CIP-006 · Physical Security of BES Cyber Systems

CIP-006: control, monitor and log who is physically there.

CIP-006 protects BES Cyber Systems with Physical Security Perimeters, controlled and logged access, escorted visitors, and physical access control systems that are maintained and tested every 24 months.

Enforceable nowCIP-006-6 (effective July 1, 2016)
Next versionCIP-006-7.1 (July 1, 2028) with the virtualization package
Applies toHigh impact and medium impact BES Cyber Systems (most parts: medium impact with ERC), plus associated EACMS, PACS and PCAs

Requirements at a glance

R1

Physical security plan

Define operational or procedural controls to restrict physical access, use one or more controls (two or more for high impact) to allow unescorted access only to authorized people, monitor for unauthorized access through a physical access point, alarm or alert within 15 minutes, log entry of each person with unescorted access, and retain those logs for at least 90 calendar days.

R2

Visitor control program

Continuously escort visitors inside the Physical Security Perimeter, log each visitor's entry and exit with the date, time and the name of the person responsible for the visitor, and retain visitor logs for at least 90 calendar days.

R3

PACS maintenance and testing

Maintain and test each Physical Access Control System and locally mounted hardware or device at the perimeter at least once every 24 calendar months to ensure they function properly.

Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.

Recurring deadlines

ObligationIntervalRequirementIn CIP Sentry
Maintain and test PACS and locally mounted hardware24 calendar monthsCIP-006-6 R3.1Auto-tracked
Retain physical access logs and visitor logsAt least 90 calendar daysCIP-006-6 R1.9, R2.3
Alarm or alert on unauthorized accessWithin 15 minutes of detectionCIP-006-6 R1.5

Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines

Physical and cyber are one program

CIP-006 depends on CIP-004. Only people authorized and trained under CIP-004 should hold unescorted access, and removals must happen within its deadlines. Many findings come from badge lists that drifted away from authorization records. Reconcile the two every quarter as part of the CIP-004 R4.2 check.

Logging and alerting that actually works

For high impact systems you need two or more different physical access controls, such as a badge plus a PIN. Monitoring must detect unauthorized access through a physical access point and raise an alarm or alert to the people who respond within 15 minutes. Test the alarm path, not just the sensor.

The 24-month PACS test

R3 is simple but easy to forget because two years is a long time. Create one test record per perimeter or device group and put the next due date on a calendar the whole team can see.

Evidence auditors typically ask for

  • Physical security plan(s) addressing every applicable R1 part
  • Floor plans or diagrams of each Physical Security Perimeter and its access points
  • Access control system configuration and authorized-access lists matching CIP-004 authorizations
  • Alarm and alert records showing response within 15 minutes
  • Visitor logs with entry/exit times and the responsible point of contact
  • Dated PACS maintenance and test records no more than 24 months apart

How CIP Sentry helps with CIP-006

Perimeters linked to systems

Physical Security Perimeters sit alongside the ESPs and BES Cyber Systems they protect, so scope is never guessed.

Visitor and access records

Track perimeter access, visitor logs and access authorizations in the Physical Security module.

24-month PACS clock

Every PACS maintenance and test is scheduled per perimeter, with the next due date computed from the last completed test.

Transmission stations too

CIP-014 risk assessments and security plans live in the same module when you own qualifying transmission stations.

CIP-006 FAQ

Do low impact assets need a PSP?

No. Low impact physical controls are covered by CIP-003 Attachment 1 Section 2.

What counts as testing a PACS?

Your documented maintenance and testing program should confirm that readers, locks, door contacts, alarms and the controllers that log them all function. Record what was tested, the result and the date.

Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

Related standards

Request a quote

Run CIP-006 without the spreadsheet.

Get a quote sized to your registered functions and impact levels, and a live walkthrough on sample data. No sales pressure, no cloud account, no commitment.