WattOpsCOMPLIANCEby Energy Compliance, Inc.

It will not tell you that you are compliant.

It tells you which obligations lack sufficient evidence, why, and what to do next. Every finding traces from the claim, to the requirement, to the exact span of the document it rests on, to the test that produced it.

8deterministic evidence tests
20standards, requirement text verbatim
14NERC RSAWs held with their file hash
867cited passages in the answer canister
WHAT A TEST RETURNS

Six answers, and "compliant" is not one of them

An evidence test reports the state of the record, not a legal conclusion. The conclusion stays with the entity and its counsel, which is where an auditor expects to find it.

SUFFICIENTEvidence found, in date, anchored to a span.
INSUFFICIENTEvidence exists and does not carry the requirement.
MISSINGNothing in the record answers this.
CONFLICTINGTwo sources disagree. Both are shown.
STALEFound, but outside the interval the standard sets.
NEEDS_SMEA judgment call. It is routed, not guessed.
TRACEABILITY

Every finding survives the question "how do you know that"

The chain is stored, not reconstructed. An auditor can walk it in either direction, and so can you, eighteen months after the person who did the work has left.

MODULES

What it does today

Everything below renders and works now. Nothing on this page is a roadmap item.

OPERATE
ReadinessRuns the evidence tests as of any date. Test by facility matrix, gap counts by sufficiency state.
FindingsProposed deficiencies with the full chain, engineering review, and one step to open a corrective action.
Ask NORAAnswers only from the canister: the standards, the RSAWs and your own procedures. Every sentence cited.
CalendarObligations, open workflow steps and open corrective actions, overdue first.
WorkflowsCorrective action, RSAW preparation, mock-audit remediation, regulatory change. Steps that state an outcome are checked against the records before they close.
EVIDENCE AND ASSETS
Evidence intakeProcedures, drawings, test reports, transcripts and email. Scans read by OCR in the browser. Standards proposed with reasons for an SME to confirm.
EvidenceContent addressed by SHA-256. Every extracted field anchored to its character span and highlighted in place.
One-line to assetsReads a one-line and proposes each device's PRC-005-6 Component Type. Every line is reviewed before commit.
Asset registerComponent list per facility, applicability with a recorded basis, the 4.2 clauses verbatim, CSV export.
AUDIT
RSAWsAnswer the entity questions, link evidence per requirement, draft the narrative, export the filled NERC .docx after the template hash is checked.
Mock AuditAn independent auditor with its own population and a seeded, reproducible sample, then reconciliation against your results.
NarrativesBuilt from typed claims, so an unsupported sentence cannot quietly become an assertion.
ApprovalsBound to a content hash. No self-approval. Changing the thing after approval voids it.
GOVERN
Registrations and scopeEvery NERC function the entity carries, and what each one pulls into scope.
ApplicabilityRules propose, an SME approves, and the basis is recorded per facility and per standard.
Regulatory LibraryStandards checked against nerc.com, requirement text reproduced from the RSAWs, evidence-test mappings marked verified or deferred.
Audit LogAppend only and hash chained. One click recomputes the chain from genesis.
CIP, BY IMPACT LEVEL

CIP-003 reaches Balancing Authorities, Distribution Providers, Generator Owners and Operators, Reliability Coordinators, and Transmission Owners and Operators. What attaches depends on the impact rating of your BES Cyber Systems, and getting that rating wrong in either direction is expensive.

Impact ratingClassification against the CIP-002 criteria, with the basis recorded per asset. Rules propose, an SME approves, and the reasoning is kept where an auditor can read it.
Low impactThe five plan areas the standard names: cyber security awareness, physical security controls, electronic access controls, incident response, and transient cyber asset and removable media risk mitigation. Each one gets an evidence test.
Medium and high impactThe full suite follows the rating. Access management, systems security, incident response and recovery, configuration change and vulnerability assessment, information protection.
Training evidenceWho was trained, on what, when, and the artifact that proves it. CIP-004 is already in the library and already applies, so the training tests start there.
Access and personnelAuthorization records tied to named people and named systems, so the question of who had access on a given date has a stored answer.
AssessmentsA program assessment against the impact rating, delivered by Energy Compliance and written up as findings you can act on.
DELIVERED BY ENERGY COMPLIANCE

Work performed by the firm rather than the software. Available now, with or without a licence. The platform itself is running at demo.wattopscompliance.com.

CIP program assessmentScoped to your impact rating. Where the program holds, where it will not, and what to fix first.
NERC and application trainingOne week, on site or remote. The standards your registration actually carries, then the platform against your own evidence.
Readiness ReadOne requirement, your evidence, findings back in writing. No charge, and yours to keep whether or not we work together.
PRICING

Configure it and see the range

Scope follows what you are registered for, not how many servers you run. Pick the functions, the facilities and the standard families that attach to you.

REGISTRATION

Every function on your NERC registration. This decides which standards attach before anything else is counted. Two functions are in the base licence. Each one after that adds 10% of base.

FACILITIES

Registered facilities under the entity. Deployment follows each facility because each one brings its own one-lines, procedures and test records.

Facilities, exact countDeployment, one time: $4,000 each through 10, $2,500 through 50, $1,500 above
STANDARD FAMILIES

All fourteen NERC subject areas. Tick the ones your registration carries. Each family brings its own evidence tests and its own RSAWs. Thirteen of them are in the licence. CIP prices by impact rating, because the rating decides how much of the standard actually attaches. We confirm applicability against your registration before anything is scoped.

MODULES

Operate, Evidence and Govern are always included. These license on top.

HOSTING AND TERM

We host, patch, back up and operate it. Multi-tenant, US region.

Additional environments+30% of the licence, each
BEFORE YOU BUY ANYTHING

Pick the requirement you are most confident about

Send us the evidence you would hand an auditor for one requirement. We read it the way an audit team will and send the findings back in writing. No charge, and you keep them whether or not we ever work together.

PICK ONEA single requirement. The one you believe the program is solid on.
SEND ITThe evidence itself. Records, dates, names, across the full audit period. Not the procedure.
GET FINDINGSWritten and specific. Where it holds, where it will not, and what to fix first.

Mutual NDA in place first if your program requires one. Write to [email protected].

TALK TO US

Tell us what you are registered for

If you configured a scope above it travels with this message, so the reply is a real number rather than a discovery call. You will hear back from Rob directly.

Keep it general. This is a first contact, not a secure channel. Nothing site-specific until an NDA is in place.

Or write to [email protected] or call 763.438.4427.