NIST SP 800-82 Rev 3 / OT Security Audit

Your IT auditor has never seen a PLC. Your insurer, your regulator, and your board no longer accept that.

We audit SCADA, ICS, and building systems against NIST SP 800-82 Rev 3 without touching production: passive methods only, every tool approved by your engineers first, findings ranked by safety and downtime consequence.

Led personally by the consultant who has advised the Nuclear Power Plant of the United Arab Emirates.

Zero-downtime methodologyFixed price, publishedYou review the report before you pay
NIST SP 800-82 OT security audit for SCADA, ICS, PLCs, and building automation systems by Atlant Security

The Three Reasons Plants Call Us

Nobody audits their OT for fun. One of these three is usually on fire.

Your cyber insurance renewal is asking OT questions you cannot answer

Underwriters now ask about OT segmentation, MFA on vendor remote access, and tested backups of PLC logic. A wrong answer risks claim denial. A truthful answer risks a surcharge or an OT exclusion. An SP 800-82 audit gives you defensible answers before the renewal date.

A regulator or customer gave you a deadline

TSA Security Directives require annual pipeline cybersecurity assessments. EPA and AWIA recertification waves are hitting water systems through 2026. NERC CIP-003-9 became enforceable in April 2026. NIS2 enforcement started across the EU. Large customers exercise right-to-audit clauses. All of them accept an audit mapped to NIST SP 800-82.

The board asked: could Clorox happen to us?

Clorox lost around $356 million to a help-desk social engineering attack that halted production. MKS Instruments lost about $200 million in one quarter, and its customer Applied Materials warned of a $250 million ripple. When the board asks whether your plants are exposed, only an audit produces a real answer.

The 2023 Clorox OT shutdown cost around 356 million dollars after a help desk social engineering attack halted production

What Is NIST SP 800-82?

NIST SP 800-82 Revision 3, the Guide to Operational Technology Security, is the US government's reference for securing the systems that touch the physical world. Published September 28, 2023, the 316-page guide superseded the old Industrial Control Systems edition and widened its scope: OT now explicitly covers SCADA, distributed control systems, PLC-based topologies, building automation, physical access control, environment monitoring, safety systems, and Industrial IoT.

Its core engineering insight is that OT is not IT. Rebooting is often unacceptable. Outages are planned weeks ahead. Human safety outranks confidentiality. A security measure that impairs a safety function is, in the standard's own framing, unacceptable. Auditing OT with IT tools and IT assumptions produces broken production lines and useless findings.

The heart of an audit is Appendix F: a formal OT overlay that tailors NIST SP 800-53 Rev 5 controls across 19 families at low, moderate, and high impact. That overlay, plus the Purdue-model segmentation architecture of Section 5, is the yardstick we audit against. It is guidance rather than law, but TSA directives, EPA water requirements, NERC CIP expectations, cyber insurers, and enterprise customers all accept it as the standard of evidence.

OT systems in scope under NIST SP 800-82 Rev 3: SCADA, DCS, PLC topologies, building automation, physical access control, safety systems, and IIoT
The SP 800-82 Appendix F OT overlay tailors 19 NIST SP 800-53 Rev 5 control families for operational technology

Where the Audit Looks: Every Purdue Level

From the enterprise network down to the sensors and valves, an SP 800-82 audit verifies segmentation, boundary protection, and controls at every level, with special attention to the DMZ, the dual-homed workstations that defeat it, and the safety layer attackers now target directly.

Purdue reference model levels 0 to 5 showing enterprise IT, the DMZ, site operations, supervisory control, basic control, and the physical process audited under NIST SP 800-82

In Scope: All Six OT System Families

SCADA systems

Supervisory control across pipelines, grids, and water networks

DCS

Distributed control systems running process plants

PLC-based topologies

The controllers running your lines, skids, and machines

Building automation

HVAC, elevators, power, and access in commercial buildings and data centers

Safety systems

Safety instrumented systems that keep processes from killing people

IIoT and monitoring

Industrial IoT sensors and physical environment monitoring

What We Audit, Area by Area

Ten areas, mapped to the structure of SP 800-82 Rev 3 itself. Each finding lands against a specific overlay control, so your remediation roadmap doubles as compliance evidence.

