bR2bR Compliance Officer — Energy
Run governed NERC CIP, TSA pipeline and OT security audits from bRRAIn, with verified citations and findings that hold up.
- Level
- Practitioner
- Learning time
- 18 hours
- Price
- $499
- Credential
- Valid 3 years
What changed in this edition.
- The bR2bR engagement is now taught as a method built from real mechanisms: per-project read grants, two recorded approvals, the auditee's hash-chained audit log, Robo Compliance sealed sessions and the auditor portal (which has no NERC CIP or TSA template, and we say so).
- Regulatory content corrected and brought to October 2026: CIP-003-9 with six Attachment 1 sections including vendor remote access, CIP-014 cited to Order No. 802, CIP-015-1 as FERC-approved, CIRCIA as pending, and the TSA SD-02 series through 02E (July 2024) with a current-revision discipline instead of a memorized revision.
- New lessons on CIP-004-7 and CIP-011-3 for BCSI stored in bRRAIn, CIP-008-6 reporting, the CMEP and RSAWs, AI model governance (the Handler, LLM Registry, LLMOps) and closing an engagement.
- Seven AI role-play labs (CIP Senior Manager, Regional Entity mock auditor, pipeline security coordinator, OT lead, renewables CISO, compliance director) and a written capstone, all scored against published rubrics.
- A fresh LOFT exam bank: 96 selected-response items and 6 AI-conducted performance items, each referenced to the lesson that teaches it; no v1 items carried over.
- Seat time is now 18 hours of focused lessons and labs, replacing the v1 60-hour estimate.
What you will be able to do.
- You will be able to set up and close governed access to an energy auditee's evidence in bRRAIn, with two recorded approvals, a model rule for BCSI and SSI, and a reconciled audit trail.
- You will be able to test NERC CIP-002 through CIP-015 evidence at the revisions in force, with exact requirement and part citations and correct interval arithmetic.
- You will be able to assess a pipeline operator against the TSA directive revision and approved plan it holds, and against API 1164 where adopted.
- You will be able to analyze OT architectures with the Purdue model, IEC 62443 zones, conduits and security levels, and NIST SP 800-82 Rev 3, recommending OT-safe remediation.
- You will be able to facilitate a C2M2 v2.1 evaluation and assess inverter-based resource management planes by grid impact.
- You will be able to write findings with calibrated severity, mitigation plans and remediation roadmaps, and verify every AI-drafted claim in a ledger.
Who it's for
- NERC CIP compliance leads and analysts at utilities, cooperatives, municipal utilities and generation owners
- Pipeline cybersecurity and TSA coordinator roles at pipeline and LNG operators
- OT security engineers at oil and gas, power generation and renewables companies
- Internal auditors and consultants who assess energy-sector cybersecurity
Not covered here
- Physical and safety regulation such as PHMSA pipeline safety (CIP-014 physical security of transmission is covered)
- Environmental compliance
- Other industry overlays (compliance-financial, compliance-healthcare, compliance-dod)
- NERC, Regional Entity or TSA auditor status, which have their own pathways
7 modules, 61 lessons.
About 18 hours of learning. Open a module to see every lesson.
-
Audit Engagement Setup and Governed Access
The bR2bR engagement method built from real mechanisms, energy scope with revisions in effect and BCSI/SSI need-to-know, the MCP session method for your own record, governed access with two recorded approvals, sealed sessions and the auditor portal, AI model governance, and halting cleanly on out-of-scope evidence.
