Chemical plant SCADA compliance means facing a regulatory stack unlike any other industry: a federal security program in limbo (CFATS), two overlapping process-safety regimes with real audit cycles (OSHA PSM and EPA RMP), and a functional-safety standard (IEC 61511) that now explicitly demands cybersecurity for safety instrumented systems. Your SCADA platform sits in the middle of all of it - every setpoint change is a potential management-of-change event, every alarm record is potential audit evidence, and every remote-access path is a potential finding. This guide maps which standards actually apply, explains the audit processes and their three- and five-year cycles, gives honest cost and timeline ranges, and lays out what to demand from a SCADA vendor before it touches a covered process.
Part of the Merobix OT security guide collection - vendor vetting to industry compliance.
Three drivers push cybersecurity and record-keeping obligations onto chemical plant SCADA and control systems. First, counter-terrorism security: the CFATS program regulated facilities holding chemicals of interest until its 2023 lapse, and its risk-based performance standards still shape sector practice. Second, process safety law: OSHA PSM and EPA RMP bind facilities with threshold quantities of hazardous chemicals, and both reach the control system through management of change, process safety information, and audit requirements. Third, engineering standards: IEC 61511 governs safety instrumented systems and now explicitly requires security risk assessment, while the IEC 62443 series published by ISA and IEC defines what a secure control architecture looks like. Insurers, corporate customers, and joint-venture partners increasingly ask for evidence against all three layers, regardless of what the law currently compels.
The Chemical Facility Anti-Terrorism Standards required high-risk facilities holding chemicals of interest to submit Top-Screens, develop site security plans, and satisfy eighteen Risk-Based Performance Standards - including RBPS-8, the cyber standard covering access control, monitoring, incident response, and training for systems that monitor or control chemicals of interest. On July 28, 2023, the program's statutory authority expired when Congress did not reauthorize it, and as of mid-2026 it has not been restored. CISA cannot currently enforce CFATS obligations and instead runs the voluntary ChemLock assistance program.
Treat the lapse as procedural, not substantive. The threat CFATS addressed did not expire with it, reauthorization bills keep appearing, and a facility that dismantled its security program would face an expensive rebuild if authority returns - likely with less goodwill from regulators. Practically: keep the CFATS-era program alive, use RBPS-8 as your cyber benchmark for systems touching chemicals of interest, and document continuity so any future re-registration is a filing exercise rather than a project.
OSHA's Process Safety Management standard (29 CFR 1910.119) applies to processes holding threshold quantities of highly hazardous chemicals, and several of its fourteen elements land directly on the control system:
EPA's Risk Management Program (40 CFR Part 68) mirrors PSM for offsite consequences, and its 2024 amendments tightened prevention-program expectations for covered processes. If PSM applies to you, assume RMP does too, and run one integrated program.
IEC 61511 - maintained with ISA's ISA84 committee and available for purchase from ISA and IEC - is the process-sector functional safety standard: it governs how safety instrumented functions are specified, designed to a safety integrity level (SIL 1 through 4), independently validated, and proof-tested so they work on demand. Its relevance to a SCADA evaluation is twofold. First, independence: the SIS must remain functionally separate from the basic process control system, so a SCADA failure - or compromise - cannot disable the layer that prevents the worst outcome. Your monitoring platform should observe SIS status, never write to it through the same pathway operators use for process control. Second, security: the current edition of IEC 61511 explicitly requires a security risk assessment of the SIS, and points to IEC 62443 methodology to perform it. The 2017 Triton/TRISIS incident - malware built specifically to manipulate safety controllers at a petrochemical plant, documented in CISA's HatMan malware analysis report - is the case study that turned that clause from paperwork into practice.
The division of labor is worth stating plainly: 61511 protects against accidents; 62443 protects against attackers. A chemical plant needs both, engineered together - zones and conduits that isolate the SIS, control networks that accept no inbound connections, and monitoring that can see both layers without weakening either. Our guides to securing SCADA on OT networks and chemical plant SCADA monitoring cover the architecture side in depth.
| Standard / Rule | Issued By | Status / Legal Force | What It Demands of SCADA |
|---|---|---|---|
| CFATS / RBPS-8 | CISA (DHS) | Lapsed July 2023; voluntary ChemLock continues | Cyber controls for systems monitoring or controlling chemicals of interest: access control, monitoring, incident response |
| OSHA PSM (1910.119) | OSHA | Binding for threshold quantities | PSI documentation, MOC on control changes, PSSR, mechanical integrity records, 3-year audits |
| EPA RMP (Part 68) | EPA | Binding for covered processes; 2024 amendments | Mirrors PSM for offsite risk; prevention program and audit evidence |
| IEC 61511 / ISA 84 | IEC / ISA | Industry standard; referenced as good engineering practice | SIS independence, SIL-rated design, proof testing, and a security risk assessment of the SIS |
| IEC 62443 | IEC / ISA | Voluntary; contractual and insurance-driven | Zones and conduits, security levels, vendor and component security requirements |
Honest effort and cost ranges - which vary widely with plant size, process count, and starting posture: a focused control-system security assessment typically runs two to eight weeks and 20,000 to 80,000 dollars with outside help; a full PSM compliance audit for a mid-size site commonly runs 30,000 to 100,000 dollars; PHA revalidations are typically staffed in team-weeks per process unit. Remediation spans from free configuration discipline to capital projects for segmentation or SIS upgrades. Integrating cyber into existing PSM cycles is far cheaper than running a parallel program - the auditors are already coming; give them one coherent evidence trail.
