Compliance & Certifications • Chemical Sector

Chemical Plant SCADA Compliance:
CFATS, OSHA PSM & IEC 61511

Merobix Engineering • • 11 min read

Chemical plant SCADA compliance means facing a regulatory stack unlike any other industry: a federal security program in limbo (CFATS), two overlapping process-safety regimes with real audit cycles (OSHA PSM and EPA RMP), and a functional-safety standard (IEC 61511) that now explicitly demands cybersecurity for safety instrumented systems. Your SCADA platform sits in the middle of all of it - every setpoint change is a potential management-of-change event, every alarm record is potential audit evidence, and every remote-access path is a potential finding. This guide maps which standards actually apply, explains the audit processes and their three- and five-year cycles, gives honest cost and timeline ranges, and lays out what to demand from a SCADA vendor before it touches a covered process.

Back to Blog

Part of the Merobix OT security guide collection - vendor vetting to industry compliance.

3Year OSHA PSM Compliance Audit Cycle
5Year PHA Revalidation Requirement
4Safety Integrity Levels in IEC 61511

The Chemical Regulatory Stack: Who Demands What

Three drivers push cybersecurity and record-keeping obligations onto chemical plant SCADA and control systems. First, counter-terrorism security: the CFATS program regulated facilities holding chemicals of interest until its 2023 lapse, and its risk-based performance standards still shape sector practice. Second, process safety law: OSHA PSM and EPA RMP bind facilities with threshold quantities of hazardous chemicals, and both reach the control system through management of change, process safety information, and audit requirements. Third, engineering standards: IEC 61511 governs safety instrumented systems and now explicitly requires security risk assessment, while the IEC 62443 series published by ISA and IEC defines what a secure control architecture looks like. Insurers, corporate customers, and joint-venture partners increasingly ask for evidence against all three layers, regardless of what the law currently compels.

CFATS: Lapsed, Not Irrelevant

The Chemical Facility Anti-Terrorism Standards required high-risk facilities holding chemicals of interest to submit Top-Screens, develop site security plans, and satisfy eighteen Risk-Based Performance Standards - including RBPS-8, the cyber standard covering access control, monitoring, incident response, and training for systems that monitor or control chemicals of interest. On July 28, 2023, the program's statutory authority expired when Congress did not reauthorize it, and as of mid-2026 it has not been restored. CISA cannot currently enforce CFATS obligations and instead runs the voluntary ChemLock assistance program.

Treat the lapse as procedural, not substantive. The threat CFATS addressed did not expire with it, reauthorization bills keep appearing, and a facility that dismantled its security program would face an expensive rebuild if authority returns - likely with less goodwill from regulators. Practically: keep the CFATS-era program alive, use RBPS-8 as your cyber benchmark for systems touching chemicals of interest, and document continuity so any future re-registration is a filing exercise rather than a project.

OSHA PSM: Where Process Safety Meets Your SCADA

OSHA's Process Safety Management standard (29 CFR 1910.119) applies to processes holding threshold quantities of highly hazardous chemicals, and several of its fourteen elements land directly on the control system:

EPA's Risk Management Program (40 CFR Part 68) mirrors PSM for offsite consequences, and its 2024 amendments tightened prevention-program expectations for covered processes. If PSM applies to you, assume RMP does too, and run one integrated program.

IEC 61511 and the SIS: Safety Meets Security

IEC 61511 - maintained with ISA's ISA84 committee and available for purchase from ISA and IEC - is the process-sector functional safety standard: it governs how safety instrumented functions are specified, designed to a safety integrity level (SIL 1 through 4), independently validated, and proof-tested so they work on demand. Its relevance to a SCADA evaluation is twofold. First, independence: the SIS must remain functionally separate from the basic process control system, so a SCADA failure - or compromise - cannot disable the layer that prevents the worst outcome. Your monitoring platform should observe SIS status, never write to it through the same pathway operators use for process control. Second, security: the current edition of IEC 61511 explicitly requires a security risk assessment of the SIS, and points to IEC 62443 methodology to perform it. The 2017 Triton/TRISIS incident - malware built specifically to manipulate safety controllers at a petrochemical plant, documented in CISA's HatMan malware analysis report - is the case study that turned that clause from paperwork into practice.

