ISO 9001 Cyber Schedules: When Manufacturers Face Penetration Testing Clauses

ISO 9001 Cyber Schedules: When Manufacturers Face Penetration Testing Clauses

By EJN Labs · 26 Aug 2026 · 8 min read

ISO 9001 does not require penetration testing. It is a quality management standard and contains no cyber security clauses. The requirement almost always arrives through a customer cyber schedule bolted onto your supply contract, which asks for independent testing evidence. Most UK manufacturers meet a typical schedule with a 4 to 6 day engagement costing £4,400 to £8,400 at day rates of £1,100 to £1,400.

Why ISO 9001 cyber schedules are pushing manufacturers towards penetration testing

Cyber schedules are pushing manufacturers towards testing because the demand comes from customers, not the standard. ISO 9001 says nothing about cyber security and does not mandate a penetration test, yet supplier questionnaires and contract renewals mention both in the same breath.

If you are searching for ISO 9001 cyber schedules penetration testing requirements, you have probably just received one of those documents. Thousands of UK manufacturers, food producers, construction firms and property organisations hold ISO 9001 certification.

What has changed is buyer behaviour. Large customers, particularly in automotive, aerospace, food retail and construction, now attach cyber schedules to their supply agreements. These sit alongside the quality requirements your certificate satisfies and add separate security obligations: patching commitments, incident notification windows, minimum controls, and increasingly a clause requiring independent security testing of the systems that touch the buyer’s data or production schedule.

The result is that manufacturers who have never bought penetration testing suddenly face a contractual deadline for it.

The contractual driver: what a cyber schedule actually asks for

Let us be precise about the source of the requirement, because it changes how you respond. ISO 9001 is published by ISO and certification is voluntary. Nothing in the standard requires security testing, and no ISO 9001 auditor will ask for a penetration test report.

The real driver is the cyber schedule itself: a contractual annex written by the buyer’s procurement and security teams. These vary widely, but the testing clauses we see in UK manufacturing supply chains usually fall into three patterns:

  • A requirement for annual independent penetration testing of internet-facing systems, with a summary report or attestation letter shared on request.
  • A requirement to test any system that processes the buyer’s data, designs or order information, which can pull ERP portals, EDI connections and shared cloud environments into scope.
  • A softer requirement for “regular vulnerability assessment”, which a well-scoped penetration test satisfies comfortably and a bare automated scan often does not.

Because the obligation is contractual rather than regulatory, the buyer decides what counts as acceptable evidence. In practice, UK buyers respond well to a report from a CREST-accredited firm, because CREST accreditation gives their security team an externally verified benchmark for methodology and tester competence without having to audit your supplier themselves.

What to test in a manufacturing estate

Manufacturers are not typical office-based businesses, and copying a generic scope wastes budget. The systems a buyer’s cyber schedule cares about are the ones that connect your operation to theirs. In our experience scoping manufacturing engagements, four areas come up repeatedly.

External infrastructure and remote access

Your internet-facing perimeter is the minimum viable scope for almost every cyber schedule: VPN endpoints, remote support gateways used by machine vendors, firewalls and any exposed services. This is where most real-world manufacturing breaches begin, and it is the first thing a buyer’s security team will ask about. See our external infrastructure penetration testing service for what this covers.

Customer-facing portals and EDI

Order portals, supplier extranets and EDI or API integrations carry the buyer’s own data, so schedules frequently name them explicitly. If your customers place orders or exchange design files through an API, an API penetration test against that integration is usually the single most persuasive piece of evidence you can produce.

ERP and cloud environments

Production planning, stock and despatch increasingly run in Azure or AWS hosted ERP. A configuration-focused cloud penetration test checks the identity, storage and network settings that a perimeter test cannot see.

The IT and OT boundary

Few cyber schedules demand testing of production machinery itself, and testing live OT carries operational risk. What buyers do want to know is whether a compromise of your office network can reach the shop floor. A controlled assessment of the segmentation between IT and OT networks answers that question without touching a single PLC. When we scope this kind of work, we test from the IT side against the boundary, agree a strict exclusion list of production assets with your operations team first, and schedule sensitive work around production windows.

How an engagement runs

A manufacturing engagement follows a predictable path, starting with scoping: a short call to map the systems named in your cyber schedule to a concrete asset list, agree what is excluded, and confirm testing windows that avoid production-critical periods such as month-end despatch.

