Pipeline SCADA in Oil and Gas: Monitoring, Leak Detection, and API 1164 Security

Oil and Gas

February 26, 2024

10 minutes read

scada oil and gas

Pipeline SCADA is the supervisory control and data acquisition system that monitors and operates an oil or gas pipeline from a central control room, gathering pressure, flow, and temperature data from remote field devices across hundreds of miles. For regulated hazardous liquid pipelines it is not optional infrastructure, because federal rules require an effective leak detection system built on that data.

This guide covers what pipeline SCADA monitors, how computational leak detection works and what the regulations require, the API standards that govern SCADA displays and control room management, the cybersecurity framework under API 1164, and the power dependency that determines whether remote sites report at all.

It is written for midstream operators, pipeline controllers and integrity engineers, and the I&C and facilities teams responsible for keeping remote monitoring online.

What Pipeline SCADA Monitors and Controls

Pipeline SCADA collects real-time pressure, flow, temperature, and equipment status from field devices distributed along the pipeline, and presents that data to controllers who operate the line from a central control room. The system spans distances no local control panel can cover.

The field assets a pipeline SCADA system typically reaches:

  • Remote terminal units (RTUs) and PLCs at stations and valve sites, acquiring instrument data and executing local logic.
  • Pump stations and compressor stations, where drivers, pressures, and flows are monitored and controlled.
  • Block valves and mainline valves, which can be monitored and in many cases operated remotely.
  • Metering and custody transfer points, where flow measurement accuracy has direct commercial consequence.
  • Tank farms and terminals, monitoring level, temperature, and transfer status.

Communication runs over long-distance telemetry rather than plant networks. Because monitoring and control locations are usually remote from pump and compressor sites, pipeline operators depend heavily on third-party telecommunication services, using licensed radio, cellular, satellite, or fiber backhaul with protocols such as DNP3, Modbus, and IEC 60870-5-104.

That distributed architecture is what makes pipeline SCADA different from plant SCADA. A refinery system supervises assets inside a fence; a pipeline system supervises assets across hundreds of miles of terrain where nobody is standing. The underlying real-time monitoring and control principles are shared across both; the distances, the telemetry dependency, and the regulatory exposure are not.

Leak Detection: What the Regulations Actually Require

Federal regulation requires hazardous liquid pipelines to have an effective leak detection system, and where that system is computational, it must be built to API RP 1130. This is a legal obligation, not a best practice, and it is the single strongest driver of pipeline SCADA investment.

Under 49 CFR 195.134, each hazardous liquid pipeline transporting liquid in single phase must have a leak detection system complying with 49 CFR 195.444. Pipelines constructed on or after October 1, 2019 had to comply by October 1, 2020, and pipelines constructed before that date had to comply by October 1, 2024. Offshore gathering and regulated rural gathering lines are excepted.

The design requirement is specific. A new computational pipeline monitoring (CPM) leak detection system, or a replaced component of an existing one, must be designed in accordance with section 4.2 of API RP 1130 and any other applicable design criteria in that standard. Under 49 CFR 195.444, an installed CPM system must also comply with API RP 1130 in its operation, maintenance, testing, record keeping, and dispatcher training.

CPM is defined in the regulation as a software-based monitoring tool that alerts the pipeline dispatcher to a possible operating anomaly that may indicate a commodity release. In practice it runs on SCADA data, which means leak detection performance is bounded by the quality, timing, and availability of the telemetry feeding it.

The API Standards Governing Pipeline SCADA

Pipeline SCADA is governed by a specific family of API recommended practices, several of which are incorporated by reference into federal regulation and therefore carry legal force. Citing them correctly is how operators and integrators establish that a system is compliant.

Standard

Scope

Regulatory status

API RP 1130 (Computational Pipeline Monitoring for Liquids, 3rd ed., Sept 2007)

Design, operation, and testing of CPM leak detection systems

Incorporated by reference at 49 CFR 195.134(c) and 195.444(c)

API RP 1165 (Pipeline SCADA Displays, 1st ed., Jan 2007)

Design of SCADA screens and displays used by pipeline controllers

Incorporated by reference at 49 CFR 195.446(c)

API RP 1168 (Pipeline Control Room Management, 1st ed., Sept 2008)

Control room procedures, shift handover, fatigue management, alarm handling

Incorporated by reference at 49 CFR 195.446(c) and (f)

API 1164 (Pipeline SCADA Security)

Cybersecurity for pipeline SCADA and control systems

Industry standard, aligned with NIST and TSA requirements

The inclusion of API RP 1165 is worth noting, because it makes SCADA display design a regulated matter rather than a vendor preference. The incorporation-by-reference list in 49 CFR Part 195 identifies each edition by date, so operators should verify they are working to the edition the regulation names.

Control room management under API RP 1168 matters because leak detection alerts are only useful if a controller receives, recognizes, and acts on them. The regulation addresses the human layer deliberately, covering roles, responsibilities, shift change, and alarm management alongside the technology.

API 1164 and Pipeline SCADA Cybersecurity

API 1164, Pipeline SCADA Security, is the industry standard governing cybersecurity for pipeline SCADA and control systems in the oil and natural gas sector. It provides guidance for managing SCADA system integrity and security so that cyber activity does not cause adverse effects on personnel, the environment, the public, or customers.

The standard has evolved substantially. The first edition was released in 2004 and the second in June 2009, focused on liquid pipeline operators and covering access control, communication security, network design, physical and disaster recovery considerations, operating systems, data interchange with third parties, and field device configuration.

The current revision broadens scope considerably. API 1164 Rev 3 was developed as a risk-based standard harmonized with the NIST Cybersecurity Framework and ISA/IEC 62443, extending across the full range of pipeline operational technology environments including SCADA, local controls, and industrial IoT, for both oil and natural gas pipelines.

