office@safebyte.io București, România ISO 27001:2023 · ISO 9001:2023
Research

OT/SCADA — Global Security Standards and Audit & Testing Requirements

A power plant operator in Romania, a gas pipeline company in Texas and a refinery in Saudi Arabia share the same problem: they need to prove their industrial control systems are secure. But each answers to a different regulatory framework, with different audit requirements, different testing frequencies and different penalties for non-compliance.

This study maps the relevant OT/SCADA security standards worldwide, focusing on what each framework specifically requires in terms of audits, penetration testing and vulnerability assessments. It is not an implementation guide — it is a navigation chart for security and compliance teams operating across multiple jurisdictions.

The international baseline: IEC 62443

Before discussing regional regulations, it is worth establishing the reference point. The IEC 62443 series, developed by ISA (International Society of Automation) and adopted by IEC, is the only set of standards dedicated exclusively to the security of Industrial Automation and Control Systems (IACS).

The series covers the entire ecosystem through four categories of documents:

  • IEC 62443-2-1 — security program requirements for asset owners. Defines what the organisation operating the system must do: policies, procedures, risk assessments, patch management, incident response.
  • IEC 62443-2-4 — requirements for integration and maintenance service providers. Directly relevant to firms performing security assessments: it defines the competencies, procedures and measures that integrators must follow.
  • IEC 62443-3-3 — system-level security requirements, organised by Security Levels (SL 1–4). Each level corresponds to a threat profile: SL 1 protects against accidental access, SL 2 against attackers with limited resources, SL 3 against sophisticated attackers with moderate resources, and SL 4 against state-level actors with extensive resources.
  • IEC 62443-4-2 — technical security requirements for individual components (PLCs, RTUs, SCADA software, network devices).

The standard defines seven Foundational Requirements (FR): Identification and Authentication Control (FR 1), Use Control (FR 2), System Integrity (FR 3), Data Confidentiality (FR 4), Restricted Data Flow (FR 5), Timely Response to Events (FR 6) and Resource Availability (FR 7).

Penetration testing in IEC 62443: the standard does not explicitly mandate penetration testing, but strongly implies it. IEC 62443-4-1 (secure development lifecycle) requires product security testing, including functional security testing. In practice, ISASecure certification (the certification programme based on IEC 62443) includes communication robustness testing and vulnerability assessments.

IEC 62443 certification is conducted through bodies such as ISASecure (the ISCI programme) and TÜV, with evaluations of products (62443-4-2), development processes (62443-4-1) and systems (62443-3-3).

Europe

NIS2 Directive (EU 2022/2555)

The NIS2 Directive, adopted in January 2023 with a transposition deadline of October 2024, is the centrepiece of European cybersecurity legislation. Compared to NIS1, it significantly expands scope: covered sectors include energy, transport, health, drinking water, wastewater, digital infrastructure, public administration, space, food production, waste management, chemicals, pharmaceutical manufacturing and distribution, and manufacturing of critical equipment.

Entities are classified as essential or important, with similar requirements but different supervisory regimes. Essential entities are subject to proactive supervision (audits, inspections), while important entities face reactive supervision (triggered by reports or incidents).

Testing-relevant requirements:

  • Article 21 mandates technical, operational and organisational measures based on an “all-hazards” approach, including: risk analysis policies, incident handling, business continuity, supply chain security, security in system acquisition and development, assessment of the effectiveness of cybersecurity risk management measures, and basic cyber hygiene practices.
  • The effectiveness assessment wording implies auditing and periodic testing, although the directive does not explicitly prescribe “penetration testing” as a term. National transpositions and ENISA implementing acts provide further detail.
  • Incident reporting: initial alert within 24 hours, notification within 72 hours, final report within one month.

Penalties: up to EUR 10 million or 2% of annual global turnover for essential entities; up to EUR 7 million or 1.4% for important entities. Personal liability for senior management is explicitly provided for.

