Compliance ends as paper: the report a regulator, customer or auditor holds. In OTRISK those documents generate from live assessment data, on demand. The Initial Risk Assessment and the Cybersecurity Requirements Specification come out of the IEC 62443-3-2 workflow, every requirement assessment exports its own report, and audit data exports to XLSX or PDF.
None of these is written in a text editor. Each one is produced from work already recorded in the platform: scores, targets, verdicts, approvals. Ask for it today and it describes today.
The risk picture your management signs: executive summary, the plotted risk matrix, the ranked risk register, and the scales and method behind them. It generates from the initial risk step of the IEC 62443-3-2 workflow. Until the assessment is approved, every copy carries a draft watermark. The document never claims a status the work does not have.
The work product IEC 62443-3-2 requires and the specification your integrators build against: zones, conduits and security-level targets, each with its rationale. It assembles from the work already done, behind a completeness check: no asset unassigned, no zone without a target. The cover shows the approval status, straight from the workflow: who approved, and when.
Every requirement assessment exports its own report the same way: where the assessment stands, requirement by requirement, with every verdict traceable to a person and a date. The same mechanism serves IEC 62443-3-3, 2-4, 4-1, 4-2 and 2-1, ISO/IEC 27001 and NIST SP 800-82.
Formal audit records export to XLSX or PDF: the same recorded facts, in the format the receiving side works in. A spreadsheet for the analyst, a document for the file.
Illustrative recreations of the documents · demo data, no customer content.
Every generated document is in English. Dutch and Spanish reports are on the roadmap; plan on them when they ship, not before.
The draft watermark exists on the IRA alone, and it disappears on approval. The CRS states its approval status on the cover instead. Either way, the reader sees the true state of the work.
What leaves the system today: reports as PDF, audit data as XLSX or PDF. A general structured export of assessment data is not shipped, and we will not pretend otherwise.
A consultancy report expires the day it is delivered. A generated document cannot: it is produced from the assessment as it stands, every time. Change a risk score on Tuesday, regenerate the IRA on Wednesday, and the executive summary, the matrix plot and the ranked register are already consistent. Nobody reconciles versions, because there is only one source.
The same holds at re-assessment. In OTRISK the second assessment is a review of living data, not a rebuild, and the moment it is done the new documents are one click away.
A document only works if the receiving side trusts it. These are built for three readers.
The IRA and CRS follow the structure IEC 62443-3-2 prescribes, and every verdict traces to a person and a date. Auditors can also be given their own role-based access instead of an export; the Security & architecture page describes how access and evidence downloads are guarded.
NIS2-era laws ask for demonstrable, per-installation risk management. When a supervisor asks how you decided what appropriate measures are, the IRA shows the analysis behind the answer: your risks, on your own matrix, with management approval on the record.
Customer audits and RFPs quote IEC 62443. An assessment report answers in the standard's own terms, requirement by requirement, instead of a questionnaire nobody can verify.
Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.