Standards & Regulatory Compliance
A complete compliance platform built for electric utilities — NERC CIP cybersecurity, FAC-008 facility ratings, FAC-003 vegetation management, tamper-evident evidence packages, and a unified GRC spine that turns audit readiness into a continuous, automated process.
The GridState compliance dashboard: live NERC CIP posture, BCS categorization, and applicability matrix in one view.
NERC CIP, From Categorization to Evidence
Automate the full NERC CIP lifecycle. The BES Cyber System (BCS) categorization engine applies the CIP-002 impact analysis, then drives CIP-005, CIP-007, and CIP-010 requirements through a single applicability matrix — so every asset maps to exactly the controls it must satisfy.
- CIP-002 BCS categorization with impact assessments & approval workflow
- Applicability matrix mapping assets to CIP-005/007/010 requirements
- Continuous control assessment, not point-in-time snapshots
- Audit-ready evidence generated automatically from live system state
Defensible Facility Ratings, Every Season
Maintain NERC FAC-008-compliant facility ratings with seasonal, emergency, and ambient-adjusted ratings derived from IEEE 738 (lines) and C57.91 (transformers). The most-limiting-component logic ensures every facility carries a single, traceable, methodology-backed rating.
- Seasonal, emergency, and ambient-adjusted rating methodologies
- IEEE 738 & C57.91 compliant calculations
- Most-limiting-component determination across the facility
- Full methodology provenance for every rating value
One Platform, Every Standard
Beyond CIP and facility ratings, GridState covers the standards your auditors and regulators expect — all on a shared evidence backbone.
Vegetation Management (FAC-003)
Transmission corridor management with MVCD calculations (Gallet wet equation), patrol/aerial/LiDAR inspections, and vegetation-outage categorization (growth 1A–4B).
Evidence Management
RSAW-aligned, tamper-evident evidence packages with period-coverage completeness. Generate audit binders directly from live system artifacts.
Compliance Spine (GRC)
A unified assertion → control → test → exception → mitigation model (OCEG GRC, PCAOB AU 319, NERC retention rules) shared across every standard.
Regulatory Reporting
Automated generation of compliance reports and regulatory submissions, with full traceability from requirement to evidence to responsible owner.
Make Audit Readiness Continuous
Stop scrambling before an audit. See how GridState turns NERC CIP, FAC-008, and FAC-003 into an always-current, evidence-backed posture.