Nestack Agent Care

Energy AI agent · NERC CIP evidence

NERC CIP Compliance Evidence AI Agent

Carry the evidence each CIP interval consumes — the patch date, the evaluation, the baseline, the quarterly access check — and hold it for the CIP Senior Manager named under CIP-003-9 R3.

4–6 weeksTypical delivery
Your stackDeployment
Interval-boundNamed manager
Agent CareAfter launch

What this agent does

Assembles the evidence, not the determination

In
01

A patch publishes, and CIP-007-6 Part 2.2 allows 35 calendar days to evaluate it for applicability.

02

An evaluation completes, and Part 2.3 gives 35 more days to apply or to date a mitigation plan.

Reason
03

A mitigation plan runs long, and only the CIP Senior Manager or delegate may extend it under Part 2.4.

04

A change completes, and CIP-010-4 Part 1.3 allows 30 calendar days to update the baseline.

05

An access review falls due, and CIP-004-7 Part 4.2 wants verification each calendar quarter.

Decide
06

A termination action lands, and CIP-004-7 Part 5.1 leaves 24 hours to revoke the access.

07

An incident is judged, and the CIP-008-6 Part 4.2 hour runs from determination, not detection.

Out
08

A manager changes, and CIP-003-9 R3 wants the new name documented within 30 calendar days.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent assembles and tracks intervals. The named person is the CIP Senior Manager, who approves — the self-certification itself carries no attestation.

Example workflow

One interval, evidence to approval

AgentHuman
1Interval evidence receivedPatch bulletins, baselines, access records or termination feeds
2Interval context assembledThe system, its impact rating, the standard part it answers to and the date the clock started
3Evidence set draftedThe interval, its records, the gaps and completeness
4Controls appliedInterval checks, evidence-sufficiency checks, date checks and completeness confidence
No human action required

Stages 1 to 4 run unaided, and nothing is approved at any of them — the agent is assembling, and the compliance lane opens at the completeness gate.

5DecisionSplits at the completeness gate
Evidence sufficient

Goes to the CIP Senior Manager to approve.

Anything thin

Adds a compliance analyst read first.

Compliance review

The set is held with its interval, its gaps and the systems they sit on.

Approve · Append evidence · Send to compliance
Approved — by the CIP Senior Manager
6Asset and access records updatedOnly where write access and records policy allow it
7Outcome evaluatedEvidence completeness, interval coverage, analyst corrections and what review found
Corrections

Each analyst correction is counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Determining that an incident is reportable.
Approving cyber security policies under CIP-003-9 R1.
Signing a self-certification or any CMEP submission.
Extending a mitigation plan under CIP-007-6 Part 2.4.
Automation boundaryAgent acts unaided
Hold the record each CIP interval consumes, with the date it carries.
Track each interval against the standard that sets it.
Chase the missing record before the calendar-day window closes.
Flag the determination criteria that start the one-hour.
Nothing is approved or filed except by a named person, inside the agreed boundaries.
Judging whether an interval was in fact met.
Telling a Regional Entity the estate is compliant.
Setting the impact rating a system is held at.
Changes to access, baselines or firewall rules.

Example output

One interval, annotated

Our control room copilot leaves the command to the operator; this record is what one CIP interval consumed.

Evidence set · single intervalIllustrative example
Interval
Recorded as
System
Evidence of record
Confidence
Held for
Patch evaluation, Part 2.2
Evaluated for applicability, not applicable
Medium impact
Vendor bulletin, 3 August 2026
Held unapproved
The CIP Senior Manager, by name
As receivedTaken from the vendor bulletin and the patch record — it reaches as far as those sources do.
What the record holds Vendor bulletin date Evaluation record Mitigation plan, dated
Why no interval call hereWhether the window was met is a CIP-007-6 judgement, not a model output.
ActionApproveAppend evidenceSend to compliance
What the score decidesBelow the configured threshold the set picks up a compliance read before the manager sees it.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every intervalFrom the system that owes it
03Evidence

Where the evidence is used

Our compliance reporting assistant works a register and names no regime; this page is one regime, with its own clocks and its own named role.

01Approved path

The clock starts when you say so

CIP-008-6 Part 4.2 runs one hour from determination under your own R1 Part 1.2 criteria, not from detection.

02Human review

What was checked, and not found

NERC publishes neither CIP audit reports nor noncompliance filings — they are treated as critical energy infrastructure information — and no aggregate total is published.

04Build an evidence trail

The evidence, the interval it belongs to and the manager who approved stay on the record.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Patch and vulnerability sourcesVendor bulletins · CVE feeds
Patch management systems
Configuration and baselinesCMDB · configuration monitoring
Change records
Access and personnelIdentity provider · HR feed
Termination and transfer records

Agent

NERC CIP compliance evidence

Reads the intervals
Assembles the evidence
Holds for the manager

Incident and case systemsSIEM · ticketing
Determination criteria records
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six meshes between the model and the manager

