OT, IoT & Physical Security

OT Security: Vendor Assessment Checklist

Published 16 Sep 2026
12 min read
OT Security: Vendor Assessment Checklist

Every third-party connection you allow into an Operational Technology (OT) environment can carry risk your safety systems were not designed to absorb. A checklist for evaluating third-party vendor security in OT environments gives your team a repeatable, defensible process for catching gaps before they reach a Safety Instrumented System (SIS) or a Distributed Control System (DCS). This article walks you through a practical vendor security assessment workflow, a weighted scoring rubric you can adapt, and the common pitfalls that undermine even mature programs. You will also find a tools comparison table and a mapping to recognized standards. Whether you run a refinery, a water treatment plant, or a discrete manufacturing line, these steps help you hold vendors to the same safety bar you set for your own operations.


Table of Contents

  1. What Is Third-Party Vendor Security in OT?
  2. Why It Matters for Security Teams
  3. How to Evaluate Third-Party OT Security Step by Step
  4. Template: Weighted Vendor Security Scoring Rubric
  5. Best Practices
  6. Tools Comparison
  7. Real-World Example (Illustrative Scenario)
  8. Common Pitfalls in OT Vendor Compliance
  9. FAQ
  10. Next Steps

What Is Third-Party Vendor Security in OT?

Third-party vendor security in OT refers to the controls, assessments, and contractual requirements you apply to any external organization that touches your industrial control systems. This includes system integrators, equipment manufacturers, remote-support providers, and managed-service firms. Unlike pure-IT third-party risk management, the OT side must account for real-time process constraints, legacy protocols that lack authentication, and safety-critical functions where availability outweighs confidentiality.

NIST SP 800-82 Rev. 3 defines OT as "programmable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment)" [1]. The NIST Cybersecurity Framework (CSF) 2.0 addresses third-party risk explicitly in its GV.SC (Cybersecurity Supply Chain Risk Management) category, which calls for organizations to identify, establish, manage, monitor, and improve supply chain cybersecurity risk management processes [2].

In practice, this means you treat every vendor laptop, every firmware update, and every remote-access session as an attack surface you must govern.

Why It Matters for Security Teams

A misconfigured vendor update to a SIS controller can potentially disable the last layer of protection between a process upset and a physical incident. Supply chain security in OT is not an abstract compliance exercise — it is a safety discipline.

NIS 2 Directive Article 21(2)(d) lists "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers" as one of the ten mandatory cybersecurity risk-management measures [3]. CIS Controls v8.1 dedicates Control 15 (Service Provider Management) to establishing and maintaining a process for evaluating service providers who hold sensitive data or are responsible for critical IT or OT platforms [4].

In practice, this means that if a vendor with remote access to your Programmable Logic Controllers (PLCs) gets compromised, you inherit that compromise inside your safety perimeter.


How to Evaluate Third-Party OT Security Step by Step

The workflow below turns a vendor security assessment from a one-time questionnaire into a continuous governance cycle.

Five-step OT vendor security assessment workflow infographic showing prerequisites through scoring in glassmorphism style
An editorial-quality infographic illustrating the continuous OT vendor security assessment workflow described in the article. It maps the five key stages from preparation through scoring and decision, using a numbered horizontal flow layout with frosted glass panels on a dark navy background. Each step includes a concise label and a clean line icon, making the governance cycle easy to follow at a glance.

Prerequisites and Setup

Before you send a single questionnaire, complete these preparation tasks:

Preparation Task Purpose
Inventory every vendor with OT access (CIS Control 1 — Inventory and Control of Enterprise Assets) Know who can touch what
Classify each vendor by access tier (read-only telemetry, configuration access, safety-system access) Focus assessment depth where risk concentrates
Define your risk-acceptance criteria with plant management and safety engineering Establish the threshold for blocking or remediating
Gather your reference standards (NIST SP 800-82 Rev. 3, IEC 62443 series, your internal OT policy) Ensure consistent evaluation baseline

Step 1 — Issue a Structured Security Questionnaire

Build your questionnaire around seven domains that map to the checklist for evaluating third-party vendor security in OT environments:

