OTRISK
Product · Assessments & evidence

Every requirement gets an owner, evidence and a verdict.

OTRISK runs requirement assessments against the IEC 62443 series, ISO/IEC 27001 and NIST SP 800-82 as one workflow. Scope the assessment to your target level, assign the work, collect the evidence, and let a second pair of eyes confirm every verdict. What remains is a record your auditor can trace, years later.

How an assessment runs

Create an assessment, pick the standard, set the target. From there the loop is identical for every framework: four moves, each one recorded.

1

Scope.

Set the target and the requirement set trims itself. For IEC 62443-3-3 and 4-2 the security-level target (SL-T) excludes every requirement above it; for IEC 62443-2-4 and 4-1 the maturity target scopes the criteria. You assess what your target demands, nothing more.
2

Assign.

Every requirement in scope gets an owner and a deadline. Engineers see only their own assignments; the lead sees the whole runway. Overdue work surfaces by itself, nobody chases by email.
3

Evidence.

Owners answer the requirement and attach the proof: documents, photos, records, attestations. Each item stays linked to its requirement, so the file and the verdict never drift apart.
4

Review.

Someone who did not do the work accepts or rejects, with a reason, on the record. Only then is the requirement done, and it stays inspectable for years.
Assessments Pumping station Zuid IEC 62443-3-3 · SL-T 2
trimmed to SL-T 2 · requirements above target excluded
SR 1.1 Operator identification & authentication due 15 Aug 2026 JV Accepted
SR 1.5 Credential management due 15 Aug 2026 MD Awaiting review
SR 2.1 Access authorization enforcement due 22 Aug 2026 TB Rejected · reason logged
SR 3.3 Security function verification due 29 Aug 2026 JV Not started
4 of 41 shown · every verdict by a second reviewer

Illustrative recreation of the workspace · demo data, no customer content.

Review Queue 3 awaiting your verdict
EVIDENCE Backup & restore procedure SR 7.3 · j.vandenberg Accept Reject
REQUIREMENT Malware protection Stage 1 · approved by their lead third party
EVIDENCE Firewall ruleset export SR 5.1 · t.bakker Accept Reject
accept or reject · reason required · logged with name and timestamp

Nobody accepts their own work

Every verdict comes from someone other than the person who did the work; the platform enforces it. Within your team, engineers review each other through the Review Queue. When a supplier or consultancy answers inside your tenant, review runs in two stages: their lead approves internally first, your lead gives the final verdict.

Why it matters for compliance: an assessment where authors grade their own work proves little. A named, logged second reviewer on every verdict is what makes the record defensible.

Supplier & third-party audits →

Evidence lives behind a policy check

Evidence is stored on your dedicated application instance and database, hosted in the EU. Files are never public links: every download passes a policy check that verifies, per request, that the person asking may see that file.

Every change of state carries a name, a timestamp and a comment, permanently. Audit data exports to XLSX or PDF, and every assessment generates its report as a PDF on demand.

Reports & artifacts →

SR 7.3 · Evidence Accepted
backup-policy-rev3.pdf 1.2 MB · policy-checked download
2026-07-21 09:14 · m.dekker · accepted · "matches restore test of 12 Jul"
2026-07-18 14:22 · j.vandenberg · submitted for review
2026-07-18 14:19 · j.vandenberg · uploaded · "policy rev 3, restore log attached"
process log · permanent · audit data exports to XLSX and PDF

The standards it runs today

One loop, honest scoring per standard. Where a target trims the scope, the table says so; where it does not, the full set applies.

Standard Scoring What sets the scope Third-party mode
IEC 62443-3-3 Security levels The SL-T you set; requirements above it stay out Yes
IEC 62443-4-2 Security levels The SL-T you set; requirements above it stay out Yes
IEC 62443-2-4 Maturity levels Criteria scoped to the maturity level you target Yes
IEC 62443-4-1 Maturity levels Criteria scoped to the maturity level you target Yes
NIST SP 800-82 Maturity levels A focused OT selection of the guidance Yes
ISO/IEC 27001:2022 Compliance, with documentation flags The full control set Self-assessment only
IEC 62443-2-1 Compliance per requirement The asset owner's security program Self-assessment only

In third-party mode a supplier or consultancy organisation answers inside your tenant, with the two-stage review described above. IEC 62443-3-2 is not a requirement assessment but a risk workflow, and it has its own workspace. The OT risk assessment →

References, not reprints: the standards' own text stays in your licensed copies.

See the way of working.

Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.

Thirty minutes with an OT security expert. No slideware, no SDR relay.