Six meshes, coarsest first of all. Whatever drops through every one is set out in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to evidence assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and interval rules; CIP-015-1 is approved and not enforceable until 1 July 2028.Track
L4TraceabilityRecord each interval, the records behind it, the system it sits on and every read of the set.Record
L3Manager releaseHold the set for the CIP Senior Manager; it governs release, not whether an interval was met.Gate
L2Policy guardrailsTest the set against CIP-004-7, CIP-007-6 and CIP-010-4 as configured; CIP-003-11 lands 1 July 2029.Restrict
L1Confidence thresholdsRoute a thin evidence set to a compliance read before the CIP Senior Manager sees it.Require review
Model coreEvidence assembled — the interval, the system, the records and completeness
L1 – L2Test whether a set may stand
L3Puts the approval in a person's hands
L4 – L5Keep the interval and the evidence behind it
L6Holds the determination unmade when signals degrade

How Nestack evaluates it

Evaluate the whole assembly — not only the evidence set that comes out.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the set an auditor reads
Depth of coverage ▼
E1Final-output evaluationDid the set record what each interval actually consumed?
E2Step-level evaluationDid the agent read the right system, the right part and the live configuration?
E3Tool evaluationDid it read and write the correct asset record and the correct interval?
E4Confidence calibrationDo low-confidence sets actually attract more compliance corrections?
E5Slice evaluationHow does performance change across specific impact ratings?
E6Business outcomeHow many sets needed a correction before the manager approved?
Floor — the outcome the entity answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, each set at the stage where it first appears.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
IX-03

Stale interval read

The configuration read is not the one now in service.

Stage gathersThe systems, the intervals, the records and the dates
02 · Reasoning2 modes
IX-04

Interval asserted, not shown

An interval is called met without its evidence.

IX-06

Future standard read as live

CIP-015-1 is worked as though enforceable now.

Stage proposesThe intervals, their records and completeness
03 · Tool / write2 modes
IX-02

Thin set passed forward

A set moves on without the compliance read.

IX-05

Evidence bound to wrong asset

A record is filed against the wrong system.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
IX-01

Approved, evidence unrecorded

The record shows approval but not what supported it.

Stage returnsThe set a manager approves and an auditor reads
05 · Change / Version1 mode
IX-07

Silent interval regression

A configuration change moves the interval, not the record.

Stage tracksModel, prompt, interval rules and evidence fields
Sev-1 · an interval approved on no evidence Sev-2 · wrong evidence reaches the record Sev-3 · source degrades, set holds unapproved

Affected slices

Low impact absorbs the corrections

A rating-level interval-evidence figure can read clean while low impact systems carry most of the corrections. Nestack reports the correction rate by impact rating, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Low impact systems10.2%3.6× Review
Medium impact at Control Centers7.6%2.7× Review
Medium impact with routable access4.7%1.7× Watch
High impact Control Centers1.6%0.6× Normal
Bar: correction-rate lift vs. high-impact Control Center baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

What a missed window costs

A cycle closes when the missed evaluation window is a regression case. That suite is what the next interval worked is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

Correction rate rises on low impact systems.

02Diagnose

The patch that published on a Friday and was evaluated thirty-six days later is read back until one cause remains.

03Improve

The change ships numbered, and the intervals that forced it ride with it.

04Verify

Nothing releases while one touched system case is still red.

05Learn

It is retained for good, and the interval rules are amended in that same commit.

Learn → DetectThe return edge. The next interval is measured against a suite one case longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, evidence assembly, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01CIP-interval discovery and automation-boundary work.
02Patch, baseline and access sources.
03Interval-to-standard and evidence-coverage mapping.
04Interval evidence ingestion.
05System, part and record binding.
06Completeness scoring and review routing.
07Manager approval workflow.
08Asset and access-system integration.
09Interval and evidence cases.
10Guardrails and approval controls.
11Interval-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne rating, one year ProductionProduction compliance workflow AdvancedMultiple ratings / entities
Introduced at Pilot
Evidence assembly to your intervals
CIP Senior Manager release
Asset-inventory baseline
Introduced at Production
Reporting by impact rating
Approval workflow in your systems
Approved write-back
Configuration-system integration
Introduced at Advanced
Multi-entity registrations
Cross-standard evidence packs
Large asset estates
Multi-standard interval controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your registered systems and their impact ratings Asset-inventory mapping and interval captureWeek 1
02Representative patch, baseline and access records Record binding, interval logic and the evidence baselineWeek 2
03Your determination criteria under R1 Part 1.2 Interval mapping, system binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports Patch, configuration and access-source assessment, then integration setupWeek 2
05Intervals you would not want reconstructed Evaluation cases and failure-mode testingWeek 4
06What no evidence set may establish Completeness scoring, review routing, guardrails and release controlsWeek 3
07A named CIP Senior Manager to approve Manager approval workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

These bands are the weeks each phase honestly costs, and the fifth one therefore has to carry two.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1CIP workflow discovery, interval mapping and the automation boundary W2Source integration and the interval-evidence baseline W3Evidence assembly, interval logic and release controls W4Evaluation suite, interval cases and failure-mode testing W5Record integration, pilot intervals and targeted corrections W6One compliance year run under the CIP senior manager, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. The fifth week carries two because the work does.
At the end of W6Validation closes on live intervals, and Agent Care picks up the watch.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Energy AI agent

Build a CIP evidence agent around the intervals your estate already owes.

Show us one interval and the record it consumed. If patch evaluation and mitigation planning sit apart across your estate, then the Part 2.3 window is kept on trust. Your self-certification calendar is your Regional Entity's; plant OT monitoring is a different agent.

Nestack Agents · NERC CIP evidenceAGT-EN-10 · Agent Care available after launch