ENERGY COMPLIANCE, INC. Rigorous Compliance. Defensible Programs. HomeWhitepapers › EC-WP-207

Cybersecurity / CIP · EC-WP-207

CIP Evidence: Building Audit-Defensible Programs

CIP compliance is a documentation discipline. The control might be perfect; if the evidence isn't there, the auditor produces a finding.

CIP compliance is a documentation discipline. The control might be perfect; if the evidence isn't there, the auditor produces a finding. Across every CIP standard from CIP-002 through CIP-014, the audit outcome turns on whether evidence was captured, organized, and retained, and whether it actually demonstrates what the program claims it demonstrates. Programs that build evidence as a live deliverable pass cleanly. Programs that assemble evidence retrospectively get caught by what they didn't preserve. — Evidence is the backbone of CIP compliance. Without it, every control is a claim. With it, every claim is defensible. — Most CIP findings aren't control failures. They're evidence gaps that look like control failures from the auditor's seat. — Evidence aging is the slow killer. Procedures that worked perfectly two years ago produce no defensible evidence today. — Sampling is how the auditor reads the program. A clean sample of bad evidence produces worse outcomes than a sample of mixed evidence honestly characterized. — Cross-standard evidence reconciliation is where most programs leak findings. CIP-007 evidence has to align with CIP-010 baselines, which have to align with CIP-002 classification. — Documentation that exists only in someone's head isn't documentation. It's a single point of evidence failure. — An evidence program designed to answer the next RFI is good.

Contents

  1. Foreword
  2. What CIP Evidence Actually Is
  3. The Evidence Inventory Most Programs Don't Have
  4. Evidence Architecture: Built or Built Up
  5. Sampling: What the Auditor Actually Asks For
  6. Evidence Aging and the Refresh Discipline
  7. Cross-Standard Evidence Reconciliation
  8. Common Evidence Failures and What They Cost
  9. Building an Evidence Program That Survives Audit
  10. About the Author
  11. About Energy Compliance, Inc.

Read offline

The complete reference is on this page. The PDF is for circulation inside your organization.

Download the PDF

Foreword

Foreword

This professional reference is one of a series Energy Compliance, Inc. publishes for registered entities and the people who run their compliance programs.

I've spent more than thirty years on every side of the bulk electric system. I've operated control centers as a Reliability Coordinator, Transmission Operator, and Power System Operator. I've audited grid facilities and signed off on findings as a senior compliance auditor. I've worked enforcement matters from inside the regulator's process. For the last several years I've advised registered entities directly through the firm I founded.

The entities that do reliability well share a common habit. They take the standards seriously without confusing them with reliability itself. They know that a NERC Reliability Standard is a floor, not a ceiling. They know that compliance is something an auditor evaluates, but reliability is something a system either delivers or doesn't. They prepare for audits by building programs that survive real questions, not binders that look thick.

That's the perspective these references try to share. Each one focuses on a single topic. A standard family, an operational function, a regulatory framework, or an emerging industry challenge. Each one walks through how the topic actually works.

These references are written for the compliance manager who wants to understand the system, not just memorize requirements. For the legal counsel who has to brief a board honestly. For the senior operator who's been told that compliance and reliability are the same thing and suspects they aren't. And for the new compliance hire who got handed a binder and told good luck.

These references aren't marketing material disguised as content. They're the result of three decades of doing this work and watching it succeed and fail. I've written them in the same voice I use in a control room or in front of a Regional Entity audit team. Direct, evidence-grounded, honest about what the standards do and do not require.

Energy Compliance exists because most of the consulting offered to registered entities today is structured for billable hours rather than for outcomes. Every engagement is led by one senior practitioner. We don't bring five people to a meeting that needs one. We automate the work that should be automated. We apply senior judgment to the work that requires it. If that approach matches what you're looking for in a compliance partner, the back of this reference has our contact information.

If not, the reference still belongs to you. Take what's useful. Apply it well. And remember the only test that ultimately matters: when the system needs to perform, does it?

Rob Smith, Founder, Energy Compliance, Inc.

