Install any skill in seconds. Free to start, no credit card required.
Get Started Free →NERC Critical Infrastructure Protection expert. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance for BES Cyber Systems.
.claude/skills/grcengclub-us-nerc-cip-expert/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 30% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 59% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 1% | 0% |
| case-18 | ✗→✓ | ▲ Improved | 66% | 0% |
| case-13 | ✓→✗ | ▼ Worse | 198% | 0% |
Reference-depth expertise for NERC Critical Infrastructure Protection (CIP) Reliability Standards, represented in SCF as usa-federal-nerc-cip-2024. This plugin bundles the SCF crosswalk (122 SCF controls to 204 framework controls) with NERC CIP-specific assessment context.
usa-federal-nerc-cip-2024Regional Entities, and Federal Energy Regulatory Commission (FERC) in the US
the 2024 SCF crosswalk
NERC CIP is the cybersecurity and physical security standards family for Bulk Electric System (BES) reliability. It focuses on identifying BES Cyber Systems, categorizing impact, protecting electronic and physical perimeters, managing personnel risk, hardening systems, responding to incidents, recovering from events, protecting information, and managing supply chain risk. For GRC work, the assessor needs to see repeatable evidence tied to registered functions, assets, impact ratings, and Reliability Standard requirements.
NERC Reliability Standards apply across interconnected North American bulk power system jurisdictions through NERC, Regional Entities, and applicable regulatory authorities. Scope analysis starts with registered entity functions such as BA, DP, GO, GOP, RC, TO, TOP, and TP, then maps Facilities, assets, BES Cyber Systems, Electronic Security Perimeters, Physical Security Perimeters, and associated cyber assets. Do not treat NERC CIP as a generic IT security framework; applicability depends on BES reliability functions and asset impact categorization.
Evidence usually centers on CIP-002 BES Cyber System categorization records, asset inventories, impact rating rationale, security management controls, personnel training and risk assessment records, access authorization lists, electronic access control evidence, physical access control evidence, system hardening baselines, vulnerability assessments, patch management records, incident response plans and exercises, recovery plans and tests, protected information handling procedures, and supply chain risk management plans.
Cadence varies by CIP standard and requirement. Assessors should preserve the entity's compliance calendar, recurring evidence, dated approvals, test results, change records, and exception handling. Incident response, recovery testing, access reviews, vulnerability assessments, patch evaluation, configuration change management, and training records need dates and scope that align with the specific requirement being assessed.
NERC develops and enforces Reliability Standards with Regional Entities; FERC approves and enforces standards in the United States. Non-compliance can lead to findings, mitigation plans, settlement activity, penalties, and enhanced oversight. Assessment output should separate control evidence and likely gaps from legal conclusions about violation risk or penalty exposure.
NERC CIP overlaps with NIST CSF, NIST 800-53, ISO 27001, CIS Controls, and utility-specific operational technology security programs. Use the SCF crosswalk for control mechanics, but keep NERC CIP reporting focused on BES Cyber System categorization, registered functions, impact ratings, audit-ready evidence, and Reliability Standard requirement structure.
assets and cyber systems; enterprise IT may be supporting evidence but is not automatically a BES Cyber System.
programs, security management controls, access controls, incident response, and other requirement-specific evidence.
traceability, responsible entity context, dates, approvals, and scope.
in scope when they affect BES Cyber Systems or associated protected information.
/us-nerc-cip:scope - determine applicability/us-nerc-cip:assess - run a gap assessment/us-nerc-cip:evidence-checklist - enumerate evidence requirementsAll three delegate to /grc-engineer:gap-assessment with SCF framework ID usa-federal-nerc-cip-2024 for the control-by-control mechanics, and wrap the results in NERC CIP-specific terminology.
Full-depth plugins add framework-specific workflow commands tied to the audit ritual. Candidates for this framework:
/us-nerc-cip:bes-cyber-system-scope - build or review CIP-002categorization and impact-rating evidence.
/us-nerc-cip:access-review-pack - assemble CIP access authorization,revocation, and review evidence.
