Carry the evidence each CIP interval consumes — the patch date, the evaluation, the baseline, the quarterly access check — and hold it for the CIP Senior Manager named under CIP-003-9 R3.
A patch publishes, and CIP-007-6 Part 2.2 allows 35 calendar days to evaluate it for applicability.
02
An evaluation completes, and Part 2.3 gives 35 more days to apply or to date a mitigation plan.
Reason
03
A mitigation plan runs long, and only the CIP Senior Manager or delegate may extend it under Part 2.4.
04
A change completes, and CIP-010-4 Part 1.3 allows 30 calendar days to update the baseline.
05
An access review falls due, and CIP-004-7 Part 4.2 wants verification each calendar quarter.
Decide
06
A termination action lands, and CIP-004-7 Part 5.1 leaves 24 hours to revoke the access.
07
An incident is judged, and the CIP-008-6 Part 4.2 hour runs from determination, not detection.
Out
08
A manager changes, and CIP-003-9 R3 wants the new name documented within 30 calendar days.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
The agent assembles and tracks intervals. The named person is the CIP Senior Manager, who approves — the self-certification itself carries no attestation.
Example workflow
One interval, evidence to approval
AgentHuman
1Interval evidence receivedPatch bulletins, baselines, access records or termination feeds
2Interval context assembledThe system, its impact rating, the standard part it answers to and the date the clock started
3Evidence set draftedThe interval, its records, the gaps and completeness
4Controls appliedInterval checks, evidence-sufficiency checks, date checks and completeness confidence
No human action required
Stages 1 to 4 run unaided, and nothing is approved at any of them — the agent is assembling, and the compliance lane opens at the completeness gate.
5DecisionSplits at the completeness gate
Evidence sufficient
Goes to the CIP Senior Manager to approve.
Anything thin
Adds a compliance analyst read first.
Compliance review
The set is held with its interval, its gaps and the systems they sit on.
Approve · Append evidence · Send to compliance
Approved — by the CIP Senior Manager▼
6Asset and access records updatedOnly where write access and records policy allow it
7Outcome evaluatedEvidence completeness, interval coverage, analyst corrections and what review found
Corrections
Each analyst correction is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Determining that an incident is reportable.
Approving cyber security policies under CIP-003-9 R1.
Signing a self-certification or any CMEP submission.
Extending a mitigation plan under CIP-007-6 Part 2.4.
Automation boundaryAgent acts unaided
✓Hold the record each CIP interval consumes, with the date it carries.
✓Track each interval against the standard that sets it.
✓Chase the missing record before the calendar-day window closes.
✓Flag the determination criteria that start the one-hour.
Nothing is approved or filed except by a named person, inside the agreed boundaries.
Judging whether an interval was in fact met.
Telling a Regional Entity the estate is compliant.
Setting the impact rating a system is held at.
Changes to access, baselines or firewall rules.
Example output
One interval, annotated
Our control room copilot leaves the command to the operator; this record is what one CIP interval consumed.
Evidence set · single intervalIllustrative example
Interval
Recorded as
System
Evidence of record
Confidence
Held for
Patch evaluation, Part 2.2
Evaluated for applicability, not applicable
Medium impact
Vendor bulletin, 3 August 2026
Held unapproved
The CIP Senior Manager, by name
As receivedTaken from the vendor bulletin and the patch record — it reaches as far as those sources do.
What the record holdsVendor bulletin dateEvaluation recordMitigation plan, dated
Why no interval call hereWhether the window was met is a CIP-007-6 judgement, not a model output.
ActionApproveAppend evidenceSend to compliance
What the score decidesBelow the configured threshold the set picks up a compliance read before the manager sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every intervalFrom the system that owes it
03Evidence
Where the evidence is used
Our compliance reporting assistant works a register and names no regime; this page is one regime, with its own clocks and its own named role.
01Approved path
The clock starts when you say so
CIP-008-6 Part 4.2 runs one hour from determination under your own R1 Part 1.2 criteria, not from detection.
