ONR SyAPs Evidence: What Penetration Testing Do Nuclear Site Inspectors Ask to See?

ONR SyAPs Evidence: What Penetration Testing Do Nuclear Site Inspectors Ask to See?

By EJN Labs · 24 Aug 2026 · 8 min read

ONR SyAPs does not name penetration testing in a prescriptive clause. It is an outcome-focused framework, and inspectors expect dutyholders to show risk-based technical testing of the systems that deliver nuclear security functions. In practice that means recent penetration test reports, remediation evidence and retest results. Nuclear-sector engagements typically run 5 to 8 days at £1,100 to £1,400 per day, £5,500 to £11,200.

Why ONR SyAPs penetration testing evidence matters at inspection

ONR SyAPs penetration testing evidence matters because inspectors do not accept assertions alone. They want to see that your security plan’s claims have been tested against a capable adversary, and that the results fed back into the plan. It is one of the most concrete things an inspector can ask for.

The Office for Nuclear Regulation does not hand dutyholders on UK nuclear licensed sites a checklist of controls. Its Security Assessment Principles (SyAPs) set outcomes, your security plan explains how you achieve them, and the cyber security and information assurance parts of that plan are where an inspector examines the claims.

That is why penetration testing sits so naturally inside a SyAPs regime even though the document never mandates it by name: a well-scoped test is the clearest independent evidence that your protective measures work as described.

The regulatory driver: SyAPs, NISR 2003 and outcome-focused regulation

The legal foundation is the Nuclear Industries Security Regulations 2003 (NISR 2003), which require dutyholders to maintain an approved security plan covering physical, personnel, transport and cyber security. SyAPs is the framework ONR inspectors use to judge whether that plan, and the arrangements behind it, are adequate. Compliance with the plan is a mandatory expectation for dutyholders, so the practical question is not whether SyAPs applies to you but what evidence satisfies it.

On the cyber side, SyAPs expects dutyholders to identify the systems important to nuclear security and safety, understand the threat, apply graded protection proportionate to the consequences of compromise, and assure themselves the protection actually works. That last expectation, assurance, is where technical testing lives. SyAPs is a direct technical-testing trigger: it never prescribes the word “penetration test”, but it is very difficult to demonstrate risk-based assurance of a modern IT and OT estate without one. If an inspector asks why you test, the honest answer should be “because our security plan claims these controls work and testing is how we prove it”, not “because a clause told us to”.

What penetration testing evidence do inspectors actually ask to see?

Inspection conversations about testing tend to converge on the same evidence set. Expect to be asked for some combination of the following.

  • A testing programme, not a one-off: a documented, risk-based schedule showing which systems are tested, how often, and why that frequency was chosen.
  • Recent penetration test reports for the systems that deliver or protect security functions, produced by a competent independent party such as a CREST-accredited firm.
  • Scope justification: evidence that scoping decisions trace back to your security plan and consequence assessments, including anything deliberately excluded and why.
  • Remediation and retest evidence: tracked findings, risk-accepted items with sign-off, and proof that critical fixes were verified.
  • Change-driven testing: evidence that significant changes, such as new remote access routes or OT network changes, triggered fresh assessment.

A report sitting in a drawer scores poorly. Inspectors look for the loop: test, finding, fix, retest, and an updated view of risk in the security plan.

What to test across a nuclear estate

Corporate IT and the pathways into it

Most real-world intrusions into industrial operators start in ordinary IT: internet-facing services, email, VPN gateways and identity systems. External infrastructure penetration testing, plus internal testing of Active Directory and the routes from corporate IT towards protected networks, covers the attack paths a capable adversary would actually use.

OT, segregation and the zone boundaries

For operational technology, the priority is rarely to attack controllers directly. It is to verify the claims your security plan makes about segregation: that zone boundaries hold, that data diodes and firewalls are configured as documented, that jump hosts enforce the controls described, and that an attacker with a foothold in a lower-trust zone cannot reach systems important to security. Testing here is assessment-led and evidence-heavy rather than exploit-heavy.

Remote access and the supply chain

Vendor remote maintenance connections, engineering laptops and third-party support arrangements recur in inspection findings across critical infrastructure. Testing should verify who can connect, from where, with what authentication, and what they can reach once connected. Where suppliers host services for you, cloud penetration testing of those environments closes the gap between plan and reality.

How an engagement runs on a nuclear-relevant estate

Engagements in this sector are scoping-led, starting from the consequence side: which systems, if compromised, would undermine a security function, and what your security plan claims protects them. That gives a test plan an inspector can map back to the plan, with safety rules agreed before any packet is sent.

