SCADA software certification for a remote pump station is a documentation exercise, not a brand exercise: each clause on the checklist maps to a certifiable standard, a measurable test result, or a named evidence file the audit team must produce [S1][S3].
A remote pump station, defined here as an unstaffed or minimally-staffed lift station, booster station, or transfer station with a PLC/RTU, a telemetry link, and a central SCADA master, is the smallest unit at which OT cyber, alarm-management, and protocol-certification requirements all converge [S2][S5]. For municipal, mining, irrigation, and oilfield transfer duty the same five-bucket checklist applies: hardware platform, software stack, protocol marks, alarm/lifecycle standards, and audit evidence [S1][S3].
Hardware Platform Floor: Server, HMI, and Telemetry Link
SCADA server hardware for a single-station master should meet at least the recommended column of any 2026 reference build: Intel Core i7/Xeon (v4+) CPU, 16-32 GB ECC RAM, 512 GB SSD for the OS plus 2+ TB HDD for trend archives, and Windows Server 2019/2022 or a hardened Linux LTS as the OS [S2]. Dual 1 GbE NICs are the de facto minimum so the SCADA service, the historian, and the firewall/VPN can be physically segmented without resorting to VLAN tricks at a remote site [S2].
For the HMI client, the 1920×1080 minimum and dual-monitor recommended configuration in the reference table are the practical floor for a pump-station mimic that has to show pump run state, VFD speed, suction/discharge pressure, and tank level on a single screen [S2]. Industrial panel PCs in this duty typically run a fanless Atom or i3 class CPU, 8 GB RAM, and a 12-15 in sunlight-readable touch display, sized down from the server spec because no historian runs locally.
For the outstation, an RTU or compact PLC handles level floats, pressure transmitters, flow meters, and VFD control lines; the certification-relevant question is not the brand but whether the telemetry link carries DNP3 (serial or TCP), IEC 60870-5-104, or MQTT with TLS 1.3, each of which has its own conformance regime [S5].
Software Stack: SCADA Platform, Historian, and Tag Licensing Model
Selection of the SCADA platform itself is a licensing model decision before it is a features decision: Wonderware InTouch, AVEVA Citect, and several legacy packages license per tag, while Ignition by Inductive Automation licenses per server/client with unlimited tags, and the per-tag math dominates total cost once a station exceeds roughly 2,000 I/O [S2]. For a remote pump station that typically sits between 200 and 1,500 tags, the per-server model is usually cheaper; for a 20-station fleet, the per-tag model is often cheaper, so the procurement clause must include a 10-year tag-growth projection [S3].
Other software-stack items that must appear on the checklist: native SQL/ODBC connectivity to a historian, OPC UA server (TCP 4840) for cross-vendor integration, MQTT publisher for cloud telemetry, and explicit support for the pump-station protocols in use, typically Modbus TCP (port 502) for VFDs, EtherNet/IP for Allen-Bradley PLCs, and Profinet for Siemens S7 stations [S2][S5].
Redundancy is a checklist line, not an option: hot-failover SCADA servers (WinCC Redundant, FactoryTalk View SE redundancy, Ignition redundant gateway pair) are required when the remote pump station feeds a process that cannot tolerate a 30-minute SCADA outage, and the evidence file is a recorded failover test with a timestamp and a screen capture of the partner server taking over the polling [S2][S3].
Protocol Certification: OPC UA, DNP3, IEC 60870, BACnet

Protocol certification is the easiest bucket to get wrong, because the certifier is not the SCADA vendor; it is the protocol owner, and the evidence must trace back to that owner [S3]. For OPC UA, the OPC Foundation runs a product certification process and publishes a public database of certified and non-certified products, and the checklist should require the certificate ID, the conformance profile (e.g. Micro Embedded Device Server), and the test lab name [S3].