02Human review
What was checked, and not found
NERC publishes neither CIP audit reports nor noncompliance filings — they are treated as critical energy infrastructure information — and no aggregate total is published.
04Build an evidence trail
The evidence, the interval it belongs to and the manager who approved stay on the record.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Patch and vulnerability sourcesVendor bulletins · CVE feeds Patch management systems
Configuration and baselinesCMDB · configuration monitoring Change records
Access and personnelIdentity provider · HR feed Termination and transfer records
Agent
NERC CIP compliance evidence
Reads the intervals Assembles the evidence Holds for the manager
Incident and case systemsSIEM · ticketing Determination criteria records
A rating-level interval-evidence figure can read clean while low impact systems carry most of the corrections. Nestack reports the correction rate by impact rating, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Low impact systems
10.2%
3.6×
Review
Medium impact at Control Centers
7.6%
2.7×
Review
Medium impact with routable access
4.7%
1.7×
Watch
High impact Control Centers
1.6%
0.6×
Normal
Bar: correction-rate lift vs. high-impact Control Center baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What a missed window costs
A cycle closes when the missed evaluation window is a regression case. That suite is what the next interval worked is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on low impact systems.
02Diagnose
The patch that published on a Friday and was evaluated thirty-six days later is read back until one cause remains.
03Improve
The change ships numbered, and the intervals that forced it ride with it.
04Verify
Nothing releases while one touched system case is still red.
05Learn
It is retained for good, and the interval rules are amended in that same commit.
Learn → DetectThe return edge. The next interval is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, evidence assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01CIP-interval discovery and automation-boundary work.
02Patch, baseline and access sources.
03Interval-to-standard and evidence-coverage mapping.
04Interval evidence ingestion.
05System, part and record binding.
06Completeness scoring and review routing.
07Manager approval workflow.
08Asset and access-system integration.
09Interval and evidence cases.
10Guardrails and approval controls.
11Interval-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne rating, one yearProductionProduction compliance workflowAdvancedMultiple ratings / entities
Introduced at Pilot
Evidence assembly to your intervals✓✓✓
CIP Senior Manager release✓✓✓
Asset-inventory baseline✓✓✓
Introduced at Production
Reporting by impact rating—✓✓
Approval workflow in your systems—✓✓
Approved write-back—✓✓
Configuration-system integration—✓✓
Introduced at Advanced
Multi-entity registrations——✓
Cross-standard evidence packs——✓
Large asset estates——✓
Multi-standard interval controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your registered systems and their impact ratings→Asset-inventory mapping and interval captureWeek 1
02Representative patch, baseline and access records→Record binding, interval logic and the evidence baselineWeek 2
03Your determination criteria under R1 Part 1.2→Interval mapping, system binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Patch, configuration and access-source assessment, then integration setupWeek 2
05Intervals you would not want reconstructed→Evaluation cases and failure-mode testingWeek 4
06What no evidence set may establish→Completeness scoring, review routing, guardrails and release controlsWeek 3
07A named CIP Senior Manager to approve→Manager approval workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
These bands are the weeks each phase honestly costs, and the fifth one therefore has to carry two.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1CIP workflow discovery, interval mapping and the automation boundaryW2Source integration and the interval-evidence baselineW3Evidence assembly, interval logic and release controlsW4Evaluation suite, interval cases and failure-mode testingW5Record integration, pilot intervals and targeted correctionsW6One compliance year run under the CIP senior manager, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. The fifth week carries two because the work does.
At the end of W6Validation closes on live intervals, and Agent Care picks up the watch.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Energy AI agent
Build a CIP evidence agent around the intervals your estate already owes.
Show us one interval and the record it consumed. If patch evaluation and mitigation planning sit apart across your estate, then the Part 2.3 window is kept on trust. Your self-certification calendar is your Regional Entity's; plant OT monitoring is a different agent.