EC-WP-207 CIP Evidence

What CIP Evidence Actually Is

What CIP Evidence Actually Is

CIP evidence is anything that would convince an objective reviewer that the control existed, executed correctly, and was applied consistently. Definition matters.

CIP evidence is not a single artifact. It's the body of records, logs, screenshots, configurations, signatures, attestations, and metadata that, taken together, demonstrate that a CIP requirement was met. Different requirements call for different evidence types. A CIP-005 perimeter review needs network diagrams, firewall rule sets, and change records. A CIP-007 patching evidence needs patch lists, applicability assessments, deployment records, and exception documentation. Knowing what counts as evidence for each requirement is foundational.

The auditor's perspective on evidence is consistent across CIP standards. Evidence has to be authentic, provably from the system or process it claims to document. Evidence has to be contemporaneous, created at the time the control executed, not assembled afterward. Evidence has to be complete, covering the full audit period and the full scope of the requirement. Evidence has to be coherent, internally consistent and reconciled across related artifacts.

Programs that internalize these four characteristics build evidence as a continuous output of operations. Programs that treat evidence as something to assemble before audit produce material that fails one or more characteristics, and the auditor identifies the failure. The most common failure: evidence that exists but wasn't preserved when the system that generated it was decommissioned, replaced, or reconfigured.

FROM THE FIELD Evidence has four jobs: authenticity, contemporaneity, completeness, coherence. Miss any of the four and the audit notices. Evidence assembled retrospectively rarely passes the contemporaneity test. The auditor can tell. What counts as evidence is requirement-specific. Programs that use the same evidence template for every CIP standard misframe the work.

The Evidence Inventory Most Programs Don't Have

The Evidence Inventory Most Programs Don't Have

ave Programs that don't catalog their evidence sources can't tell what's missing until the auditor asks for it.

Most CIP programs have evidence. Few have an evidence inventory. The difference matters at audit. An inventory tells the program what evidence exists, where it's stored, who maintains it, how long it's retained, and which CIP requirements it supports. Without an inventory, evidence is a series of artifacts the program hopes will be sufficient when the audit asks.

Building an evidence inventory is a one-time effort followed by ongoing maintenance. The one-time effort: catalog every evidence source that supports any CIP requirement, document its retention policy, identify the CIP requirement(s) it satisfies, and assign an owner. The ongoing maintenance: every operational change that affects evidence sources triggers an inventory update.

The payoff at audit is significant. The program can answer evidence-related RFIs in hours instead of days because the evidence location is known. The program can demonstrate completeness by referring to the inventory rather than searching for gaps in real time. The program can identify evidence gaps early, during the inventory exercise, rather than during the audit when the cost of correction is much higher.

The cost of not having an inventory is also significant. RFI response times stretch. Evidence gaps surface during audit when remediation is no longer possible for the audit period. The program's apparent maturity to the auditor is reduced. None of these alone are catastrophic. Together, they shape the audit posture in negative ways.

FROM THE FIELD An evidence inventory turns evidence from artifacts into infrastructure. Programs that can answer evidence RFIs in hours have inventories. Programs that can't, don't. The audit catches the gaps the inventory would have surfaced earlier. The cost of finding them late is the audit finding itself.

Evidence Architecture: Built or Built Up

Evidence Architecture: Built or Built Up

Evidence systems are either designed for compliance or accreted from operational artifacts. The two have different audit profiles.

Evidence comes from somewhere. In some programs, it comes from systems explicitly designed to produce compliance evidence, automated logging, continuous monitoring, structured documentation workflows. In others, it comes from operational systems that happen to also produce records that can serve as evidence. The difference shapes the audit experience.

Designed evidence systems produce consistent, complete, contemporaneous records. The evidence comes out the way it was designed to. The audit reads it cleanly. Designed systems require investment up front and ongoing maintenance, but they pay back in audit efficiency and finding avoidance.

Accreted evidence systems use what's available. Operational logs that happen to capture compliance-relevant events. Email trails that happen to document approvals. Calendar entries that happen to show meeting frequency. The evidence is real, but it's irregular, sometimes incomplete, and frequently requires interpretation. The audit reads it with more friction.

