SHT 08.1 Site survey - Critical National Infrastructure

Clearance-aware. Audit-ready.

Identity for critical national infrastructure operators. NPSA-aligned physical security, vetting enforcement, and contractor lifecycle, built in, not bolted on.

01 Why this sector is different

What this sector demands.

In critical national infrastructure, the access policy is the security policy. A zone that handles sensitive materials has different access rules depending on vetting status and clearance level. A contractor whose vetting lapsed at midnight cannot enter a secured area at 00:01, regardless of what the list used to say.

ID-ware is one of the few European PIAM platforms built from the ground up with clearance levels as first-class policy objects. Not a tag. Not a group membership. A structured credential - issuer, subject, level, validity, revocation hook - checked at every door.

02 Perimeter plan

The site, drawn to clearance.

The survey draws itself outside-in: fence line, vehicle gate, turnstile, then the nested CTC, SC and DV zones. Every reader dot is a policy decision point. When a clearance is revoked, the red trace runs from the margin to the turnstile - and the site answers before anyone reaches the door.

Perimeter plan - a DV clearance card denied at the margin Plan view of a secure site: dashed fence line with a vehicle gate, guard house and turnstile, and nested rectangular clearance zones labelled CTC, SC and DV with reader dots at each zone door. A clearance card enters at the vehicle gate and passes the CTC and SC gates (granted), but at the DV boundary its clearance is insufficient: the DV edge flashes red and the card is turned back, denied at the turnstile. A crosshair marks the muster point. FENCE LINE VEHICLE GATE GUARD HOUSE TURNSTILE CTC SC DV MUSTER
Fig 08.1 - perimeter plan. Nested clearance zones CTC / SC / DV. The card clears CTC and SC; at the DV boundary its clearance is insufficient - revoked at the margin, denied at the turnstile.
< 30 s muster
Alarm raisedNamed roll-call
< 3 s revoke-to-denial
Clearance revokedDenied at the turnstile

03 Capabilities

What the sector pack does.

Clearance

Clearance gates

Access granted only when clearance level AND currency match policy. Expired vetting denies at the reader.

Vetting

Vetting enforcement

Secured areas locked to verified vetting status and clearance level. Every access decision logged for audit.

Contractors

Contractor lifecycle

Time-bound, project-bound, auto-revoked on programme close. No orphaned access after a contract ends.

Safety

Muster & evacuation

Real-time presence by zone, named roll-call in under 30 seconds. Life-safety grade on alarm.

Two-person

Two-person rule

Dual-authorisation enforced at the reader for classified storage, control rooms, and server halls.

Zones

Classified zones

Compartmentalised access, need-to-know enforcement, zone transitions flagged to the SOC live.

04 Compliance

Frameworks covered.

Sheet 08.1 CNI · AEROSPACE / DEFENCE
Clearance model CTC / SC / DV First-class policy objects
Policy propagation to door controllers < 6 s PACS push
Certifications ISO 9001 / ISO/IEC 27001 / TISAX (DEKRA-certified) / GDPR · NIS2 · DORA support
NPSA

National Protective Security Authority aligned physical security controls.

NCSC CAF

Cyber Assessment Framework controls mapped and evidenced.

NIS Regulations

Network and Information Systems Regulations compliance built in.

ISO 27001

Information security management system certified.

Cyber Essentials+

Aligned to Cyber Essentials Plus controls.

BS 7858

Screening of individuals working in a secure environment.

IEC 62443

Industrial automation and control systems security.

TISAX

Trusted Information Security Assessment Exchange.

05 Next step

See it in context.

Watch a door-enforcement scenario run end to end - rules written in the platform, enforced at the reader.