OT asset inventory and system characterization

Do you actually know every PLC, HMI, historian, drive, and safety controller you run, what firmware is on them, and which physical process each one touches? Roughly a third of operators have no centralized OT inventory at all.

Network architecture and Purdue segmentation

Defense-in-depth across the Purdue levels, a real DMZ between IT and OT, firewall rules between zones, and no path from the internet to a controller. One dual-homed engineering workstation defeats all of it, which is exactly how the 2016 Kyiv grid attack got in.

The Appendix F OT overlay, control by control

SP 800-82 Rev 3 tailors NIST SP 800-53 Rev 5 across 19 control families at low, moderate, and high impact. We verify each applicable control, document justified deviations, and map compensating controls where the overlay expects them.

Remote access and vendor connections

Every OEM VPN, TeamViewer install, and cellular modem inventoried, with MFA, jump hosts, session logging, and least privilege. About half of OT incidents originate from external remote access. We find the links you do not know about.

Patch and configuration management under OT constraints

A patch process that acknowledges reality: outages planned weeks ahead, OEM certification limits, machines that cannot reboot. Where patching is infeasible, we verify compensating controls instead of writing "patch everything" like an IT auditor would.

Monitoring, logging, and detection

Passive OT network monitoring, log collection from devices that can log, and compensations for the ones that cannot. Only about 13 percent of operators report full visibility across the ICS kill chain.

Incident response and recovery for OT

An IR capability that prioritizes safe process state over forensics, tested backups of PLC logic and HMI configurations, and the ability to run in manual mode. Norsk Hydro survived LockerGoga on pen and paper because it could.

Safety system independence

Safety instrumented systems assessed separately and verified independent from basic process control, so one compromise cannot defeat both layers. Triton proved attackers target the safety layer itself.

Supply chain and integrator risk

The security of the vendors, system integrators, and software update channels that reach your OT. NotPetya entered through a trojanized vendor update and cost Merck $1.4 billion.

Governance, training, and ownership

A named owner for OT security, OT-specific policies distinct from IT policy, and training for the engineers who actually operate the systems, so audit findings do not fall into the gap between the CISO and the plant.

The Question Every Plant Asks First: Will You Break Something?

Every OT engineer has a war story about a vulnerability scan that tripped a line. It is the single biggest reason plants refuse security assessments, and the fear is justified: legacy controllers are known to hang under unexpected traffic.

So our answer is structural, not reassuring words. We never run active IT-grade scans against live controllers. The audit is built from passive network captures, offline configuration reviews, physical walkthroughs, and interviews. Your engineers review and approve every tool and every method before anything connects to your network, and a written stop-work and rollback plan is agreed before fieldwork begins.

We also coordinate with your system integrator and OEM support channels so nothing we do jeopardizes a support contract or warranty.

Zero-downtime OT audit methodology: passive network captures, configuration reviews, engineer-approved tools, and a written stop-work plan
Atlant Security's founder has consulted for the Nuclear Power Plant of the United Arab Emirates

Trusted Where Failure Is Not an Option

There is one environment where OT security has no margin for error, no tolerance for consultants learning on the job, and no patience for IT-grade methods: a nuclear power plant. Atlant Security's founder has consulted for the Nuclear Power Plant of the United Arab Emirates.

That work sits on top of 200+ security assessments across 14 countries since 2013, a Microsoft Security Consulting background, and a CISSP. When we say the same person who carries that experience walks your plant floor, interviews your engineers, and writes your report, that is the entire delivery model. No leverage pyramid, no juniors, no handoffs.

The OEMs will audit you to sell you their platform. The Big-4 will send people who have never seen a safety instrumented system. We have exactly one thing to sell: the audit itself.

Why Plants Choose Atlant Over the OT Establishment

The OT assessment market is enterprise platforms, automation OEMs auditing their own install base, and Big-4 leverage models. Here is the honest comparison.