You receive a fixed quote based on days of effort, not a percentage of turnover.

Testing itself typically takes between two and nine days depending on scope. UK-based testers work through the agreed assets, validating every finding manually so the report you hand to your customer contains exploitable issues, not scanner noise. Reporting follows within a few days: an executive summary written for your buyer’s procurement team, technical detail for whoever fixes the findings, and a remediation retest so you can evidence closure. Our penetration testing checklist walks through how to prepare before day one.

What it costs and how scope drives the price

UK penetration testing is priced by days of effort at a day rate, typically £1,100 to £1,400 for a CREST-accredited firm. The scope your cyber schedule demands is what moves the number. Typical ranges for manufacturers:

ScopeTypical effortTypical UK cost
External infrastructure only2 to 3 days£2,200 to £4,200
External plus customer portal or API4 to 6 days£4,400 to £8,400
External, application and cloud ERP review6 to 9 days£6,600 to £12,600

Most manufacturers responding to a first cyber schedule land in the middle band: a 4 to 6 day engagement at £4,400 to £8,400 covering the perimeter and the systems that hold customer data. For a fuller breakdown of what drives these numbers, see our guide to penetration testing cost in the UK. Exact pricing depends on your asset list, so the fastest route to a firm figure is our quote form.

How EJN Labs approaches cyber schedule testing for manufacturers

EJN Labs is a UK-based, CREST-accredited penetration testing firm, certified to ISO 27001 and ISO 9001 ourselves, so we understand both sides of the paperwork you are being asked to produce. When a manufacturer brings us a cyber schedule, we start by reading the schedule, not by selling a package. We map each testing clause to the smallest scope that genuinely satisfies it, flag clauses that need clarification with your customer before money is spent, and write the report so that a buyer’s security team can sign it off without a follow-up call.

All testing is delivered by UK-based testers, findings are manually validated, and every engagement includes a free remediation retest. If you are comparing suppliers, our guide to choosing the best UK penetration testing provider sets out the questions worth asking any firm, including us.

Frequently Asked Questions

Does ISO 9001 require penetration testing?

No. ISO 9001 is a quality management standard and contains no cyber security or penetration testing requirements. The obligation manufacturers encounter comes from customer cyber schedules attached to supply contracts, which sit alongside quality requirements and ask for independent security testing evidence.

Check the wording of your contract annex, not the ISO standard, to understand exactly what you must provide.

What does penetration testing for a manufacturer cost?

Expect £1,100 to £1,400 per day for a CREST-accredited firm. An external infrastructure test takes 2 to 3 days, so £2,200 to £4,200, and most manufacturers meeting a customer cyber schedule need 4 to 6 days covering the perimeter plus a portal or API, which is £4,400 to £8,400.

Wider scopes including cloud ERP run 6 to 9 days, £6,600 to £12,600.

What evidence will my customer accept?

Most UK buyers accept an executive summary or attestation letter from a CREST-accredited firm confirming the scope, dates, methodology and that findings were remediated. Because a cyber schedule is contractual, your customer defines acceptable evidence, so ask your contact which format their security team expects.

Few buyers demand the full technical report, and you should not hand one over by default, since it details your weaknesses.

Will testing disrupt production?

Not if scoped properly. Cyber schedules focus on IT systems, portals and internet-facing infrastructure, none of which requires touching production machinery. Where segmentation between IT and OT networks is in scope, testing runs from the IT side against an agreed exclusion list of production assets, with sensitive work scheduled around production windows. Live OT equipment is only ever assessed with explicit agreement and tight controls.

How often do cyber schedules require testing?

Annual testing is the most common contractual requirement, often with an added obligation to retest after significant changes such as a new customer portal, an ERP migration or a change of hosting. One well-scoped report can usually satisfy several cyber schedules at once.

If you supply several large customers, align the scopes into one annual engagement rather than running separate tests per contract.

Turn your cyber schedule into a signed-off report

If a customer contract has landed a testing clause on your desk, send us the schedule and your rough asset list. We will map the clauses to a right-sized scope and return a fixed quote from UK-based testers at a CREST-accredited firm. Start with our penetration testing quote form and we will respond the same working day.

Leave a Reply

Your email address will not be published. Required fields are marked *