Re-credentialing Requirements: What You Need to Know
What makes re-credentialing hard?
Is it the rules, the volume, the timing, or the pressure to get everything right?
Well, in all honesty, it's all of them at once.
Re-credentialing occurs continuously, with providers due for review each month.
Payors expect licenses, certifications, sanctions, and history to be re-verified, even if the provider has been in the network for years.
To create an efficient recredentialing system, you need structure. You need to plan ahead, track deadlines, and follow a process to stay compliant.
Underneath it all, there's one fixed number. Every provider you credential starts a 36-month clock on the day the decision gets made, and it keeps running whether or not anyone's watching. Once you treat your roster as a rolling calendar of those clocks running out, the work stops feeling like a scramble. It turns into something you can schedule around.
In this guide, we'll break down what payors require for re-credentialing and how to manage it effectively. So we'll walk through the cycle itself, what starts the clock, and what can trigger a review outside it. Then we'll get into everything you need to re-verify and the dates you should work backward from.
What is Re-Credentialing
Re-credentialing is the mandated, periodic process of reviewing a healthcare provider's qualifications. This review is essential to verify that the provider continues to meet the compliance and participation standards set by regulatory bodies like NCQA and CMS, as well as by most payors.
Re-credentialing covers the provider's own qualifications and nothing beyond them. It doesn't renegotiate your payer contracts, and it doesn't re-enroll anyone with a payer either. Those are separate pieces of work running on their own schedules, so don't fold them into the same tracker. See our breakdown of credentialing versus payer enrollment if the distinction is new to your team.
The core of re-credentialing involves a complete re-verification of primary source documents, which includes checking:
- Licenses and certifications
- Sanction history
- Work experience
Once the necessary documentation is compiled, a credentialing committee must review and approve the file. Ultimately, this process confirms the provider's ongoing qualifications, eligibility, and safety for continued participation in the network.
Re-Credentialing vs Initial Credentialing: What’s the Difference?
It’s easy to assume re-credentialing is easier than initial credentialing. After all, the provider is already in the network, so there’s history, and there’s an existing relationship. But that’s not the case.
Re-credentialing assumes the provider is already approved, which can streamline tasks such as confirming continuous work history or reusing previously submitted background details. But even with this, payors still expect the same level of verification and oversight. For the full first-time sequence, see our guide to the medical credentialing process. We've also broken down how long provider credentialing takes.
Here is a comparison between recredentialing and initial credentialing:
36-Month Cycle: Timeline Requirements
Under the National Committee for Quality Assurance (NCQA) standards, providers must be re-credentialed at least every 36 months (3 years).
That wording carries more weight than it looks like it does. "At least every 36 months" sets an outer limit, so finishing early is fine and finishing late is a finding.
When the clock actually starts
Your 36 months run from the date of the previous credentialing decision. It isn't the hire date, the contract effective date, or the license expiration date. Those other dates are the ones credentialing teams usually have closest at hand, which is exactly why files slip.
So the number that belongs in your tracker is the date your committee last approved that provider. The due date is 36 months after it, and everything else on the calendar hangs off that one field.
NCQA does leave a little room at the end. If you finish the process and make the decision within 30 days of the due date, you can still recredential. Past that, there's no grace period, and a provider who hasn't been recredentialed within 36 months gets scored down at an audit.
The cycle can only be extended in situations that NCQA recognizes, such as an active-duty military assignment or medical leave. A backed-up committee agenda isn't one of them.
You might have trouble with timing. Many people make the mistake of starting on the day of the deadline.
Here are the critical timing rules that are important:
- The re-credentialing process should begin 90 to 120 days before the expiration date.
- The provider's attestation must be current at the time of the committee decision. The allowed window depends on the element and the program; the attestation section below shows the current numbers.
- All Primary Source Verifications must be completed before the committee review.
- There's no grace period once the 30-day completion allowance passes; a lapsed file is a compliance finding.
Here's an example timeline:
- Provider last credentialed: January 15, 2023
- Re-credentialing due by: January 15, 2026
- Process should begin: September 2025 (about 120 days before)
- Verifications completed by: December 2025
- Committee review: Early January 2026
The important thing to remember is that you don't start at the due date, as it would be impossible to complete.