Atlant SecurityTypical OT Assessment Vendor
Who shows upThe founder, who has consulted for the Nuclear Power Plant of the United Arab Emirates, does the fieldwork and writes the reportA partner sells it, juniors with IT backgrounds deliver it
IndependenceNothing to sell you afterwards: no sensors, no platform, no managed serviceOEMs and platform vendors whose findings map suspiciously well to their own products
PricingPublished, fixed, and scoped before we startNo public pricing anywhere; enterprise minimums and MSA negotiations
Method on live systemsPassive captures and config reviews, every tool pre-approved by your engineers, written stop-work planIT-grade scanners that legacy PLCs are known to crash under
FindingsRanked by safety and downtime consequence, scoped to what you can fix this yearA CVSS-sorted risk register telling you to patch what cannot be patched
SpeedFieldwork scheduled in weeks, report 2 to 3 weeks afterMonths of scheduling, then a four-month wait for the deck

SP 800-82 Audit Pricing

Almost nobody in OT security publishes prices. We do. Effort drives the price, not the size of the standard: the same 19 overlay control families take radically different work depending on your sites, systems, and vendor connections, and sometimes 10 percent of the controls are 95 percent of the effort. That is why every engagement is scoped and fixed in writing before we start.

Remote OT Gap Assessment

The right start for a first-ever OT assessment or multi-site prioritization. No site visit required.

From $8,000fixed price
  • Architecture and firewall configuration review
  • Purdue segmentation analysis
  • Guided passive captures by your team
  • Policy and program review against Section 3
  • Gap mapping to the Appendix F overlay
  • Consequence-ranked remediation roadmap
Book Free Strategy Call

Zero-risk: you review the report before you pay.

Most Common

On-Site OT Security Audit

The full SP 800-82 Rev 3 audit, from the control room to the cabinets.

From $15,000fixed price
  • Everything in the Remote Gap Assessment
  • On-site fieldwork with safety inductions and escorts
  • Physical security of control rooms and field cabinets
  • Vendor and integrator remote access discovery
  • Safety system independence verification
  • Regulator, insurer, and customer mapping table
  • Executive briefing for the board
Book Free Strategy Call

Zero-risk: you review the report before you pay.

Multiple plants, substations, or a fleet of sites? Multi-site programs are scoped per site with volume pricing. Remediation support and an OT incident response retainer are separate, scoped add-ons.

Who Needs an SP 800-82 Audit?

Manufacturers with PLCs, robots, and MES the IT team has never audited
Water and wastewater utilities facing EPA, AWIA, and state cyber mandates
Energy and pipeline operators under NERC CIP or TSA Security Directives
Data centers and commercial buildings running BMS, HVAC, and access control
Pharma and food plants where change control makes every fix a project
Ports, logistics, and transportation systems that cannot afford three days offline
One SP 800-82 audit reused for TSA Security Directives, NERC CIP, EPA and AWIA, IEC 62443, NIS2, and cyber insurance questionnaires

How the Audit Works: 5 Steps, 2 to 3 Weeks

1

Scoping and system characterization

We map your sites, systems, and vendor connections, review existing inventories and network diagrams, and agree the exact scope in writing. You approve every tool and method before anything touches your network.

2

Architecture and segmentation review

Configuration reviews of firewalls, switches, and boundary devices against the Purdue model, plus passive traffic captures from SPAN ports where available. No active scanning of live controllers, ever.

3

On-site fieldwork

Control room and plant floor walkthroughs with your escorts, safety inductions and PPE, physical security checks of cabinets and field devices, and structured interviews with the engineers who run the process.

4

Gap analysis against the OT overlay

Every finding mapped to the SP 800-82 Rev 3 Appendix F overlay of NIST SP 800-53 Rev 5, categorized by impact level, with justified deviations documented the way an assessor or regulator expects.

5

Consequence-ranked roadmap

Findings prioritized by safety, downtime, and product impact rather than raw CVSS scores, with fixes your plant can actually execute given maintenance windows, staffing, and budget. Plus a mapping table for your regulator, insurer, or customer.

The 5-step NIST SP 800-82 audit process from scoping and inventory to the consequence-ranked remediation roadmap

Audit the Plant. Keep It Running.

One strategy call. A fixed-price proposal within 24 hours. An audit your regulator, your insurer, and your board all accept, done by the consultant a nuclear power plant trusted, without a single minute of downtime.