The division of labor is worth stating plainly: 61511 protects against accidents; 62443 protects against attackers. A chemical plant needs both, engineered together - zones and conduits that isolate the SIS, control networks that accept no inbound connections, and monitoring that can see both layers without weakening either. Our guides to securing SCADA on OT networks and chemical plant SCADA monitoring cover the architecture side in depth.

How the Standards Compare

Standard / Rule Issued By Status / Legal Force What It Demands of SCADA
CFATS / RBPS-8CISA (DHS)Lapsed July 2023; voluntary ChemLock continuesCyber controls for systems monitoring or controlling chemicals of interest: access control, monitoring, incident response
OSHA PSM (1910.119)OSHABinding for threshold quantitiesPSI documentation, MOC on control changes, PSSR, mechanical integrity records, 3-year audits
EPA RMP (Part 68)EPABinding for covered processes; 2024 amendmentsMirrors PSM for offsite risk; prevention program and audit evidence
IEC 61511 / ISA 84IEC / ISAIndustry standard; referenced as good engineering practiceSIS independence, SIL-rated design, proof testing, and a security risk assessment of the SIS
IEC 62443IEC / ISAVoluntary; contractual and insurance-drivenZones and conduits, security levels, vendor and component security requirements

The Compliance and Audit Process, Step by Step

  1. Determine coverage. Inventory chemicals against PSM/RMP threshold quantities and the CFATS chemicals-of-interest list (for when authority returns). Coverage determinations, in writing, are your foundation.
  2. Build or refresh the PHA for covered processes - and include control system and cyber failure modes in the what-if and HAZOP worksheets.
  3. Assess the control estate against RBPS-8 and IEC 62443: remote access paths, account hygiene, network segmentation between corporate, control, and safety layers, and logging coverage.
  4. Wire MOC and PSSR into the control system. Setpoint and configuration changes should be technically gated behind change approval where feasible - not policed by memo after the fact.
  5. Run the SIS security risk assessment required by IEC 61511, with the 62443 zone model as the frame.
  6. Close gaps by consequence: exposed access first, then authentication and account separation, then segmentation, alarm management, and evidence automation.
  7. Audit on cycle: PSM compliance audit every three years, PHA revalidation every five, RMP updates on their schedule - with corrective actions tracked to closure, because auditors always check the last audit's findings first.

Honest effort and cost ranges - which vary widely with plant size, process count, and starting posture: a focused control-system security assessment typically runs two to eight weeks and 20,000 to 80,000 dollars with outside help; a full PSM compliance audit for a mid-size site commonly runs 30,000 to 100,000 dollars; PHA revalidations are typically staffed in team-weeks per process unit. Remediation spans from free configuration discipline to capital projects for segmentation or SIS upgrades. Integrating cyber into existing PSM cycles is far cheaper than running a parallel program - the auditors are already coming; give them one coherent evidence trail.

What to Look For in a SCADA Vendor for Chemical Plants

The distinctive demand in this industry is change-governed control. Generic security features are table stakes; a chemical facility should additionally require:

This list is not hypothetical. Merobix ships management-of-change and pre-startup safety review gates (where configured), explicit writable-tag configuration with setpoint bounds checking and validation before dispatch, role and competency checks on control actions, step-up authentication for high-risk workflows such as permit signing, command states with read-back verification where supported, and immutable audit records of commands and acknowledgements - behind an outbound-only gateway that leaves nothing listening at the plant. On assurance, Merobix runs a SOC 2 readiness program, maps its controls to IEC 62443, and treats independent penetration testing as part of its ongoing validation program. The architecture is documented on our security page, and you can walk a live MOC-gated setpoint change in a demo.

