SCADA/ICS Penetration Testing Providers

SCADA/ICS penetration testing evaluates the security of industrial control systems, supervisory control and data acquisition (SCADA) systems, and operational technology (OT) environments. These systems control physical processes in critical infrastructure including power generation, water treatment, oil and gas, manufacturing, and transportation.

Testing requires specialised expertise as ICS/SCADA environments use different protocols (Modbus, DNP3, OPC, BACnet), have unique safety requirements, and often run legacy systems that cannot tolerate aggressive testing techniques. ICS pen testers assess network segmentation between IT and OT environments, the security of human-machine interfaces (HMIs), programmable logic controllers (PLCs), remote terminal units (RTUs), and engineering workstations.

Testing identifies vulnerabilities that could allow attackers to manipulate physical processes, cause safety incidents, or disrupt operations. ICS/SCADA pen testing follows specialised frameworks and standards including IEC 62443, NIST SP 800-82, and NERC CIP. This testing is increasingly critical as OT environments become more connected to IT networks and face growing threats from nation-state actors and cybercriminals targeting critical infrastructure.

Related compliance:NIS 2NIST CSFISO 27001
14 providers
Oxford, United Kingdom · Checked Sept 2026

Global enterprise cybersecurity consultancy founded in 1999 in Oxford, holding rare CREST STAR-FS accreditation and delivering penetration testing, red and purple teaming, and PCI QSA services across five international offices.

Accreditations: CREST, CHECK, STAR, ISO 27001, PCI QSA +1
Services: Web Application, Network, Red Teaming, Purple Teaming +7
London, United Kingdom · Checked Sept 2026

Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.

Accreditations: CREST, CHECK, CBEST, STAR, ISO 27001 +1
Services: Web Application, Network, IoT, Cloud +9
Birmingham, United Kingdom · Checked Sept 2026

CHECK and CREST-accredited Birmingham-based cyber security consultancy with over 15 years of experience delivering penetration testing, red teaming, and OT security assessments for government and private sector clients.

Accreditations: CREST, CHECK, ISO 27001, Cyber Essentials, Cyber Essentials Plus +1
Services: Web Application, Network, Mobile App, Cloud +7
Atlanta, Georgia, United States · Checked Sept 2026

US penetration testing firm founded in 2011, running 600+ engagements a year with a fully remote, US-based team. Manual, expert-led testing across web, network, cloud, mobile, wireless, OT/ICS, and AI/LLM. Gartner Sample Vendor for PTaaS.

Accreditations: OSCP Employer
Services: Web Application, Network, Mobile App, Cloud +12

PCA Cyber Security

PartnerEmbedded Security Specialist
Munich, Germany · Checked Sept 2026

Munich- and Budapest-based embedded cybersecurity experts focused on financial services, automotive and mobility, manufacturing and industrial automation, energy and more. The services and platform go beyond compliance, supporting the requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and other standards and regulations.

Services: IoT, Network, Source Code Review, API +11
Paris, France · Checked Sept 2026

Cybersecurity division of the Thales Group, with ANSSI, CREST, FedRAMP 3PAO, and NATO-cleared personnel. Defence, government, and critical infrastructure penetration testing worldwide.

Accreditations: CREST, FedRAMP 3PAO, ISO 27001, ISO 9001
Services: Web Application, Network, Cloud, IoT +9
Cardiff, United Kingdom · Checked Sept 2026

Cardiff-based CREST and CHECK-accredited cyber security company delivering penetration testing, red teaming, and OT security assessments as part of the Chess Group.

Accreditations: CREST, CHECK, NCSC Assured, Cyber Essentials
Services: Web Application, Network, Cloud, Red Teaming +4
Sydney, Australia · Checked Sept 2026

Australia and New Zealand's largest pure-play cybersecurity firm with offices in every major ANZ capital. CREST ANZ accredited and IRAP-listed for Australian Government testing.

Accreditations: CREST, ISO 27001, SOC 2
Services: Web Application, Network, Mobile App, Cloud +6
Tampa, Florida, United States · Checked Sept 2026

Compliance audit firm delivering web application and network penetration testing with findings mapped to MITRE ATT&CK, alongside the SOC 2, ISO 27001, CMMC, and FedRAMP assessments the results feed into, from a testing team kept independent of the audit side.

Accreditations: FedRAMP 3PAO, CMMC C3PAO, HITRUST Authorized Assessor, PCI QSA
Services: Web Application, Network, Cloud, Red Teaming +3
Vienna, Austria · Checked Sept 2026

Vienna-headquartered Austrian cybersecurity consultancy with a prolific Vulnerability Lab research program and deep expertise in IoT and embedded systems security across the DACH region.

Accreditations: ISO 27001
Services: Web Application, Network, Mobile App, IoT +7
Seattle, Washington, United States · Checked Sept 2026

Boutique security consultancy specialising in IoT, SCADA/ICS, embedded systems, and hardware security research with world-renowned researchers.

Accreditations: OSCP Employer
Services: Web Application, Network, IoT, SCADA/ICS +7
Paris, France · Checked May 2026

Airbus group cybersecurity consultancy with ANSSI PASSI qualification. Aerospace, defence, and critical infrastructure penetration testing across Europe.

Accreditations: ANSSI PASSI, ISO 27001, Cyber Essentials
Services: Web Application, Network, Cloud, IoT +8

SCADA/ICS Penetration Testing FAQs

Is it safe to pen test live SCADA/ICS systems?+

Testing live production systems carries risk. Experienced ICS pen testers use passive techniques on live systems and may use lab environments or digital twins for active exploitation. Safety is always the top priority.

What qualifications should ICS pen testers have?+

Look for testers with ICS-specific certifications like GICSP, knowledge of industrial protocols, and demonstrated experience in OT environments. General pen testing certifications alone are not sufficient.

How often should ICS/SCADA systems be tested?+

Annual testing is recommended as a minimum, with additional testing after significant changes to the OT environment or when new threats emerge targeting your industry sector.