bR2bR Compliance · Practitioner
v2.0

bR2bR Compliance Officer — Energy

Run governed NERC CIP, TSA pipeline and OT security audits from bRRAIn, with verified citations and findings that hold up.

Level
Practitioner
Learning time
18 hours
Price
$499
Credential
Valid 3 years
What's new in v2.0

What changed in this edition.

  • The bR2bR engagement is now taught as a method built from real mechanisms: per-project read grants, two recorded approvals, the auditee's hash-chained audit log, Robo Compliance sealed sessions and the auditor portal (which has no NERC CIP or TSA template, and we say so).
  • Regulatory content corrected and brought to October 2026: CIP-003-9 with six Attachment 1 sections including vendor remote access, CIP-014 cited to Order No. 802, CIP-015-1 as FERC-approved, CIRCIA as pending, and the TSA SD-02 series through 02E (July 2024) with a current-revision discipline instead of a memorized revision.
  • New lessons on CIP-004-7 and CIP-011-3 for BCSI stored in bRRAIn, CIP-008-6 reporting, the CMEP and RSAWs, AI model governance (the Handler, LLM Registry, LLMOps) and closing an engagement.
  • Seven AI role-play labs (CIP Senior Manager, Regional Entity mock auditor, pipeline security coordinator, OT lead, renewables CISO, compliance director) and a written capstone, all scored against published rubrics.
  • A fresh LOFT exam bank: 96 selected-response items and 6 AI-conducted performance items, each referenced to the lesson that teaches it; no v1 items carried over.
  • Seat time is now 18 hours of focused lessons and labs, replacing the v1 60-hour estimate.
Outcomes

What you will be able to do.

  • You will be able to set up and close governed access to an energy auditee's evidence in bRRAIn, with two recorded approvals, a model rule for BCSI and SSI, and a reconciled audit trail.
  • You will be able to test NERC CIP-002 through CIP-015 evidence at the revisions in force, with exact requirement and part citations and correct interval arithmetic.
  • You will be able to assess a pipeline operator against the TSA directive revision and approved plan it holds, and against API 1164 where adopted.
  • You will be able to analyze OT architectures with the Purdue model, IEC 62443 zones, conduits and security levels, and NIST SP 800-82 Rev 3, recommending OT-safe remediation.
  • You will be able to facilitate a C2M2 v2.1 evaluation and assess inverter-based resource management planes by grid impact.
  • You will be able to write findings with calibrated severity, mitigation plans and remediation roadmaps, and verify every AI-drafted claim in a ledger.

Who it's for

  • NERC CIP compliance leads and analysts at utilities, cooperatives, municipal utilities and generation owners
  • Pipeline cybersecurity and TSA coordinator roles at pipeline and LNG operators
  • OT security engineers at oil and gas, power generation and renewables companies
  • Internal auditors and consultants who assess energy-sector cybersecurity

Not covered here

  • Physical and safety regulation such as PHMSA pipeline safety (CIP-014 physical security of transmission is covered)
  • Environmental compliance
  • Other industry overlays (compliance-financial, compliance-healthcare, compliance-dod)
  • NERC, Regional Entity or TSA auditor status, which have their own pathways
Syllabus

7 modules, 61 lessons.

About 18 hours of learning. Open a module to see every lesson.

  1. Audit Engagement Setup and Governed Access 10 lessons · 2 h 45 min

    The bR2bR engagement method built from real mechanisms, energy scope with revisions in effect and BCSI/SSI need-to-know, the MCP session method for your own record, governed access with two recorded approvals, sealed sessions and the auditor portal, AI model governance, and halting cleanly on out-of-scope evidence.

    1. Pretest: audit engagement setup and governed access Diagnostic pretest · 5 min
    2. The bR2bR audit engagement method for energy audits Reading · 15 min
    3. Scope, revision in effect, and need-to-know for BCSI and SSI Reading · 15 min
    4. Opening the engagement in your own bRRAIn: the MCP session method Worked example · 15 min
    5. Governed access to auditee evidence: grants, two approvals and the audit log Reading · 15 min
    6. Sealed audit sessions and the auditor portal on an energy engagement Reading · 15 min
    7. Which model may touch BCSI and SSI: the Handler, the LLM Registry and LLMOps Reading · 15 min
    8. Out-of-scope evidence: recognizing it and halting cleanly Scenario · 15 min
    9. Lab: Set up governed access with a utility's CIP Senior Manager AI role-play lab · 45 min
    10. Retrieval: 8 questions across Module 1 Retrieval check · 10 min
  2. NERC CIP: Categorization and High/Medium Controls 9 lessons · 2 h 30 min

    CIP-002 categorization, CIP-005-7 perimeters and remote access, CIP-007-6 system security, CIP-010-4 change and vulnerability management, CIP-013-2 supply chain, and CIP-004-7 with CIP-011-3 for people and BCSI, including BCSI stored in bRRAIn.

