The scope of NERC compliance continues to evolve — and for many organizations, especially those newly registered or expanding their footprint, CIP standards represent an entirely new layer of complexity.

Today, data phleet is excited to announce the release of our CIP-002 automation module, extending our platform beyond PRC standards and into cyber asset identification and classification.

What is CIP-002 and why does it matter?

Under standards from the North American Electric Reliability Corporation, CIP-002-5.1a is foundational to all CIP compliance. It requires organizations to:

This sounds straightforward — but in practice, it is one of the most judgment-heavy and audit-sensitive requirements in NERC.

The problem: CIP-002 is still largely manual

Most organizations today rely on:

This creates risk: inconsistent classification logic, outdated asset inventories, gaps between field reality and documentation, and high audit exposure.

The data phleet approach: automate the classification layer

data phleet's CIP-002 module brings the same philosophy applied to PRC — let software perform the work, your team reviews the results. Our automation:

Why this matters now

As more generation assets — especially inverter-based resources — come under NERC oversight, many organizations are encountering CIP requirements for the first time. CIP-002 is the entry point, and getting it right is critical because it determines the scope of all downstream CIP obligations, errors cascade into multiple standards, and auditors focus heavily on classification methodology.

Expanding the automation footprint

With this release, data phleet now automates CIP-002-5.1a alongside PRC-005-6, PRC-019-2, PRC-024-3, PRC-025-2, PRC-028, PRC-029-1, and PRC-030-1 — and many more are on the way this year.

The bigger picture

The industry is moving toward continuous compliance, not periodic checks. data phleet is building the system that enables that shift: automated validation, continuous monitoring, always audit-ready.