Requirements at a glance
Physical security plan
Define operational or procedural controls to restrict physical access, use one or more controls (two or more for high impact) to allow unescorted access only to authorized people, monitor for unauthorized access through a physical access point, alarm or alert within 15 minutes, log entry of each person with unescorted access, and retain those logs for at least 90 calendar days.
Visitor control program
Continuously escort visitors inside the Physical Security Perimeter, log each visitor's entry and exit with the date, time and the name of the person responsible for the visitor, and retain visitor logs for at least 90 calendar days.
PACS maintenance and testing
Maintain and test each Physical Access Control System and locally mounted hardware or device at the perimeter at least once every 24 calendar months to ensure they function properly.
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
Recurring deadlines
| Obligation | Interval | Requirement | In CIP Sentry |
|---|---|---|---|
| Maintain and test PACS and locally mounted hardware | 24 calendar months | CIP-006-6 R3.1 | Auto-tracked |
| Retain physical access logs and visitor logs | At least 90 calendar days | CIP-006-6 R1.9, R2.3 | |
| Alarm or alert on unauthorized access | Within 15 minutes of detection | CIP-006-6 R1.5 |
Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines
Physical and cyber are one program
CIP-006 depends on CIP-004. Only people authorized and trained under CIP-004 should hold unescorted access, and removals must happen within its deadlines. Many findings come from badge lists that drifted away from authorization records. Reconcile the two every quarter as part of the CIP-004 R4.2 check.
Logging and alerting that actually works
For high impact systems you need two or more different physical access controls, such as a badge plus a PIN. Monitoring must detect unauthorized access through a physical access point and raise an alarm or alert to the people who respond within 15 minutes. Test the alarm path, not just the sensor.
The 24-month PACS test
R3 is simple but easy to forget because two years is a long time. Create one test record per perimeter or device group and put the next due date on a calendar the whole team can see.
Evidence auditors typically ask for
- Physical security plan(s) addressing every applicable R1 part
- Floor plans or diagrams of each Physical Security Perimeter and its access points
- Access control system configuration and authorized-access lists matching CIP-004 authorizations
- Alarm and alert records showing response within 15 minutes
- Visitor logs with entry/exit times and the responsible point of contact
- Dated PACS maintenance and test records no more than 24 months apart
How CIP Sentry helps with CIP-006
Perimeters linked to systems
Physical Security Perimeters sit alongside the ESPs and BES Cyber Systems they protect, so scope is never guessed.
Visitor and access records
Track perimeter access, visitor logs and access authorizations in the Physical Security module.
24-month PACS clock
Every PACS maintenance and test is scheduled per perimeter, with the next due date computed from the last completed test.
Transmission stations too
CIP-014 risk assessments and security plans live in the same module when you own qualifying transmission stations.
CIP-006 FAQ
Do low impact assets need a PSP?
No. Low impact physical controls are covered by CIP-003 Attachment 1 Section 2.
What counts as testing a PACS?
Your documented maintenance and testing program should confirm that readers, locks, door contacts, alarms and the controllers that log them all function. Record what was tested, the result and the date.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