Programs that have grown into accreted evidence systems often don't notice until the audit. The evidence has been "adequate" for years, in the sense that no auditor has flagged it as deficient. Then a more thorough audit cycle arrives, and the gaps become visible. The remediation requires not just fixing individual evidence sources but redesigning the evidence architecture, which takes longer and costs more than the original investment would have.

FROM THE FIELD Evidence systems are either designed for compliance or accreted from operations. The audit can tell the difference. Designed evidence systems require investment. Accreted evidence systems require explanation. The cost of redesigning an accreted evidence system after a finding exceeds the cost of designing it intentionally from the start.

Sampling: What the Auditor Actually Asks For

Sampling: What the Auditor Actually Asks For

CIP audits sample. The sample selection is not random. Knowing how auditors sample lets programs prepare effectively.

The auditor doesn't review every artifact in the audit period. They sample. Understanding how they sample is one of the more practical pieces of audit-preparation knowledge a CIP program can possess. Sampling isn't random. The auditor selects samples designed to test specific risk hypotheses about the program's operation.

Common sampling strategies: stratified samples across asset classes (representative coverage), risk-weighted samples (concentration on high-impact systems), temporal samples (spanning the audit period to detect drift), boundary samples (testing the edges of scope or classification), and exception samples (focusing on entries that look unusual). Each strategy probes a different aspect of program quality.

Programs that anticipate sampling prepare differently than programs that don't. Anticipating programs ensure that every category of asset, every time period, every classification boundary, and every exception case has clean, defensible evidence. They run their own internal samples before the audit to identify weak points. They strengthen the weak points before the auditor finds them.

The other consequence of sampling: the audit's view of the program is shaped by the samples drawn. A sample that produces clean results frames the program favorably and may shorten the audit. A sample that produces issues frames the program unfavorably and triggers expanded sampling. Programs that handle the first sample well have meaningfully shorter audits. Programs that don't, often have audits that grow.

FROM THE FIELD Auditors sample. Sampling isn't random. Knowing the strategies lets programs pre-test their weak points. A clean first sample shortens the audit. A dirty first sample lengthens it. Programs that run internal sampling before audit identify the issues at internal cost. Programs that don't, identify them at audit cost.

Evidence Aging and the Refresh Discipline

Evidence Aging and the Refresh Discipline

Evidence has a useful life. Programs that don't refresh aging evidence end up defending stale records against current standards.

CIP standards revise. Evidence requirements change. Equipment gets replaced. Systems get reconfigured. Personnel rotate. Each of these events ages the evidence base. Evidence that perfectly demonstrated compliance two years ago may not demonstrate compliance against the current standard, and the program needs a refresh discipline to keep current.

The refresh discipline has two parts. First, periodic re-validation: at defined intervals, evidence is re-examined to confirm it still supports the requirement it was originally captured for. Standards may have revised, scope may have shifted, the system the evidence comes from may have changed. The re-validation catches these issues. Second, change-triggered refresh: any operational change that affects an evidence source triggers a review. Equipment replacement triggers re-capture of equipment-specific evidence. System reconfiguration triggers re-documentation. Personnel changes trigger handoff documentation.

Programs without a refresh discipline accumulate stale evidence. The accumulation is invisible until audit, when the auditor compares evidence dates against system change records and finds that evidence dated 2022 references a configuration that was retired in 2023. The finding follows.

The cost of refresh is small relative to the cost of stale-evidence findings. A quarterly evidence refresh review takes hours. A finding on stale evidence takes weeks of mitigation, regulatory engagement, and documentation overhead.

FROM THE FIELD Evidence has a useful life. Programs without a refresh discipline are accumulating findings they can't see. Quarterly evidence refresh takes hours. Stale evidence findings take weeks. The math is one-sided. The auditor compares evidence dates against system change records. Programs that don't, find out the auditor did.