/us-nerc-cip:vulnerability-and-patch-review - assess vulnerabilityassessment, patch evaluation, mitigation, and exception evidence.
/us-nerc-cip:incident-exercise-review - review incident response plan,testing, lessons learned, and reportability evidence.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-04 | fail→fail | 15,463 | 14,526 | -6% | 1 | 1 | 0% | 2,240 | 3,506 | +57% | 0 | 0 | — |
case-01 | fail→pass | 9,239 | 2,709 | -71% | 1 | 1 | 0% | 1,378 | 1,788 | +30% | 0 | 0 | — |
case-02 | pass→pass | 15,891 | 15,164 | -5% | 1 | 1 | 0% | 2,316 | 3,481 | +50% | 0 | 0 | — |
case-03 | pass→pass | 10,396 | 12,025 | +16% | 1 | 1 | 0% | 1,703 | 3,391 | +99% | 0 | 0 | — |
case-05 | pass→pass | 13,925 | 14,944 | +7% | 1 | 1 | 0% | 2,064 | 3,593 | +74% | 0 | 0 | — |
case-06 | pass→pass | 18,136 | 16,116 | -11% | 1 | 1 | 0% | 2,593 | 3,683 | +42% | 0 | 0 | — |
case-07 | pass→pass | 16,908 | 9,703 | -43% | 1 | 1 | 0% | 2,394 | 2,759 | +15% | 0 | 0 | — |
case-08 | fail→pass | 7,496 | 5,020 | -33% | 1 | 1 | 0% | 1,145 | 1,823 | +59% | 0 | 0 | — |
case-09 | pass→pass | 6,399 | 7,763 | +21% | 1 | 1 | 0% | 952 | 2,512 | +164% | 0 | 0 | — |
case-10 | pass→pass | 12,698 | 10,096 | -20% | 1 | 1 | 0% | 1,966 | 2,836 | +44% | 0 | 0 | — |
case-11 | pass→pass | 12,672 | 12,358 | -2% | 1 | 1 | 0% | 1,888 | 3,249 | +72% | 0 | 0 | — |
case-12 | pass→pass | 12,585 | 16,548 | +31% | 1 | 1 | 0% | 1,805 | 3,759 | +108% | 0 | 0 | — |
case-13 | pass→fail | 7,455 | 13,475 | +81% | 1 | 1 | 0% | 1,136 | 3,382 | +198% | 0 | 0 | — |
case-19 | fail→pass | 12,773 | 2,751 | -78% | 1 | 1 | 0% | 1,773 | 1,798 | +1% | 0 | 0 | — |
case-14 | pass→pass | 11,370 | 8,946 | -21% | 1 | 1 | 0% | 1,607 | 2,603 | +62% | 0 | 0 | — |
case-15 | pass→pass | 19,152 | 20,868 | +9% | 1 | 1 | 0% | 2,737 | 4,332 | +58% | 0 | 0 | — |
case-16 | pass→pass | 9,216 | 11,165 | +21% | 1 | 1 | 0% | 1,429 | 3,056 | +114% | 0 | 0 | — |
case-17 | pass→pass | 2,946 | 4,530 | +54% | 1 | 1 | 0% | 442 | 2,115 | +379% | 0 | 0 | — |
case-18 | fail→pass | 13,929 | 13,435 | -4% | 1 | 1 | 0% | 2,026 | 3,373 | +66% | 0 | 0 | — |
case-20 | pass→pass | 14,938 | 17,067 | +14% | 1 | 1 | 0% | 2,363 | 4,462 | +89% | 0 | 0 | — |
case-21 | pass→fail | 19,780 | 17,323 | -12% | 1 | 1 | 0% | 3,084 | 4,024 | +30% | 0 | 0 | — |
case-22 | pass→pass | 15,970 | 10,806 | -32% | 1 | 1 | 0% | 2,378 | 3,002 | +26% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +9 percentage points is the difference between those two pass rates over the 22 comparable cases. 2 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.