What puts a provider back in front of your committee
Most of your files open because the calendar says so, and that's the whole point of a fixed cycle. But the calendar isn't the only thing that opens one; off-schedule files are the ones that catch teams out.
Between cycles, you're required to keep monitoring sanctions, license actions, and complaints. So anything those checks turn up has to be dealt with when you find it, not parked until the next due date. Beyond that requirement, most organizations write their own list of triggers into their credentialing policy.
The usual triggers:
- The 36-month due date. The scheduled cycle and the bulk of your volume.
- A sanction or exclusion identified through ongoing monitoring. An OIG or state exclusion doesn't wait for your calendar, so the file has to be pulled forward and reviewed independently.
- A license or DEA registration that lapses or gets restricted mid-cycle. The provider can't practice on the strength of a three-year-old verification once the underlying license has changed.
- A new malpractice claim, settlement, or adverse action. Whether the provider discloses it or your monitoring finds it, the committee needs to see it before the next scheduled review.
- A material change in how the provider practices. A new specialty, a new site, or a new set of hospital privileges usually means new elements to verify.
- A payer or delegation requirement. A delegated credentialing agreement can set its own triggers and reporting deadlines in addition to the NCQA cycle. So read yours rather than assuming the 36 months govern everything.
The re-credentialing calendar, stage by stage
The easiest way to tell whether a file is on track is to work backwards from its due date. The table below lays out the cycle that way, with each stage pinned to how far out it should occur.
The decision date behind you and the due date ahead of you don't change. Everything in between does. So build the middle of the schedule around those two anchors, and expect it to compress when a provider is slow to answer. If your committee meets only monthly, count backward from the last meeting before the due date rather than from the due date itself.
What must be re-verified during re-credentialing? (full checklist)
Once re-credentialing starts, payors expect a full confirmation of the provider's status. We built our credentialing platform to run these verifications automatically across 2,000+ primary sources, so you don't have to reconcile mismatched data by hand.
Here is the full set of elements that must be re-verified during re-credentialing. These are the elements you have to re-verify every cycle.
Attestation requirements
In addition to verification, the provider must submit a current attestation. This confirms that no material has changed and that the information on file is accurate.
The provider must attest to:
- Ability to perform essential job functions
- No physical or mental impairment affecting patient care
- Any history of loss or restriction of license or privileges
- Any felony convictions
- Current malpractice insurance coverage
- Accuracy and completeness of the application
Timing is also very important here. An attestation submitted outside the allowed window can delay committee review, even if all required verifications are complete.
What counts as "current" isn't one flat number across every element. NCQA's corrections and clarifications to the 2025 CR-PN standards changed the application and attestation processing limit from 90 to 120 calendar days. The work history limit changed to 120 calendar days as well, and CRA 4 Element A factor 5 is set at 180.
Both apply to files processed on or after July 1, 2025. So check the limits for the element and the program you're working in before you build a rule around a single figure. We've broken the rest of the changes down in our guide to the 2025 NCQA credentialing standards updates.
Re-credentialing process: step by step
Re-credentialing gets much easier once the same routine runs every time. When the steps are consistent, fewer files come back from the committee with questions.
So this is the sequence to run.
Step 1: Identify providers due for re-credentialing
Start by pulling a report of providers whose 36-month period ends in the next 120 days. Measure that from their last committee decision, not from a license expiry date. Sort the list by due date so the most urgent files come first.
At this stage, it helps to flag providers with known issues, such as prior malpractice claims, past sanctions, or delayed responses in previous cycles. This allows extra time to make corrections.
Step 2: Request updated information from the provider
Once you have identified your providers, send out the re-credentialing request. This is usually an attestation form or short application update. If required, ask for an updated CV.
Set a clear response deadline, most often 30 days, and track the replies you get. Follow up early with providers who have not responded.
Step 3: Conduct primary source verifications
After receiving the provider's information, begin PSV. Run all required checks, including licenses, sanctions, malpractice coverage, and work history.
For each verification, document the source and the date it was completed. If anything is expired, missing, or does not match the application, flag it immediately.
Step 4: Review for red flags
Before preparing the committee file, review the record carefully.
Look for malpractice claims since the last credentialing, sanctions or exclusions, license restrictions, gaps in work history, or attestation disclosures that need follow-up. This step is about determining whether the file is clean or requires additional information before committee review.
