Skip to content

Evidence request lists

UK Security and Emergency Measures Direction (SEMD) - Water Industry

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cyber Security and Operational Technology

SEMD-CS-1
Operational Technology Protection

Cyber security controls must protect operational technology systems that manage water treatment and distribution.

Artefacts an auditor will ask for
  • Drinking Water Inspectorate (DWI) reporting submissions
  • Emergency response exercise records and after-action reports
  • Risk and resilience assessment for water assets
  • Security plan submitted to Defra under SEMD
Where this commonly fails
  • Vulnerable customer list incomplete or stale
  • Outdated security plan not aligned to current threat picture
  • OT and SCADA segmentation not formally documented
  • Insufficient exercise frequency or scope of scenarios
SEMD-CS-2
NIS Regulations Compliance

Companies must comply with the Network and Information Systems Regulations 2018 as operators of essential services.

Artefacts an auditor will ask for
  • Alternative water supply deployment plan
  • Emergency response exercise records and after-action reports
  • Drinking Water Inspectorate (DWI) reporting submissions
  • Risk and resilience assessment for water assets
Where this commonly fails
  • Vulnerable customer list incomplete or stale
  • OT and SCADA segmentation not formally documented
  • Insufficient exercise frequency or scope of scenarios
  • Missing alternative water deployment logistics
SEMD-CS-3
Cyber Resilience

Companies must demonstrate holistic resilience covering both cyber protection and recovery capabilities.

Artefacts an auditor will ask for
  • Drinking Water Inspectorate (DWI) reporting submissions
  • Alternative water supply deployment plan
  • Vulnerable customer register and outreach procedures
  • Security plan submitted to Defra under SEMD
Where this commonly fails
  • Vulnerable customer list incomplete or stale
  • Missing alternative water deployment logistics
  • Outdated security plan not aligned to current threat picture
  • Insufficient exercise frequency or scope of scenarios

Emergency Planning

UKSEMD-1
Emergency Planning, Designated Officers, Site Security

Per UK SEMD (Security and Emergency Measures Direction) Water Industry: Emergency Plan + Designated SEMD Officer + Deputies + Site Security and Access Control + Public Communications During Emergencies.

Artefacts an auditor will ask for
  • SEMD evidence for UKSEMD-1
Where this commonly fails
  • plan + officer partial

Emergency Response and Customer Protection

SEMD-ER-1
Emergency Exercise and Testing

Companies must carry out regular testing and exercising with Local Resilience Forum partners and other agencies.

Artefacts an auditor will ask for
  • Security plan submitted to Defra under SEMD
  • Emergency response exercise records and after-action reports
  • Risk and resilience assessment for water assets
  • Drinking Water Inspectorate (DWI) reporting submissions
Where this commonly fails
  • Missing alternative water deployment logistics
  • Vulnerable customer list incomplete or stale
  • Outdated security plan not aligned to current threat picture
  • Insufficient exercise frequency or scope of scenarios
SEMD-ER-2
Alternative Water Deployment

Companies must test alternative water supply arrangements including static tanks, tankering, and alternative water stations.

Artefacts an auditor will ask for
  • Risk and resilience assessment for water assets
  • Alternative water supply deployment plan
  • Vulnerable customer register and outreach procedures
  • Emergency response exercise records and after-action reports
Where this commonly fails
  • Insufficient exercise frequency or scope of scenarios
  • Vulnerable customer list incomplete or stale
  • OT and SCADA segmentation not formally documented
  • Outdated security plan not aligned to current threat picture
SEMD-ER-3
Vulnerable Customer Protection

Companies must maintain Priority Service Register data and identify vulnerable sites including hospitals, schools, and care homes.

Artefacts an auditor will ask for
  • Emergency response exercise records and after-action reports
  • Vulnerable customer register and outreach procedures
  • Security plan submitted to Defra under SEMD
  • Alternative water supply deployment plan
Where this commonly fails
  • OT and SCADA segmentation not formally documented
  • Insufficient exercise frequency or scope of scenarios
  • Vulnerable customer list incomplete or stale
  • Missing alternative water deployment logistics
SEMD-ER-4
DWI Reporting and Compliance

Companies must report to the Drinking Water Inspectorate and comply with enforcement under Section 18 of the Water Industry Act 1991.

Artefacts an auditor will ask for
  • Emergency response exercise records and after-action reports
  • Alternative water supply deployment plan
  • Drinking Water Inspectorate (DWI) reporting submissions
  • Vulnerable customer register and outreach procedures
Where this commonly fails
  • Outdated security plan not aligned to current threat picture
  • Missing alternative water deployment logistics
  • Insufficient exercise frequency or scope of scenarios
  • OT and SCADA segmentation not formally documented

Incident

UKSEMD-3
Incident Response and Reporting

Per SEMD: incident response + reporting + cooperation with Defra + DWI + CISC + ACSC equivalents.

Artefacts an auditor will ask for
  • SEMD evidence for UKSEMD-3
Where this commonly fails
  • plan + officer partial

Physical and Site Security

SEMD-PS-1
Critical Infrastructure Protection

Physical security measures must protect critical water supply and sewerage infrastructure from unauthorized access and sabotage.

Artefacts an auditor will ask for
  • Critical asset register
  • Protection strategy document
  • Resilience test reports
  • Liaison records with regulator
Where this commonly fails
  • Register incomplete
  • No resilience testing
  • Regulator liaison informal
SEMD-PS-2
Site Security Measures

Water treatment works and key installations must have appropriate physical barriers, CCTV, and access controls.

