OTRISK
OT compliance platform · IEC 62443-native

From standard to signed‑off.

IEC 62443 tells you what good OT security looks like. NIS2 and its national laws demand you prove it. OTRISK connects the two: the standard's own method becomes your working system, and every cycle ends in the document a regulator, customer or auditor actually accepts.

Risk assessment · Pumping station Zuid IEC 62443-3-2 · matrix v4 · frozen
ZCR 1 ZCR 2 ZCR 3 · Zones & conduits ZCR 4 ZCR 5 ZCR 6 ZCR 7
Z1 · Process control network
SL-T 2
Accepted
Z2 · Safety instrumented system
SL-T 3
Pending review
C1 · Plant DMZ conduit
SL-T 2
Accepted
Z3 · Packaging line
SL-T 1
Above tolerance
Reviewed · m.dekker · 2026-07-21 09:32 · ZCR 3 partitioning accepted

Sound familiar?

The spreadsheet is the system.
Version 23_final_v2.xlsx. Three owners, forty tabs, zero audit trail. Everyone knows it's broken. Nobody dares to touch it.
Accountability without authority.
The law makes your management liable for OT risk. The suppliers who run half of your OT answer to procurement, not to you. You own the gap.
The re-assessment cliff.
Last year's risk assessment took four months and a consultant. It was stale the day it was delivered. Doing that every year is not a plan.

Nobody chose this. It grew over the years. You don't have to keep it.

The law tells you that. The standard tells you what. OTRISK is how you prove it.

NIS2, the Cyberbeveiligingswet, the Cyber Resilience Act: none of them name a product. All of them demand demonstrable risk management. Select any box to trace the path from law to proof.

The pressure
What it demands
How you evidence it
How OTRISK proves it
Audit trail & reports Every verdict ends the same way: logged with actor and timestamp, reports regenerating from live data.
Trace the path. Laws create duties, duties are evidenced by standards, standards run in OTRISK. Select any box to light up its trace.
Facts verified 2026-07 against EUR-Lex, the European Commission, Rijksoverheid and NCSC.

One system, three moves

ZCR 1 · Asset inventory source: PFD-B-rev12.pdf
PLC · Line 4 dosing S7-1500 parsed
HMI · Control room WinCC parsed
Historian OSIsoft PI parsed
Remote access gateway unknown flagged
Deterministic parse · nothing guessed · 3 of 41 assets flagged for a human
Step 1

Scope your system.

Start from what you already have: import the network drawing, build the asset inventory, define the System under Consideration. The diagram parser reads deterministically and never guesses; what it can't read, it flags for a human.

Step 2

Assess against the standard.

Walk the IEC 62443-3-2 steps exactly as written, on your own risk matrix, or run requirement assessments (IEC 62443, ISO 27001, NIST SP 800-82) trimmed to your security-level target. Every requirement has an owner, a deadline and an independent reviewer. Nobody accepts their own work.

Requirement assessment · IEC 62443 series trimmed to SL-T 2 · 41 in scope
Operator account control JV
Accepted
Vendor remote access policy MK
Pending review
Historian backup and restore test TB
Pending review
Packaging line segregation JV
Overdue
Review queue · 4 open · nobody accepts their own submission
Initial risk assessment
Generated 2026-07-21 · current
Cybersecurity requirements specification
Approved · on the record
Step 3

Hand over proof.

Generate the Initial Risk Assessment, the Cybersecurity Requirements Specification or the assessment report from live data, whenever asked. Change something Tuesday; the document is current Wednesday.

Built with the people who answer to regulators

Clause-faithful. The IEC 62443-3-2 workspace follows the standard step by step; we maintain a clause-by-clause gap analysis and publish what we don't do yet.
Four-eyes on everything. Two-person review on every risk-assessment step; two-stage review when third parties deliver evidence.
Your security team will ask. We answer first. Dedicated application instance and database per client, EU hosting, MFA, policy-checked evidence downloads.
No IEC 62443 veterans on staff? We make some. Guided onboarding and team training, on-site or at ours, designed to make themselves unnecessary. Onboarding & enablement →

Where do you sit?

I operate plants or infrastructure.
You own the risk, even where suppliers run the systems. Set targets, collect evidence, prove it.
I integrate or maintain OT.
Your customers now write IEC 62443 into contracts. Turn conformance into a bid advantage instead of overhead.
I build products or machines.
CRA, RED 3.3 and the Machinery Regulation are converging on you. IEC 62443-4-1/4-2 is the industrial route through.

Consultancy or auditor? You can run client assessments inside OTRISK. For partners →

The standards, natively

IEC 62443-3-2
IEC 62443-3-3
IEC 62443-2-1
IEC 62443-2-4
IEC 62443-4-1
IEC 62443-4-2
ISO/IEC 27001
NIST SP 800-82

Not another checklist import. Zones, conduits, security-level targets and maturity levels are first-class objects here, because the platform was built for this standard, not adapted to it.

From the field notes: the Polish CHP breach ran on connections nobody drew →

Bring one installation in mind. Leave with concrete next steps and pricing.

Thirty minutes with an OT security expert. No slideware, no SDR relay. We show you which parts of OTRISK fit your situation and how the way of working looks.

Request the sample IRA report →