Step 5: Prepare the committee file
Once verifications are complete, assemble the committee file. Include all verification results and clearly note any concerns that require discussion. Prepare a recommendation, such as approval, approval with conditions, or denial, based on the information collected.
Step 6: Committee review and decision
Present the file to the credentialing committee. The committee reviews the information and makes a decision, which must be documented in the meeting minutes.
If the decision is conditional or a denial, required follow-up and notification steps must be followed.
Step 7: Notify provider and update systems
After the decision, notify the provider of their re-credentialing status.
Update the credentialing system with the new approval date and next cycle deadline. If applicable, update payor rosters and set the reminder for the next re-credentialing cycle. That new approval date starts the next 36 months. So getting it into the system correctly is the last step of this cycle and the first step of the next.
NCQA standards for re-credentialing
Re-credentialing is guided by the National Committee for Quality Assurance (NCQA) credentialing standards.
These standards define how often re-credentialing must occur, what must be reviewed, and how decisions must be made.
Here are some of the standards for recredentialing:
Re-credentialing cycle
As noted in the timeline section, NCQA requires providers to be re-credentialed at least every 36 months. The 36-month cycle covered above must be supported by a documented process. Informal tracking or manual reminders are not enough. Your organization must be able to show how providers are identified, reviewed, and approved on schedule.
Verification sources
Primary source verification is required during re-credentialing. This includes verification of licensure, sanctions, and disciplinary actions. NCQA specifies acceptable sources for each element, and those sources must be used. Keep in mind that secondary confirmation or prior-cycle verification does not meet the standard.
Application and attestation
Re-credentialing files must include a provider application or attestation. Required attestation includes your ability to perform duties, lack of impairment, disclosure of any adverse actions, and confirmation of malpractice coverage.
The attestation window varies by element rather than being a single flat number; see the attestation section above for the current figures. An expired attestation can invalidate the file, even if all verifications are complete.
Credentialing committee
NCQA's published standards describe a peer-review process and a designated credentialing committee. That committee reviews practitioner credentials and makes credentialing recommendations. Final authority and legal accountability stay with your governing body, so the committee recommends and the board decides. Every approval or denial still has to be documented. Informal approvals or staff-only decisions do not meet NCQA standards.
Ongoing monitoring
NCQA also requires ongoing monitoring between re-credentialing cycles. This includes tracking sanctions, license actions, and complaints.
If you identify any issues mid-cycle, address them.
How to track re-credentialing at scale
When your organization has more than a handful of providers, it becomes very difficult to track re-credentialing.
Spreadsheets, email reminders, and calendar notes may work for a small team. But once you're at 50, 100, or more providers, you'll miss a deadline sooner or later.
A good tracking system should:
- Send automatic alerts at 90, 60, and 30 days before credentials expire
- Allow providers to complete attestations and upload documents themselves
- Support or integrate with PSV, so checks are not done manually
- Generate committee-ready packets without rebuilding files each time
- Maintain a clear audit trail showing actions, dates, and decisions
- Provide real-time reports on upcoming expirations and file status
When this tracking system is in place, it's easier for you to practice re-credentialing. We've gone deeper into the tooling side in our credential automation guide. Some common tracking options include:
Some of the most important metrics to monitor are:
- Providers expiring in the next 30/60/90 days
- Re-credentialing completion rate
- Average time from initiation to completion
- Overdue re-credentials (a compliance risk)
We built Assured for exactly this, so we'll be upfront about the fact that we have a stake in what comes next. We're an NCQA-certified Credentials Verification Organization. For re-credentialing, the work that matters most happens between cycles. We monitor every expiration date on your roster and recheck Medicare, Medicaid, and OIG exclusions every month. So a sanction or a lapsed license shows up when it happens, not at the next review.
When a cycle does come due, we start the renewal workflow 60 days before the expiration date. Nobody has to spot it on a report first. Our PSVs then run in parallel across 2,000+ primary sources instead of one after another.
We report a turnaround time of less than 2 days, compared with a common baseline of over 60. That's our own number rather than an industry benchmark, so weigh it accordingly. Either way, you're working a due list in advance instead of chasing one.
Consequences of re-credentialing expiration for providers and organizations
So what actually happens once a file goes past its date?
