Does IEC 62443 Require Penetration Testing for UK Water Company OT Systems?

Does IEC 62443 Require Penetration Testing for UK Water Company OT Systems?

By EJN Labs · 13 Aug 2026 · 8 min read

Not by law. IEC 62443 is a voluntary international standard, so no UK water company is legally forced to pen test under it. But it is a direct OT security testing framework: its security levels are defined against attacker capability, and proving a zone actually meets its target level means technical testing. Typical engagements run 4 to 9 days, £4,400 to £12,600 at UK day rates of £1,100 to £1,400.

Where IEC 62443 penetration testing fits for UK water companies

IEC 62443 penetration testing occupies a different position from most compliance-driven testing. The IEC 62443 series for industrial automation and control systems security is voluntary in itself: no UK statute names it. Yet across energy, water and other OT-heavy sectors it has become the default language for describing how secure a control environment should be, and unusually, security assessment and testing are built into its design rather than bolted on as an audit afterthought.

This post is for OT security leads, engineering directors, CISOs and asset managers in UK water companies weighing what testing the standard actually expects.

Why IEC 62443 matters for water company OT

UK water undertakers already sit under mandatory security and resilience regimes, and the direction of travel is towards evidence rather than assertion. IEC 62443 gives that evidence a structure: which parts of the estate are protected to which level, against what sort of adversary.

The estates make this hard. A typical water company runs decades-old telemetry and SCADA alongside cloud analytics, hundreds of unmanned outstations, vendor remote maintenance connections, and an IT network that touches the operational one somewhere. IEC 62443 responds by carving the estate into zones and conduits, each with a target security level. That model is only as good as the boundaries it draws, and paper boundaries leak.

What IEC 62443 actually says about testing

IEC 62443 does not contain a line that says “commission an annual penetration test”. It is a family of standards covering four areas: the asset owner’s security programme, risk assessment and zoning, system-level security requirements, and secure product development for suppliers.

Its UK status is voluntary, contractual, or regulator evidence of good practice under regimes such as UK NIS.

What the standard does do, more directly than almost any other framework, is make technical verification unavoidable. Its security levels, SL1 to SL4, are defined by the capability of attacker each level must resist, from casual misuse up to well-resourced adversaries. Declaring that a treatment works control zone meets a target level is a claim about how it withstands attack, and no document review can substantiate that; someone competent has to attempt the attack under controlled conditions. That is why the series reads as a direct OT security assessment and testing framework.

The same logic reaches the supply chain. SCADA suppliers, OT integrators, remote maintenance providers and equipment vendors selling into water companies face IEC 62443-shaped procurement questions: what security level the product supports, and what testing sits behind that statement.

What to test in an IEC 62443-aligned water estate

Zone and conduit boundaries

The central claim in any IEC 62443 architecture is that zones are separated and traffic flows only through defined conduits. Testing this means an assumed-breach start in a lower-trust zone, usually corporate IT, then attempting to pivot into control zones through historians, jump servers, shared directory services, dual-homed engineering workstations and permissive firewall rules. Every path found is a conduit you did not know you had.

External perimeter and remote access

Most real OT intrusions start on the internet-facing edge: VPN concentrators, engineer remote access, vendor support gateways and exposed telemetry management interfaces. An external infrastructure penetration test attacks this surface first, because one weak remote access route can put an attacker a hop from a zone that assumed they could never get there.

SCADA, telemetry and outstations

Control components are assessed carefully rather than aggressively: architecture and configuration review against the zone’s target level, credential and protocol weaknesses, and safe verification of what an attacker who reached the zone could do. Unmanned outstations deserve attention because they pair physical exposure with network trust back to the core.

Cloud platforms and data APIs

Modern water estates push telemetry into cloud analytics and smart network platforms, which quietly become conduits in their own right. Cloud penetration testing and API testing cover the identity, storage and interface layer that carries operational data out of the estate and, sometimes, commands back into it.

How an IEC 62443-driven engagement runs

Testing live water infrastructure is nothing like testing a web application:

  1. Scoping against your zone model. We start from your zone and conduit diagram and target security levels, then agree which claims each phase will evidence and which systems are observe-only.
  2. Safety and change control. Testing windows, named engineering contacts, and written stop conditions. Active exploitation stays on IT and perimeter layers; OT verification is passive or on reference and standby systems.
  3. Testing. External perimeter first, then assumed-breach work against zone boundaries, then the agreed OT, telemetry, cloud and API scope.
  4. Reporting mapped to your architecture. Findings are ranked by realistic impact on continuity of supply, each stating which zone boundary or security level claim it undermines.
  5. Retesting. Fixed findings are verified to close the evidence chain.

