Invite integrators, maintenance parties and product suppliers to answer requirements inside your OTRISK tenant: IEC 62443-2-4, 3-3, 4-1, 4-2 or NIST SP 800-82, against the target you set. They submit, your team accepts, and both verdicts stay on the record.
Illustrative recreation of the workspace · demo data, no customer content.
Supplier oversight deserves the same discipline as your own assessments. Same system, same rules.
A supplier audit in OTRISK is a normal assessment with one difference: the organisation answering is not yours. The flow enforces who does what.
The supplier submits. Their lead approves, stage one. Your reviewer decides, stage two. The platform enforces the order and the separation: nobody accepts their own submission, and a supplier approval never counts as your acceptance.
Why it matters for procurement: when the renewal or the next bid comes, nobody trades recollections. Both sides look at the same requirement, the same evidence and the same logged verdicts, each with a name, a timestamp and a reason. The conversation stays factual.
A questionnaire leaves and silence follows. A supplier audit in your own tenant behaves differently: you watch it move.
Every requirement shows its owner, its deadline and its state. Overdue items surface on their own; nobody chases by email.
Each piece of evidence stays linked to its requirement and both verdicts, for years. Downloads are policy-guarded.
Generate the assessment report as a PDF whenever someone asks, and export the audit data to XLSX or PDF for procurement or your auditor.
IEC 62443-2-4 describes the security capabilities an OT service provider must bring: staffing, architecture, remote access, patching, backup and more. That makes it the natural baseline for integration and maintenance contracts: agree the profile and the maturity target in the contract, then keep a standing assessment against it in your tenant.
Contract renewals change character. Instead of a fresh questionnaire, you open the record: what was accepted, what was rejected and why, and what changed since last year.
Five requirement standards support the supplier flow today. Each runs the same loop: their answer, their lead's first-stage review, your verdict.
The risk assessment stays a self-assessment: the risk decision is yours, taken with two-person review. Supplier evidence can inform it; it never replaces it.
Owning OT risk across supplier-run systems: targets, evidence, proof.
The other side of the audit: answer once, properly, and reuse it every bid.
The requirement, owner, evidence, verdict loop that every standard runs on.
Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.