For DNP3 and IEC 60870-5-104, conformance is administered by the DNP Users Group and the IEC TC 57 ecosystem respectively, and pump-station projects in North American water/wastewater almost always specify DNP3 while European utilities default to IEC 60870-5-104, so the cert path depends on jurisdiction [S5]. Modbus TCP and Modbus RTU are open protocols without a formal mark, but the checklist should still require a successful round-trip test against a reference simulator (e.g. Modbus Poll, MBSlave) for each register map the SCADA reads [S5].
For HVAC-adjacent stations, BACnet and BACnet/SC carry the BTL (BACnet Testing Laboratories) mark, and the checklist should list the BTL listing number and the device profile (e.g. B-AAC, B-ASC); the ICONICS guidance is explicit that BACnet/SC and legacy BACnet/IP are independently certifiable paths [S3]. IEEE 1815 (DNP3) and IEC 61850 (substation) are not interchangeable with BACnet; do not let a vendor claim one mark as covering the other [S5].
Alarm Management, Cybersecurity, and Lifecycle Standards
Alarm management on a remote pump station is governed by ISA-18.2 (Management of Alarm Systems for the Process Industries), and the checklist should require a documented alarm philosophy, a rationalised alarm set (target: fewer than 150 per operator per hour at design rate, far below the unfiltered 1,000+/hr raw rate seen on un-manned stations), and a recorded alarm-override log [S3]. The SCADA platform must support ISA-18.2 shelving, deadbands, and priority tiers natively, not via a custom scripting layer that breaks during version upgrades [S3].
Cybersecurity is the second standards line: ISA/IEC 62443 (zone/conduit model, SL-1 to SL-4 targets), the U.S. NIST SP 800-82 for industrial control systems, and NERC CIP for any station that touches the bulk-electric system; the checklist should ask for a zone drawing, a conduit list, and a patch-management SOP dated within the last 12 months [S3][S4]. The CSSA (Certified SCADA Security Architect) and GICSP (Global Industrial Cyber Security Professional) credentials are operator-side evidence, useful for the engineering team but not substitutes for the platform certification [S4].
Data integrity for dosing or compliance-relevance flow metering additionally requires FDA 21 CFR Part 11 support, which is the audit-trail, electronic-signature, and access-control regime, and the SCADA must ship a vendor Part 11 compliance statement that the owner signs off against the application scope [S3]. ISA-95 is the integration layer: the SCADA must expose a documented northbound interface (OPC UA, MQTT, REST/SQL) so the MES/ERP layer can pull the pump-station data without screen-scraping the HMI [S3].
Evidence Files and Pre-Audit Verification

The audit-day evidence is a folder structure, not a binder: per SCADA standard sections 1-5 plus appendices in the reference template, each numbered clause should be backed by a file (PDF, screenshot, or signed test record) that an auditor can open in under 30 seconds [S1]. The Wayne County SCADA Standards template (Revision 1.1, dated June 2010) is still in use as a structural model because it cleanly separates General System, Electrical Design, Hardware Design, and Control System Software standards into sections an auditor can walk linearly [S1].
Each section maps to a checklist line: Section 2 (General) covers environment, training, and lifecycle, Section 3 (Electrical) covers cabinet layout and bonding, Section 4 (Hardware) covers the I/O list, the bill of materials, and the approved-vendors list (AVL), and Section 5 (Software) covers PLC/HMI programming standards, version control, and backup/restore procedures [S1]. A practical pre-audit step is to spot-check the AVL against the delivered BOM: every CPU, every pressure transmitter, every centrifugal pump VFD, and every HMI panel must appear on the AVL with the revision date the BOM was built against.
For an outstation pump fleet, the most common failure point is not a missing certificate but a stale one: an OPC UA certificate issued against a 2018 test profile is no longer valid after the 2022 profile update, and the DNP3 conformance certificate expires when the firmware branch is end-of-life, so the checklist should require the certificate issue date AND the firmware version it was tested against on the same line [S3]. Two trackable signals: (a) the OPC Foundation's certified-products database, which is updated within 30 days of a certificate change, and (b) the DNP Users Group device list, which exposes the test lab and conformance level for each listed outstation.
Background reading: Bucket elevator selection map for retail distribution: capacity, discharge type, and.