Requirements at a glance
Security awareness
Reinforce cyber security practices at least once each calendar quarter for personnel with authorized access.
Cyber security training
Role-based training covering the required topics before access is granted (except CIP Exceptional Circumstances), then at least once every 15 calendar months.
Personnel risk assessment (PRA)
Confirm identity and perform a seven-year criminal history check before granting access, with a documented evaluation process. Repeat at least once every 7 years.
Access management
Authorize electronic, unescorted physical and (in CIP-004-7) related access based on need. Verify quarterly that individuals with active access have an authorization record, and every 15 months that access privileges are correct and necessary.
Access revocation
Remove unescorted physical access and Interactive Remote Access within 24 hours of a termination action, remove other access by the end of the next calendar day for reassignments no longer needing it, and handle shared accounts and passwords within 30 days.
Access to BCSI
Authorize, verify and revoke provisioned access to BES Cyber System Information (moved here from R4 in CIP-004-7, the change that enabled compliant cloud storage of BCSI).
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
Recurring deadlines
| Obligation | Interval | Requirement | In CIP Sentry |
|---|---|---|---|
| Security awareness reinforcement | Each calendar quarter | CIP-004-7 R1.1 | Auto-tracked |
| Cyber security training | 15 calendar months | CIP-004-7 R2.3 | Auto-tracked |
| Personnel risk assessment | 7 years | CIP-004-7 R3.5 | Auto-tracked |
| Verify active access has authorization records | Each calendar quarter | CIP-004-7 R4.2 | Auto-tracked |
| Verify access privileges are correct and necessary | 15 calendar months | CIP-004-7 R4.3 | Auto-tracked |
| Revoke physical access and Interactive Remote Access after termination | 24 hours | CIP-004-7 R5.1 | Auto-tracked |
| Change shared account passwords after a termination or reassignment | 30 calendar days | CIP-004-7 R5.4 | Auto-tracked |
Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines
Why CIP-004 is so often violated
CIP-004 is mostly about timing across departments. HR knows when someone leaves, IT or OT removes accounts, security removes badges, and compliance has to prove all of it happened within hours. When those steps live in different systems, a single late ticket becomes a possible violation.
Building a revocation process that holds
- One trigger. Make the HR termination action automatically notify everyone who removes access, and record the timestamp.
- One checklist per person. List every access type the person holds: electronic accounts, Interactive Remote Access, badge, keys and BCSI repositories.
- Evidence at the moment of removal. Screenshots or system logs with timestamps are far easier than reconstructing events months later.
- Shared accounts. Change shared account passwords within 30 days of a termination or reassignment, unless technically infeasible and documented.
Quarterly versus 15-month reviews
R4.2 asks a simple quarterly question: does everyone with active access have an authorization record? R4.3 asks a deeper question every 15 months: are the privileges each person holds still correct and necessary? Both need dated evidence, and discrepancies need to be corrected and recorded.
Evidence auditors typically ask for
- Awareness materials and dated proof of quarterly distribution
- Training content mapped to the required topics, with completion records and dates
- PRA records showing identity confirmation, the seven-year check and the evaluation outcome
- Access authorization records per person and per system or BCSI repository
- Quarterly and 15-month verification records, including any corrections made
- HR termination timestamps next to access-removal timestamps
How CIP Sentry helps with CIP-004
Personnel & Access module
Personnel risk assessments, training, grants and revocations live in one place, per person and per system.
Revocation deadlines computed
When access should end, the revocation and shared-password deadlines appear immediately as compliance clocks, counted in hours and days.
Training and PRA expiry
Each person's 15-month training and 7-year PRA dates are tracked automatically, with reminders before they lapse.
Privilege reviews
Quarterly and 15-month access verifications are scheduled, recorded and reportable.
CIP-004 FAQ
When does the 24-hour clock start?
At the termination action, typically the time HR processes the termination. Align HR and security processes so the time is recorded and access removal is triggered immediately.
What changed in CIP-004-7?
Access management for BES Cyber System Information moved into a new Requirement R6, focused on provisioned access to BCSI. Together with CIP-011-3, this created a compliant path for storing BCSI with third-party and cloud providers. It took effect January 1, 2024.
Is training required before access?
Yes. R2.2 requires training to be completed before authorization, except during CIP Exceptional Circumstances.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