Germany — BSI and IT-Sicherheitsgesetz 2.0

Germany has transposed NIS2 and operates its own framework through the Federal Office for Information Security (BSI). Critical infrastructure operators (KRITIS) have specific obligations:

  • Mandatory audit every two years under §8a BSIG (BSI Act). Auditors must be BSI-approved.
  • BSI publishes the ICS-Security-Kompendium, a reference guide for securing industrial systems, and IT-Grundschutz, a comprehensive security framework with dedicated ICS/SCADA modules.
  • IT-Sicherheitsgesetz 2.0 (2021) expanded KRITIS requirements and introduced obligations for “entities of special public interest” (UBI — Unternehmen im besonderen öffentlichen Interesse).
  • Incident reporting to BSI is mandatory for KRITIS operators.

France — ANSSI and OIV

France implemented a strict regime as early as 2013 through the Military Programming Law (LPM), which defined Operators of Vital Importance (OIV). ANSSI (Agence Nationale de la Sécurité des Systèmes d’Information) sets security requirements for OIV:

  • Mandatory security audits, performed by PASSI-qualified providers (Prestataires d’Audit de la Sécurité des Systèmes d’Information).
  • ANSSI has published specific guidelines for industrial system security, including recommendations for OT network segmentation.
  • Security testing for OIV is mandatory — PASSI qualification includes intrusive testing competency.

United Kingdom — NIS Regulations and NCSC CAF

Post-Brexit, the UK maintains its own NIS Regulations (2018), implemented separately from the EU directive. The NCSC (National Cyber Security Centre) developed the Cyber Assessment Framework (CAF), an evaluation framework based on 14 security principles organised into four objectives: managing security risk, protecting against cyber attack, detecting cybersecurity events and minimising the impact of incidents.

Operators of Essential Services (OES) are assessed periodically by competent authorities (Ofgem for energy, Ofwat for water, etc.) using CAF as the reference. Penetration testing is not explicitly prescribed as a separate requirement, but is implied by Principle B4 (security testing and assessment).

ENISA — EU-level guidance

The European Union Agency for Cybersecurity (ENISA) publishes technical guidelines for ICS/SCADA security. Key documents include:

  • ICS SCADA Good Practices for the Energy Sector — practical security recommendations.
  • Good Practices for Security of Internet of Things in the context of Smart Manufacturing — relevant for IT/OT convergence.
  • ENISA does not impose mandatory requirements, but its guidance informs national NIS2 transpositions.

United States

NERC CIP (Critical Infrastructure Protection)

NERC CIP standards are the most rigorous mandatory cybersecurity requirements in the US, applied to the Bulk Electric System (BES). NERC (North American Electric Reliability Corporation) issues the standards, while FERC (Federal Energy Regulatory Commission) approves them and enforces penalties.

CIP standards relevant to testing and auditing:

  • CIP-005 (Electronic Security Perimeters) — defines requirements for electronic security perimeters, including network traffic control at security zone boundaries.
  • CIP-007 (System Security Management) — requirements for system security management, including port and service management, patch management and malicious code protection.
  • CIP-010 (Configuration Change Management and Vulnerability Assessments) — Requirement R3 mandates vulnerability assessments at least once every 15 calendar months for high and medium impact BES Cyber Systems. The assessment must identify, evaluate and address vulnerabilities.
  • CIP-003 (Security Management Controls) — requirements for organisational-level cybersecurity policies.

Penetration testing in NERC CIP: CIP standards do not explicitly mandate penetration testing. CIP-010 R3 requires “vulnerability assessments,” which include configuration review, vulnerability scanning and documentation review. Active penetration testing is not mentioned as a requirement, although NERC has published guidance recommending it as a supplementary practice.

Penalties: FERC can impose penalties exceeding USD 1 million per violation, per day. The exact amount depends on severity, violation duration and entity size.

Audit cycle: entities are audited based on a CMEP (Compliance Monitoring and Enforcement Program) monitoring plan, which includes periodic audits, investigations on referral and self-reporting.

NIST SP 800-82 (Guide to OT Security)

NIST SP 800-82 Revision 3, published in September 2023 under the title Guide to Operational Technology (OT) Security, is the US federal government’s reference guide for OT security. It is not a mandatory regulation but guidance; however, it becomes de facto mandatory when referenced by other regulations.