Key takeaway: In a chemical plant, cybersecurity and process safety are the same discipline wearing different badges. An unauthorized setpoint change is simultaneously a security incident, an MOC violation, and a potential loss-of-containment precursor - so buy a SCADA platform where the change controls are enforced by the software, not just described in the binder. CFATS may be lapsed, but OSHA's audit cycle is not, and IEC 61511 has already made SIS security assessment an engineering obligation.

Chemical facilities rarely stand alone in a compliance program - if your operation also runs batch pharma lines or discrete manufacturing, the same platform decisions ripple into pharmaceutical SCADA compliance under 21 CFR Part 11 and the framework choices manufacturers face between ISO 27001, NIST CSF, and IEC 62443.

Frequently Asked Questions

Is CFATS still in effect for chemical facilities?

No - the statutory authority for the Chemical Facility Anti-Terrorism Standards lapsed on July 28, 2023, when Congress failed to reauthorize the program, and as of 2026 it has not been restored. CISA can no longer enforce CFATS obligations such as Top-Screen submissions or site security plan approvals, and instead offers the voluntary ChemLock program. Most established operators have kept their CFATS-era security programs running anyway, because the underlying risk did not lapse, reauthorization proposals keep circulating, and Risk-Based Performance Standard 8 (cyber) remains a widely used benchmark for chemical-sector cybersecurity programs.

Does OSHA PSM apply to chemical plant SCADA systems?

Yes, in several concrete ways. OSHA's Process Safety Management standard (29 CFR 1910.119) applies to facilities with threshold quantities of highly hazardous chemicals, and its elements reach the control system directly: process safety information must document control system design, management of change applies to modifications of controls, alarms, and setpoints - not just piping - pre-startup safety reviews must confirm systems are ready before hazardous startup, mechanical integrity covers instrumentation and interlocks, and process hazard analyses must consider control system failures. Unauthorized or unreviewed changes to SCADA configuration are exactly the kind of change PSM exists to prevent, which is why change-gated control workflows matter.

What is the difference between IEC 61511 and IEC 62443?

IEC 61511 is the functional safety standard for safety instrumented systems (SIS) in the process industries: it governs how safety functions are specified, designed to safety integrity levels (SIL 1 through 4), validated, and maintained so they work on demand. IEC 62443 is the cybersecurity standard series for industrial automation: zones and conduits, security levels, and requirements for vendors and operators. They meet in the middle - IEC 61511 explicitly requires a security risk assessment of the SIS, and 62443 supplies the methodology for it. In short: 61511 protects against accidents, 62443 protects against attackers, and a modern chemical plant needs both, engineered so the SIS remains independent of, and protected from, the control network.

How often are PSM audits and PHA revalidations required?

OSHA PSM requires a compliance audit at least every three years, certifying that procedures and practices under the standard are adequate and followed, with the two most recent audit reports retained. Process hazard analyses must be revalidated at least every five years. EPA's Risk Management Program mirrors these cycles for covered processes on the environmental side. For the control system this means a standing evidence obligation: audit trails of setpoint and configuration changes, management-of-change records, alarm system performance, and operator training records are all fair game for auditors, and gaps in electronic records are findings waiting to be written.

What should a chemical plant require from a SCADA vendor?

Require controls that map to the sector's stack: change-governed control (management-of-change and pre-startup safety review gates on control actions where configured), explicit writable-tag allowlists with setpoint bounds checking, role and competency checks before commands, full audit records of every command and acknowledgement, unique named accounts with MFA, and no inbound network exposure at the plant. Ask how the platform keeps the SIS independent (monitor the safety layer, never write to it through the same path), how alarm delivery is assured, and what evidence exports exist for PSM audits. Finally, probe the vendor's own assurance program - security development practices, testing, and how claims are validated.

Sources & Further Reading

Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.

Change-Governed Control, Enforced by Software

MOC and PSSR gates, setpoint bounds, command audit chains, and zero inbound exposure - see how Merobix fits PSM-covered processes.

Request a Demo → See Our Security Architecture
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →