27019
ISO/IEC 27019:2024 · Information security for the energy utility industry

ISO/IEC 27019Energy sector security

Information security controls for energy utilities — process control systems, SCADA, smart metering and grid operations, built on ISO/IEC 27001.

SCHEME CARD · INFORMATION SECURITY
ISO/IEC 27019Energy utility information security · 2024
Who it's for
Energy utilities, grid operators and more
Audit model
Stage 1 + Stage 2 + surveillance
Certificate validity
3 years
Typical timeline
4–6 weeks (with 27001)
Listed in public registerCombines with ISO/IEC 27001, ISA/IEC 62443
3 yrscertificate validity, with annual surveillance audits
2audit stages — documentation review, then on-site assessment
4–6weeks from application to certificate, typical timeline
1business day to a fixed offer after your application
Why companies certify

Who needs ISO/IEC 27019— and when

ISO/IEC 27019 extends ISO/IEC 27001 with controls for the energy sector: process control systems, operational technology, smart metering, legacy systems and the physical security of control and substation sites.

INDUSTRIES WE CERTIFY TO ISO/IEC 27019

Power generationTransmission & distributionGas & heat supplySmart meteringRenewables operators
Not sure whether ISO/IEC 27019 fits? Our auditors run a short diagnostic review and suggest the scheme — or a combination of two or three — that answers your customers' requirements.
Inside the standard

What the audit examines

01Process control systems

Security of SCADA, DCS and other OT systems.

02Legacy systems

Protection of equipment that cannot be patched or replaced.

03Control sites

Physical security of control rooms and substations.

04Smart metering

Security of metering data and communication.

05Supplier access

Control of vendor and remote maintenance access.

What the audit covers

Requirements,clause by clause

ISO/IEC 27019 is audited against these requirement areas. Open each one to see what auditors look for in your company.

Clause 4Context of the organisation+
Interested parties, internal and external issues, and how the scope of the system is defined.
Clause 5Leadership+
Top management commitment, a policy that fits the business, roles and responsibilities.
Clause 6Planning+
Risks and opportunities identified and addressed; measurable objectives with plans to reach them.
Clause 7Support+
Resources, competence and awareness, communication, control of documented information.
Clause 8Operation+
How processes are planned, controlled and delivered day to day.
Clauses 9–10Evaluation & improvement+
Monitoring, internal audits, management review — and how nonconformities become corrective actions.
Benefits

What ISO/IEC 27019certification gives you

  • Evidence of security for regulators and grid partners
  • Support for NIS2 obligations in the energy sector
  • Documented OT security practices
  • Certified together with ISO/IEC 27001
  • Lower risk of outages caused by cyber incidents
Integrated audit

Hold more than one standard? One audit.

ISO/IEC 27019 shares its structure with ISO/IEC 27001, ISA/IEC 62443. We audit them together — one team, one visit, one report.

−25%audit days on average
1lead auditor for all standards
The path to certificate

Five steps from application to ISO/IEC 27019

Scroll the steps — the bar shows where you are in the process. Every step has a named coordinator and a fixed timeline.

STEP 1 / 5 · Application & offer
STEP 11 business day
Application & offer

You send a short application; a coordinator sizes the audit and sends a fixed offer.

→ Offer with audit plan
STEP 21–2 days
Stage 1 audit

Documentation review and readiness check — remote or on site. Gaps are listed, not penalised.

→ Readiness report
STEP 3By calculation
Stage 2 audit

On-site assessment of implementation and effectiveness with a team that knows your sector.

→ Audit report
STEP 45–10 days
Decision & certificate

Independent certification decision; the certificate is issued and entered into the public register.

→ ISO/IEC 27019 certificate
STEP 5Annual
Surveillance & renewal

Annual surveillance keeps the certificate in force; re-certification in year three.

→ Certificate maintained
Readiness check

Are you readyfor Stage 1?

Tick what you already have. You do not need a perfect system to apply — you need a working one.

Your readiness
0%

Based on the items ticked on the left. Indicative — the Stage 1 audit gives the formal picture.

Apply for ISO/IEC 27019 →
FAQ · ISO/IEC 27019

Questions companiesask before certifying

Did not find yours? Call us — a coordinator answers within the same business day.

+38 (044) 332-30-76
How long is the certificate valid?+
Three years, maintained through annual surveillance audits and renewed by a re-certification audit in year three.
Can we combine it with other standards?+
Yes — integrated audits reduce total audit days and cost. Tell us which standards you hold and we size one combined audit.
How is the audit priced?+
Audit duration is calculated by international rules from headcount, sites and complexity, so quotations are comparable between certification bodies.
Related schemes

Often certifiedtogether

Get certifiedto ISO/IEC 27019

Send an application — we define scope and audit duration, and issue a fixed offer within one business day.

  • Auditors with experience in your industry
  • Fixed price — no surprises after Stage 1
  • Certificate listed in the public register
By sending the form you agree to the processing of the data for preparing a quotation.