What OT Security Leads Ask SCADA Suppliers About RIIO Cyber Compliance

What OT Security Leads Ask SCADA Suppliers About RIIO Cyber Compliance

By EJN Labs · 6 Aug 2026 · 8 min read

RIIO cyber security assurance is the evidence Ofgem-licensed energy networks produce to show their cyber resilience plans are working. The requirements do not name supplier penetration testing directly: licensees pass assurance obligations to SCADA suppliers by contract. Independent testing of your product, remote access and update paths is the evidence OT security leads ask for most, typically 3 to 12 days at £1,100 to £1,400 per day (£3,300 to £16,800).

Why RIIO cyber security assurance lands on SCADA suppliers

RIIO assurance lands on SCADA suppliers because Ofgem funds cyber resilience work through the RIIO price controls and expects licensees to demonstrate the money delivered improvement, which they cannot do while their control estate depends on suppliers whose security they have never verified.

If you sell SCADA platforms, RTUs, historians or remote maintenance services into UK gas and electricity networks, you have probably noticed the security questionnaires getting longer. That is this assurance requirement working its way down the supply chain.

So the OT security lead at a network operator is not asking awkward questions out of curiosity. Their cyber resilience delivery plan commits them to specific assurance activities, and your product, your engineers’ remote access and your patch pipeline all sit inside the estate they must assure. Your answers become evidence they stand behind in front of their regulator.

What the Ofgem RIIO requirements actually say

Some precision helps here, because the reality is layered.

  • RIIO is Ofgem’s price control framework for energy network companies. Within it, Ofgem funds cyber resilience plans covering both operational technology and IT and holds operators to them through the price control.
  • The requirements are mandatory where included in a licensee’s licence conditions or price control settlement. They bind the network operator, not you.
  • The framework’s position on testing is regulatory assurance and testing in line with the licensee’s delivery plan. No clause names penetration testing of third-party SCADA products.
  • What does reach you is contractual. Licensees translate their obligations into procurement requirements, security schedules and audit rights, and those documents very often name independent testing explicitly.

That is the honest picture: RIIO does not mandate a penetration test of your product by law, but the licensee’s delivery plan commits them to assurance evidence they cannot produce without one. The requirement arrives as a contract term or an onboarding blocker, and it carries the same commercial weight as a regulation.

The questions OT security leads actually ask

Across supplier assurance reviews in the energy sector, the same questions recur. Answer them with evidence rather than assertions and you are ahead of most of the market.

  • Has your product been independently security tested, by whom, against what scope, and how recent is the report?
  • How does your remote support access work? Who can connect, through what authentication, and what can they reach once inside?
  • How are firmware and software updates built, signed and delivered, and could a compromised build pipeline reach our control network?
  • What happens when a vulnerability is found in your platform? Is there a disclosure route, fix timelines and operator notification?
  • If your product includes a cloud or web management layer, has it been tested to the same standard as the on-premise components?

Almost every question resolves to the same request: show us independent technical evidence. A recent test report from a CREST-accredited firm answers most of them in one document. Our penetration testing checklist is a useful starting point for mapping these questions onto a concrete scope.

What evidence satisfies a RIIO-regulated customer

The evidence pack that closes these conversations usually contains four things.

  • A product-level penetration test covering the SCADA platform, HMI applications, engineering workstation software and the protocols and services the equipment exposes.
  • A remote access assessment covering the full support path: VPN or jump-host entry, authentication and MFA, session controls, and what a compromised support account could reach.
  • Testing of any web, API or cloud management layer, which operators treat as part of the attack surface.
  • A retest confirmation showing the significant findings were fixed, not just reported.

Two practical points from delivering this work: none of it requires touching a live control network, since we test staging systems, factory acceptance environments or lab builds; and the report must serve both the OT security lead who reads every finding and the compliance function who files it as delivery plan evidence.

How a supplier-side engagement runs

A typical supplier engagement follows five stages.

