UK Security and Emergency Measures Direction (SEMD) - Water Industry
Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cyber Security and Operational Technology
Cyber security controls must protect operational technology systems that manage water treatment and distribution.
- Drinking Water Inspectorate (DWI) reporting submissions
- Emergency response exercise records and after-action reports
- Risk and resilience assessment for water assets
- Security plan submitted to Defra under SEMD
- Vulnerable customer list incomplete or stale
- Outdated security plan not aligned to current threat picture
- OT and SCADA segmentation not formally documented
- Insufficient exercise frequency or scope of scenarios
Companies must comply with the Network and Information Systems Regulations 2018 as operators of essential services.
- Alternative water supply deployment plan
- Emergency response exercise records and after-action reports
- Drinking Water Inspectorate (DWI) reporting submissions
- Risk and resilience assessment for water assets
- Vulnerable customer list incomplete or stale
- OT and SCADA segmentation not formally documented
- Insufficient exercise frequency or scope of scenarios
- Missing alternative water deployment logistics
Companies must demonstrate holistic resilience covering both cyber protection and recovery capabilities.
- Drinking Water Inspectorate (DWI) reporting submissions
- Alternative water supply deployment plan
- Vulnerable customer register and outreach procedures
- Security plan submitted to Defra under SEMD
- Vulnerable customer list incomplete or stale
- Missing alternative water deployment logistics
- Outdated security plan not aligned to current threat picture
- Insufficient exercise frequency or scope of scenarios
Emergency Planning
Per UK SEMD (Security and Emergency Measures Direction) Water Industry: Emergency Plan + Designated SEMD Officer + Deputies + Site Security and Access Control + Public Communications During Emergencies.
- SEMD evidence for UKSEMD-1
- plan + officer partial
Emergency Response and Customer Protection
Companies must carry out regular testing and exercising with Local Resilience Forum partners and other agencies.
- Security plan submitted to Defra under SEMD
- Emergency response exercise records and after-action reports
- Risk and resilience assessment for water assets
- Drinking Water Inspectorate (DWI) reporting submissions
- Missing alternative water deployment logistics
- Vulnerable customer list incomplete or stale
- Outdated security plan not aligned to current threat picture
- Insufficient exercise frequency or scope of scenarios
Companies must test alternative water supply arrangements including static tanks, tankering, and alternative water stations.
- Risk and resilience assessment for water assets
- Alternative water supply deployment plan
- Vulnerable customer register and outreach procedures
- Emergency response exercise records and after-action reports
- Insufficient exercise frequency or scope of scenarios
- Vulnerable customer list incomplete or stale
- OT and SCADA segmentation not formally documented
- Outdated security plan not aligned to current threat picture
Companies must maintain Priority Service Register data and identify vulnerable sites including hospitals, schools, and care homes.
- Emergency response exercise records and after-action reports
- Vulnerable customer register and outreach procedures
- Security plan submitted to Defra under SEMD
- Alternative water supply deployment plan
- OT and SCADA segmentation not formally documented
- Insufficient exercise frequency or scope of scenarios
- Vulnerable customer list incomplete or stale
- Missing alternative water deployment logistics
Companies must report to the Drinking Water Inspectorate and comply with enforcement under Section 18 of the Water Industry Act 1991.
- Emergency response exercise records and after-action reports
- Alternative water supply deployment plan
- Drinking Water Inspectorate (DWI) reporting submissions
- Vulnerable customer register and outreach procedures
- Outdated security plan not aligned to current threat picture
- Missing alternative water deployment logistics
- Insufficient exercise frequency or scope of scenarios
- OT and SCADA segmentation not formally documented
Incident
Per SEMD: incident response + reporting + cooperation with Defra + DWI + CISC + ACSC equivalents.
- SEMD evidence for UKSEMD-3
- plan + officer partial
Physical and Site Security
Physical security measures must protect critical water supply and sewerage infrastructure from unauthorized access and sabotage.
- Critical asset register
- Protection strategy document
- Resilience test reports
- Liaison records with regulator
- Register incomplete
- No resilience testing
- Regulator liaison informal
Water treatment works and key installations must have appropriate physical barriers, CCTV, and access controls.
