Treat vendor access as time-bounded, session-level privileged access with identity proof, logging and review. External maintenance activity should be attributable, constrained to the task and easy to reconstruct later, otherwise the organisation creates an OT blind spot at the point of highest operational sensitivity.
How Vendor Production-Floor Access Should Be Structured
External vendors should not be treated as informal helpers on the factory floor. The access model should look like privileged third-party access: time-bounded, task-scoped, sponsored, logged and reviewed. That means clear approval, explicit scope, and a way to prove who did what without giving the vendor standing access to operational systems or shared credentials.
For production environments, the practical question is not whether the vendor is trusted, but how much access the task genuinely requires. Remote or on-site maintenance should be mediated through a controlled path, with session visibility and a defined start and end. That is especially important where vendor action can affect safety, uptime, quality, or line control.
When the access path is well designed, the organisation can distinguish between routine support and high-risk intervention. Privileged Session Management Guide is a useful reference for how brokered, recorded sessions support this model, while Third-Party, B2B and Contractor Access Guide covers sponsorship, time limits and third-party review patterns for external access.
Why Production-Floor Vendor Access Becomes an OT Exposure Point
Production-floor access is sensitive because OT environments often have weaker user separation, shared terminals, and legacy tooling that can make attribution difficult. If a vendor can log in broadly, reuse access across jobs, or bypass normal supervision, the organisation loses the ability to reconstruct actions after an incident or fault.
That loss of visibility is not just a governance issue. It can become an availability and integrity issue if a maintenance session changes control settings, downloads unsafe logic, or opens a path from enterprise support tools into the plant network. OT and ICS Identity and Access Guide addresses the access model that helps reduce those blind spots, and CircleCI breach 2023 is a reminder that exposed sessions and secrets can turn maintenance pathways into broader compromise paths.
A stronger model separates authentication from session privilege. The vendor should be individually identified, approved for the task, and connected through a session that can be monitored, filtered, and terminated. If the organisation cannot trace access to a person, a ticket, and a time window, it should assume the control is too weak for production use.
What Good Practice Looks Like for External Maintenance Access
Good practice combines least privilege, short duration, and reconstructability. The vendor should receive only the commands, systems, and time needed for the maintenance event, not a reusable standing account that can be used later for unrelated work. Review should happen both before access is granted and after the session closes.
Third-Party, B2B and Contractor Access Guide supports the access governance side of that model, while Privileged Session Management Guide supports the operational side by showing how to make sessions observable and reviewable. In OT settings, that combination is more useful than relying on policy alone because it gives the organisation evidence when something goes wrong.
Vendor access should also be designed for recovery. If a maintenance session fails, overruns, or behaves unexpectedly, the organisation should be able to suspend it quickly, rotate any exposed secrets, and determine whether follow-up action is needed on adjacent systems. That is the difference between controlled support and a lingering access dependency.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-9 — Identifier and Authentication (Service and Non-Organizational Users) | Vendor production access relies on strong non-organizational user authentication. |
| AC-6 — Least Privilege | External maintenance access should be limited to the task and time window. | |
| AU-2 — Event Logging | Production-floor vendor activity must be attributable and reconstructable later. | |
| Recommendation — Require individually authenticated vendor sessions with strong proofing and traceable credentials. Restrict vendor permissions to the minimum needed for the approved maintenance task. Log vendor session activity so maintenance actions can be reviewed and reconstructed. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Cloud control mapping for governing third-party access, sponsorship and session limits. |
| Recommendation — Enforce sponsored, time-bound access and periodic review for external vendor identities. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Vendor access is fundamentally an access-control governance problem. |
| Recommendation — Apply formal access approval, restriction and review for external production access. | ||
Practitioner Guidance
What to prioritise: Put the approval and session-control path in front of the vendor, not behind it. If the access cannot be time-limited and individually attributable, do not grant production-floor access as a normal convenience.
What to verify: Confirm that every external maintenance session maps to a named person, a specific task, and a defined end time. If you cannot reconstruct the session later from logs and review evidence, the control has not been implemented deeply enough.
Common mistake: Treating the vendor as a trusted exception and issuing broad standing access because the task is urgent. Urgency is exactly when scope drift and weak oversight become most dangerous.
Practitioner takeaway: The right control objective is not simply keeping vendors out, it is ensuring that any vendor who must enter production does so through a narrow, observable, and reversible access path.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- How should security teams run access reviews for non-human identities?
- How should security teams govern non-human identities that have persistent access?
- When do NHI access reviews create more value than a one-time cleanup?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org