By EJN Labs · 24 Jul 2026 · 8 min read
Ofgem NIS penetration testing applies to designated operators of essential services in the downstream gas and electricity sector in Great Britain: large generators, network operators and suppliers that meet the thresholds in the NIS Regulations 2018. Ofgem is the competent authority for these operators, and the Cyber Assessment Framework it works from sets out technical testing proportionate to risk. Typical supporting penetration tests run £4,800 to £16,800 depending on scope.
Why Ofgem NIS matters for energy companies
Ofgem NIS matters because the Network and Information Systems Regulations 2018 are the UK’s legal framework for protecting essential services from cyber attack, energy sits at the top of the list, and serious failures carry penalties of up to £17 million.
If your organisation generates, transmits, distributes or supplies gas or electricity at scale in Great Britain, Ofgem is your competent authority under NIS.
The question we hear most from OT security leads, engineering directors and CISOs is a scoping one: are we actually in scope, and does Ofgem NIS require a penetration test? This post answers both honestly.
Which energy companies are in scope of Ofgem NIS?
Operators of essential services (OES) are in scope. In the downstream gas and electricity sector in Great Britain, an organisation becomes an OES either by meeting the designation thresholds set out in the Regulations or because the competent authority designates it directly as essential.
The thresholds are defined by scale, using measures such as generation capacity and the number of final customers supplied. The categories most likely to be in scope are:
- Large electricity generators whose capacity meets the threshold in the Regulations
- Electricity transmission and distribution network operators
- Gas transporters, including national and regional network operators
- Electricity and gas suppliers serving large numbers of final customers
- Interconnector operators and other infrastructure the competent authority designates as essential
If you are close to a threshold, do not assume you are out of scope. Designation can follow growth, acquisition or a change in the market, so confirm your status with Ofgem directly and document the answer. Suppliers to OES, such as OT integrators and SCADA vendors, are not themselves OES under NIS, but they increasingly inherit security and testing obligations through their customers’ contracts.
Does Ofgem NIS mandate a penetration test?
Here is the honest answer: the NIS Regulations do not contain a clause that says “carry out an annual penetration test”. They require OES to take appropriate and proportionate measures to manage risks to the network and information systems their essential service relies on.
Ofgem gives that duty shape through the NCSC Cyber Assessment Framework, the CAF, adapted for the energy sector. Operators self-assess against the CAF and Ofgem reviews the results, sets improvement expectations and can inspect. The CAF’s outcomes on security assurance and vulnerability management expect operators to identify weaknesses through methods proportionate to the risk, and for nationally significant infrastructure that bar is high. Independent penetration testing is one of the strongest forms of evidence an operator can present that its assessment reflects reality rather than paperwork, and the regulator can drive deeper technical assurance where the risk profile or an incident warrants it.
So the accurate framing is this: penetration testing is not named as a legal requirement, but for an in-scope energy OES it is the expected way to evidence several CAF outcomes, and a self-assessment with no technical testing behind it is unlikely to survive regulator scrutiny.
What to test in an energy estate
Energy operators run two worlds that meet in the middle: corporate IT and operational technology. Most real-world OT compromises start in IT and cross over, so scope should follow the attack path. The areas that matter most are:
- External infrastructure and remote access. Internet-facing systems, VPNs, jump hosts and vendor remote maintenance routes into OT. Our external infrastructure penetration testing targets exactly this perimeter.
- IT/OT segmentation. Testing whether the boundary between the corporate network and control networks actually holds, including firewall rules, data diodes and historian connections.
- Corporate IT and identity. Active Directory, Microsoft 365 and the credentials that, if stolen, would let an attacker pivot towards engineering systems.
- Cloud and APIs. Telemetry platforms, customer portals and market-facing integrations, covered by cloud penetration testing and API penetration testing.
- Scenario-based exercises. For mature operators, red teaming that simulates a capable adversary attempting to reach control systems, mapped to CAF outcomes.
A critical point on OT: live control systems are rarely tested with intrusive techniques. Good practice is to test aggressively up to the OT boundary, validate segmentation, and assess controllers and engineering workstations through passive analysis, configuration review or testing against offline and replica environments. Our penetration testing checklist walks through how to prepare scope decisions like these before an engagement starts.
How an Ofgem NIS engagement runs
An Ofgem NIS engagement follows a predictable arc: scoping, testing in agreed windows, reporting, then a retest of remediated findings to close the loop. Scoping maps the essential service and the systems it depends on, and aligns the exercise to the CAF outcomes you need to evidence.
