Sector: Nuclear Supply Chain

Penetration Testing for the UK Nuclear Supply Chain

CREST-accredited penetration testing for civil nuclear engineering, construction, maintenance and specialist technology suppliers working with nuclear licensees and prime contractors. We test the supplier’s own systems, engineering collaboration platforms, maintenance portals and controlled-document exchanges, from the IT side of any boundary with operational or site-security systems. We are not a nuclear site licensee or a nuclear security regulator.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
ONR SyAPs
FSyP 7 Evidence
ISO 27001
Certified
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
REGULATORY CONTEXT
3

third-party roles we separate on a nuclear supply-chain platform in every test: contractor, subcontractor and site-licensee reviewer, each with a different level of access to controlled technical documents.

What ONR Security Assessment Principles Expect

ONR Security Assessment Principles. Regulation 4 of the Nuclear Industries Security Regulations 2003 requires an approved security plan for each nuclear premises, describing the standards, procedures and arrangements that protect the site, its nuclear material and associated information. The Office for Nuclear Regulation assesses those plans against its Security Assessment Principles (SyAPs); Fundamental Security Principle 7 covers Cyber Security and Information Assurance in outcome-based terms and does not name penetration testing as the method. A scoped test on your own systems is one way to generate evidence for the FSyP 7 outcomes. NISR 2003, regulation 4; ONR: Security Assessment Principles.

Cascaded into supplier contracts. Regulation 4 applies to the licensee’s own nuclear premises, not to every supplier. In our experience, nuclear licensees and prime contractors commonly cascade their own SyAPs-driven expectations into supplier contracts and portal access agreements, and increasingly ask engineering, maintenance and technology suppliers for independent security testing evidence on the systems used to collaborate with them.

Engineering and maintenance systems, tested safely. We test engineering collaboration platforms, maintenance portals and vendor remote-access pathways from the IT side of the boundary: authentication, privileged command interfaces and the paths your own systems use to talk to site or engineering equipment. We do not test live nuclear safety, control or site-security systems, and any work that reaches towards them only goes ahead against an agreed safe test plan, with your engineering team, defined change windows and a kill switch.

Who we test for. Civil nuclear engineering, construction, maintenance and specialist technology suppliers working with nuclear licensees and prime contractors. We test the supplier’s own systems; we are not a nuclear site licensee, and assessing compliance with SyAPs sits with ONR and the licensee’s own accountable security team, not with us.

SCOPE

What We Test in the Nuclear Supply Chain

COLLAB

Engineering Collaboration Platforms

CAD, technical query and design-review platforms shared with prime contractors and subcontractors. Third-party account provisioning, drawing and revision access control, and the boundary between your systems and each collaborator’s own network.

PORTAL

Maintenance & Contractor Portals

Portals for scheduling site visits, uploading method statements and competency certificates, and tracking permits to work. Contractor and subcontractor account separation, and confirmation that an expired or revoked permit cannot still authorise access.

DOCS

Controlled Document Exchange

Storage and distribution of drawings, specifications and export-controlled technical data. Contractor, subcontractor and site-licensee reviewer roles, each with a different level of access, plus watermarking, download logging and link expiry.

APIS

Supplier & Prime Integration APIs

API integrations between your systems and a prime contractor’s procurement, logistics or asset-management platforms. Object-level authorisation, rate and quota abuse, and the trust boundary between your platform and theirs.

VPN

Vendor Remote Access & Engineering Workstations

Remote-access services and engineering workstations used to support equipment or software once it reaches site, tested from the IT side of the boundary. We do not test live nuclear safety, control or site-security systems.

EXT

External Perimeter & Remote Access

External-facing infrastructure supporting engineering, project and back-office functions: VPN gateways, exposed management interfaces and cloud consoles. CREST methodology identifies exposed services, weak authentication and unpatched systems reachable from the internet.

RED

Red Team

Multi-week assume-breach engagements scoped to your IT estate: spear phishing against engineering, procurement and finance staff, persistent command and control, and lateral movement testing up to the boundary with any operational or site-security system. Live nuclear safety and site-security systems are out of scope.

PHISH

Phishing Defence

Targeted phishing simulation against engineering, procurement and finance staff, using supply-chain-aware lures such as fake purchase-order changes and supplier-payment fraud.

OUR PROCESS

From Scope to Attestation in 4-6 Weeks

01

Scoping Call

30-minute technical scoping call covering engineering collaboration, maintenance and document-exchange systems in scope, rules of engagement, and any boundary with operational or site-security systems. Fixed-price quote within 24 hours.