When EJN Labs scopes work for operators of sensitive estates, the agreed rules of engagement cover passive discovery first, no active scanning of fragile OT components, production-adjacent systems tested in maintenance windows or against representative replicas, and named contacts with stop authority on both sides. Clearances and on-site handling requirements are settled during scoping, and all work is delivered by UK-based testers.

Delivery follows a familiar arc: reconnaissance, controlled testing, daily washups so nothing in the report is a surprise, and a findings report written for both the engineers who will fix issues and the inspector who will read it as assurance evidence. A retest of critical and high findings completes the loop. If you are building your own scoping notes, our penetration testing checklist is a practical starting point.

What it costs and how scope drives the price

Nuclear-sector testing is priced by effort, and effort is driven by scope: the number of zones and boundaries, the size of the external estate, clearance constraints, and how much work must happen inside maintenance windows. Typical UK day rates for CREST-accredited work run £1,100 to £1,400.

EngagementTypical effortTypical cost
External infrastructure and remote access review3 to 5 days£3,300 to £7,000
Internal IT and Active Directory attack-path testing5 to 8 days£5,500 to £11,200
OT segregation and zone-boundary assessment5 to 8 days£5,500 to £11,200
Combined IT and OT assurance programme10 to 15 days£11,000 to £21,000

These are typical UK ranges rather than quotes; an exact price follows a short scoping call. For how testing is priced across sectors, see our guide to penetration testing costs in the UK.

How EJN Labs approaches SyAPs assurance testing

EJN Labs is a UK firm delivering CREST-accredited penetration testing, certified to ISO 27001 and Cyber Essentials Plus, with all work performed by UK-based testers. For dutyholders and their critical suppliers we write reports as inspection evidence: every finding is mapped to the control claim it undermines, scope decisions carry their rationale, and the executive summary lets a non-specialist inspector follow the argument from threat to test to result. Where estates are too sensitive for direct testing, we agree evidence-equivalent methods such as configuration review and controlled boundary probing, and state plainly in the report which method was used and why.

Frequently Asked Questions

Does ONR SyAPs require penetration testing?

Not by name. SyAPs is outcome-focused, expecting dutyholders to apply graded, risk-informed protection to systems important to nuclear security and to assure themselves those protections work. Penetration testing is the most direct way to provide that assurance for IT and OT estates.

That is why inspectors routinely ask to see test reports even though no clause prescribes them.

What penetration testing evidence do ONR inspectors ask to see?

ONR inspectors typically ask to see a risk-based testing programme, recent reports from an independent and competent provider, scope justifications that trace back to the security plan, tracked remediation with retest evidence, and proof that significant changes triggered fresh assessment.

The strongest evidence shows a closed loop from finding to fix to an updated view of risk, not a standalone report.

What does ONR SyAPs penetration testing cost?

Expect £5,500 to £11,200 for most nuclear-sector engagements, which run 5 to 8 days at typical UK day rates of £1,100 to £1,400 for CREST-accredited work. A combined IT and OT assurance programme of 10 to 15 days runs £11,000 to £21,000. Exact pricing is confirmed after a short scoping call.

Engagements at the 5 to 8 day size typically cover internal attack-path testing or an OT segregation assessment, with the final figure depending on scope.

Can penetration testing be done safely on operational nuclear systems?

Yes, with the right method. Safe practice means passive discovery first, no active scanning of fragile OT components, testing production-adjacent systems in maintenance windows or against representative replicas, and agreed stop authority on both sides for the duration of the work.

Where direct testing is inappropriate, configuration review and controlled boundary probing provide equivalent assurance evidence, clearly labelled as such in the report.

Who should carry out testing used as SyAPs evidence?

An independent, demonstrably competent provider should carry out any testing used as SyAPs evidence. In practice that means a CREST-accredited firm with UK-based testers, experience of OT and segregated environments, and the ability to meet your clearance and information-handling requirements in full.

Independence matters because testing performed by the team that built or operates the controls carries far less weight with an inspector than third-party assurance.

Turn your next inspection question into a confident answer

If your security plan makes claims you have not yet tested, close that gap before an inspector asks. EJN Labs scopes SyAPs-aligned testing around your estate, constraints and evidence needs. Get a CREST penetration testing quote and we will come back with a scoped plan and a fixed price.

Leave a Reply

Your email address will not be published. Required fields are marked *