IEC 62443 tells you what good OT security looks like. NIS2 and its national laws demand you prove it. OTRISK connects the two: the standard's own method becomes your working system, and every cycle ends in the document a regulator, customer or auditor actually accepts.
Nobody chose this. It grew over the years. You don't have to keep it.
NIS2, the Cyberbeveiligingswet, the Cyber Resilience Act: none of them name a product. All of them demand demonstrable risk management. Select any box to trace the path from law to proof.
Start from what you already have: import the network drawing, build the asset inventory, define the System under Consideration. The diagram parser reads deterministically and never guesses; what it can't read, it flags for a human.
Walk the IEC 62443-3-2 steps exactly as written, on your own risk matrix, or run requirement assessments (IEC 62443, ISO 27001, NIST SP 800-82) trimmed to your security-level target. Every requirement has an owner, a deadline and an independent reviewer. Nobody accepts their own work.
Generate the Initial Risk Assessment, the Cybersecurity Requirements Specification or the assessment report from live data, whenever asked. Change something Tuesday; the document is current Wednesday.
Consultancy or auditor? You can run client assessments inside OTRISK. For partners →
Not another checklist import. Zones, conduits, security-level targets and maturity levels are first-class objects here, because the platform was built for this standard, not adapted to it.
From the field notes: the Polish CHP breach ran on connections nobody drew →
Thirty minutes with an OT security expert. No slideware, no SDR relay. We show you which parts of OTRISK fit your situation and how the way of working looks.