02

Active Testing

3-15 days of hands-on testing by CREST-certified UK-based pen testers, against non-production environments or a defined safe-test window wherever site or engineering schedules matter. Daily status updates.

03

Reporting

Executive summary plus full technical report with CVSS scores, reproduction steps, screenshots, and specific remediation. 60-minute walkthrough call.

04

Free Retest

After remediation, we retest at no extra charge. Letter of attestation provided for prime-contractor due diligence, licensee security review, or buyer audit.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST nuclear supply chain pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Aligned to Every Framework

Findings map to specific control references in each framework, so your audit team submits the report directly without translation work.

ONR SyAPs FSyP 7

Outcome-based evidence for Cyber Security and Information Assurance under regulation 4 of the Nuclear Industries Security Regulations 2003. Penetration testing is never named as the method.

ISO 27001

Annex A 8.8 technical vulnerability management, once you declare that control applicable.

ISO 9001

No security-testing requirement of its own. Independent testing evidence on nuclear supply contracts is driven by your customer’s own requirements, not by the standard.

Cyber Essentials Plus

An audit, not a penetration test. Often requested by primes and site licensees alongside independent testing evidence. Certified directly by us as an IASME certification body.

UK GDPR

Article 32(1)(d) evidence that you regularly test the effectiveness of your security measures, for personnel and contractor data.

Cyber Insurance

Findings and remediation documented against the questions on your broker or insurer’s proposal form. Requirements vary by insurer and policy.

PRICING

Indicative Engagement Pricing

Fixed-price quotes confirmed during scoping. Free retest, executive summary, walkthrough call, and letter of attestation included.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
Free retests, no time limit
Free rescheduling
No cancellation fees
24-hour scope to active testing
Live findings to client portal
Executive + technical report
60-min walkthrough call
Letter of attestation
SMALL / SMB
£3,500–£8,000
Depends on service + scope

External / web / API / mobile single-target engagement. CREST-certified delivery. Around 3 to 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£18,000+
Depends on service + scope

Full-stack engagement (multiple cloud accounts, hybrid AD, complex web + API + mobile). Typically 12-15+ days.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Nuclear Supply Chain Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What does a nuclear supply-chain test look at that a standard web app test does not?

Contractor, subcontractor and site-licensee reviewer role separation, controlled-document access and watermarking, permit-to-work validation, and safe testing windows around site and engineering schedules.

Do you test nuclear power stations, reactors or live safety systems?

No. We test your organisation’s own IT systems, engineering collaboration platforms, maintenance portals and remote-access pathways. We are not a nuclear site licensee and we do not test live nuclear safety, control or site-security systems. Any work that reaches towards them only goes ahead against an agreed safe test plan with your engineering team.

Which nuclear supply-chain organisations do you test for?

Civil nuclear engineering, construction, maintenance and specialist technology suppliers working with nuclear licensees and prime contractors.

Can you provide evidence for our ONR Security Assessment Principles submission?

We can test your systems and provide a CVSS-scored report and letter of attestation your security team can use as evidence towards Fundamental Security Principle 7 outcomes. We do not assess your compliance with SyAPs directly; that assessment sits with ONR and your own accountable security team.

Can you test our SharePoint-based engineering document library before we grant subcontractor access?

Yes. We test document libraries such as SharePoint for permission scoping, sharing-link expiry, versioning integrity and the boundary between internal staff and external contractor or subcontractor accounts. See our SharePoint penetration testing page.

How do you handle export-controlled or security-classified technical data during testing?

We ask for a non-production environment with synthetic or redacted technical data wherever possible. Where genuinely controlled data cannot be avoided, we agree handling and storage terms with you before testing begins.

What happens if testing surfaces something that could affect a live site?

We do not test live site-security or nuclear safety systems, so this should not arise directly from our testing. If something on your own systems could plausibly affect a live site, we stop, tell your nominated contact straight away, and support your escalation to the site licensee and ONR as your own process requires.

What’s in the report?

Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.

Do you sign NDAs?

Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.

How quickly can you start?

From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.

Are your testers UK-based and what certifications do they hold?

Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get my Nuclear Supply Chain pen test scope

A CREST-certified UK-based pen tester will contact you within one business day with a fixed price aligned to your nuclear supply-chain systems and ONR SyAPs evidence needs.