Bulk electric system evidence
NERC CIP Audit Evidence Support
Technical evidence that traces back to the control: requirement, source system, test result, and correction remain connected for the review period supplied by the Registered Entity.
The engagement
Requirement to source, without gaps
GDF helps utilities and service providers collect, test, and organize technical records for NERC CIP requirements that the Registered Entity has placed in scope. Applicability depends on registration, NERC function, Bulk Electric System responsibilities, asset and system categorization, the governing standard and requirement version, implementation dates, and the review period.
The Registered Entity, compliance team, Regional Entity, and counsel retain applicability, interpretation, attestation, and submission decisions. GDF does not provide a legal compliance opinion. The engagement produces the underlying technical record the accountable roles then use.
The evidence map records the Responsible Entity designation used by the client, relevant NERC function, Regional Entity, BES Cyber System categorization, standard and requirement identifier, version and effective date, audit or review period, control owner, covered population, source system, collection method, reviewer, exception path, and retention location.
Scope
Asset and scope reconciliation
BES Cyber Asset and BES Cyber System inventories reconciled against network records, configuration exports, engineering files, and change data. Categorization decisions and their basis are recorded.
Electronic security perimeter evidence
ESP boundary records: firewall rules, remote-access paths, jump hosts, dial-up and cellular access, and dial-back or approval workflows. Exceptions and compensating controls are tracked with dated approvals.
Identity, privilege, and termination
Account inventories, privileged access reviews, termination workflows, shared-account justifications, and periodic review evidence. Sample selection and completeness are documented for the review period.
Vulnerability, patch, and configuration
Vulnerability scan coverage, patch source records, testing evidence, configuration baselines, change approvals, and exception documentation. Excluded assets and untested controls are recorded rather than treated as passed.
Incident, backup, recovery, and exercise
Incident response evidence, backup test records, recovery exercise participation, corrective action tracking, and lessons-learned records reconciled against dated obligations.
Physical and information protection records
Where in scope, physical access, monitoring, information handling, and awareness evidence collected against the requirement version in effect during the review period.
Reporting and evidence packaging
Evidence organized by requirement identifier, sub-requirement, and reviewer expectation. Each item carries source system, collection date, operator, and hash where applicable.
Methodology
How CIP evidence work runs
-
Scope
The Registered Entity provides categorization, review period, requirement versions, and the applicable Regional Entity. GDF confirms scope and identifies source systems and owners.
-
Collect
Configuration exports, tickets, log records, identity data, and process records are collected with source, date, operator, hash, and exception notes.
-
Reconcile
Evidence is reconciled against requirement text, sampled, and cross-checked. Gaps become exceptions with owner, correction plan, and retest date.
-
Package
The evidence set is indexed by requirement, cross-referenced to source system, and organized for Regional Entity review. Readiness work for future dates is labeled separately.
Evidence commonly examined
Evidence reviewed
- Firewall, router, and remote-access configuration exports
- Identity provider records, privileged access reviews, and account terminations
- Vulnerability scan coverage, patch tickets, and exception approvals
- Change management, configuration baseline, and testing records
- Incident response tickets, backup test logs, and exercise records
- Physical access, monitoring, and information protection records where in scope
What you can expect
What you receive
- Evidence map from requirement identifier to source system
- Requirement-by-requirement evidence package with sampling notes
- Exception and corrective-action register with owner and dates
- Readiness memoranda for future enforcement dates, clearly separated
- Reviewer-ready index with hashes and collection timestamps
Frequently asked
Common questions
Do you issue a compliance opinion or attest to CIP compliance?
No. GDF collects, organizes, and explains the underlying technical record. The Registered Entity, compliance team, and counsel retain applicability, interpretation, attestation, and submission.
Can readiness work be presented as current compliance evidence?
No. Readiness reviews for approved future standards or requirement versions are labeled as readiness and are not presented as evidence that a currently-effective requirement has been satisfied.
How are OT constraints handled during evidence collection?
Active methods require operator-designated authority, an approved process condition, stop points, and recovery steps. Passive review and configuration analysis are used where active methods could create risk. Exceptions and inaccessible sources are recorded.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189