By EJN Labs · 4 Aug 2026 · 8 min read
Transport operators regulated under the Network and Information Systems Regulations 2018 must manage supply chain risk, so their procurement teams ask suppliers for NIS regulations security assurance evidence. A recent penetration test report from a CREST-accredited firm is the strongest single answer. A focused supplier assessment typically takes 4 to 6 days at £1,100 to £1,400 per day, so £4,400 to £8,400.
Why NIS regulations security assurance decides transport contracts
NIS security assurance decides transport contracts because UK rail, aviation, maritime and road operators are legally accountable for their network and information systems, including the parts they buy from you. That accountability makes supplier security review the gate between your proposal and a signed contract.
If you sell software, managed services or cloud hosting to one of these operators, expect that review. Operators of essential services (OES) in transport answer to a competent authority, and that authority’s remit covers how the operator manages supplier security.
The practical effect for suppliers is blunt. A ticketing SaaS, a telematics feed or an MSP with remote access to depot networks all sit inside the operator’s risk assessment. If the operator cannot evidence that your service is secure, the gap lands on their compliance record, so they push the burden of proof down the supply chain through questionnaires, security schedules and requests for independent test evidence. Suppliers who arrive with that evidence in hand shorten the review by weeks; those who do not sometimes lose the deal to a rival who came prepared.
What the NIS Regulations actually require, and of whom
The Network and Information Systems Regulations 2018 are mandatory for designated operators of essential services and for relevant digital service providers, so the transport operator you are selling to is the regulated entity. As a supplier you are usually not directly in scope unless you fall into those categories.
The Regulations are UK law, enforced by sector competent authorities under a framework set by the UK Government.
Be precise about what the Regulations say on testing; vendors who overstate it lose credibility with a transport security team. NIS does not name penetration testing as a universal mandatory control. The regime is risk-based: operators must take appropriate and proportionate measures, and competent authorities may require evidence, audits and technical testing to confirm those measures work. In practice, most transport operators map their obligations to the NCSC Cyber Assessment Framework, whose supply chain and assurance principles generate the questions you receive. An independent penetration test is the most direct form of that evidence, which is why it appears in contracts even though the statute never uses the phrase.
What transport operators ask suppliers to prove
Security schedules from rail, aviation and port operators converge on the same asks:
- Independent security testing of the product or service being procured, usually within the last 12 months, by an accredited third party.
- A summary report or attestation letter, with critical and high findings remediated and retested.
- Testing that covers the interfaces the operator will actually use: the web portal, the integration APIs, and any remote access route into their environment.
- Baseline hygiene certification, commonly Cyber Essentials or Cyber Essentials Plus, alongside ISO 27001 where data volumes are significant.
- A commitment to annual retesting and to notifying the operator of incidents that could affect the essential service.
Operators increasingly reject self-assessment for anything touching operational systems; they want a third-party report. And scope matters more than volume: a 100-page report on your marketing website will not satisfy a reviewer whose concern is the API that feeds passenger data into their systems. Our penetration testing checklist walks through the scoping decisions before you commission anything.
How a supplier assurance engagement runs
A NIS-driven supplier test is shaped by the contract you are trying to win, so the engagement starts with the operator’s security schedule rather than a generic methodology:
- Scoping call. We review the security questionnaire or contract clauses with you and agree a scope that answers the operator’s questions rather than ours.
- Testing. That usually means API penetration testing for integration points, application testing for customer-facing portals, cloud penetration testing for the hosting environment, and review of any remote access path into operator networks.
- Reporting. You receive a full technical report plus an executive summary written for the operator’s procurement and security teams.
- Remediation and retest. Critical and high findings are fixed and verified, and the report is updated to show closure, the state most operators require before signature.
- Attestation. We provide a letter confirming the test, scope and outcome, which slots directly into the operator’s supplier assurance file.
Timed well, the cycle fits inside a normal procurement window; started late, it becomes the reason the contract slips a quarter.