    1. Pretest: NERC CIP categorization and High/Medium controls Diagnostic pretest · 5 min
    2. CIP-002: BES Cyber System categorization Reading · 15 min
    3. CIP-005-7: Electronic Security Perimeters, remote access and vendor sessions Worked example · 15 min
    4. CIP-007-6: System security management, R1 to R5 Reading · 15 min
    5. CIP-010-4: Configuration change management and vulnerability assessments Worked example · 15 min
    6. CIP-013-2: Supply chain risk management Reading · 15 min
    7. CIP-004-7 and CIP-011-3: People, access and BES Cyber System Information Reading · 15 min
    8. Lab: Walk a CIP evidence sample with the CIP Senior Manager AI role-play lab · 45 min
    9. Retrieval: 8 questions across Module 2 Retrieval check · 10 min
  3. NERC CIP: Low Impact, Physical Security, Incidents, Monitoring and the Audit Process 8 lessons · 2 h 15 min

    CIP-003-9 low impact plans with six Attachment 1 sections, CIP-014 physical security (Order No. 802), CIP-008-6 incident response and reporting with CIRCIA as pending, CIP-015-1 internal network security monitoring, and how Regional Entities examine compliance under the CMEP with RSAWs.

    1. Pretest: Low impact, physical security, incidents, monitoring and the audit process Diagnostic pretest · 5 min
    2. Low impact BES Cyber Systems under CIP-003-9 Reading · 15 min
    3. CIP-014: Physical security of critical transmission stations and substations Reading · 15 min
    4. CIP-008-6: Incident response and reporting, and what CIRCIA does not yet require Worked example · 15 min
    5. CIP-015-1 and internal network security monitoring Reading · 15 min
    6. How CIP compliance is examined: Regional Entities, the CMEP and RSAWs Reading · 15 min
    7. Lab: Mock audit interview with a Regional Entity auditor AI role-play lab · 45 min
    8. Retrieval: 8 questions across Module 3 Retrieval check · 10 min
  4. TSA Pipeline Security Directives and API 1164 8 lessons · 2 h 15 min

    The SD Pipeline-2021-01 and -02 series and the current-revision discipline (02E issued July 2024), SSI handling, the Cybersecurity Coordinator, the TSA-approved implementation plan, incident response plan and assessment program, pipeline incident reporting, and API 1164 for pipeline control systems.

    1. Pretest: TSA pipeline security directives and API 1164 Diagnostic pretest · 5 min
    2. The TSA pipeline security directives: the series and the current-revision discipline Reading · 15 min
    3. The Cybersecurity Coordinator and the SD-01 series Reading · 15 min
    4. The Cybersecurity Implementation Plan, incident response plan and assessment program Worked example · 15 min
    5. Cyber incident reporting for pipelines: TSA, CISA and what is still pending Reading · 15 min
    6. API 1164: pipeline control system cybersecurity Reading · 15 min
    7. Lab: Verify pipeline cyber posture with a pipeline security coordinator AI role-play lab · 45 min
    8. Retrieval: 8 questions across Module 4 Retrieval check · 10 min
  5. OT Architecture: Purdue, IEC 62443 and NIST SP 800-82 9 lessons · 2 h 30 min

    OT versus IT for auditors, the Purdue model and boundary-crossing flow analysis, the IEC 62443 series with the 3-2 zone and conduit method, Foundational Requirements and security levels, NIST SP 800-82 Rev 3 with its 800-53 overlay, and keeping safety and security distinct.

    1. Pretest: ICS/OT architecture, NIST SP 800-82, IEC 62443 and Purdue Diagnostic pretest · 5 min
    2. OT versus IT: why availability and safety change the audit Reading · 15 min
    3. The Purdue reference model: levels, the industrial DMZ and boundary-crossing flows Worked example · 15 min
    4. IEC 62443: the series, zones and conduits, and the 3-2 risk assessment Reading · 15 min
    5. IEC 62443-3-3 and 4-2: Foundational Requirements and Security Levels Reading · 15 min
    6. NIST SP 800-82 Rev 3: an OT security program and the 800-53 overlay Reading · 15 min
    7. Safety and security: keeping the layers distinct and connected Scenario · 15 min
    8. Lab: Purdue and IEC 62443 analysis of a plant network with its OT lead AI role-play lab · 45 min
    9. Retrieval: 8 questions across Module 5 Retrieval check · 10 min
  6. DOE C2M2 and Renewables Cybersecurity 7 lessons · 2 h

    C2M2 v2.1 domains, practices and cumulative MILs, C2M2 alongside NERC CIP, inverter-based resources with BES status, registration and IEEE 1547-2018, and the inverter management plane prioritized by grid impact.

