MERIDIAN · Critical Infrastructure · Patent Pending
$1.4M/day NERC Penalties

Real-time audit trails for critical infrastructure, backed by cryptography.

There are 14 NERC CIP standards, and penalties for missing them can run $1.4M a day. MERIDIAN checks every SCADA command, every access event, and every grid operation in real time. So when auditors show up, you don't scramble to prepare. You just show them the dashboard.

14 NERC CIP Standards CNSA 2.0 Ready CIP-015 Ready Patent Pending
The Risk

Non-compliance isn't just a headache for your operations team. It costs real money.

NERC enforcement is active and it's picking up speed. These penalties are real, they're documented, and they're growing.

$1.4M/day

Maximum NERC penalty exposure

FERC's penalty guidelines allow up to $1.4M per day per violation for CIP non-compliance. Enforcement actions have already cost some utilities tens of millions of dollars in a single settlement.

Duke Energy: $2.7M · PG&E: $10M settlement · Average enforcement up 340% since 2019
+220%

Rise in physical security intrusions since 2022

Physical attacks on grid infrastructure have surged since 2022. CIP-006 and CIP-014 require you to log and prove every physical access event. Manual logs don't hold up once enforcement starts digging.

NERC GridEx data · DHS CISA advisory AA22-265A · 2023 substation incidents
Oct 2028

CIP-015 deadline: internal network monitoring

NERC CIP-015 makes internal network security monitoring mandatory for high- and medium-impact BES Cyber Systems. Right now, most utilities don't have tools that meet the standard. The deadline is October 2028.

NERC CIP-015-1 · FERC Order 887 · Effective enforcement Q4 2028
What MERIDIAN covers

Every operation gets signed. Nothing can be changed. It holds up in court.

Six areas of coverage that together answer every NERC CIP evidence request an auditor can make.

SCADA Command Logging

Every grid operation, whether it's a breaker operation, a setpoint change, or a load shedding command, generates an ML-DSA-65 signed receipt in real time. Nothing happens without a record.

ML-DSA-65 · FIPS 204 · per-command

Access Control Attestation

Every badge swipe, electronic login, and physical access event gets logged with identity, timestamp, and authorization context, all signed. That covers CIP-004 and CIP-006.

CIP-004 · CIP-006 · identity-bound

Security Event Monitoring

You get real-time alerts with an evidence chain nobody can change. Every anomaly, whether it's an unauthorized access attempt, a configuration change, or a network intrusion, gets logged, signed, and time-stamped before you're even alerted.

CIP-007 · CIP-008 · CIP-015

NERC Compliance Dashboard

One screen shows your compliance status across all 14 CIP standards. Export an auditor-ready report in one click. Gap analysis updates itself as your environment changes.

14 CIP standards · real-time · exportable

Post-Quantum Security

Every signature uses ML-DSA-65, also called CRYSTALS-Dilithium, the standard NIST picked as FIPS 204. It's CNSA 2.0 ready and built for the NSA's 2030 post-quantum mandate. Records signed today can still be checked in 2040.

CNSA 2.0 · FIPS 204 · 2030 mandate ready

Offline Verification

Auditors can check any evidence package in 8.6ms without needing network access. Each signed receipt is self-contained, so there's no Hive infrastructure to reach, no API call, no internet connection needed. It works in air-gapped environments too.

8.6ms · offline · air-gap ready
NERC CIP Coverage

All 14 standards. Every requirement covered.

MERIDIAN generates evidence for every NERC CIP standard in scope. No gaps, no manual log exports, and no scrambling before an audit.

CIP-002
BES Cyber System Categorization
CIP-003
Security Management Controls
CIP-004
Personnel & Training
CIP-005
Electronic Security Perimeter
CIP-006
Physical Security of BES
CIP-007
Systems Security Management
CIP-008
Incident Reporting & Response
CIP-009
Recovery Plans for BES
CIP-010
Config Change Management
CIP-011
Information Protection
CIP-012
Communications Between Control Centers
CIP-013
Supply Chain Risk Management
CIP-014
Physical Security of Transmission
CIP-015
Internal Network Security Monitoring · Oct 2028
Compliance Dashboard

When auditors arrive, you show them this.

