/ NERC CIP coverage

NERC CIP change management without the audit-week scramble

Approval, deployment and audit of every PLC, SCADA and HMI change — aligned to NERC CIP from day one, generated as a by-product of the work, not assembled the week before the audit.

/ 01Scope

What counts as an OT change

/ Change type

PLC code

Logic edits, routine changes, function-block swaps, firmware updates.

/ Change type

SCADA tags

Point database additions, alarm threshold edits, scaling changes.

/ Change type

HMI graphics

Screen layout, button bindings, operator permission scopes.

/ Change type

Recipes

Production recipes, setpoints, batch parameters, ingredient lists.

/ Change type

Machine parameters

Drive parameters, IO config, safety thresholds, network topology.

/ 02NERC CIP

How VEM aligns to NERC CIP

NERC CIP-010 R1 requires a documented baseline for every BES Cyber System and a controlled change process that updates the baseline whenever the system changes. CIP-010 R2 requires monitoring for unauthorised changes against that baseline at least every 35 calendar days. VEM holds the baseline, ingests configuration on a continuous cadence, surfaces drift between the running asset and the approved baseline, and generates the evidence package CIP auditors expect — without manual baseline spreadsheets. See the broader the complete OT change management guide for the cross-regime crosswalk.

/ Use case

A transmission operator with 140 medium-impact BES Cyber Systems across six substations replaced quarterly manual baseline reviews with VEM's continuous drift detection. The last CIP audit closed with zero R2 findings and a quarter of the prior cycle's engineering hours.

/ 03Process

Request → Review → Deploy → Audit

/ 01

Request

Engineer files a change with the proposed diff attached.

/ 02

Review

CAB or single approver reviews the diff, risk and deployment plan.

/ 03

Deploy

VEM pushes the approved version, captures before/after signatures.

/ 04

Audit

Immutable record links request, approval, diff and deployment.

/ 04Compliance

Other regimes covered

Want the full framework? the complete OT change management guide.

/ 05FAQ

NERC CIP change management — common questions

Make NERC CIP change evidence a by-product, not a project.

Book a demo →