  1. Network architecture and segmentation — Does the vendor enforce a demilitarized zone (DMZ) between enterprise and control networks?
  2. Authentication and access control — Does the vendor support multi-factor authentication (MFA) for all remote sessions?
  3. Patch and firmware management — What is the vendor's documented process for qualifying and deploying patches on safety-critical devices?
  4. Incident response — Does the vendor maintain a documented incident response plan that includes notification timelines?
  5. Data handling and encryption — How is engineering data (logic files, configuration backups) protected in transit and at rest?
  6. Personnel security — Does the vendor perform background checks and role-based access reviews?
  7. Compliance and certification — Does the vendor hold relevant certifications (e.g., IEC 62443-4-1 for product development, ISO/IEC 27001:2022 for ISMS)?

ISO/IEC 27001:2022 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system [5].

Step 2 — Conduct a Technical Validation

Questionnaire answers are claims. Validate them:

  • Review network architecture diagrams the vendor supplies; compare them against your own boundary documentation.
  • Verify that the vendor's remote-access solution terminates inside a monitored jump host in the OT DMZ, not directly on a controller subnet.
  • Request evidence of patch-qualification testing on representative hardware or a staging environment.
  • If the vendor ships firmware, confirm they sign updates cryptographically and that your asset-management tooling verifies signatures before deployment.

Step 3 — Score and Decide

Use the weighted rubric below to produce a quantified, comparable score for each vendor. Vendors that fall below your organization's agreed risk threshold require a remediation plan before access is granted or renewed.

In practice, this means that a vendor with excellent network segmentation but no incident response plan receives a score that reflects the gap — and you can trace the decision back to documented criteria.


Template: Weighted Vendor Security Scoring Rubric

This rubric is an original artifact you can adapt to your environment. Adjust weights to reflect your plant's risk profile: a facility with extensive remote access may weight the access-control domain higher, while a site with frequent firmware updates may increase the patch-management weight.

Domain Weight 0 — Not Addressed 1 — Partial 2 — Meets Baseline 3 — Exceeds Baseline
Network segmentation 20% No DMZ; flat network DMZ exists but not monitored DMZ monitored; vendor isolated to jump host Microsegmentation with protocol-aware firewalls
Authentication & access 20% Shared credentials Individual accounts, no MFA MFA enforced; session recording MFA + just-in-time access with time-bound tokens
Patch & firmware management 15% No documented process Ad-hoc patching Qualification testing on staging environment Signed firmware; automated verification
Incident response 15% No plan Generic IT plan; no OT specifics OT-specific plan; notification within 24 hours Joint exercises with asset owner; playbooks tested
Data handling & encryption 10% No encryption Encryption in transit only Encryption at rest and in transit Hardware security modules (HSMs) for key storage
Personnel security 10% No checks Background checks at hire only Annual reviews; role-based access Continuous vetting; privileged-access reviews
Compliance & certification 10% No certifications Partial IEC 62443 ISO/IEC 27001:2022 certified IEC 62443-4-1 certified + independent audit

How to use: Score each domain 0–3, multiply by the weight, and sum. A perfect score is 3.00. Define your decision thresholds in advance — for example, any vendor scoring below 1.50 overall or scoring 0 in any safety-critical domain (network segmentation, authentication, patch management) triggers a mandatory remediation plan before access is approved. The exact threshold depends on your organization's risk appetite and the access tier involved.


Best Practices

  • Embed vendor security assessment into procurement. The assessment should start before contract signature, not after the vendor is already on-site.
  • Require contractual security obligations. Include patching SLAs, breach-notification timelines, and the right to audit in master service agreements.
  • Reassess on a defined cadence. Annual reassessment is a common baseline, with triggered reassessments after significant vendor changes (mergers, product end-of-life, security incidents).
  • Maintain a vendor risk register. Track each vendor's current score, open findings, and remediation deadlines alongside your asset inventory.
  • Align with NIST SP 800-161 Rev. 1. This publication provides cybersecurity supply chain risk management practices for systems and organizations [6].