1. Immediate impacts
Once credentialing expires, your provider is no longer compliant with the payor's rules. This simply means:
- The provider technically cannot see patients under payer contracts
- Claims tied to dates after expiration may be denied, delayed, or held
- A compliance violation is created, even if the expiration is short
These issues usually show up weeks later, when claims are reviewed or audited, not on the day the credential expires.
2. Organizational risks
A single expired file can create larger problems for the organization. Some common risks include:
- Audit findings that require corrective action or monitoring
- Payer contract violations, especially under delegated credentialing agreements
- Increased scrutiny from accrediting bodies like the NCQA and The Joint Commission
- Potential impact on accreditation status if expirations are frequent or systemic
3. Patient care implications
Credentialing lapses also affect patients. When a provider is removed from schedules or payers:
- Appointments may be canceled or rescheduled
- Patients may be redirected to other providers
- Continuity of care can be disrupted, especially for ongoing treatment
4. Recovery process
Fixing an expiration issue is not easy or quick. In many cases:
- The provider must go through full re-credentialing, not an expedited review
- There is a gap in network participation during the review period
- Revenue may be lost while claims cannot be billed or paid
The longer the lapse, the harder and more expensive it becomes to recover.
Common re-credentialing pitfalls
Many re-credentialing problems are predictable. They happen due to time gaps, missed follow-ups, or weak documentation.
Here are the most common re-credentialing mistakes to avoid:
1. Starting too late
Beginning re-credentialing 30 days before expiration leaves you no room to correct any mistakes. One delayed response, slow verification, or a missed committee date can cause the credential to expire.
Start the process 90 to 120 days before the expiration date. This gives you time to resolve your issues without turning the file into an emergency.
2. Provider non-response
If the provider never returns the attestation or application, the file stalls. It can expire before verification has even started. To prevent this, set a clear response deadline, send scheduled reminders, and create an escalation path. Inform your team that failure to respond can affect scheduling or payer participation.
3. Incomplete verifications
A single missing item can invalidate your entire file.
To avoid this, use a checklist-driven workflow and track each verification by source and completion date. Files should not progress until you have completed every required element.
4. Outdated attestation
This occurs when the attestation is signed too early and falls outside the allowed window by the time the committee reviews it. To prevent this, request time attestation carefully. If your committee review is delayed, request a new attestation rather than risk an expired one.
5. Missing committee documentation
This happens when the committee reviews the provider, but the decision is not clearly documented in the meeting minutes.
Use a standardized minutes template that records the provider name, decision, date, and any conditions. If it is not written down, it does not count.
6. Ignoring ongoing monitoring
This happens when a sanction, license action, or complaint occurs between cycles and goes undetected.
You can prevent this by running regular sanctions checks and continuously monitoring licenses. Re-credentialing is not the only compliance checkpoint.
Frequently Asked Questions
How often is recredentialing required?
At least every 36 months, which is three years. That's an outer limit rather than a target, so finishing early is fine, and finishing late is a finding at audit. The 36 months run from your committee's last decision on that provider. If you complete the process within 30 days of the due date, you can still recredential rather than start a fresh initial file.
What is the difference between credentialing and recredentialing?
Credentialing is the first comprehensive check for a provider joining your network, built from scratch. Recredentialing repeats that same depth of check on a provider you already have, on a fixed cycle. The verification standard doesn't drop the second time around. What you're reviewing is continuity and anything new since the last decision, rather than a whole career from scratch.
When should you start a recredentialing file?
90 to 120 days before the due date. That leaves room for a provider who takes three weeks to return an attestation. It also covers a verification that comes back mismatched and a committee that meets only occasionally. Start at 30 days, and there's no room for error, so one slow reply can push the file past its date.
Can a recredentialing cycle be extended?
Only in the situations NCQA names, like an active duty military assignment or medical leave. A busy month, a full committee agenda, or a provider who won't answer email doesn't qualify. Outside the 30-day completion allowance, a provider who isn't recredentialed within 36 months gets scored down at audit.
What are you supposed to be doing between recredentialing cycles?
Ongoing monitoring is required, not optional. You track sanctions, license actions, and complaints across the whole roster, and you act on whatever turns up at the point you find it. A three-year gap with nothing in between doesn't meet the standard, even when every cycle itself closes on time.
Never miss a re-credentialing deadline. See how we automate the process.



