UK Security and Emergency Measures Direction (SEMD) — Water Industry
The UK Security and Emergency Measures Direction (SEMD, 2022) issued by Defra (Department for Environment, Food and Rural Affairs) under the Water Industry Act 1991 establishes security requirements for water and sewerage companies in England and Wales. SEMD requires water companies to protect their infrastructure against threats including cyber attacks, physical security threats, and contamination. Water companies must conduct risk assessments, implement security measures, and maintain emergency plans. The Drinking Water Inspectorate (DWI) oversees drinking water quality security. Cyber resilience requirements align with NIS Regulations 2018 (and NIS2 transposition) as water is designated a critical national infrastructure sector.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Assurance
| Code | Title |
|---|---|
| SEMD-2.8 | Periodic SEMD Audit by DEFRA |
Communications
| Code | Title |
|---|---|
| SEMD-1.10 | Public Communications During Emergencies |
Cyber Security
| Code | Title |
|---|---|
| SEMD-1.5 | Operational Technology and Control System Security |
Cyber Security and Resilience
| Code | Title |
|---|---|
| SEMD-CS-1 | Operational Technology Protection |
| SEMD-CS-2 | NIS Regulations Compliance |
| SEMD-CS-3 | Cyber Resilience |
Emergency Response and Testing
| Code | Title |
|---|---|
| SEMD-ER-1 | Emergency Exercise and Testing |
| SEMD-ER-2 | Alternative Water Deployment |
| SEMD-ER-3 | Vulnerable Customer Protection |
| SEMD-ER-4 | DWI Reporting and Compliance |
External Engagement
| Code | Title |
|---|---|
| SEMD-2.7 | Co-operation with Local Resilience Forums |
Governance
| Code | Title |
|---|---|
| SEMD-1.3 | Designated SEMD Officer and Deputies |
Information Security
| Code | Title |
|---|---|
| SEMD-2.3 | Information Handling and Classification |
Long Term Resilience
| Code | Title |
|---|---|
| SEMD-2.9 | Climate and Drought Resilience |
Mutual Aid
| Code | Title |
|---|---|
| SEMD-1.9 | Mutual Aid Arrangements Between Undertakers |
Operational Continuity
| Code | Title |
|---|---|
| SEMD-2.6 | Telemetry and SCADA Backup |
Operational Resilience
| Code | Title |
|---|---|
| SEMD-1.7 | Treatment Works Resilience |
Personnel Security
| Code | Title |
|---|---|
| SEMD-2.1 | Personnel Security and Vetting |
Physical Security
| Code | Title |
|---|---|
| DSPF-PHYS-1 | Physical Security Management |
| DSPF-PHYS-2 | Facility Security Zones |
| DSPF-PHYS-3 | Physical Access Controls |
| DSPF-PHYS-4 | Security Equipment |
| DSPF-PHYS-5 | Visitor Management |
| PSPF-PHYS-1 | Physical Security Management |
| PSPF-PHYS-2 | Facility Security Zones |
| PSPF-PHYS-3 | Physical Access Controls |
| PSPF-PHYS-4 | Physical Security of ICT |
| SEMD-1.4 | Site Security and Access Control |
| SEMD-PS-1 | Critical Infrastructure Protection |
| SEMD-PS-2 | Site Security Measures |
| SEMD-PS-3 | Supply Chain Security |
Physical Security
Requirements for physical protection of Defence facilities, information and assets
| Code | Title |
|---|---|
| DSPF-PHYS-1 | Physical Security Management |
| DSPF-PHYS-2 | Facility Security Zones |
| DSPF-PHYS-3 | Physical Access Controls |
| DSPF-PHYS-4 | Security Equipment |
| DSPF-PHYS-5 | Visitor Management |
| PSPF-PHYS-1 | Physical Security Management |
| PSPF-PHYS-2 | Facility Security Zones |
| PSPF-PHYS-3 | Physical Access Controls |
| PSPF-PHYS-4 | Physical Security of ICT |
| SEMD-1.4 | Site Security and Access Control |
| SEMD-PS-1 | Critical Infrastructure Protection |
| SEMD-PS-2 | Site Security Measures |
| SEMD-PS-3 | Supply Chain Security |
Planning
| Code | Title |
|---|---|
| SEMD-1.2 | Emergency Plan Maintenance and Review |
Power Resilience
| Code | Title |
|---|---|
