NERC CIP-aligned service evidence, plant-wide.
Power generation operators and utilities run turbines, transformers, switchgear, and protection systems under NERC CIP — Critical Infrastructure Protection for the bulk electric system. CIP-002 governs BES Cyber System categorization (High / Medium / Low impact); CIP-004 governs personnel & training; CIP-007 governs system security and patch management; CIP-010 governs configuration change management; CIP-013 governs supply-chain risk for vendor-supplied equipment service. ISO 55000 sits as the asset-management overlay. Wēlr lives on the corporate-network side of the Electronic Security Perimeter, integrated with work execution at the OT boundary — where baseline changes, patch evidence, personnel currency, and vendor access converge into one work-management record.
Four pains the NERC CIP auditor will surface.
- 01
CIP-010 baseline changes drift from the work orders that caused them.
Configuration baselines for BES Cyber Assets (CIP-010 R1) are tracked in one system; the work that changed them is tracked in another. The 30-day documentation window (R1.5) and the variance analysis (R3) become reconciliation projects — not a posture. CIP-010 R1 is consistently among NERC's highest-finding requirements; baseline-to-work-order reconciliation is the cleanest product-fit story.
- 02
CIP-007 R2 patch management evidence assembled audit-side.
Patch sourcing, evaluation, and installation evidence (CIP-007 R2) runs on a 35-day clock per applicable system and requires documentation of patch source, evaluation, applicability, and disposition. Most utilities assemble this from email threads, ticketing systems, and patch-tool exports the week of the audit. CIP-007 R2 is the highest-finding CIP requirement in recent NERC enforcement data.
- 03
CIP-004 personnel currency tracked by spreadsheet.
CIP-004-7 requires documented training (R2), personnel risk assessment with a 7-year renewal cycle (R3), access authorization (R3.5), and quarterly access reviews (R4). Currency, PRA-renewal due dates, and quarterly review cadence live on a spreadsheet rebuilt before every audit. The findings are frequent but procedural — and they accumulate.
- 04
CIP-013 vendor performance self-reported by the vendor.
Long-term service agreements with the turbine OEM, transformer OEM, and protection-relay vendor include performance commitments. CIP-013 R1 requires a documented supply-chain risk management plan and verifiable execution evidence (R1.2 vendor security risk identification). Most utilities verify vendor service performance and vendor-access risk after the fact — and the CIP-013 R1.6 audit can't confirm what wasn't tracked.
Four primitives. One BES-aware record.
CIP-010 baseline + work order on one record
Baseline changes are linked to the work order that caused them. Baseline changes timestamped against the 30-day CIP-010 R1.5 documentation window automatically. Variance analysis (R3) runs against the live record. The work order is the baseline change record.
CIP-007 R2 patch evidence by construction
Patch source, evaluation, applicability, and disposition entries auto-generated against the 35-day CIP-007 R2 clock per applicable system. Patch evidence is a query against the live record, not an assembly project the week of the audit.
CIP-004 personnel record on the dispatch path
Training currency (R2), PRA initial completion + 7-year renewal due date (R3), access authorization (R3.5), and quarterly access reviews (R4 — last reviewed, next due, reviewer) live as first-class attributes. Auth-gated dispatch fails closed when currency lapses or quarterly review is overdue.
CIP-013 vendor-personnel + vendor-performance record
Vendor risk-assessment cadence, scope, and outcome tracked on the record (CIP-013 R1.2) — Wēlr records execution evidence, the utility makes the risk decision. Vendor service performance verified by utility data, not vendor self-report.
Why not extend the CMMS / patch-tool / GRC stack you already run?
Most utilities run a CMMS for work orders, a patch tool for CIP-007 evidence, a GRC platform for CIP-004 access tracking, and a separate CIP-010 baseline reconciliation cycle. Four systems, four audit trails — and a spreadsheet on top.
| Capability | Wēlr | Generic CMMS + patch tool + GRC Maximo + WSUS / Ivanti + Sailpoint / Saviynt | Custom utility build Internal enclave + custom apps |
|---|---|---|---|
| CIP-010 baseline = work order on one record | Single workflow · R1.5 30-d auto | Two systems · manual reconcile | Custom integration |
| CIP-007 R2 patch evidence against the 35-d clock | Auto-generated, audit-on-demand | Patch tool + audit-week assembly | Custom |
| CIP-004 personnel record on dispatch path | Auth-gated · fails closed · R4 quarterly tracked | Spreadsheet · GRC tool | Custom development |
| CIP-013 R1.2 vendor-risk execution evidence | Per-task, per-window structural | After-the-fact review | Custom |
| CIP-008 / CIP-009 IR + recovery test cadence | Annual test scheduling + evidence in-band | Manual collection cycle | Annual project |
CIP-004 personnel currency, with dispatch-time enforcement.
When the regional entity audits CIP-004, they want training currency, PRA 7-year renewal posture, and the quarterly R4 access-review record across every individual with access to BES Cyber Systems. Wēlr maintains that matrix as a live record. A technician whose CIP-004 R2.2.3 refresher has lapsed cannot be dispatched against a BES Cyber System work order. The system enforces what the spreadsheet describes — and the quarterly review cadence runs against the calendar, not against the audit.
- Auth-gated dispatch — training lapse, PRA renewal overdue, or quarterly review missed all fail dispatch closed
- PRA tracked as initial completion + 7-year renewal due (CIP-004-7 R3) — not as a single expiration timestamp
- Quarterly R4 access reviews scheduled by the system · last reviewed, next due, reviewer identity, outcome — all in-band
- Vendor personnel (CIP-013 R1.2) scoped per outage window · Wēlr records risk-assessment execution; the utility makes the risk decision
If any of these are true, we should talk.
- ✓Your CIP-010 baseline change records and the work orders that changed them live in different systems, and the 30-day R1.5 documentation cycle is reconciled by hand.
- ✓Your CIP-007 R2 patch evidence — source, evaluation, applicability, disposition against the 35-day clock — is assembled from email threads and patch-tool exports the week of the audit.
- ✓Your CIP-004 personnel currency (training, PRA 7-year renewal, quarterly R4 access reviews) is tracked on a spreadsheet rebuilt before every audit.
- ✓Your CIP-013 R1.2 vendor-risk-management execution is verified after the fact — not at the work-order or access-decision boundary.
- ✓A NERC regional-entity audit found a CIP-007, CIP-010, or CIP-004 gap the team traced to evidence that couldn't be reconstructed inside the response window.
A small founding cohort is shaping Wēlr for power generation & utilities.
Founding partners get preferential pricing, a direct line to engineering, and meaningful influence over the Energy & utilities roadmap. Limited to a small cohort per vertical.
- Preferential pricing
- Direct line to engineering
- Roadmap influence
- Limited cohort
Ready to stop stitching service evidence together?
If your team is juggling PDFs, support packages, work orders, customer updates, and QA evidence across five systems, Wēlr is worth a look.
Welr LLC · Delaware