- Pretest: audit engagement setup and governed access
- The bR2bR audit engagement method for energy audits
- Scope, revision in effect, and need-to-know for BCSI and SSI
- Opening the engagement in your own bRRAIn: the MCP session method
- Governed access to auditee evidence: grants, two approvals and the audit log
- Sealed audit sessions and the auditor portal on an energy engagement
- Which model may touch BCSI and SSI: the Handler, the LLM Registry and LLMOps
- Out-of-scope evidence: recognizing it and halting cleanly
- Lab: Set up governed access with a utility's CIP Senior Manager
- Retrieval: 8 questions across Module 1
-
NERC CIP: Categorization and High/Medium Controls
CIP-002 categorization, CIP-005-7 perimeters and remote access, CIP-007-6 system security, CIP-010-4 change and vulnerability management, CIP-013-2 supply chain, and CIP-004-7 with CIP-011-3 for people and BCSI, including BCSI stored in bRRAIn.
- Pretest: NERC CIP categorization and High/Medium controls
- CIP-002: BES Cyber System categorization
- CIP-005-7: Electronic Security Perimeters, remote access and vendor sessions
- CIP-007-6: System security management, R1 to R5
- CIP-010-4: Configuration change management and vulnerability assessments
- CIP-013-2: Supply chain risk management
- CIP-004-7 and CIP-011-3: People, access and BES Cyber System Information
- Lab: Walk a CIP evidence sample with the CIP Senior Manager
- Retrieval: 8 questions across Module 2
-
NERC CIP: Low Impact, Physical Security, Incidents, Monitoring and the Audit Process
CIP-003-9 low impact plans with six Attachment 1 sections, CIP-014 physical security (Order No. 802), CIP-008-6 incident response and reporting with CIRCIA as pending, CIP-015-1 internal network security monitoring, and how Regional Entities examine compliance under the CMEP with RSAWs.
- Pretest: Low impact, physical security, incidents, monitoring and the audit process
- Low impact BES Cyber Systems under CIP-003-9
- CIP-014: Physical security of critical transmission stations and substations
- CIP-008-6: Incident response and reporting, and what CIRCIA does not yet require
- CIP-015-1 and internal network security monitoring
- How CIP compliance is examined: Regional Entities, the CMEP and RSAWs
- Lab: Mock audit interview with a Regional Entity auditor
- Retrieval: 8 questions across Module 3
-
TSA Pipeline Security Directives and API 1164
The SD Pipeline-2021-01 and -02 series and the current-revision discipline (02E issued July 2024), SSI handling, the Cybersecurity Coordinator, the TSA-approved implementation plan, incident response plan and assessment program, pipeline incident reporting, and API 1164 for pipeline control systems.
- Pretest: TSA pipeline security directives and API 1164
- The TSA pipeline security directives: the series and the current-revision discipline
- The Cybersecurity Coordinator and the SD-01 series
- The Cybersecurity Implementation Plan, incident response plan and assessment program
- Cyber incident reporting for pipelines: TSA, CISA and what is still pending
- API 1164: pipeline control system cybersecurity
- Lab: Verify pipeline cyber posture with a pipeline security coordinator
- Retrieval: 8 questions across Module 4
-
OT Architecture: Purdue, IEC 62443 and NIST SP 800-82
OT versus IT for auditors, the Purdue model and boundary-crossing flow analysis, the IEC 62443 series with the 3-2 zone and conduit method, Foundational Requirements and security levels, NIST SP 800-82 Rev 3 with its 800-53 overlay, and keeping safety and security distinct.
- Pretest: ICS/OT architecture, NIST SP 800-82, IEC 62443 and Purdue
- OT versus IT: why availability and safety change the audit
- The Purdue reference model: levels, the industrial DMZ and boundary-crossing flows
- IEC 62443: the series, zones and conduits, and the 3-2 risk assessment
- IEC 62443-3-3 and 4-2: Foundational Requirements and Security Levels
- NIST SP 800-82 Rev 3: an OT security program and the 800-53 overlay
- Safety and security: keeping the layers distinct and connected
- Lab: Purdue and IEC 62443 analysis of a plant network with its OT lead
- Retrieval: 8 questions across Module 5
-
DOE C2M2 and Renewables Cybersecurity
C2M2 v2.1 domains, practices and cumulative MILs, C2M2 alongside NERC CIP, inverter-based resources with BES status, registration and IEEE 1547-2018, and the inverter management plane prioritized by grid impact.