Cross-Standard Evidence Reconciliation

Cross-Standard Evidence Reconciliation

CIP standards interlock. Evidence supporting one standard has to align with evidence supporting related standards. Inconsistency triggers findings on multiple standards at once.

The CIP standards don't operate independently. CIP-002 classification flows into CIP-005 perimeter scope. CIP-005 perimeter flows into CIP-007 system security. CIP-007 baselines flow into CIP-010 change management. CIP-010 changes flow into CIP-011 information protection. The standards form a connected control architecture, and the evidence has to reconcile across the architecture.

Cross-standard inconsistency is one of the more expensive audit failure modes. The auditor finds that a system classified as Medium Impact under CIP-002 doesn't appear in the CIP-005 perimeter inventory. Or a baseline change under CIP-010 doesn't show up in CIP-007 patch records. Or a cyber asset on the CIP-005 inventory isn't reflected in the CIP-002 classification list. Each inconsistency triggers a finding on the standard with the gap, plus questions about the related standards.

Programs that maintain cross-standard evidence reconciliation share a common practice: a single, authoritative asset inventory that all CIP standards reference. The inventory has every cyber asset, every classification, every perimeter assignment, every baseline reference. Updates flow through the inventory, not around it. Evidence captured for any standard is anchored to inventory entries.

This isn't trivial to build, and it's harder to retrofit than to design from the start. But it's the foundation that makes large CIP programs auditable at scale. Without it, every audit becomes a forensic exercise in reconciling separate evidence streams. With it, the audit becomes a verification exercise.

FROM THE FIELD CIP standards interlock. Evidence has to interlock too. Inconsistency triggers findings across multiple standards. A single authoritative asset inventory is the foundation of cross-standard evidence reconciliation. Without it, audit becomes forensics. Cross-standard inconsistencies cost more than single-standard gaps. The auditor extends scrutiny when reconciliation fails.

Common Evidence Failures and What They Cost

Common Evidence Failures and What They Cost

The evidence failure patterns are repeatable. Knowing them in advance is most of the prevention.

The patterns of evidence failure across CIP audits are public and reproducible. Most failures fall into a small number of categories, and programs that prepare specifically for these categories avoid most of the findings other programs accept.

Pattern one: missing evidence for required controls. The control was implemented. The evidence was not preserved, was deleted, or was never captured. The auditor finds the gap. Penalty exposure depends on the requirement; some have specific evidence retention rules.

Pattern two: evidence that doesn't match the control description. The evidence shows the control was executed differently than the documented procedure. The auditor records both versions. The finding can run against the procedure (it didn't reflect operations) or against the control (it didn't follow procedure).

Pattern three: evidence with provenance gaps. The auditor can't determine where the evidence came from, who captured it, or whether it's authentic. Findings here often involve broader programmatic concerns about evidence integrity.

Pattern four: evidence inconsistency across related artifacts. Logs that don't match procedures that don't match attestations. The cross-references break, and the auditor can't reconstruct what actually happened.

Pattern five: stale evidence that no longer reflects current operations. Discussed earlier; the most common single failure mode in CIP audits.

Each pattern has a prevention strategy. Programs that work through the patterns systematically have measurably better audit outcomes than programs that prepare generically.

FROM THE FIELD Evidence failure patterns are repeatable. Knowing them in advance is most of the prevention. Provenance gaps in evidence trigger broader programmatic concerns. The finding extends beyond the specific evidence to the program's evidence integrity. Generic audit preparation produces generic results. Pattern-specific preparation produces measurably better outcomes.

Building an Evidence Program That Survives Audit

Building an Evidence Program That Survives Audit

An evidence program designed for survival is built around five principles. Programs that follow them outperform programs that don't.

The CIP evidence programs that consistently survive audits without surprises share five characteristics. None are exotic. All require sustained discipline.

Principle one: evidence is captured as part of the operation, not after. Every control execution generates evidence as a byproduct. Evidence-by-design, not evidence-by-assembly.

Principle two: evidence is inventoried. The program knows what evidence exists, where it's stored, who maintains it, and which requirements it supports. The inventory is current.

