PI or SCADA systems. It is a compliance evidence and audit-readiness system of record for CIP, O&P and IBR obligations. Generator Owners with a GADS reporting obligation need a separate GADS tool.
- How does BizNerva handle CIP-015 and INSM?
- Internal Network Security Monitoring evidence is tracked against CIP-015. FERC Order 887 directed NERC to develop INSM requirements, and FERC approved Reliability Standard CIP-015-1 in Order 907, with a United States effective date of October 1, 2028. Compliance is phased: Control Centers and backup Control Centers on the effective date, and other medium impact BES Cyber Systems with External Routable Connectivity within 24 calendar months after it. BizNerva tracks the evidence and review records for the standard; it is not itself a network monitoring or OT security tool.
- Can a consultant or advisory firm manage several registered entities?
- Yes. Every NERC surface has a partner view, so a Fractional Compliance Officer or NERC consultant can run multiple client programs from one login, with personally identifiable information redacted on partner reads.
- What does BizNerva not replace?
- BizNerva does not replace legal counsel, real-time system operations and dispatch, GADS performance and availability reporting, engineering studies, OT security tooling, or managed security operations. It is the system of record for compliance obligations, evidence and audit preparation.