Key aspects:

  • Complete mapping to NIST SP 800-53 Rev. 5 controls, with tailoring recommendations for OT environments.
  • The guide explicitly acknowledges the tension between availability (the top priority in OT) and confidentiality (the top priority in IT), and provides adapted recommendations.
  • Penetration testing is recommended, but with significant caveats: testing must be planned to avoid disrupting physical processes, should be performed on test systems or during maintenance windows, and teams must understand industrial protocols (Modbus, DNP3, OPC, etc.).
  • Recommends regular vulnerability assessments and security testing as part of an ongoing risk management programme.

NIST Cybersecurity Framework (CSF) 2.0

CSF 2.0, published in February 2024, applies to all sectors including OT. Compared to version 1.1, it adds a new function — Govern — and explicitly extends scope beyond critical infrastructure to any organisation.

CSF 2.0 does not prescribe penetration testing, but the Identify function (ID.RA — Risk Assessment) and the Protect function (PR.IR — Incident Response) imply periodic security assessments.

TSA Security Directives (oil and gas pipelines)

Following the Colonial Pipeline ransomware attack (May 2021), TSA (Transportation Security Administration) issued mandatory security directives for TSA-designated pipeline operators:

  • SD Pipeline-2021-01 (May 2021) — mandates reporting cybersecurity incidents to CISA, designating a cybersecurity coordinator and reviewing current practices.
  • SD Pipeline-2021-02 (July 2021, revised as 02C, 02D) — requires implementation of a cybersecurity implementation plan, including specific measures for network segmentation, access control, continuous monitoring and incident response planning and testing.

TSA directives do not explicitly mention “penetration testing,” but requirements to assess the effectiveness of security architecture imply active testing. TSA references API 1164 and NIST CSF as baseline standards.

CISA — role and resources

CISA (Cybersecurity and Infrastructure Security Agency) serves as the coordinating authority for ICS/OT security at the federal level:

  • ICS Advisories — CISA publishes weekly security advisories for ICS products, with technical details on vulnerabilities and mitigations.
  • CSET (Cybersecurity Evaluation Tool) — a free self-assessment tool based on security standards (IEC 62443, NIST, NERC CIP).
  • VADR (Validated Architecture Design Review) — a free OT security architecture assessment service offered to critical infrastructure operators.
  • Cross-Sector Cybersecurity Performance Goals (CPGs) — recommended, not mandatory, performance objectives.

NRC 10 CFR 73.54 (nuclear sector)

The Nuclear Regulatory Commission’s rule 10 CFR 73.54 requires US nuclear power plants to implement cybersecurity programmes for digital systems that perform safety, security and emergency preparedness functions.

  • Implementation follows the NEI 08-09 guideline, endorsed by NRC.
  • Nuclear plants must maintain a defence-in-depth approach with complete isolation of safety networks.
  • Security assessments are part of the cybersecurity programme, and NRC conducts periodic inspections.
  • Penetration testing of nuclear safety systems is a sensitive matter: it must be strictly coordinated to avoid any impact on safety functions.

CFATS (Chemical Facility Anti-Terrorism Standards)

CFATS, administered by DHS/CISA, expired in July 2023 after Congress failed to reauthorise the programme. Before expiry, CFATS required high-risk chemical facilities to develop and implement security plans (Site Security Plans — SSPs) validated against Risk-Based Performance Standards (RBPS). RBPS 8 specifically addressed cybersecurity. The programme has not been formally replaced, leaving a regulatory gap for the US chemical sector.

Asia-Pacific

Australia — SOCI Act and AESCSF

The Security of Critical Infrastructure Act 2018 (SOCI), significantly amended in 2021-2022, covers 11 critical infrastructure sectors, expanded from four in the original version. Key obligations:

  • CIRMP (Critical Infrastructure Risk Management Program) — the risk management programme, mandatory for designated entities. Includes requirements for identifying material risks, implementing mitigation measures and annual reporting.
  • Incident reporting is mandatory: critical incidents within 12 hours, other significant incidents within 72 hours.
  • Penetration testing is not explicitly prescribed, but is implied by the obligation to manage cyber security risks.

AESCSF (Australian Energy Sector Cyber Security Framework), developed by AEMO (Australian Energy Market Operator), is a voluntary framework based on a maturity model. Participation in the annual AESCSF assessment is recommended, and the framework includes references to security testing as part of maturity evaluation.