Book Your Free OT Strategy Call

Schedule Your Free OT Strategy Call

NIST SP 800-82 Audit FAQ

Will your assessment crash our PLCs or stop production?
No, and this is the difference between an OT audit and an IT penetration test. We never run active IT-grade scanners against live controllers. Legacy PLCs and RTUs are known to hang under unexpected traffic, so our method is passive: network captures from SPAN ports, offline configuration reviews, interviews, and physical walkthroughs. Your engineers review and approve every tool and method before anything connects, and a written stop-work and rollback plan is agreed before fieldwork starts.
What exactly is NIST SP 800-82 and is it mandatory?
NIST SP 800-82 Revision 3, the Guide to Operational Technology Security, is the US government reference for securing OT: SCADA, DCS, PLCs, building automation, physical access control, and safety systems. It is guidance rather than law, but regulators build on it: TSA Security Directives, EPA water sector requirements, and NERC CIP expectations all align with it, and an audit mapped to 800-82 is accepted evidence across those regimes, by cyber insurers, and in customer security reviews.
What changed in Revision 3?
Revision 3, published September 28, 2023, renamed the document from Industrial Control Systems to Operational Technology and widened its scope: building automation, physical access control systems, environment monitoring, transportation systems, and IIoT are now explicitly covered alongside classic ICS. It added a full OT cybersecurity program section, applied all seven Risk Management Framework steps to OT, and introduced the Appendix F OT overlay, which tailors NIST SP 800-53 Rev 5 controls across 19 families for OT environments. NIST is already drafting Revision 4, so audits done now stay current.
How much does an SP 800-82 audit cost?
Our remote OT gap assessment starts at $8,000 and the full on-site audit at $15,000, both fixed price. OT audits cost more than IT audits because effort, not the page count of the standard, drives the work: the same 19 control families must be verified against plant constraints, safety systems need separate assessment, and fieldwork happens on your schedule with your escorts. Sometimes 10 percent of the controls are 95 percent of the effort, which is why we scope and fix the price before we start. Almost no competitor publishes OT assessment pricing at all.
Do you understand our equipment, or are you IT people?
We audit environments running Siemens, Rockwell and Allen-Bradley, Schneider, Honeywell, Emerson, GE, and Unitronics equipment, and we know why that last one matters: internet-exposed Unitronics PLCs with default passwords were exactly what Iranian-affiliated attackers hit at US water utilities in 2023. Our founder has consulted for the Nuclear Power Plant of the United Arab Emirates, an environment where the standard for OT security work is as unforgiving as it gets.
Can you audit us without a site visit?
Substantially, yes. The remote gap assessment covers architecture and firewall configuration review, network captures your team collects with our guidance, policy and program review, and structured interviews, mapped to the same SP 800-82 overlay. It is the right start for a first-ever OT assessment or a multi-site prioritization. Physical security, cabinet-level checks, and floor walkthroughs require the on-site audit.
Which regulations does the report map to?
The report maps findings to the SP 800-82 Rev 3 Appendix F overlay and cross-references TSA Pipeline and Rail Security Directives, NERC CIP, EPA and AWIA requirements, IEC 62443, NIS2, and the CISA Cross-Sector Cybersecurity Performance Goals. You buy one audit and reuse it for your regulator, your insurer, and your customers.
How do you handle our network diagrams and PLC programs?
Everything we collect is encrypted at rest, access is limited to the consultant doing the work, nothing goes into third-party AI tools or offshore delivery centers, and all engagement data is destroyed on a documented schedule after delivery. You get the destruction confirmation in writing.
What do we get at the end?
A gap assessment against the SP 800-82 OT overlay with every finding mapped to a control; a consequence-ranked remediation roadmap scoped to your maintenance windows, staffing, and budget; an executive summary the board can read; and the regulatory mapping table. You review the full report before you pay.
How fast can this happen?
The remote gap assessment takes about 2 weeks from kickoff. The on-site audit typically runs 3 weeks end to end: one week of preparation and remote review, fieldwork days on your schedule, then analysis and reporting. Compare that with the enterprise OT vendors, where scheduling alone is measured in months.

Related Services