Discrete and process manufacturers occupy a strange compliance position: no dedicated regulator polices your plant-floor cybersecurity, yet the pressure to prove it keeps arriving anyway - from cyber insurers who now refuse coverage without MFA and tested backups, from enterprise customers flowing security requirements down their supply chains, and from the Department of Defense if any of your parts end up in its programs. This guide explains which frameworks actually matter for manufacturing SCADA compliance - ISO 27001, NIST CSF, IEC 62443, and CMMC - how to choose between them, what the compliance process concretely looks like with honest cost and timeline ranges, and how your SCADA platform choice makes the whole exercise easier or harder.
Part of the Merobix OT security guide collection - vendor vetting to industry compliance.
Manufacturing SCADA compliance is driven by contracts, not regulators: in practice it means adopting NIST CSF as the organizing framework, applying IEC 62443 on the plant floor, and adding ISO 27001 certification or CMMC only when customers or defense contracts demand them. Power utilities have NERC CIP. Pipelines have TSA security directives. General manufacturing has - nothing equivalent. That does not mean manufacturers escape compliance; it means the obligations arrive through four commercial channels instead of one legal one:
The strategic consequence: because no regulator picks your framework for you, framework selection is your decision - and picking well saves real money, because every questionnaire you receive afterward gets answered from the same body of evidence.
The NIST Cybersecurity Framework (CSF 2.0) is a free, voluntary framework organized around six functions - Govern, Identify, Protect, Detect, Respond, Recover. It is a common language for describing your posture, not a certifiable standard. Its strength is communication: boards, insurers, and customers all understand a CSF profile. Its weakness is that "we align with NIST CSF" is unverifiable by itself.
ISO/IEC 27001 is the international standard for an information security management system (ISMS), with 93 controls in Annex A of the 2022 revision. It is the one with a real certificate: an accredited certification body audits you (stage 1 documentation review, stage 2 implementation audit), then runs annual surveillance audits on a three-year recertification cycle. Read the scope statement on any ISO 27001 certificate carefully - a certificate scoped to "corporate IT services" says nothing about the plant floor. Our ISO 27001 deep dive covers the process end to end.
IEC 62443 is the standard family written specifically for industrial automation and control systems, developed by ISA and IEC (the standard documents themselves are available for purchase from those bodies). It brings the concepts CSF and ISO 27001 lack: zones and conduits for network segmentation, four security levels (SL1–SL4) graded by attacker capability, and separate requirement sets for asset owners, integrators, and product vendors. For what happens between your PLCs, your SCADA, and your enterprise network, 62443 is the reference - see our IEC 62443 certification guide for the levels and the ISASecure-style certification schemes.
| Attribute | NIST CSF 2.0 | ISO/IEC 27001 | IEC 62443 | CMMC / NIST 800-171 |
|---|---|---|---|---|
| What it is | Voluntary risk framework, six functions | Certifiable management-system standard, 93 Annex A controls | OT/ICS-specific standard family with security levels SL1–SL4 | DoD contract requirement verifying 110 controls (Level 2) |
| Third-party certificate? | No - self-assessed profile | Yes - accredited certification bodies, 3-year cycle | Yes for products/systems (ISASecure, exida); asset owners typically assess, not certify | Yes - C3PAO assessment for most Level 2 contracts |
| Plant-floor (OT) coverage | Generic; needs OT tailoring via NIST SP 800-82 | Only if OT is explicitly in ISMS scope | Purpose-built for OT | Applies where CUI touches systems, including OT |
| Typical trigger | Insurance questionnaires, board reporting | Enterprise customer or international market demands certificate | OT risk assessments, vendor evaluation, engineering standards | Defense supply chain contracts |
| Typical first-cycle cost | Internal time; free framework | Mid five figures to low six figures, varies | Assessment and remediation costs vary widely by scope | Tens of thousands to low six figures, varies |
For most mid-market manufacturers, the annual insurance renewal is now the toughest audit of the year. Underwriting questionnaires have converged on a control set that maps directly onto your SCADA environment: multi-factor authentication on all remote access, no internet-exposed RDP or VNC, network segmentation between IT and OT, immutable or offline backups, endpoint detection, logging and monitoring, and an incident response plan. Answering "no" to the MFA or backup questions can be disqualifying by itself.
Two practical notes from the trenches. First, answer accurately - misrepresenting controls on an application has led insurers to contest claims. Second, the plant floor is where honest answers get hard: the twenty-year-old HMI with a shared operator password is the "no" on your questionnaire. This is a place where modernizing the SCADA layer directly buys back insurability - a platform with enforced MFA, named accounts, and an outbound-only gateway that needs zero inbound firewall rules converts three questionnaire noes into yeses in one project.
Enterprise customers manage their own supply-chain risk by pushing requirements downstream. Expect security addenda in supplier contracts, annual questionnaires, and - for strategic suppliers - the right to audit. The requests are converging on the same demands as insurers, plus a few specific ones: evidence of vulnerability management on production systems, notification duties after incidents (often 24–72 hours), and increasingly a certificate - ISO 27001 for general suppliers, CMMC status for defense, sometimes TISAX in automotive Europe.
The efficient response is to stop answering questionnaires one at a time and build a single evidence base: one control set (CSF or ISO 27001 organized), one document repository, one owner. Your SCADA vendor belongs in that evidence base too - when a customer asks "how is your production monitoring system secured?", the answer should quote the vendor's documented architecture. Merobix publishes its architecture openly for exactly this purpose - tenant isolation enforced with PostgreSQL row-level security, signed telemetry envelopes with replay detection, immutable audit records, and runtime threat monitoring with SIEM delivery - see the security page for the specifics you can paste into a questionnaire response.