API 1164 does not sit alone in the compliance picture. Pipeline operators also work to TSA Pipeline Security Directives issued following the Colonial Pipeline incident, NIST SP 800-82 guidance for industrial control system security, and PHMSA integrity management obligations. A credible SCADA program is assessed against all of them together.

The Power Dependency Behind Every Remote Site

A pipeline SCADA system reports only as reliably as the power feeding its remote field devices, and at gathering sites, block valves, and remote stations, that power is often the weakest link in the chain. This dependency is routinely under-engineered relative to the SCADA hardware itself.

The failure mode is straightforward. An RTU without power stops transmitting, a telemetry radio without power stops relaying, and the control room loses visibility of that segment. From the controller's screen, a powered-down site and a communications failure can look similar, and neither produces the pressure and flow data that CPM leak detection depends on.

Remote sites are exposed because they are unmanned and often far from any grid connection. Typical arrangements include solar with battery banks, thermoelectric generators, small gas-fired gensets running on line gas, or utility service where it exists, and each has failure modes that surface in extreme cold, prolonged low irradiance, or after long service intervals.

The practical implication for operators is that SCADA availability targets should be set against the power system, not just the control hardware. Sizing battery autonomy for the worst realistic weather window, and monitoring site power as a telemetry point in its own right, prevents the situation where a leak detection system is nominally compliant but blind across part of the line.

How Prismecs Supports Pipeline SCADA Operations

Prismecs supports pipeline SCADA through I&C engineering, control system integration, and the remote power infrastructure those systems depend on, so operators get both the monitoring layer and the power that keeps it online. This combination is what distinguishes an integrator from a partner who can keep the data flowing.

The Prismecs capability set for pipeline and field SCADA:

  • SCADA integration and legacy consolidation: connecting remote equipment to centralized monitoring and bringing legacy assets onto a common platform.
  • I&C engineering: instrumentation, control panels, RTU and PLC integration, and protocol interfacing across DNP3, Modbus, and IEC 60870.
  • Remote site power: engineered power for unmanned RTU, telemetry, and valve sites, including solar and battery, gas-fired generation, and hybrid arrangements sized for real autonomy requirements.
  • Distributed energy and backup: power solutions for stations and terminals where a supply interruption would take monitoring or control offline.
  • O&M and field response: maintenance and 24/7 support across control and power assets, so a failure at a remote site is a service call rather than a blind segment.

The differentiator is covering both layers. System integrators deliver the SCADA platform and leave site power to the operator, while power suppliers deliver generation with no view of the control system. Prismecs engineers the control and power infrastructure together, which is where remote monitoring reliability is actually won.

Frequently Asked Questions

What is pipeline SCADA?

Pipeline SCADA is the supervisory control and data acquisition system that monitors and operates an oil or gas pipeline from a central control room. It collects real-time pressure, flow, temperature, and equipment status from remote terminal units at pump stations, compressor stations, block valves, and metering points, transmitted over long-distance telemetry using protocols such as DNP3, Modbus, and IEC 60870-5-104.

Is leak detection legally required on oil pipelines?

Yes. Under 49 CFR 195.134, each hazardous liquid pipeline transporting liquid in single phase must have a leak detection system complying with 49 CFR 195.444. Pipelines built on or after October 1, 2019 had to comply by October 1, 2020, and older pipelines by October 1, 2024. Offshore gathering and regulated rural gathering lines are excepted from that requirement.

What is CPM leak detection?

Computational pipeline monitoring (CPM) is a software-based monitoring tool that alerts the pipeline dispatcher to a possible operating anomaly that may indicate a commodity release. It analyses SCADA data such as pressure and flow to infer leaks. Under 49 CFR 195.134(c), a new CPM system or replaced component must be designed in accordance with section 4.2 of API RP 1130.

What standards govern pipeline SCADA?

Four standards matter most. API RP 1130 governs computational leak detection, API RP 1165 governs SCADA display design, and API RP 1168 governs control room management, all incorporated by reference into 49 CFR Part 195. API 1164 governs pipeline SCADA cybersecurity and, in its current revision, is harmonized with the NIST Cybersecurity Framework and ISA/IEC 62443.

What does API 1164 cover?

API 1164, Pipeline SCADA Security, provides guidance for managing SCADA system integrity and security in the oil and natural gas sector. Earlier editions addressed access control, communication security, network design, physical security, operating systems, and field device configuration. The current revision is risk-based, harmonized with the NIST Cybersecurity Framework and ISA/IEC 62443, and extends to SCADA, local controls, and industrial IoT.

Why does remote site power matter for SCADA reliability?

Because an RTU or telemetry radio without power stops transmitting, and the control room loses visibility of that pipeline segment. Remote sites are unmanned and often off-grid, relying on solar with batteries, thermoelectric generators, or small gas-fired units. Since CPM leak detection depends on continuous pressure and flow data, site power availability directly limits leak detection performance.

Why Pipeline SCADA Is a Compliance and Reliability Decision

Pipeline SCADA carries regulatory weight that plant monitoring does not, because leak detection built on its data is federally mandated, its display and control room practices are governed by incorporated standards, and its cybersecurity is scrutinized under API 1164 and TSA directives. Every part of the chain, from the field device to the controller's screen, sits inside that framework.

Operators need a partner who understands the standards, integrates the control layer, and engineers the remote power those field devices depend on. That is the Prismecs model: I&C and SCADA integration backed by field power infrastructure and 24/7 support.

To discuss pipeline SCADA integration, remote site power, or field monitoring reliability, call +1 (888) 774-7632 or email sales@prismecs.com.

Tags: pipeline SCADA CPM leak detection API 1164 pipeline security API RP 1130 remote site power