SHT 08.1 Site survey - Critical National Infrastructure
Clearance-aware. Audit-ready.
Identity for critical national infrastructure operators. NPSA-aligned physical security, vetting enforcement, and contractor lifecycle, built in, not bolted on.
01 Why this sector is different
What this sector demands.
In critical national infrastructure, the access policy is the security policy. A zone that handles sensitive materials has different access rules depending on vetting status and clearance level. A contractor whose vetting lapsed at midnight cannot enter a secured area at 00:01, regardless of what the list used to say.
ID-ware is one of the only European PIAM platforms built from the ground up with clearance levels as first-class policy objects. Not a tag. Not a group membership. A structured credential - issuer, subject, level, validity, revocation hook - checked at every door.
02 Perimeter plan
The site, drawn to clearance.
The survey draws itself outside-in: fence line, vehicle gate, turnstile, then the nested CTC, SC and DV zones. Every reader dot is a policy decision point. When a clearance is revoked, the red trace runs from the margin to the turnstile - and the site answers before anyone reaches the door.
03 Capabilities
What the sector pack does.
Clearance gates
Access granted only when clearance level AND currency match policy. Expired vetting denies at the reader.
Vetting enforcement
Secured areas locked to verified vetting status and clearance level. Every access decision logged for audit.
Contractor lifecycle
Time-bound, project-bound, auto-revoked on programme close. No orphaned access after a contract ends.
Muster & evacuation
Real-time presence by zone, named roll-call in under 30 seconds. Life-safety grade on alarm.
Two-person rule
Dual-authorisation enforced at the reader for classified storage, server rooms, and flight lines.
Classified zones
Compartmentalised access, need-to-know enforcement, zone transitions flagged to the SOC live.
04 Compliance
Frameworks covered.
National Protective Security Authority aligned physical security controls.
Cyber Assessment Framework controls mapped and evidenced.
Network and Information Systems Regulations compliance built in.
Information security management system certified.
Cyber Essentials Plus certified infrastructure.
Screening of individuals working in a secure environment.
Industrial automation and control systems security.
Trusted Information Security Assessment Exchange.
05 Next step
See it in context.
Watch a clearance revocation run end to end - HR record to a denied read at the turnstile, with door enforcement and the full lifecycle workflow in view.