If Department of Defense work is anywhere in your revenue - even two tiers removed through a prime - CMMC is the compliance program you do not get to choose. The CMMC Program rule (32 CFR Part 170) defines three levels: Level 1 (basic safeguarding of Federal Contract Information, annual self-assessment), Level 2 (protection of Controlled Unclassified Information - implementing the 110 controls of NIST SP 800-171 Rev. 2, with third-party assessment by a C3PAO for most contracts), and Level 3 (a subset of NIST SP 800-172 for the most sensitive programs, government-assessed). Requirements are phasing into new contracts, and primes are already demanding evidence from subcontractors ahead of the mandate.
The OT angle manufacturers miss: if CUI - drawings, specifications, technical data - flows through systems connected to your production network, those systems can land in scope. Segmenting production properly, and keeping CUI out of the SCADA environment entirely, is usually the cheapest scoping decision available. Expect a Level 2 journey to take 9–18 months for an unprepared organization; assessment and remediation costs vary from tens of thousands to low six figures depending on scope and starting point.
Honest totals: a mid-size manufacturer starting from average maturity should expect 6–12 months to a defensible CSF/62443 posture and 12–24 months to an ISO 27001 certificate covering the plant, with combined external costs anywhere from the low tens of thousands to well into six figures. Every one of those numbers varies with size, legacy debt, and scope - distrust anyone who quotes a flat price before a gap assessment.
Key takeaway: Manufacturers rarely get to certify once and be done - insurers, customers, and primes each ask in their own format. The winning move is one deliberately chosen control framework (NIST CSF organized, IEC 62443 on the plant floor, ISO 27001 certificate only when demanded, CMMC when defense revenue requires it), one evidence repository, and infrastructure choices - including your SCADA platform - that generate that evidence by default instead of by heroics.
Your SCADA platform appears in every assessment listed above. Select vendors on their ability to shrink your compliance surface:
If you are consolidating plant monitoring as part of this effort, our manufacturing SCADA monitoring guide covers the operational side, and you can walk the security architecture against your own questionnaire in a live demo.
In most cases, no - general manufacturing in the US has no equivalent of NERC CIP or TSA pipeline directives. The obligations arrive through contracts instead: defense work pulls in DFARS, NIST SP 800-171 and CMMC; automotive and aerospace customers flow down security requirements in supplier agreements; cyber insurers make controls like MFA and tested backups a condition of coverage; and manufacturers selling into or operating in the EU may fall under NIS2. The practical effect is the same as regulation - you must adopt a framework and prove it - but you get to choose which framework, which is a real strategic decision.
Start with NIST CSF as the organizing map - it is free, widely understood by customers and insurers, and lets you self-assess quickly. Layer IEC 62443 concepts onto the plant floor, because CSF alone does not address OT specifics like zones and conduits or safety-instrumented systems. Pursue ISO 27001 certification when customers or overseas markets demand third-party proof - it is the framework with a formal certificate. Defense suppliers do not get a choice: CUI on your network means NIST SP 800-171 and CMMC at the level your contracts specify. Most mid-size manufacturers land on CSF plus 62443 practices, adding ISO 27001 only when a large customer forces the issue.
Honest ranges, because it genuinely varies: certification-body fees for stage 1 and stage 2 audits typically run from around ten thousand to fifty thousand dollars depending on organization size and scope, with smaller annual surveillance audit fees in years two and three. Consultant support commonly adds ten to eighty thousand dollars for a first-time implementation, and internal effort is usually 6 to 12 months of part-time work from several people. Total first-cycle cost for a mid-size manufacturer commonly lands in the mid five figures to low six figures. Scoping is the biggest cost lever - certifying a data center and office IT while excluding the plant floor is cheaper but may not satisfy the customer who asked for the certificate, so read scope statements carefully.
CMMC (Cybersecurity Maturity Model Certification) is the US Department of Defense program that verifies contractors actually implement the security controls their contracts already required. Level 1 covers basic safeguarding for Federal Contract Information and allows annual self-assessment. Level 2 applies when you handle Controlled Unclassified Information - most machine shops and component makers in defense supply chains - and generally requires implementing the 110 controls of NIST SP 800-171, with third-party assessment for most contracts. Level 3 adds requirements from NIST SP 800-172 for the most sensitive programs. Requirements are phasing into new DoD contracts now, and primes are pushing them down to subcontractors, so if defense work matters to your revenue, a Level 2 gap assessment belongs on this year's plan, not next year's.
Your SCADA platform either produces compliance evidence for free or becomes the gap every assessment flags. Frameworks and questionnaires keep asking for the same things: unique named accounts with MFA, role-based least privilege, audit logs of operator and admin actions, encrypted communications, no exposed remote access, and monitored security events. A platform that ships those by default - for example, Merobix provides TOTP and passkey MFA, per-site role-based authorization, tamper-evident audit records, TLS everywhere, an outbound-only gateway with no inbound firewall ports, and SIEM-ready security alerting - lets you answer insurer and customer questionnaires from the product's documented behavior instead of building compensating controls around a legacy HMI.
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
MFA, named accounts, audit trails, segmentation-friendly outbound-only connectivity, SIEM alerting - see how much of your next insurance or customer questionnaire Merobix answers out of the box.