What API 1164 Compliance Work Involves
Reading what API 1164 is takes an afternoon; doing the work it implies takes a program. This page is about the work - the profile selection, risk assessment, control implementation, and evidence that aligning pipeline SCADA to API 1164 actually requires - for the OT security or controls lead who has to execute rather than explain. It focuses on the doing, not on re-explaining the standard's structure.
API 1164 Compliance Work in one line: API 1164 compliance work is a program, not a document review. In practice it means scoping the pipeline SCADA system, selecting the appropriate security profile for the environment, running a risk assessment, implementing and documenting the resulting controls, and maintaining the evidence and reassessment cadence over time. The profile-based approach lets you scale the effort to the system's risk rather than applying one flat checklist.
Scope the System and Pick the Profile
The first real task is defining what you are securing. Inventory the pipeline SCADA components - control room, communications, field devices, and the interfaces between them - because you cannot assess or protect what you have not scoped. This is the same asset-inventory discipline any OT security baseline starts from.
API 1164's profile-based approach then lets you match the depth of controls to the system's risk rather than applying a single flat standard everywhere. Selecting the right profile is a judgment call that a risk assessment should inform, and it is where the work is scaled up for a high-consequence transmission line or scaled down for a lower-risk asset.
Assess Risk and Implement Controls
With scope and profile set, the assessment work identifies threats and vulnerabilities against the SCADA environment and prioritizes them. The output is a set of controls to implement - access control, network segmentation, monitoring, patching discipline, and incident response among them. Each control is a project, not a checkbox, and the assessment is what keeps effort focused on real risk rather than a generic list.
This is also where API 1164 connects to the wider regulatory and standards picture. It aligns conceptually with the broader OT security framework of IEC 62443 and with the pipeline-specific expectations captured in the TSA pipeline security directives. Doing the 1164 work well usually satisfies much of the overlapping expectation, which is why operators map their controls across all three rather than duplicating effort.
Maintain Evidence and Reassess
Compliance is not a one-time state. The controls have to be operated, monitored, and evidenced - and the risk reassessed as the system, the threat landscape, and the pipeline change. The unglamorous deliverable is a maintained body of evidence: the asset inventory, the risk assessment, the control documentation, and the records showing controls are actually operating.
For cloud or hosted pipeline SCADA, part of this evidence lives with the platform provider and part with the operator, so the work includes understanding that shared-responsibility split. What the provider secures versus what the operator must configure and monitor should be documented explicitly, because an auditor will ask who owns which control.
Common Misconceptions
The first misconception is that a product can be 'API 1164 certified.' API 1164 describes an operator's security program for pipeline SCADA; there is no product certification that discharges the operator's own risk-assessment and control work. A vendor can support alignment, but the program is the operator's.
The second is that 1164, IEC 62443, and the TSA directives are three separate projects. They overlap heavily. Treating them as one mapped program - do the work once, evidence it against each - saves enormous effort compared with three parallel binders that say nearly the same thing.
Frequently Asked Questions
Can a SCADA product be API 1164 certified?
No. API 1164 describes the security program an operator maintains for pipeline SCADA. There is no product certification that removes the operator's obligation to scope, assess, and control their own environment. Vendors can support alignment but cannot discharge it.
What is the profile-based approach in API 1164?
It lets an operator match the depth of security controls to the risk of the specific SCADA environment rather than applying one flat standard everywhere. A higher-risk system takes a more demanding profile; a lower-risk one takes a lighter profile, informed by a risk assessment.
How does API 1164 relate to the TSA pipeline directives?
They overlap substantially. API 1164 provides a pipeline-SCADA security framework that aligns with the pipeline-specific TSA security directives and with IEC 62443. Operators typically map their controls across all three and do the work once rather than in parallel.
Sources and verification
This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.
- ISA/IEC 62443 Series of Standards - International Society of Automation
- API Standard 1164, Pipeline Control Systems Cybersecurity - American Petroleum Institute (3rd ed., 2021)
Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.
Automation services
Need help turning this into a working system?
Merobix integrates SCADA, programs Allen-Bradley and Siemens PLCs, and designs and fabricates industrial control panels.
Meeting requests are reviewed before confirmation.