OTRISK runs requirement assessments against the IEC 62443 series, ISO/IEC 27001 and NIST SP 800-82 as one workflow. Scope the assessment to your target level, assign the work, collect the evidence, and let a second pair of eyes confirm every verdict. What remains is a record your auditor can trace, years later.
Create an assessment, pick the standard, set the target. From there the loop is identical for every framework: four moves, each one recorded.
Illustrative recreation of the workspace · demo data, no customer content.
Every verdict comes from someone other than the person who did the work; the platform enforces it. Within your team, engineers review each other through the Review Queue. When a supplier or consultancy answers inside your tenant, review runs in two stages: their lead approves internally first, your lead gives the final verdict.
Why it matters for compliance: an assessment where authors grade their own work proves little. A named, logged second reviewer on every verdict is what makes the record defensible.
Evidence is stored on your dedicated application instance and database, hosted in the EU. Files are never public links: every download passes a policy check that verifies, per request, that the person asking may see that file.
Every change of state carries a name, a timestamp and a comment, permanently. Audit data exports to XLSX or PDF, and every assessment generates its report as a PDF on demand.
One loop, honest scoring per standard. Where a target trims the scope, the table says so; where it does not, the full set applies.
| Standard | Scoring | What sets the scope | Third-party mode |
|---|---|---|---|
| IEC 62443-3-3 | Security levels | The SL-T you set; requirements above it stay out | Yes |
| IEC 62443-4-2 | Security levels | The SL-T you set; requirements above it stay out | Yes |
| IEC 62443-2-4 | Maturity levels | Criteria scoped to the maturity level you target | Yes |
| IEC 62443-4-1 | Maturity levels | Criteria scoped to the maturity level you target | Yes |
| NIST SP 800-82 | Maturity levels | A focused OT selection of the guidance | Yes |
| ISO/IEC 27001:2022 | Compliance, with documentation flags | The full control set | Self-assessment only |
| IEC 62443-2-1 | Compliance per requirement | The asset owner's security program | Self-assessment only |
In third-party mode a supplier or consultancy organisation answers inside your tenant, with the two-stage review described above. IEC 62443-3-2 is not a requirement assessment but a risk workflow, and it has its own workspace. The OT risk assessment →
References, not reprints: the standards' own text stays in your licensed copies.
Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.
Thirty minutes with an OT security expert. No slideware, no SDR relay.