  1. Scoping. We map your product architecture, the remote support path and any cloud components, agree a target environment (usually a staging rig or lab replica) and set OT-aware rules of engagement.
  2. Testing. UK-based testers work through the agreed scope: network services and protocol handling, authentication, privilege escalation, the update mechanism, and the external infrastructure supporting remote support.
  3. Reporting. Findings are rated by real-world impact on an operator’s estate, with remediation guidance your engineering team can act on.
  4. Remediation and retest. You fix, we verify, and the report is updated to show closure.
  5. Evidence pack. A summary suitable for sharing with your energy network customers, so one engagement supports multiple assurance conversations.

What it costs and how scope drives the price

Supplier-side assurance testing in the UK is priced by effort, driven by how much of your product surface goes in scope. Day rates typically run £1,100 to £1,400, and the ranges below reflect that.

EngagementTypical effortTypical UK cost
Single product or component assessment (one SCADA platform or HMI application)3 to 5 days£3,300 to £7,000
Remote access and support path assessment4 to 6 days£4,400 to £8,400
Full supplier assurance package (product, remote access, API or cloud layer, retest and customer-facing evidence pack)8 to 12 days£8,800 to £16,800

Scope is the lever. A single HMI application with no cloud component sits at the bottom of these ranges; a platform spanning embedded devices, a server tier, an API and a vendor-hosted portal sits at the top. For a broader view of how UK testing is priced, see our guide to penetration testing costs in the UK. An exact figure comes from a short scoping call and a written quote.

How EJN Labs approaches RIIO supplier assurance testing

EJN Labs is a UK firm delivering CREST-accredited penetration testing, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we understand what it means to produce compliance evidence that stands up to scrutiny. All testing is delivered by UK-based testers, which matters in a sector where customers routinely ask where their supplier’s supplier sits.

When we scope a SCADA supplier engagement, we start from the questions your customers will ask rather than a generic methodology. We look hard at the remote support path early, because in our experience it worries OT security leads most: it is the one route that crosses from your corporate network into their operational estate. We test against staging or lab environments, never live control systems, and write findings in terms of operator impact. If you are comparing firms, our guide to choosing a UK penetration testing provider sets out the questions worth asking.

Frequently Asked Questions

Does RIIO require SCADA suppliers to carry out penetration testing?

Not directly. Ofgem’s RIIO cyber resilience requirements bind the licensed network operator, and no clause names supplier penetration tests. In practice licensees pass assurance obligations to suppliers through contracts and security schedules, and independent testing is the evidence most commonly demanded.

The requirements position testing as regulatory assurance delivered through the licensee’s plan, so the requirement reaches you commercially even though it is not written into law.

What evidence should a SCADA supplier prepare for a RIIO-regulated customer?

Prepare four items: a recent independent penetration test of the product itself, an assessment of the remote support and maintenance access path, testing of any web, API or cloud management layer, and a retest confirmation showing significant findings were fixed.

Together they cover most requests. A report from a CREST-accredited firm, written with a customer-shareable summary, answers the majority of supplier assurance questionnaires in one document.

What does supplier-side RIIO assurance testing cost?

Between £3,300 and £16,800 depending on scope. Typical UK engagements run 3 to 12 days at day rates of £1,100 to £1,400, with a single product or component assessment sitting at the lower end of that range and a full assurance package at the top.

A single product or component assessment is usually 3 to 5 days (£3,300 to £7,000), a remote access assessment 4 to 6 days (£4,400 to £8,400), and a full assurance package 8 to 12 days (£8,800 to £16,800). An exact price comes from a scoping call.

Can testing be done without touching a live OT environment?

Yes, and it should be. Supplier-side testing is carried out against staging systems, factory acceptance environments or representative lab builds of your product, never against a customer’s live control network, so the platform and its access paths are proven without any risk to plant or supply.

This is also the approach energy network operators themselves prefer when they review supplier evidence.

How often do energy networks expect supplier testing to be repeated?

Annually is the working norm in supplier assurance reviews, with an additional test after any major release, architecture change or new remote access mechanism. Because licensees report progress against multi-year delivery plans, they tend to ask for evidence dated within the last twelve months.

Aligning your testing cycle to your release calendar keeps the evidence current without paying for tests you do not need.

Turn customer assurance questions into a closed deal

If a RIIO-regulated customer has asked for testing evidence, or you want the pack ready before the next tender, we can scope it in one short call and come back with a fixed written quote. Get a CREST penetration testing quote today.

Leave a Reply

Your email address will not be published. Required fields are marked *