NIST SP 800-53 Rev. 5 control family SA (System and Services Acquisition) includes controls for supply chain risk management that complement the vendor assessment process [7].

In practice, this means your vendor risk register becomes a living document reviewed in monthly OT security governance meetings, not a spreadsheet filed after the initial assessment.


Tools Comparison

Tool Primary Function OT Relevance License
Nessus Vulnerability scanning OT plugins for SCADA/ICS devices; use in passive or credentialed mode to avoid disruption Commercial
Claroty xDome OT asset discovery and risk scoring Purpose-built for ICS/SCADA; maps vendor connections and firmware versions Commercial
Dragos Platform OT threat detection and asset visibility ICS-specific threat intelligence; identifies vendor-related indicators of compromise Commercial
Nozomi Networks Guardian OT network monitoring Deep packet inspection for industrial protocols (Modbus, DNP3, EtherNet/IP) Commercial
OpenVAS Vulnerability scanning Free alternative; requires careful tuning to avoid active-scan disruption in OT Open source
Wireshark Packet capture and protocol analysis Verify vendor traffic stays within expected protocol boundaries Open source
OT security tools comparison infographic showing six tools across function, OT relevance, and license type in glassmorphism style
A structured comparison infographic presenting six OT and ICS security tools featured in the article's tools comparison section. Laid out as a two-column card grid, the infographic captures each tool's primary function, OT relevance, and license type — commercial or open source — using the article's real terminology. Frosted glass cards on a dark navy background with yellow and green brand accents make the distinctions between purpose-built OT platforms and general-purpose tools immediately clear.

Real-World Example (Illustrative Scenario)

⚠️ Disclaimer: The following scenario is an illustrative example based on typical industry patterns. The specific metrics are hypothetical estimates designed to demonstrate realistic outcomes, not measured data from a documented project. They should not be cited as factual benchmarks.

Context: A mid-sized water utility with 12 remote sites relies on four OT vendors for SCADA maintenance, PLC programming, telemetry, and chemical-dosing system support. Before implementing a structured assessment program, vendor access was governed by informal trust relationships and shared VPN credentials.

Challenge: An internal audit revealed that two vendors retained persistent VPN access with shared credentials, and one vendor's laptop had outdated antivirus signatures. No contractual clause required breach notification. The operations team had no visibility into which vendor sessions touched safety-critical controllers.

Solution: The security team deployed the weighted scoring rubric described above, issued structured questionnaires to all four vendors, and validated responses with network-architecture reviews and a passive traffic analysis using Wireshark on the OT DMZ. They also renegotiated contracts to include patch SLAs, 24-hour breach notification, and the right to audit. Remote access was migrated from persistent VPN to a monitored jump host with MFA and session recording.

Results (illustrative estimates):

  • Vendor access incidents reduced by approximately 70% in the first assessment cycle (illustrative)
  • Mean time to detect unauthorized vendor sessions decreased from days to under 2 hours (illustrative)
  • Compliance coverage against CIS Control 15 improved from partial to substantially implemented (illustrative)
  • Two vendors were placed on remediation plans; one achieved full compliance within 90 days (illustrative)

Key Takeaways:

  • A structured rubric transforms a subjective trust judgment into a documented, repeatable decision.
  • Passive network monitoring validates vendor claims without risking process disruption.
  • Contractual enforcement is as important as technical controls — without breach-notification clauses, you may learn about a vendor compromise only after its effects reach your control network.

Common Pitfalls in OT Vendor Compliance

These mistakes are among the most frequent failure modes observed across OT vendor compliance programs:

  1. Treating the questionnaire as the assessment. A completed questionnaire is a starting point. Without technical validation (network-diagram review, traffic analysis, credential audit), you are trusting self-reported answers with no verification.

  2. Granting persistent remote access. Persistent VPN tunnels that remain open 24/7 give an attacker who compromises the vendor a standing path into your OT network. Use time-bound, just-in-time access that requires approval for each session.