- Site security plan
- Perimeter inspection reports
- Intrusion detection configuration
- Response drill records
- Inspections overdue
- Drills not conducted
- Detection coverage incomplete
Security of chemical deliveries and other supply chain elements critical to water treatment must be maintained.
- Supply chain security procedure
- Delivery verification records
- Tamper inspection reports
- Vendor security agreements
- No tamper inspection
- Vendor agreements lack security clauses
- Verification records absent
Resilience
Per SEMD: critical national infrastructure protection + threat intelligence + CNI risk assessment + Defra + UK Water Industry Council cooperation.
- SEMD evidence for UKSEMD-2
- plan + officer partial
Resources and Capability
Companies must ensure they have the necessary capability and capacity to implement their security and emergency plans.
- Drinking Water Inspectorate (DWI) reporting submissions
- Vulnerable customer register and outreach procedures
- Risk and resilience assessment for water assets
- Security plan submitted to Defra under SEMD
- Outdated security plan not aligned to current threat picture
- Insufficient exercise frequency or scope of scenarios
- Missing alternative water deployment logistics
- Vulnerable customer list incomplete or stale
Companies must maintain the necessary facilities and resources for plan implementation including alternative water deployment.
- Vulnerable customer register and outreach procedures
- Alternative water supply deployment plan
- Drinking Water Inspectorate (DWI) reporting submissions
- Emergency response exercise records and after-action reports
- Vulnerable customer list incomplete or stale
- Missing alternative water deployment logistics
- Insufficient exercise frequency or scope of scenarios
- Outdated security plan not aligned to current threat picture
Staff must be trained and prepared for security and emergency response with appropriate competencies maintained.
- Alternative water supply deployment plan
- Risk and resilience assessment for water assets
- Security plan submitted to Defra under SEMD
- Drinking Water Inspectorate (DWI) reporting submissions
- Vulnerable customer list incomplete or stale
- Insufficient exercise frequency or scope of scenarios
- Outdated security plan not aligned to current threat picture
- OT and SCADA segmentation not formally documented
Security Planning
Water companies must make, keep under review, test and revise plans to ensure the provision of essential water supply and sewerage services at all times.
- Drinking Water Inspectorate (DWI) reporting submissions
- Vulnerable customer register and outreach procedures
- Risk and resilience assessment for water assets
- Security plan submitted to Defra under SEMD
- Missing alternative water deployment logistics
- Insufficient exercise frequency or scope of scenarios
- OT and SCADA segmentation not formally documented
- Vulnerable customer list incomplete or stale
Undertakers must identify security risks including assessing long-term risks to the provision of water supply or sewerage services.
- Risk and resilience assessment for water assets
- Vulnerable customer register and outreach procedures
- Alternative water supply deployment plan
- Emergency response exercise records and after-action reports
- Insufficient exercise frequency or scope of scenarios
- OT and SCADA segmentation not formally documented
- Outdated security plan not aligned to current threat picture
- Vulnerable customer list incomplete or stale
Companies must maintain systems in the interests of national security and ensure plans address threats to national security.
- Vulnerable customer register and outreach procedures
- Risk and resilience assessment for water assets
- Alternative water supply deployment plan
- Drinking Water Inspectorate (DWI) reporting submissions
- Outdated security plan not aligned to current threat picture
- Insufficient exercise frequency or scope of scenarios
- OT and SCADA segmentation not formally documented
- Missing alternative water deployment logistics
Plans must address mitigation of the effects of any civil emergency that may occur affecting water supply or sewerage.
- Emergency response exercise records and after-action reports
- Alternative water supply deployment plan
- Drinking Water Inspectorate (DWI) reporting submissions
- Vulnerable customer register and outreach procedures
- Insufficient exercise frequency or scope of scenarios
- Outdated security plan not aligned to current threat picture
- OT and SCADA segmentation not formally documented
- Missing alternative water deployment logistics
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Security and Emergency Measures Direction (SEMD) - Water Industry framework page.