You do not need a security operations center, a consulting engagement, or a six-figure budget to know where your OT security actually stands. You need an honest afternoon and a list that does not flinch. This is that self-audit: 30 evidence-based checks across six domains - identity and access, network and remote access, devices and gateways, data protection, detection and response, and governance - each scored one point, each answerable by a two-person team in a day. The output is a number you can track, a remediation list ordered by real risk, and a clear-eyed view of what to demand from your SCADA vendor versus what only you can fix.
Part of our SCADA security guide library - 60+ articles on securing industrial operations.
Three rules make the difference between a useful audit and a feel-good exercise. First, score on evidence, not memory: a point is earned only if you can produce the artifact - a screenshot, a config export, a log entry, a dated test record. "I'm pretty sure MFA is on" is a zero. Second, one point per item, no partial credit: partial credit is how 12-point programs report themselves as 25s. Third, write down the gap while you are looking at it - the remediation list you build during scoring is worth more than the score.
The checklist draws on the control families that recur across NIST SP 800-82 Rev. 3, the ISA/IEC 62443 series, and the CISA cross-sector performance goals, compressed to what a small team can actually verify. It applies whether your SCADA is on-premise, cloud, or hybrid - items your platform vendor should be answering for you are flagged as vendor questions, and our 50 vendor security questions covers that side of the fence in full. Interpret your total with this rubric:
| Score | What It Means | What to Do Next |
|---|---|---|
| 0–14 | Foundational gaps - likely including exposed access paths, shared logins, or untested backups | Stop planning, start fixing: the five highest-risk items below, this quarter |
| 15–22 | Typical mid-maturity operation - core hygiene present, discipline uneven | Work the remediation list top-down; re-score in six months |
| 23–27 | Strong program by most industry standards | Shift energy to drills, reviews, and independent validation |
| 28–30 | Excellent - or optimistically scored | Have someone outside the team re-check the evidence; consider a professional assessment |
If a customer, insurer, or regulator later asks which standard your self-audit follows, the honest answer is "the intersection of several." Items 1–5 and 26–30 track the identification, access control, and governance functions of the NIST Cybersecurity Framework and the account-management expectations that appear in every IEC 62443 conversation about asset owners. Items 6–10 are the zone-and-conduit segmentation model of IEC 62443-3-2 and the network architecture chapters of NIST SP 800-82. Items 11–15 correspond to component and device hardening themes from 62443-4-2, and items 16–25 line up with the data protection, detection, and response functions that CISA's cross-sector cybersecurity performance goals distilled for operators without security teams. None of this makes a self-audit a certification - but it does mean the evidence folder you build here becomes the starting inventory for any formal assessment you pursue later, from a 62443 gap analysis to an insurer's questionnaire, instead of starting that work from a blank page.
Prioritize by risk, not by domain order. One internet-exposed HMI (item 6) outweighs five missing documents; fix exposure, MFA, shared accounts, backup restores, and lockout alerting before anything else on the list. Then work the remainder as a standing backlog - one or two items per month is a realistic pace for a small team, and it compounds fast. Re-run the audit twice a year and after major changes, and track the trajectory rather than worshiping the number. If you are a three-person operation wondering how any of this is feasible without headcount, the honest answer is that platform choice does a third of the list for you - a cloud platform with MFA, roles, signed telemetry, audit trails, and alerting built in converts a dozen of these items from projects into defaults, which is the argument laid out in SCADA security for small operators.
Key takeaway: a self-audit's value is not the score - it is the honest, evidence-backed remediation list it forces into existence. Thirty questions, one day, no consultants: you will finish knowing your five most dangerous gaps, and most operations can close all five inside a quarter. Merobix was built so that many of these items are platform defaults rather than customer projects - see the security architecture, or walk the checklist against the live platform in a demo.
Use a structured checklist, answer from evidence rather than memory, and score honestly. This guide's 30 points cover six domains - identity and access, network and remote access, devices and gateways, data protection, detection and response, and governance and vendors. For each item, award the point only if you can produce the evidence: a screenshot, a config export, a log entry, a dated document. A two-person team - one operations, one IT - can complete the exercise in a day, and the output doubles as a prioritized remediation list.
Twice a year as a rhythm, plus after any significant change - a new site, a SCADA migration, a vendor switch, an incident, or a major staffing change. Some items deserve their own faster cadence: user access reviews are commonly quarterly, and backup restore tests should happen at least quarterly as well. The score matters less than the trajectory; a 19 that was a 14 six months ago is a healthy program, while a 24 that nobody can evidence is theater.
As a rough band: below 15 means foundational gaps that deserve urgent attention - typically exposed remote access, shared accounts, or untested backups; 15 to 22 is a typical mid-maturity operation with a clear remediation list; 23 to 27 is a strong program by most industry standards; 28 or higher usually indicates either genuine excellence or optimistic self-scoring - re-check the evidence. Prioritize by risk, not score: one exposed inbound port outweighs five missing policy documents.
If you can only fix five things, fix these in order: eliminate internet-exposed inbound access to OT (VPN-less port forwarding, exposed HMIs and VNC/RDP); enforce MFA on every remote account; eliminate shared logins so every action traces to a person; prove a backup restore actually works before ransomware asks; and turn on lockout plus alerting for repeated failed logins. These five close the doors most real-world industrial incidents walk through.
No - it complements one. A self-audit finds the gaps you can see and fixes the cheap ones, which makes a later professional assessment dramatically more valuable because the assessors spend time on subtle problems instead of re-discovering missing MFA. Standards like IEC 62443 and guidance like NIST SP 800-82 expect periodic independent assessment for higher-criticality environments, and self-audits keep you honest between them. Run the self-audit first; bring in professionals when the obvious list is closed.
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
MFA, roles, unique device identities, signed telemetry, audit trails, and alerting - built into the platform so your self-audit starts from twenty, not zero.