We agree which networks can be tested directly and which need safe-approach methods. Testing runs with change-freeze awareness and a named contact on both sides, and reporting lands as two documents: a technical report your engineers can action, and findings mapped to CAF contributing outcomes your regulatory team can lift straight into the self-assessment.
What it costs and how scope drives the price
Penetration testing for energy operators is priced by effort, and effort follows scope. UK day rates for CREST-accredited testing typically run £1,200 to £1,400. Your exact price depends on estate size, remote access routes, and how much of the IT/OT boundary is in scope.
| Engagement | Typical effort | Typical UK cost |
|---|---|---|
| External infrastructure and remote access routes | 4 to 6 days | £4,800 to £8,400 |
| IT/OT segmentation and internal network testing | 6 to 9 days | £7,200 to £12,600 |
| Wider estate including cloud, APIs and identity | 8 to 12 days | £9,600 to £16,800 |
For how these figures compare across sectors, see our guide to penetration testing costs in the UK. The fastest route to an exact figure is our quote form.
How EJN Labs approaches Ofgem NIS penetration testing
EJN Labs is a UK-based, CREST-accredited penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, with all testing delivered by UK-based testers. That matters in a sector where network topology data is itself sensitive infrastructure information.
When we scope an energy estate, we start from the essential service and work outwards: which systems would interrupt supply if compromised, which routes reach them from the internet, and where the IT/OT boundary genuinely sits rather than where the diagram says it sits. We agree explicit rules of engagement for anything adjacent to control networks and use non-intrusive methods where availability risk is unacceptable. Findings are mapped to CAF outcomes so the report does double duty as engineering guidance and regulatory evidence. If you are comparing firms, our guide to choosing the best UK penetration testing provider sets out the questions worth asking, and our CREST penetration testing page explains what the accreditation guarantees.
Frequently Asked Questions
Does Ofgem NIS legally require a penetration test?
No clause in the NIS Regulations names penetration testing. The legal duty is to take appropriate and proportionate measures to manage risk, assessed by Ofgem through the Cyber Assessment Framework, and independent testing is how an energy OES is expected to evidence the relevant CAF outcomes.
Those outcomes cover security assurance and vulnerability management, and a self-assessment without technical testing behind it is unlikely to satisfy the regulator.
Which energy companies are in scope of the NIS Regulations?
Operators of essential services in the downstream gas and electricity sector in Great Britain are in scope: large generators, transmission and distribution network operators, gas transporters, interconnector operators and large suppliers that meet the designation thresholds set in the Regulations.
Ofgem can also designate operators below the thresholds where the service is judged essential. If you are near a threshold, confirm your status with Ofgem and document the answer.
What does Ofgem NIS penetration testing cost?
Expect £4,800 to £16,800 for Ofgem NIS penetration testing, based on UK day rates of £1,200 to £1,400 for CREST-accredited testing. The price depends on how much of the estate is in scope, from external infrastructure and remote access up to cloud, APIs and identity.
External infrastructure and remote access testing is typically 4 to 6 days, £4,800 to £8,400. IT/OT segmentation and internal testing is typically 6 to 9 days, £7,200 to £12,600. A wider estate including cloud, APIs and identity is typically 8 to 12 days, £9,600 to £16,800. Exact pricing comes from scoping.
Can penetration testing safely touch live OT systems?
Yes, with limits. Intrusive testing of live control systems is rarely appropriate. Good practice tests the perimeter and IT/OT segmentation with full intensity, then assesses controllers, historians and engineering workstations through passive traffic analysis, configuration review or offline and replica environments.
Clear rules of engagement, agreed testing windows and a named contact on both sides keep availability risk controlled throughout the engagement.
How often should an energy OES carry out penetration testing?
Test annually as the baseline, and again after significant change: new remote access routes, network re-architecture, major OT upgrades or an acquisition. A repeating testing cycle with tracked remediation is far stronger evidence for an operator of essential services than a single historic report.
The NIS risk-management duty is ongoing rather than point-in-time, so the cadence itself forms part of the evidence you present.
Evidence your CAF assessment with a scoped test
If you are an in-scope energy operator, or expect to be designated, the strongest next step is a scoped penetration test aligned to the CAF outcomes you need to evidence. Tell us about your estate through our CREST pentesting quote form and we will return a defined scope and fixed price from UK-based testers.




Leave a Reply