MERIDIAN's compliance dashboard shows your real-time standing across all 14 CIP standards. Every number is backed by a signed chain of evidence.

meridian.thehiveryiq.com · NERC CIP Compliance Dashboard LIVE
14 / 14
CIP Standards Covered
100%
SCADA Commands Signed
8.6ms
Avg Verification Time
0
Open Audit Gaps
NERC CIP COMPLIANCE POSTURE
14 / 14 standards · AUDIT READY
Deployment

No rip-and-replace. It runs alongside your systems, live in four weeks.

MERIDIAN works with the OT security stack you already have. Your SCADA systems stay untouched. Your auditors see results in 30 days.

Works with your OT security vendors

MERIDIAN adds a layer of signed proof. It doesn't replace anything. It plugs into the OT security infrastructure you already run.

Dragos Claroty Nozomi Networks Fortinet OT Cisco CX
It runs alongside your systems. Your existing SCADA systems, PLCs, and HMI platforms stay exactly as they are. MERIDIAN watches and signs. It never routes or changes operational traffic.
Air-gap compatible. Works in classified, disconnected, and physically isolated BES environments. No internet dependency for operational logging.

From signed contract to audit-ready in 4 weeks

  • W1
    WEEK ONE
    SCADA logging active
    MERIDIAN gets deployed alongside your systems. All SCADA commands start generating ML-DSA-65 signed receipts. Real-time signing gets checked and confirmed.
  • W2
    WEEK TWO
    All 14 CIP standards covered
    Access control, physical security, and network event logging all go live. The dashboard shows your live compliance status across every CIP standard.
  • W3
    WEEK THREE
    Evidence library built
    30 days of signed evidence piles up. Gap analysis is done. Any open findings get surfaced, with a documented plan to fix them.
  • W4
    WEEK FOUR
    First NERC audit readiness package
    You export a complete audit package: signed evidence, a CIP-by-CIP coverage report, a gap remediation log, and a bundle of receipts anyone can check offline.
Comparison

Manual logs won't survive a NERC audit.

Here's why the usual approaches leave utilities exposed, and what MERIDIAN does differently.

Capability Manual Logs + Spreadsheets Existing NERC Tools MERIDIAN
Real-time attestation Manual, delayed Batch, next-day Sub-second, every event
Post-quantum signatures None None ML-DSA-65 / FIPS 204
Court-admissible evidence Disputed in enforcement Partial Cryptographic, tamper-evident
CIP-015 ready Not addressed Partial roadmap Fully covered
Offline verification N/A Requires connectivity 8.6ms, air-gap ready
Cost per signed event Immeasurable liability $0.08 to $0.40 Fixed annual, $150K/yr
Audit package generation Weeks of manual work Days, manual export One-click, instant
SCADA command logging Incomplete, mutable Vendor-dependent 100%, cryptographically signed
Who uses MERIDIAN

Three types of buyers. One urgent problem.

NERC enforcement affects every regulated utility. These are the organizations that move first.

Best first customer

Utility under active NERC enforcement

You've received a Notice of Penalty or a compliance violation finding. Your legal team is managing the settlement. You need evidence you can defend going forward, and you need it fast.

Why MERIDIAN fits
  • Immediate audit trail from day one
  • Cryptographic evidence withstands scrutiny
  • Pilot ROI visible within 30 days
RTO / ISO

Regional transmission operator managing multi-utility compliance

You coordinate reliability across dozens of member utilities. Each one has its own NERC CIP status and its own audit cycle. Pulling evidence together from all of them by hand is a nightmare every quarter.

Why MERIDIAN fits
  • Multi-entity compliance dashboard
  • Cross-utility evidence consolidation
  • CIP-012 inter-control-center coverage
CIP-015 Preparation

Utility preparing for CIP-015 before October 2028

CIP-015's internal network security monitoring rules are final. The compliance date is October 2028. Most utilities don't have tools that generate the evidence it requires. The window to build it is closing.

Why MERIDIAN fits
  • CIP-015 evidence built in from day one
  • FERC Order 887 compliance pathway
  • Deploy now, audit-ready before 2028
Get started

When NERC auditors arrive, you don't scramble to prepare. You show them the dashboard.

$150,000/year. $1.4M/day is the alternative.

Pilot deployment takes four weeks and covers all the CIP standards, for a fixed annual cost. No per-event billing, and no infrastructure for you to run.

Patent Pending · CNSA 2.0 · FIPS 204 · CIP-015 Ready · ML-DSA-65

Private by design. Hive does not store your prompts. Every request is already receipted by a one-way SHA-256 fingerprint, not the words. Proof, not surveillance.