Open an assessment in OTRISK and the tabs are the standard: risk-assessment steps, requirement sets, maturity levels, exactly as the IEC 62443 series structures them. Your own risk matrix, your own network diagrams, your own targets. Methodology debates end, because the methodology is on screen.
Illustrative recreation of the workspace · demo data, no customer content.
Every law and every customer audit ends in the same demand: show that your risks are managed. A standard defines what "show" looks like, and OTRISK runs the standard as a workflow. The loop never changes: each requirement gets an owner, a deadline, evidence and an independent verdict. Whichever framework you're held to, the proof comes out the same shape.
Set a target first, and only the requirements your target demands enter the assessment. Nobody works through 400 clauses because a checklist said so.
New frameworks join as requirement sets: same owners, same review, same permanent log. Your team doesn't relearn a thing.
References, not reprints: the standards' own text stays in your licensed copies.
IEC 62443-3-2 structures the OT risk assessment as seven gated steps, and the workspace walks them in order, each one submitted by one person and accepted by another. If a law brought you here, this is the piece it asks for first: the demonstrable, per-installation risk analysis that decides what "appropriate measures" means for you. In our own words:
Deep dive: the full IEC 62443-3-2 risk assessment workflow →
Risk managers rightly distrust tools that impose a risk model. In OTRISK your organisation's matrix is configured once: impact levels, likelihood scale, consequence categories such as Safety & Health, Environment, Operations, Financial and Product Quality, tolerable-risk bands and the mapping to security-level targets. Every assessment freezes its own copy, so results stay comparable across years even when the matrix evolves.
Why it matters for compliance: "appropriate" is measured against your own tolerance. When the auditor asks why a zone's target is what it is, the answer traces to a matrix your management approved, not a vendor default.
Every submission, whether a piece of evidence, an assessment step or a document, is accepted by someone other than its author; the platform enforces it. Every change of state carries a name, a timestamp and a comment, permanently. When the auditor asks "who reviewed the zone partitioning, and when", the answer is a click, not an archaeology project.
Why it matters for compliance: the laws put accountability on management. A permanent record of who decided and who verified is what "accountable" looks like on paper.
Compliance ends as paper: the document you hand the regulator, the customer or the auditor. These two are generated, not written. In plain terms they say "we know our risks" and "here is what our system must meet".
The risk picture your management signs: executive summary, the plotted matrix, the ranked register, scales and method, all generated from live data.
The spec your integrators build against: the work product IEC 62443-3-2 requires, with the approval status on the cover.
Both regenerate on demand, and requirement assessments export their own report the same way. Your assessment ages; the documents don't. Request the sample IRA report →
Scope-dependent. The workflow is built so the initial risk assessment of a first System under Consideration is measured in weeks, not months, and re-assessments become review passes because nothing is rebuilt.
The workflow encodes the method, which lowers the bar considerably, but risk decisions remain yours. If you want guidance, our OT security experts co-run the first assessment and train your team until it runs alone; and if you work with an OT security consultancy, they can deliver inside your environment with their own roles. Onboarding & enablement →
The IRA and CRS follow the structure the standard prescribes, and every verdict in them is traceable to a person and a date. Auditors can be given their own access instead of an export.
A network drawing (any common format), a list of the people involved, and one system you care about. That's the first workshop.
On a dedicated application instance and database per client, hosted in the EU, behind role-based access and MFA. Prefer evidence files not to move at all? Register a reference to your SharePoint, Tresorit or DMS instead of uploading; OTRISK keeps the pointer and the verdict. Details on the Security & architecture page.
Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.