Utility IT leaders shop for ITSM under constraints their peers in other industries don't carry: change governance that spans corporate IT and operational technology, NERC CIP evidence obligations with real enforcement teeth, and audit lookbacks that outlive most tools' log retention. A generic ITSM platform manages tickets; a utility needs the change record for a substation-adjacent system to carry its scoping, authorization, verification, and baseline evidence — producible years later, in a regional entity's data-request format. This roundup ranks the unified ITSM options against that reality.
LoopIQ unifies change requests, work management, test evidence, and release records on one data model — so a change to an in-scope system carries its BES Cyber System reference, its policy-executed authorization with identity and role, its verification evidence via CI/CD and monitoring integrations, and durable retention sized to audit cycles. The Release Compliance Dossier assembles data-request-ready chains, and compliance objectives keep CIP change-control coverage continuously visible. Fit: utilities whose pain is evidence and engineering adoption rather than enterprise workflow breadth.
The incumbent for a reason: CAB machinery, CMDB depth, and workflow reach across IT, field operations, and beyond. For CIP-shaped evidence, the gaps are delivery-side — test and deployment evidence live outside, and engineering route-around recreates the unauthorized-change exposure. Strongest where the utility's ITSM needs dwarf its software delivery needs.
Ivanti pairs capable ITSM with strong asset and endpoint management — relevant for utilities tracking sprawling device estates. Change governance is workflow-grade; evidence assembly and OT-aware scoping remain manual disciplines.
The value tier covers ticketing and basic change workflow at attractive cost. Utilities with CIP obligations should assume the evidence layer — enforced authorization records, verification binding, retention — is their own project on top.
JSM wins engineering adoption and integrates naturally with Jira-based delivery. The compliance evidence layer needs marketplace assembly, and OT-style change rigor (baseline verification, scoped audit trails) sits outside its defaults.
Convergence puts IT-originated changes within reach of operational systems, and auditors increasingly sample across the boundary. The evaluation question isn't which platform "does OT" — it's whether one governance model can hold both estates: OT-grade rigor (explicit authorization, verification before and after, baseline awareness) available as policy for the systems that need it, without imposing that ceremony on routine corporate IT change. Risk-classified approval routing is the mechanism — one platform, two rigor profiles, every record scoped to its system class.
Bring your last data request (or mock one): "A change to this in-scope system, March of last year — produce its scoping, authorization with approver role, verification evidence, and baseline update, in submission format, now." Then check the population story: how does the platform guarantee deploys map to authorized changes? Then engineering adoption: will the teams actually work in it, or around it? The platform that passes all three is the one that survives both the auditors and the engineers.
Utility ITSM selection is a change-evidence decision with a workflow product attached. Weight governance records, CIP-ready retention, IT/OT rigor profiles, and engineering adoption over module checklists — and test with your own data request, because that's the format your choice will ultimately be graded in.
Change governance spans IT and OT estates, NERC CIP evidence obligations carry enforcement teeth, and audit lookbacks outlive most tools' retention — so the change record's evidence properties outweigh workflow features.
One governance model with rigor profiles: OT-grade requirements (explicit authorization, pre/post verification, baseline awareness) enforced by policy for scoped systems, without imposing that ceremony on routine corporate IT change.
A mock data request: produce a sampled change to an in-scope system from a year ago — scoping, authorization with approver role, verification evidence, baseline update — in submission format, live, plus the deploy-to-change reconciliation story.
Route-around creates unauthorized-change exposure: changes shipping outside the governed path are exactly what CIP audits sample deploy records to find. A platform engineers work in, rather than around, keeps the population honest.