Artefacts an auditor will ask for
  • Site security plan
  • Perimeter inspection reports
  • Intrusion detection configuration
  • Response drill records
Where this commonly fails
  • Inspections overdue
  • Drills not conducted
  • Detection coverage incomplete
SEMD-PS-3
Supply Chain Security

Security of chemical deliveries and other supply chain elements critical to water treatment must be maintained.

Artefacts an auditor will ask for
  • Supply chain security procedure
  • Delivery verification records
  • Tamper inspection reports
  • Vendor security agreements
Where this commonly fails
  • No tamper inspection
  • Vendor agreements lack security clauses
  • Verification records absent

Resilience

UKSEMD-2
Resilience, Critical National Infrastructure, Threat Intelligence

Per SEMD: critical national infrastructure protection + threat intelligence + CNI risk assessment + Defra + UK Water Industry Council cooperation.

Artefacts an auditor will ask for
  • SEMD evidence for UKSEMD-2
Where this commonly fails
  • plan + officer partial

Resources and Capability

SEMD-RC-1
Capability and Capacity

Companies must ensure they have the necessary capability and capacity to implement their security and emergency plans.

Artefacts an auditor will ask for
  • Drinking Water Inspectorate (DWI) reporting submissions
  • Vulnerable customer register and outreach procedures
  • Risk and resilience assessment for water assets
  • Security plan submitted to Defra under SEMD
Where this commonly fails
  • Outdated security plan not aligned to current threat picture
  • Insufficient exercise frequency or scope of scenarios
  • Missing alternative water deployment logistics
  • Vulnerable customer list incomplete or stale
SEMD-RC-2
Facilities and Resources

Companies must maintain the necessary facilities and resources for plan implementation including alternative water deployment.

Artefacts an auditor will ask for
  • Vulnerable customer register and outreach procedures
  • Alternative water supply deployment plan
  • Drinking Water Inspectorate (DWI) reporting submissions
  • Emergency response exercise records and after-action reports
Where this commonly fails
  • Vulnerable customer list incomplete or stale
  • Missing alternative water deployment logistics
  • Insufficient exercise frequency or scope of scenarios
  • Outdated security plan not aligned to current threat picture
SEMD-RC-3
Workforce Readiness

Staff must be trained and prepared for security and emergency response with appropriate competencies maintained.

Artefacts an auditor will ask for
  • Alternative water supply deployment plan
  • Risk and resilience assessment for water assets
  • Security plan submitted to Defra under SEMD
  • Drinking Water Inspectorate (DWI) reporting submissions
Where this commonly fails
  • Vulnerable customer list incomplete or stale
  • Insufficient exercise frequency or scope of scenarios
  • Outdated security plan not aligned to current threat picture
  • OT and SCADA segmentation not formally documented

Security Planning

SEMD-SP-1
Security Plan Development

Water companies must make, keep under review, test and revise plans to ensure the provision of essential water supply and sewerage services at all times.

Artefacts an auditor will ask for
  • Drinking Water Inspectorate (DWI) reporting submissions
  • Vulnerable customer register and outreach procedures
  • Risk and resilience assessment for water assets
  • Security plan submitted to Defra under SEMD
Where this commonly fails
  • Missing alternative water deployment logistics
  • Insufficient exercise frequency or scope of scenarios
  • OT and SCADA segmentation not formally documented
  • Vulnerable customer list incomplete or stale
SEMD-SP-2
Risk Identification and Assessment

Undertakers must identify security risks including assessing long-term risks to the provision of water supply or sewerage services.

Artefacts an auditor will ask for
  • Risk and resilience assessment for water assets
  • Vulnerable customer register and outreach procedures
  • Alternative water supply deployment plan
  • Emergency response exercise records and after-action reports
Where this commonly fails
  • Insufficient exercise frequency or scope of scenarios
  • OT and SCADA segmentation not formally documented
  • Outdated security plan not aligned to current threat picture
  • Vulnerable customer list incomplete or stale
SEMD-SP-3
National Security Considerations

Companies must maintain systems in the interests of national security and ensure plans address threats to national security.

Artefacts an auditor will ask for
  • Vulnerable customer register and outreach procedures
  • Risk and resilience assessment for water assets
  • Alternative water supply deployment plan
  • Drinking Water Inspectorate (DWI) reporting submissions
Where this commonly fails
  • Outdated security plan not aligned to current threat picture
  • Insufficient exercise frequency or scope of scenarios
  • OT and SCADA segmentation not formally documented
  • Missing alternative water deployment logistics
SEMD-SP-4
Civil Emergency Preparedness

Plans must address mitigation of the effects of any civil emergency that may occur affecting water supply or sewerage.

Artefacts an auditor will ask for
  • Emergency response exercise records and after-action reports
  • Alternative water supply deployment plan
  • Drinking Water Inspectorate (DWI) reporting submissions
  • Vulnerable customer register and outreach procedures
Where this commonly fails
  • Insufficient exercise frequency or scope of scenarios
  • Outdated security plan not aligned to current threat picture
  • OT and SCADA segmentation not formally documented
  • Missing alternative water deployment logistics
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Security and Emergency Measures Direction (SEMD) - Water Industry framework page.