The distinctive demand in this industry is change-governed control. Generic security features are table stakes; a chemical facility should additionally require:
This list is not hypothetical. Merobix ships management-of-change and pre-startup safety review gates (where configured), explicit writable-tag configuration with setpoint bounds checking and validation before dispatch, role and competency checks on control actions, step-up authentication for high-risk workflows such as permit signing, command states with read-back verification where supported, and immutable audit records of commands and acknowledgements - behind an outbound-only gateway that leaves nothing listening at the plant. On assurance, Merobix runs a SOC 2 readiness program, maps its controls to IEC 62443, and treats independent penetration testing as part of its ongoing validation program. The architecture is documented on our security page, and you can walk a live MOC-gated setpoint change in a demo.
Key takeaway: In a chemical plant, cybersecurity and process safety are the same discipline wearing different badges. An unauthorized setpoint change is simultaneously a security incident, an MOC violation, and a potential loss-of-containment precursor - so buy a SCADA platform where the change controls are enforced by the software, not just described in the binder. CFATS may be lapsed, but OSHA's audit cycle is not, and IEC 61511 has already made SIS security assessment an engineering obligation.
Chemical facilities rarely stand alone in a compliance program - if your operation also runs batch pharma lines or discrete manufacturing, the same platform decisions ripple into pharmaceutical SCADA compliance under 21 CFR Part 11 and the framework choices manufacturers face between ISO 27001, NIST CSF, and IEC 62443.
No - the statutory authority for the Chemical Facility Anti-Terrorism Standards lapsed on July 28, 2023, when Congress failed to reauthorize the program, and as of 2026 it has not been restored. CISA can no longer enforce CFATS obligations such as Top-Screen submissions or site security plan approvals, and instead offers the voluntary ChemLock program. Most established operators have kept their CFATS-era security programs running anyway, because the underlying risk did not lapse, reauthorization proposals keep circulating, and Risk-Based Performance Standard 8 (cyber) remains a widely used benchmark for chemical-sector cybersecurity programs.
Yes, in several concrete ways. OSHA's Process Safety Management standard (29 CFR 1910.119) applies to facilities with threshold quantities of highly hazardous chemicals, and its elements reach the control system directly: process safety information must document control system design, management of change applies to modifications of controls, alarms, and setpoints - not just piping - pre-startup safety reviews must confirm systems are ready before hazardous startup, mechanical integrity covers instrumentation and interlocks, and process hazard analyses must consider control system failures. Unauthorized or unreviewed changes to SCADA configuration are exactly the kind of change PSM exists to prevent, which is why change-gated control workflows matter.
IEC 61511 is the functional safety standard for safety instrumented systems (SIS) in the process industries: it governs how safety functions are specified, designed to safety integrity levels (SIL 1 through 4), validated, and maintained so they work on demand. IEC 62443 is the cybersecurity standard series for industrial automation: zones and conduits, security levels, and requirements for vendors and operators. They meet in the middle - IEC 61511 explicitly requires a security risk assessment of the SIS, and 62443 supplies the methodology for it. In short: 61511 protects against accidents, 62443 protects against attackers, and a modern chemical plant needs both, engineered so the SIS remains independent of, and protected from, the control network.
OSHA PSM requires a compliance audit at least every three years, certifying that procedures and practices under the standard are adequate and followed, with the two most recent audit reports retained. Process hazard analyses must be revalidated at least every five years. EPA's Risk Management Program mirrors these cycles for covered processes on the environmental side. For the control system this means a standing evidence obligation: audit trails of setpoint and configuration changes, management-of-change records, alarm system performance, and operator training records are all fair game for auditors, and gaps in electronic records are findings waiting to be written.
Require controls that map to the sector's stack: change-governed control (management-of-change and pre-startup safety review gates on control actions where configured), explicit writable-tag allowlists with setpoint bounds checking, role and competency checks before commands, full audit records of every command and acknowledgement, unique named accounts with MFA, and no inbound network exposure at the plant. Ask how the platform keeps the SIS independent (monitor the safety layer, never write to it through the same path), how alarm delivery is assured, and what evidence exports exist for PSM audits. Finally, probe the vendor's own assurance program - security development practices, testing, and how claims are validated.
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
MOC and PSSR gates, setpoint bounds, command audit chains, and zero inbound exposure - see how Merobix fits PSM-covered processes.