OTRISK
Product · Reports & artifacts

The document you hand across the table.

Compliance ends as paper: the report a regulator, customer or auditor holds. In OTRISK those documents generate from live assessment data, on demand. The Initial Risk Assessment and the Cybersecurity Requirements Specification come out of the IEC 62443-3-2 workflow, every requirement assessment exports its own report, and audit data exports to XLSX or PDF.

Four artifacts, generated on demand

None of these is written in a text editor. Each one is produced from work already recorded in the platform: scores, targets, verdicts, approvals. Ask for it today and it describes today.

DRAFT
INITIAL RISK ASSESSMENT · GENERATED REPORT
Pumping station Zuid
IEC 62443-3-2 · matrix v4 · generated 2026-07-28 14:06
Executive summary
Initial risk · worst case per zone
Ranked risk register
R-01
U
R-04
VH
R-07
H
OTRISK · draft watermark until approvalPage 1 of 14

Initial Risk Assessment (IRA)

The risk picture your management signs: executive summary, the plotted risk matrix, the ranked risk register, and the scales and method behind them. It generates from the initial risk step of the IEC 62443-3-2 workflow. Until the assessment is approved, every copy carries a draft watermark. The document never claims a status the work does not have.

CYBERSECURITY REQUIREMENTS SPECIFICATION
Pumping station Zuid
IEC 62443-3-2 · CRS · version 1.0 · 24 Jul 2026
Approved · T. Bakker, asset owner · 24 Jul 2026 · on the record
Zones, conduits and targets
Z1 · Process control networkSL-T 2
Z2 · Safety instrumented systemSL-T 3
Z3 · Packaging lineSL-T 1
C1 · Plant DMZ conduitSL-T 2
completeness · every asset assigned · characteristics provided · SL-T per zone & conduit
Approval status on the coverPage 1 of 9

Cybersecurity Requirements Specification (CRS)

The work product IEC 62443-3-2 requires and the specification your integrators build against: zones, conduits and security-level targets, each with its rationale. It assembles from the work already done, behind a completeness check: no asset unassigned, no zone without a target. The cover shows the approval status, straight from the workflow: who approved, and when.

ASSESSMENT REPORT · GENERATED
Pumping station Zuid
IEC 62443-3-3 · SL-T 2 · generated 2026-07-28 14:06
In scope
96
Accepted
61
Open
35
Per requirement
SR 1.1 Human user identification Accepted
SR 1.5 Authenticator management Accepted
SR 2.1 Authorization enforcement Open
every verdict · a name · a datePage 1 of 22

Assessment report

Every requirement assessment exports its own report the same way: where the assessment stands, requirement by requirement, with every verdict traceable to a person and a date. The same mechanism serves IEC 62443-3-3, 2-4, 4-1, 4-2 and 2-1, ISO/IEC 27001 and NIST SP 800-82.

audit-pumping-station-zuid.xlsx 214 rows
Req
Verdict
Reviewer
Date
SR 1.1
accepted
m.dekker
21-07
SR 1.2
accepted
m.dekker
21-07
SR 2.1
rejected
t.bakker
18-07
SR 2.3
accepted
j.vdberg
17-07
SR 3.1
accepted
m.dekker
16-07
Export XLSX Export PDF process log included

Audit export

Formal audit records export to XLSX or PDF: the same recorded facts, in the format the receiving side works in. A spreadsheet for the analyst, a document for the file.

Illustrative recreations of the documents · demo data, no customer content.

Three facts, stated plainly

Reports are English-only today.

Every generated document is in English. Dutch and Spanish reports are on the roadmap; plan on them when they ship, not before.

Only the IRA is watermarked.

The draft watermark exists on the IRA alone, and it disappears on approval. The CRS states its approval status on the cover instead. Either way, the reader sees the true state of the work.

No general data export yet.

What leaves the system today: reports as PDF, audit data as XLSX or PDF. A general structured export of assessment data is not shipped, and we will not pretend otherwise.

Your assessment ages. The documents do not.

A consultancy report expires the day it is delivered. A generated document cannot: it is produced from the assessment as it stands, every time. Change a risk score on Tuesday, regenerate the IRA on Wednesday, and the executive summary, the matrix plot and the ranked register are already consistent. Nobody reconciles versions, because there is only one source.

The same holds at re-assessment. In OTRISK the second assessment is a review of living data, not a rebuild, and the moment it is done the new documents are one click away.

Documents · Pumping station Zuid live data
Initial Risk Assessment (IRA)
PDF · draft watermark until approval
Generate
Cybersecurity Requirements Specification
PDF · approval status on the cover
Generate
Assessment report · IEC 62443-3-3
PDF · verdicts per requirement
Generate
Audit export
XLSX or PDF
Export
generated from the assessment as it stands · English

Written for the people who receive them

A document only works if the receiving side trusts it. These are built for three readers.

Auditors and certification bodies

The IRA and CRS follow the structure IEC 62443-3-2 prescribes, and every verdict traces to a person and a date. Auditors can also be given their own role-based access instead of an export; the Security & architecture page describes how access and evidence downloads are guarded.

Regulators and supervisors

NIS2-era laws ask for demonstrable, per-installation risk management. When a supervisor asks how you decided what appropriate measures are, the IRA shows the analysis behind the answer: your risks, on your own matrix, with management approval on the record.

Customers

Customer audits and RFPs quote IEC 62443. An assessment report answers in the standard's own terms, requirement by requirement, instead of a questionnaire nobody can verify.

Want to hold one first? We share a redacted sample IRA with teams evaluating OTRISK. Request the sample IRA report →

See the documents with your own eyes.

Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.