- Pretest: DOE C2M2 and renewables cybersecurity
- DOE C2M2 v2.1: ten domains and the MIL ladder
- C2M2 and NERC CIP: maturity and compliance side by side
- Inverter-based resources: IEEE 1547, registration and cybersecurity scope
- The inverter management plane: what to look for in a renewables audit
- Lab: C2M2 and inverter-fleet review with a renewables CISO
- Retrieval: 7 questions across Module 6
-
Findings, AI Verification, Remediation and the Capstone
Defensible finding anatomy, calibrated severity, mitigation plans and remediation roadmaps, pipeline findings under SSI, AI failure modes and the verification ledger, closing the engagement, a lab catching AI failures, and the written capstone.
- Pretest: findings, AI verification, remediation and closure
- Writing energy findings that hold up
- Severity: calibrating findings within one level
- Mitigation plans and remediation roadmaps for CIP findings
- Reporting findings to a TSA-regulated pipeline operator
- AI failure modes in energy compliance and the verification ledger
- Closing the engagement: access, records and handover
- Lab: Catch and correct AI failures in a draft findings package
- Retrieval: 8 questions across Module 7
- Capstone: Readiness attestation package for Halden County Electric
Practice against someone who pushes back.
Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.
-
Lab 1 · Audit Engagement Setup and Governed Access
AI role-play: agreeing scope, access, model use and closure with a utility's CIP Senior Manager
-
Lab 2 · NERC CIP: Categorization and High/Medium Controls
AI role-play: walking a CIP evidence sample with a CIP Senior Manager who pushes back
-
Lab 3 · NERC CIP: Low Impact, Physical Security, Incidents, Monitoring and the Audit Process
AI role-play: mock audit interview with a former Regional Entity CIP auditor
-
Lab 4 · TSA Pipeline Security Directives and API 1164
AI role-play: verifying pipeline cyber posture with a pipeline security coordinator
-
Lab 5 · OT Architecture: Purdue, IEC 62443 and NIST SP 800-82
AI role-play: Purdue and IEC 62443 analysis of a combined-cycle plant with its OT lead
-
Lab 6 · DOE C2M2 and Renewables Cybersecurity
AI role-play: C2M2 scoring and inverter-fleet review with a renewables CISO
-
Lab 7 · Findings, AI Verification, Remediation and the Capstone
AI role-play: correcting an AI-drafted findings package with a compliance director
-
Lab 8 · Findings, AI Verification, Remediation and the Capstone
Written readiness attestation package from an evidence set
Readiness attestation package for Halden County Electric
Artefact submitted in the capstone lab, AI-scored against the published rubric
Pass mark: 72%
Scored on
- Engagement governance and access15%
- CIP findings and citations25%
- Segmentation and flow analysis15%
- Low impact and inverter-based resources15%
- AI verification and regulatory currency15%
- Severity, roadmap and executive communication15%
One exam. A credential anyone can verify.
The exam
- Items per form
- 59
- Time allowed
- 120 min
- Pass mark
- 72%
- Performance tasks
- 4
- Attempts included
- 2
- Wait between attempts
- 7 days
- Online and timed, taken on learn.brrain.io.
- Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
- Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.
The credential
- A verifiable digital badge in your name.
- A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
- Valid for 3 years.
- Renewal: Renewal at 3 years by passing the then-current exam
Where this course sits.
Frequently asked.
Do I need to install anything for the labs?
No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.
How is the exam delivered?
Online and timed: 59 items in 120 minutes, on a form assembled for you from the course's item bank. 4 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 72%.
What if I don't pass first time?
You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.
How long is the credential valid?
3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.
I hold the v1 credential. Is it still valid?
Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.
Can my company enroll a team?
Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.
bR2bR Compliance Officer — Energy
Run governed NERC CIP, TSA pipeline and OT security audits from bRRAIn, with verified citations and findings that hold up.