Principle three: evidence reconciles across standards. A single authoritative asset inventory anchors evidence for all CIP standards. Cross-standard relationships are explicit and verified.

Principle four: evidence is refreshed on cadence and on change. Periodic re-validation catches drift. Change-triggered refresh catches obsolescence.

Principle five: evidence is internally audited before the external audit arrives. The program runs its own samples, identifies its own gaps, and addresses its own issues before the Region does.

Programs that operate under these five principles spend less on audit defense, produce fewer findings, mitigate findings faster when they do occur, and present better to the Region during ongoing oversight. The principles aren't a checklist to be applied in the months before audit. They're program design choices made early and reinforced continuously over years.

FROM THE FIELD Five principles, sustained over years, separate evidence programs that survive from those that don't. Evidence-by-design beats evidence-by-assembly at every audit. The investment shows. Programs that audit themselves before the Region does have shorter, cleaner external audits. The internal cost is the prevention.

About the Author

About the Author

Rob Smith is a senior electric industry professional with over thirty years of experience across every major function of the North American Bulk Electric System. His work spans reliability coordination, transmission operations, regulatory compliance, and cybersecurity reliability.

Rob has worked directly in real-time grid operations as a Reliability Coordinator, Transmission Operator, and Power System Operator within RTO/ISO and utility control center environments. He has also held senior regulatory and oversight roles, including senior compliance auditor and subject matter expert for NERC Reliability Standards. In those roles he audited grid facilities for compliance with applicable standards, evaluated the adequacy of mitigation actions, supported the development of violation notifications and settlements as part of FERC-directed enforcement actions, and participated in risk-based oversight of utility mitigation activities.

Rob founded Energy Compliance, Inc. to bring senior, regulator-side compliance authority to registered entities directly, without the layered staffing, billable-hour overhead, and generalist advice typical of larger consulting firms. Every Energy Compliance engagement is led by Rob personally.

About Energy Compliance, Inc.

About Energy Compliance, Inc.

Energy Compliance, Inc. is an independent consulting and advisory firm focused exclusively on electric reliability, cybersecurity reliability, and regulatory compliance for organizations connected to the North American Bulk Electric System.

Our work supports registered entities, including Generator Owners and Operators, Transmission Owners and Operators, Reliability Coordinators, Balancing Authorities, and Distribution Providers. We work across NERC Reliability Standards, FERC orders, RTO/ISO market participation rules, Regional Entity oversight, and state regulatory frameworks.

We do this work differently than larger consulting firms. Engagements are led by a single senior practitioner with regulator-side experience. We don't staff for billable hours. We staff for outcomes. Our deliverables are written to be operationally executable and audit-defensible, not to manufacture activity. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.

Energy Compliance is not affiliated with, sponsored by, or endorsed by the North American Electric Reliability Corporation, the Federal Energy Regulatory Commission, or any Regional Entity.

Services Provided Our services are written to be clearly defensible. Operationally executable in real time. Audit-defensible at compliance review. Every deliverable is structured for the auditor's question, not the consultant's binder.

Energy Compliance services include, but are not limited to:

  • NERC reliability and compliance advisory support
  • Reliability governance and program assessments
  • Registration and applicability analysis
  • Operational and engineering reliability alignment
  • Compliance program design and improvement
  • Audit and enforcement support (non-advocacy)
  • Mitigation planning and Self-Report development
  • Training and executive briefings on reliability frameworks
  • Regulator-perspective program reviews

Each engagement is scoped to the entity's role, function, and bulk system impact.

ENERGY COMPLIANCE PROFESSIONAL REFERENCE

Rigorous Compliance. Defensible Programs. Energy Compliance, Inc. partners with registered entities on the institutional and technical questions that define strong reliability and cybersecurity programs, from classification through audit through enforcement response.

NERC COMPLIANCE SENIOR ADVISORY Program support, interpretation, and audit Direct engagement on complex reliability preparation. questions.

INDUSTRY ENGAGEMENT AUDIT DEFENSE Standards development and working-group Notice of Penalty response and settlement participation. posture.

CONNECT WITH US

Cybersecurity / CIP