  3. Ignoring safety-system boundaries. Vendors who maintain standard PLCs often receive the same access level as those who maintain SIS controllers. Failing to differentiate access tiers by safety criticality can expose your highest-consequence assets to the lowest-maturity vendor.

  4. Forgetting firmware supply chain integrity. A vendor may patch on schedule but deliver unsigned firmware over unencrypted channels. Without cryptographic verification, you cannot distinguish a legitimate update from a tampered one.

  5. Skipping reassessment after vendor changes. A vendor's security posture can shift overnight due to mergers, staff turnover, or infrastructure changes. A one-time assessment becomes stale if you do not reassess on a defined cadence or after material events.

  6. Omitting OT-specific incident response requirements. Many vendor contracts reference generic IT incident response plans. An OT incident involving a process-safety system demands different escalation paths, different containment strategies (you may not be able to isolate the device without shutting down a process), and different notification timelines.


Next Steps

  1. Download and adapt the scoring rubric to your plant's risk profile. Adjust domain weights to reflect your most critical access tiers and process-safety boundaries.
  2. Inventory your current vendor connections by mapping every active remote-access path and classifying vendors by access tier.
  3. Issue your first structured questionnaire to your highest-tier vendors — those with access to safety-critical systems — and schedule technical validation within 30 days.
  4. Review NIST SP 800-82 Rev. 3 [1] and NIST SP 800-161 Rev. 1 [6] for supplementary guidance on OT security architecture and supply chain risk management.
  5. Embed the vendor assessment into your procurement workflow so that no new vendor gains OT access without a documented, scored evaluation.

Sources

[1] NIST, "Guide to Operational Technology (OT) Security," NIST Special Publication 800-82 Rev. 3, National Institute of Standards and Technology, 2023. [Online]. Available: https://csrc.nist.gov/pubs/sp/800/82/r3/final

[2] NIST, "The NIST Cybersecurity Framework (CSF) 2.0," NIST Cybersecurity White Paper 29, National Institute of Standards and Technology, 2024. [Online]. Available: https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final

[3] European Parliament and Council, "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive)," 2022. [Online]. Available: https://eur-lex.europa.eu/eli/dir/2022/2555/oj

[4] Center for Internet Security, "CIS Critical Security Controls Version 8.1," 2024. [Online]. Available: https://www.cisecurity.org/controls/v8-1

[5] ISO/IEC, "ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements," 2022. [Online]. Available: https://www.iso.org/standard/82875.html

[6] NIST, "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations," NIST Special Publication 800-161 Rev. 1, National Institute of Standards and Technology, 2022. [Online]. Available: https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final

[7] NIST, "Security and Privacy Controls for Information Systems and Organizations," NIST Special Publication 800-53 Rev. 5, National Institute of Standards and Technology, 2020. [Online]. Available: https://csrc.nist.gov/pubs/sp/800/53/r5/final

FAQ

What should an OT vendor security checklist cover? +

It should cover at minimum: network segmentation, authentication and access control, patch and firmware management, incident response, data handling, personnel security, and compliance certifications. The weighted rubric above maps these domains to a quantified scoring model.

How do you evaluate third-party OT security when the vendor resists sharing architecture details? +

Resistance to transparency is itself a risk signal. You can mitigate information gaps by conducting passive network monitoring on your side of the connection, reviewing the vendor's publicly available certifications, and including contractual audit rights that compel disclosure.

What is an industrial control vendor assessment and how does it differ from an IT vendor assessment? +

An industrial control vendor assessment evaluates the same security domains as an IT assessment but adds OT-specific criteria: safety-system boundaries, real-time availability requirements, legacy protocol support (Modbus, DNP3), firmware integrity, and the physical consequences of a security failure. NIST SP 800-82 Rev. 3 provides guidance on tailoring security assessments to OT environments [1].

Is there a supply chain security OT template I can start with? +

The scoring rubric in the Template section above is a ready-to-adapt artifact. Pair it with NIST SP 800-161 Rev. 1 for a comprehensive supply chain risk management framework [6], and tailor question depth by the vendor's access tier.