Resources / Checklists /
Critical Infrastructure
DOCX

ICS/SCADA (OT) Cybersecurity Self-Assessment Checklist: 154 Questions Mapped to NIST 800-82

150+ self-assessment questions for ICS and SCADA environments, organized by the five NIST CSF functions and mapped to NIST 800-82, so an OT operator can baseline site security without waiting for a formal audit.
Format:
DOCX
Last updated:
September 15, 2026
Read time:
5
min
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.

OT doesn't fail like IT. A compromised control system can open a valve, override an alarm, or disable a pump, turning a network intrusion into physical damage. And the connections that make plants efficient, remote access, business-system links, internet exposure, are the ones that create the risk. This checklist shows an operator where they stand.

Every row is one question, grouped by NIST CSF function and mapped to NIST 800-82, with columns for corrective actions and a target date, so answering it builds a remediation list, not just a score. It's a baseline, not a full plant assessment.

Key Takeaways

  • 154 questions organized by the five NIST CSF functions: Identify, Protect, Detect, Respond, and Recover.
  • Built for critical infrastructure sectors: oil and gas, water and wastewater, chemical, manufacturing, and transportation.
  • Covers the OT-specific concerns IT checklists miss: firmware update ownership, site-owner-managed firewalls and switches, physical security of control equipment, and safe-state recovery.
  • Every question has space for corrective actions and a target completion date, so the filled sheet becomes a remediation tracker.

What's Inside

Every row is one question, grouped by NIST CSF function the way the framework groups them.

  • Identify: asset management, business environment, governance, risk assessment, risk management strategy, supply chain.
  • Protect: physical security, awareness and training, data security, information protection, maintenance, protective technology.
  • Detect: anomalies and events, security continuous monitoring, detection processes.
  • Respond: response planning, communications, analysis, mitigation, improvements.
  • Recover: recovery planning, communications, improvements.

Columns for your comments or corrective actions and a target completion date on every row.

How to use it

01
Pick your scope. Work through one NIST CSF function at a time, or run all 154 questions for a full site baseline.
02
Answer honestly. Mark each question against your actual environment, not your intended one.
03
Record the gap. Use the Comments/Corrective Actions and Target Completion Date columns to turn every no into a dated action item.
04
Running critical infrastructure? Payatu's OT and ICS assessors validate this baseline on-site and test the controls under real conditions. Talk to us about a Critical Infrastructure Assessment.
Subscribe to our newsletter
Reviewed by
Red circular logo with four overlapping curved segments forming a hollow diamond shape at the center.
Critical Infrastructure Security Team