    1. Pretest: DOE C2M2 and renewables cybersecurity Diagnostic pretest · 5 min
    2. DOE C2M2 v2.1: ten domains and the MIL ladder Reading · 15 min
    3. C2M2 and NERC CIP: maturity and compliance side by side Scenario · 15 min
    4. Inverter-based resources: IEEE 1547, registration and cybersecurity scope Reading · 15 min
    5. The inverter management plane: what to look for in a renewables audit Worked example · 15 min
    6. Lab: C2M2 and inverter-fleet review with a renewables CISO AI role-play lab · 45 min
    7. Retrieval: 7 questions across Module 6 Retrieval check · 10 min
  7. Findings, AI Verification, Remediation and the Capstone 10 lessons · 4 h

    Defensible finding anatomy, calibrated severity, mitigation plans and remediation roadmaps, pipeline findings under SSI, AI failure modes and the verification ledger, closing the engagement, a lab catching AI failures, and the written capstone.

    1. Pretest: findings, AI verification, remediation and closure Diagnostic pretest · 5 min
    2. Writing energy findings that hold up Worked example · 15 min
    3. Severity: calibrating findings within one level Reading · 15 min
    4. Mitigation plans and remediation roadmaps for CIP findings Worked example · 15 min
    5. Reporting findings to a TSA-regulated pipeline operator Reading · 15 min
    6. AI failure modes in energy compliance and the verification ledger Reading · 15 min
    7. Closing the engagement: access, records and handover Reading · 15 min
    8. Lab: Catch and correct AI failures in a draft findings package AI role-play lab · 45 min
    9. Retrieval: 8 questions across Module 7 Retrieval check · 10 min
    10. Capstone: Readiness attestation package for Halden County Electric AI role-play lab · 90 min
Labs and capstone

Practice against someone who pushes back.

Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.

  • Lab 1 · Audit Engagement Setup and Governed Access

    AI role-play: agreeing scope, access, model use and closure with a utility's CIP Senior Manager

  • Lab 2 · NERC CIP: Categorization and High/Medium Controls

    AI role-play: walking a CIP evidence sample with a CIP Senior Manager who pushes back

  • Lab 3 · NERC CIP: Low Impact, Physical Security, Incidents, Monitoring and the Audit Process

    AI role-play: mock audit interview with a former Regional Entity CIP auditor

  • Lab 4 · TSA Pipeline Security Directives and API 1164

    AI role-play: verifying pipeline cyber posture with a pipeline security coordinator

  • Lab 5 · OT Architecture: Purdue, IEC 62443 and NIST SP 800-82

    AI role-play: Purdue and IEC 62443 analysis of a combined-cycle plant with its OT lead

  • Lab 6 · DOE C2M2 and Renewables Cybersecurity

    AI role-play: C2M2 scoring and inverter-fleet review with a renewables CISO

  • Lab 7 · Findings, AI Verification, Remediation and the Capstone

    AI role-play: correcting an AI-drafted findings package with a compliance director

  • Lab 8 · Findings, AI Verification, Remediation and the Capstone

    Written readiness attestation package from an evidence set

Capstone

Readiness attestation package for Halden County Electric

Artefact submitted in the capstone lab, AI-scored against the published rubric

Pass mark: 72%

Scored on

  • Engagement governance and access15%
  • CIP findings and citations25%
  • Segmentation and flow analysis15%
  • Low impact and inverter-based resources15%
  • AI verification and regulatory currency15%
  • Severity, roadmap and executive communication15%
Exam and credential

One exam. A credential anyone can verify.

The exam

Items per form
59
Time allowed
120 min
Pass mark
72%
Performance tasks
4
Attempts included
2
Wait between attempts
7 days
  • Online and timed, taken on learn.brrain.io.
  • Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
  • Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.

The credential

  • A verifiable digital badge in your name.
  • A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
  • Valid for 3 years.
  • Renewal: Renewal at 3 years by passing the then-current exam
Before and after

Where this course sits.

Questions

Frequently asked.

Do I need to install anything for the labs?

No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.

How is the exam delivered?

Online and timed: 59 items in 120 minutes, on a form assembled for you from the course's item bank. 4 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 72%.

What if I don't pass first time?

You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.

How long is the credential valid?

3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.

I hold the v1 credential. Is it still valid?

Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.

Can my company enroll a team?

Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.

Enroll

bR2bR Compliance Officer — Energy

Run governed NERC CIP, TSA pipeline and OT security audits from bRRAIn, with verified citations and findings that hold up.