What it costs and how scope drives the price
Penetration testing in the UK is priced by days of effort. UK day rates run from £1,100 to £1,400, and the number of days is driven by how much of your estate the operator’s review touches. Typical supplier assurance ranges:
| Engagement | Typical effort | Typical cost |
|---|---|---|
| External infrastructure of your hosting estate | 3 to 5 days | £3,300 to £7,000 |
| Web application or API serving the operator | 4 to 6 days | £4,400 to £8,400 |
| Cloud configuration review plus application test | 4 to 7 days | £4,400 to £9,800 |
| Combined assessment across app, API and cloud | 6 to 9 days | £6,600 to £12,600 |
These are typical UK ranges rather than quotes; the exact figure depends on the size and complexity of what needs testing. A focused single-product assessment, the most common shape for a transport supplier, usually lands in the 4 to 6 day band at £4,400 to £8,400. For a fuller breakdown of what moves the number, see our guide to penetration testing costs in the UK. Ask the operator whether they need the whole platform tested or only the tenancy and interfaces they will use; narrowing scope regularly saves days of effort.
How EJN Labs approaches NIS supplier assurance for transport
EJN Labs is a UK-based, CREST-accredited penetration testing firm, certified to Cyber Essentials Plus and ISO 27001, and all testing is carried out by UK-based testers. Operator security teams check the tester’s credentials as carefully as the report, and a CREST-accredited firm clears the accreditation question many security schedules ask explicitly.
When we scope these engagements, we start from the operator’s paperwork, not a template. We ask for the security questionnaire or contract security schedule and map each testing-related clause to a concrete scope item, so the report answers the reviewer’s questions line by line. For a typical transport supplier estate, that means enumerating every interface the operator consumes, from the public portal through the integration APIs to the cloud accounts underneath, and testing the paths an attacker would use to reach operator data through your service. Our CREST penetration testing service page covers the methodology, and our comparison of the best UK penetration testing providers explains what to check before commissioning any firm.
Frequently Asked Questions
Do the NIS Regulations require suppliers to have a penetration test?
No, not directly. The NIS Regulations bind the transport operator, not its suppliers, and they do not name penetration testing as a mandatory control. The requirement reaches you through the contract instead, because operators discharge their supply chain duties by asking suppliers for independent test evidence.
What the Regulations do require is risk-based security measures, and competent authorities may require evidence, audits and technical testing.
What does a NIS supplier assurance penetration test cost?
Expect £4,400 to £8,400 for a focused assessment of the product or service a transport operator is buying, based on 4 to 6 days at UK day rates of £1,100 to £1,400. Broader combined assessments across application, API and cloud run 6 to 9 days, or £6,600 to £12,600.
UK penetration testing is priced by effort, so the exact price depends on scope. Request a quote for a firm figure.
Which parts of our service should be in scope for a transport operator review?
Scope to what the operator consumes: the customer-facing application, the APIs their systems integrate with, the cloud environment hosting their data, and any remote access route into their networks. Reviewers care about the attack paths affecting the essential service, not your entire corporate estate.
Testing only the interfaces in the contract keeps the engagement proportionate.
How recent does the penetration test report need to be?
Within the last 12 months is the standard most transport operator security schedules ask for, and many require annual retesting for the life of the contract. A report older than a year, or one that predates major releases of your platform, is routinely rejected.
If your last test is stale, commission a fresh assessment before the procurement review starts rather than during it.
Can we share our full penetration test report with the operator?
You can, but you usually should not. Share an executive summary and an attestation letter instead, confirming scope, dates, tester accreditation and that critical and high findings were remediated and retested. Most operator security teams accept this in place of the full report.
Full reports contain technical detail about your environment that widens your exposure if circulated, and a CREST-accredited firm produces the summary and attestation letter as standard.
Get the evidence before the security review asks for it
If a transport operator contract is on your pipeline, the cheapest time to sort your security assurance evidence is now, before the questionnaire arrives. Tell us what you sell and who you are selling to, and we will scope a test that answers the operator’s NIS-driven questions the first time. Get a CREST penetration testing quote for a fixed scope and price within one working day.




Leave a Reply