Requirements at a glance
Ports and services
Enable only logical network ports needed for operation, and protect against the use of unnecessary physical input/output ports.
Security patch management
Identify patch sources, evaluate released security patches at least once every 35 calendar days, and within 35 days of the evaluation apply the patch, create a dated mitigation plan, or revise an existing one. Implement mitigation plans on time, or have the CIP Senior Manager or delegate approve an extension.
Malicious code prevention
Deter, detect or prevent malicious code, mitigate detected threats, and keep signatures or patterns current where they are used.
Security event monitoring
Log security events, alert on specified events, retain logs for 90 consecutive days, and review a summary or sample of logged events at intervals no greater than 15 calendar days (high impact).
System access control
Enforce authentication, inventory known enabled default and generic accounts, identify who has shared accounts, change default passwords, meet password length and complexity rules, change passwords at least every 15 months where technically feasible, and limit or alert on unsuccessful logins.
Plain-English summaries, not the official text. Always work from the official standard on nerc.com and your Regional Entity’s guidance.
Recurring deadlines
| Obligation | Interval | Requirement | In CIP Sentry |
|---|---|---|---|
| Evaluate security patches from each identified source | 35 calendar days | CIP-007-6 R2.2 | |
| Apply, mitigate or revise mitigation after evaluation | 35 calendar days | CIP-007-6 R2.3 | Auto-tracked |
| Review a summary or sampling of logged security events (high impact) | 15 calendar days | CIP-007-6 R4.4 | Auto-tracked |
| Retain security event logs | 90 consecutive days | CIP-007-6 R4.3 | |
| Change passwords (where technically feasible) | 15 calendar months | CIP-007-6 R5.6 |
Rows marked Auto-tracked are calculated by CIP Sentry from your own records and shown as compliance clocks. Build a free calendar of your deadlines
The 35-day patch cycle, step by step
- Identify sources. For every piece of software and firmware on each applicable Cyber Asset, record where security patches come from (vendor portal, mailing list, integrator).
- Evaluate every 35 days. Check each source, record what was released and whether it applies. “Nothing new” is still an evaluation you must record.
- Act within 35 days of evaluation. Apply it, create a dated mitigation plan, or revise an existing plan.
- Close mitigation plans on time. Missing a mitigation plan’s own date without an approved extension is a violation.
With dozens of vendors and hundreds of assets, this cycle is exactly what spreadsheets handle badly: one missed row repeats every 35 days.
Log review without drowning
For high impact systems, R4.4 requires reviewing a summary or sampling of logged events at intervals no greater than 15 calendar days. Define what your sample is, who reviews it and how findings are handled, then record every review with its date. The review record is the evidence.
Accounts and passwords
Keep an inventory of default and generic accounts, know who holds shared credentials, and document technical infeasibility where a device cannot meet password rules. Password changes every 15 months are a common miss for field devices, so put them on the same calendar as everything else.
Evidence auditors typically ask for
- Per-asset lists of enabled ports and services with a documented need
- Patch source lists, dated evaluation records every 35 days and the resulting actions
- Mitigation plans with target dates, and CIP Senior Manager approvals for any extensions
- Malware protection configuration and signature update records
- Log configuration, alert definitions and dated log review records
- Account inventories, password change records and failed-login controls
How CIP Sentry helps with CIP-007
Patch management with the 35-day clock
Track patch sources per software group, record evaluations, and see the 35-day action deadline for every applicable patch count down automatically.
Mitigation plans
When a patch can't be applied, create a mitigation plan with its own completion clock, tracked to closure.
Log review tracking
Record security event log reviews per system and get reminded on the 15-day cycle.
Baselines connected
Ports, services and installed software flow from the CIP-010 baseline so CIP-007 and CIP-010 never disagree.
CIP-007 FAQ
When does the 35-day clock start?
The evaluation clock (R2.2) runs from your last evaluation: at least once every 35 calendar days you must check each identified source for new security patches. Once a patch is evaluated as applicable, R2.3 gives you 35 calendar days to apply it, create a mitigation plan, or revise an existing plan.
Is CIP-007 really the most-violated standard?
Yes. CIP-007, CIP-010 and CIP-004 consistently account for the largest share of serious and moderate CIP noncompliance in ERO reporting. Patch timing and log review gaps are common causes.
Do we have to patch within 35 days?
No. You have to act within 35 days: apply the patch, create a dated mitigation plan, or revise an existing plan. The mitigation plan then has to be implemented within its timeframe unless the CIP Senior Manager approves an extension.
Last reviewed . Standard versions and effective dates are checked against nerc.com each quarter.