| SEMD-2.5 | Resilience to Loss of Mains Power |
Reporting
| Code | Title |
|---|---|
| SEMD-1.8 | Incident Reporting to Government |
Resourcing and Capability
| Code | Title |
|---|---|
| SEMD-RC-1 | Capability and Capacity |
| SEMD-RC-2 | Facilities and Resources |
| SEMD-RC-3 | Workforce Readiness |
Security Planning
| Code | Title |
|---|---|
| SEMD-SP-1 | Security Plan Development |
| SEMD-SP-2 | Risk Identification and Assessment |
| SEMD-SP-3 | National Security Considerations |
| SEMD-SP-4 | Civil Emergency Preparedness |
Service Continuity
| Code | Title |
|---|---|
| SEMD-1.1 | Minimum Supply of Wholesome Water in Emergencies |
Source Protection
| Code | Title |
|---|---|
| SEMD-1.6 | Source and Catchment Protection |
Supply Chain
| Code | Title |
|---|---|
| SEMD-2.4 | Supply Chain Resilience and Security |
Training and Exercise
| Code | Title |
|---|---|
| SEMD-2.2 | Training and Exercising of Emergency Response |
Your Compliance Coverage
If you comply with UK Security and Emergency Measures Direction (SEMD) — Water Industry, you already cover:
Defence Security Principles Framework (DSPF)
22%
10 controls mapped
Compare →Protective Security Policy Framework (PSPF) Release 2024
22%
10 controls mapped
Compare →US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements
22%
10 controls mapped
Compare →+ 494 more: NIST SP 800-82 Rev 3 — Guide to OT Security (22%), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (20%)
See all 497 mapped frameworks ↓Maps to 497 other frameworks
Frequently Asked Questions
What is UK Security and Emergency Measures Direction (SEMD) — Water Industry?
UK Security and Emergency Measures Direction (SEMD) — Water Industry is a compliance framework from United Kingdom with 24 domains and 45 controls. The UK Security and Emergency Measures Direction (SEMD, 2022) issued by Defra (Department for Environment, Food and Rural Affairs) under the Water Industry Act 1991 establishes security requirements for water and sewerage companies in England and Wales. SEMD requires water companies to protect their infrastructure against threats including cyber attacks, physical security threats, and contamination. Water companies must conduct risk assessments, implement security measures, and maintain emergency plans. The Drinking Water Inspectorate (DWI) oversees drinking water quality security. Cyber resilience requirements align with NIS Regulations 2018 (and NIS2 transposition) as water is designated a critical national infrastructure sector. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does UK Security and Emergency Measures Direction (SEMD) — Water Industry have?
UK Security and Emergency Measures Direction (SEMD) — Water Industry has 45 controls organised across 24 domains. The largest domains are Physical Security (12 controls), Emergency Response and Testing (4 controls), Security Planning (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does UK Security and Emergency Measures Direction (SEMD) — Water Industry map to?
UK Security and Emergency Measures Direction (SEMD) — Water Industry maps to 497 other compliance frameworks. The top mapping partners are Defence Security Principles Framework (DSPF) (22% coverage), Protective Security Policy Framework (PSPF) Release 2024 (22% coverage), US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements (22% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with UK Security and Emergency Measures Direction (SEMD) — Water Industry compliance?
Start your UK Security and Emergency Measures Direction (SEMD) — Water Industry compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK Security and Emergency Measures Direction (SEMD) — Water Industry requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required