Singapore — CCoP for CII

Singapore operates one of the most prescriptive OT security frameworks in Asia. The Cybersecurity Act 2018 designates Critical Information Infrastructure (CII) sectors: energy, water, transport, healthcare, telecommunications, media, government, banking and finance, aviation, maritime and security.

Cybersecurity Code of Practice (CCoP) for CII, issued by CSA (Cyber Security Agency of Singapore):

  • Mandatory security audits of CII systems, conducted by approved auditors.
  • Mandatory penetration testing — CCoP is one of the few regulatory frameworks that explicitly mandates periodic penetration testing of CII systems.
  • Incident reporting within a short timeframe.
  • Penalties under the Cybersecurity Act: fines of up to SGD 100,000 for non-compliance.

Singapore has also launched an OT Cybersecurity Masterplan, with additional guidance for IT/OT convergence security in industrial environments.

Japan — METI CPSF

The Cyber/Physical Security Framework (CPSF), published by METI (Ministry of Economy, Trade and Industry) in 2019, addresses security in the context of “Society 5.0” — the convergence of cyberspace with physical space. The framework is based on three layers: the physical space, the cyber-physical connection and cyberspace.

  • CPSF is a voluntary framework, not a mandatory regulation.
  • Japan defines 14 critical infrastructure sectors under the basic policy of NISC (National center of Incident readiness and Strategy for Cybersecurity).
  • JPCERT/CC provides ICS vulnerability coordination services and publishes security advisories.
  • Individual sectors (electricity, gas) have their own guidelines issued by sector regulators.
  • Penetration testing is not legislatively mandatory, but is recommended in METI guidelines.

South Korea

The Act on the Protection of Information and Communications Infrastructure designates critical information infrastructure systems and requires:

  • Mandatory vulnerability assessments (at least annually) for designated systems.
  • KISA (Korea Internet & Security Agency) publishes ICS security guidelines, though these are predominantly advisory.
  • K-ISMS (Korea Information Security Management System) — certification is mandatory for certain entities and includes vulnerability assessment requirements.

India — NCIIPC and CERT-In

NCIIPC (National Critical Information Infrastructure Protection Centre), subordinate to NTRO, is the designated authority for critical information infrastructure protection in India. Covered sectors include energy, transport, telecommunications, finance and banking, government and strategic defence.

  • Section 70 of the IT Act 2000 defines “Protected Systems” and penalises unauthorised access.
  • NCIIPC issues security guidelines and responsibilities, including recommendations for vulnerability assessments.
  • CERT-In (Indian Computer Emergency Response Team) issued a 2022 directive mandating cybersecurity incident reporting within 6 hours — one of the shortest reporting windows in the world.
  • CEA (Central Electricity Authority) published in 2021 the Cyber Security in Power Sector Guidelines, with specific requirements for the energy sector, including periodic cybersecurity audits.

New Zealand

NZISM (New Zealand Information Security Manual), issued by GCSB/NCSC, applies primarily to government agencies. There is no legislation dedicated solely to critical infrastructure cybersecurity, although legislative reform is underway. NCSC publishes advisories and guidance for critical sectors, but requirements are not as prescriptive as in Australia.

Middle East

Saudi Arabia — NCA OTCC

OT Cybersecurity Controls (OTCC), issued by the NCA (National Cybersecurity Authority), are a mandatory framework for organisations operating OT/ICS systems in Saudi Arabia. OTCC builds on and extends the NCA’s ECC (Essential Cybersecurity Controls).

  • OTCC covers SCADA, DCS, PLC, RTU, SIS and other industrial automation systems.
  • The framework includes specific controls for vulnerability assessments and mandatory penetration testing.
  • Organisations must demonstrate compliance through periodic assessments.
  • NCA conducts compliance checks and can impose sanctions, although specific fine amounts are not publicly disclosed.
  • Controls are structured across multiple domains, including governance, protection, resilience and third-party management.