If you are preparing internally first, our penetration testing checklist covers the groundwork that makes the testing window far more productive.

What it costs and how scope drives the price

Penetration testing in the UK is priced by effort. Day rates for CREST-accredited work typically run £1,100 to £1,400, and days are set by scope: how many zones and conduits are in play, the size of the external estate, and how much OT verification is agreed. Typical ranges:

EngagementTypical effortTypical cost
External infrastructure and remote access4 to 6 days£4,400 to £8,400
Assumed-breach zone and conduit boundary test6 to 9 days£6,600 to £12,600
Cloud platform and telemetry API assessment5 to 8 days£5,500 to £11,200
Combined estate programme across an assessment cycle10 to 15 days£11,000 to £21,000

These are typical UK ranges, not quotes; an exact price follows a short scoping call. Our guide to penetration testing costs in the UK breaks down the drivers. For budget holders: sequence testing zone by zone in order of consequence to supply.

How EJN Labs approaches IEC 62443 testing for water companies

EJN Labs is a UK firm delivering CREST-accredited penetration testing with UK-based testers, and we hold Cyber Essentials Plus and ISO 27001 ourselves. When we scope a mixed IT and OT water estate, we begin with a joint walkthrough of your zone and conduit model with your engineering team, agree written rules of engagement naming every system where active testing is permitted, and route anything process-critical to passive analysis or standby equipment. Our reports state, per finding, which boundary or security level claim it undermines: exactly the shape IEC 62443 evidence needs.

We work with undertakers and with the SCADA suppliers, integrators and remote maintenance providers who need testing evidence to keep water sector contracts. If you are comparing firms, our guide to the best UK penetration testing provider sets out the questions worth asking any bidder.

Frequently Asked Questions

Does IEC 62443 require penetration testing?

Not as a legal mandate. IEC 62443 is a voluntary IEC standard, binding only where contracts or regulators make it so. Its security levels are defined by the attacker capability each zone must resist, though, so meeting a target level has to be demonstrated through technical assessment and testing.

In practice, penetration testing is how security level claims are evidenced rather than merely asserted.

What does IEC 62443 penetration testing cost?

Expect £4,400 to £8,400 for an external infrastructure and remote access test, based on UK day rates of £1,100 to £1,400 and 4 to 6 days of effort. Broader scopes cost more, and an exact price follows a scoping call because scope drives the day count.

An assumed-breach zone and conduit boundary test typically runs 6 to 9 days (£6,600 to £12,600), while a combined estate programme runs 10 to 15 days (£11,000 to £21,000).

Is it safe to test live SCADA and treatment systems?

Yes, live SCADA and treatment systems can be tested safely when scoped properly. Active exploitation is confined to IT and perimeter layers under agreed windows and change control, while control system components are assessed through passive, non-disruptive methods rather than direct attack.

That assessment combines passive analysis, configuration review and testing on reference or standby equipment, with named engineering contacts and written stop conditions agreed before anything starts. The goal is evidence for your security level claims, never disruption to supply.

Is IEC 62443 mandatory for UK water companies?

No, IEC 62443 is not mandatory for UK water companies. It is a voluntary international standard with no direct legal force in the UK, becoming binding only through contracts, though it is widely used as evidence of good practice towards regulators under regimes that do bind water undertakers.

UK NIS is the main example of such a regime. Many water companies adopt IEC 62443 precisely because it turns vague security duties into a structured, assessable architecture.

How do IEC 62443 security levels shape the test?

Security levels SL1 to SL4 set the intensity and technique of the test, because each level describes the sophistication of attacker a zone must withstand. The higher the target level, the more capable the adversary model the testers apply to that zone.

In practice, a zone targeting a modest level is checked against opportunistic attack paths, while a zone protecting process control is tested against a capable, deliberate adversary model, including pivoting from adjacent zones and abuse of legitimate remote access routes.

Get an OT testing quote for your water estate

If you own the zone model in an IEC 62443 programme and need testing evidence behind its security level claims, tell us about your estate through our quote form and we will come back with a scoped, day-rate priced proposal from a CREST-accredited firm with UK-based testers.

Leave a Reply

Your email address will not be published. Required fields are marked *