United Arab Emirates

The UAE operates a multi-layered regulatory landscape:

  • At the federal level, the Telecommunications and Digital Government Regulatory Authority (TDRA) — formerly TRA/NESA — coordinates cybersecurity.
  • Abu Dhabi: ADDA (Abu Dhabi Digital Authority, formerly ADSIC) imposes security requirements on government entities.
  • Dubai: DESC (Dubai Electronic Security Center) / DCSA issues standards for Dubai-based entities.
  • The oil and gas sector has additional requirements through ADNOC and other sectoral entities.
  • Requirements include security audits and vulnerability assessments; penetration testing is generally recommended or mandatory depending on the specific sector and emirate.

Qatar

The National Information Assurance Policy (NIA), issued by NCSA (National Cyber Security Agency, under MOI authority), is the primary cybersecurity framework:

  • Applicable to government entities and critical infrastructure operators.
  • Includes requirements for security assessments and vulnerability testing.
  • Penetration testing is recommended as part of periodic security evaluations.

Cross-cutting standards

ISO 27001 / ISO 27019 applied to OT environments

ISO 27001:2022 (Information Security Management Systems) is the most widely adopted international security standard. Certification involves:

  • A 3-year certification cycle, with annual surveillance audits (in years 1 and 2 after initial certification).
  • The audit has two stages: Stage 1 (documentation review) and Stage 2 (on-site audit).
  • Annex A control A.8.8 (Management of Technical Vulnerabilities) requires identifying, evaluating and treating vulnerabilities. Penetration testing is not explicitly required, but is widely practised as a method for assessing control effectiveness.

ISO 27019 (Information security controls for the energy utility industry) extends ISO 27002 with controls specific to process control systems in the energy sector. It is not independently certifiable — it is used alongside ISO 27001 as a supplementary reference.

API 1164 (Pipeline SCADA Security)

API Standard 1164 (Pipeline Control Systems Cybersecurity), issued by the American Petroleum Institute, covers cybersecurity for oil and gas pipeline control systems.

  • The 3rd edition, published in 2021, was aligned with NIST CSF and includes significantly expanded requirements compared to the previous edition.
  • API 1164 recommends vulnerability assessments and security testing as part of the risk management programme.
  • The standard gained practical importance after the 2021 TSA directives, which reference it as a baseline standard. Although API 1164 is voluntary, compliance with TSA directives (which invoke it) is mandatory for designated operators.

The landscape is converging, but not uniform

Several cross-cutting observations:

Penetration testing is rarely mandatory by law. Of all frameworks analysed, only Singapore (CCoP) and Saudi Arabia (OTCC) explicitly mandate penetration testing. NERC CIP requires vulnerability assessments, not penetration tests. NIS2 and SOCI imply testing without naming it. ISO 27001 recommends it without prescribing it. France (through PASSI/LPM) mandates it for OIV.

Audit frequency varies significantly. Germany mandates audits every two years for KRITIS. NERC CIP requires vulnerability assessments every 15 months. Singapore mandates annual audits. ISO 27001 has a 3-year cycle with annual surveillance.

Penalties reflect framework maturity. NIS2 provides for fines calculated as a percentage of turnover (the GDPR model). NERC CIP applies per-violation per-day penalties. Many frameworks in Asia and the Middle East have less transparent penalty structures.

IEC 62443 is becoming the lingua franca. Regardless of jurisdiction, IEC 62443 is referenced as the technical baseline standard in NIS2, in TSA directives, in the Saudi OTCC and in CISA guidance. An organisation that implements IEC 62443 covers a significant portion of any regional framework’s requirements.

IT/OT convergence is forcing regulatory updates. Older frameworks (NERC CIP, NRC 10 CFR 73.54) were designed for isolated OT networks. Newer frameworks (NIS2, SOCI, TSA Security Directives) reflect the reality of interconnection and impose monitoring and detection requirements that presuppose cross-domain visibility.

The CFATS expiration leaves a gap. The US chemical sector no longer has a mandatory federal cybersecurity framework after CFATS expired in July 2023 — an unresolved systemic risk.


This study reflects the situation at the date of publication. Regulatory frameworks are updated frequently — always verify current standard versions with the issuing authorities. SafeByte Consulting provides OT/SCADA security assessments and compliance support for organisations operating under any of the frameworks presented.

← Back to blog