OTRISK
Regulations

From law to proof: how EU regulations map to IEC 62443

Laws create duties. Duties are evidenced by standards. Standards run in OTRISK. Select any box to trace its path.

The pressure
What it demands
How you evidence it
How OTRISK proves it
Audit trail & reports Every verdict ends the same way: logged with actor and timestamp, reports regenerating from live data.
Trace the path. Laws create duties, duties are evidenced by standards, standards run in OTRISK. Select any box to light up its trace.
Facts verified 2026-07 against EUR-Lex, the European Commission, Rijksoverheid and NCSC. Dates change; this map is reviewed quarterly and the verified date moves with it.

The regulations, one by one

NIS2
NIS2 for OT
EU-wide cybersecurity duties for essential and important entities. In the Netherlands enforceable through the Cyberbeveiligingswet.
Read the page →
NL · Nederlandstalig
Cyberbeveiligingswet
Registratieplicht, zorgplicht en meldplicht voor zo'n 8.000 organisaties, vanaf 15 augustus 2026.
CRA
Cyber Resilience Act
Secure-by-design becomes law for products with digital elements; full obligations and CE marking from 11 December 2027.
Read the page →
RED 3.3(d/e/f)
RED & EN 18031
Cybersecurity requirements for internet-connected radio equipment, in force since 1 August 2025 until the CRA takes over.
Read the page →
2023/1230
Machinery Regulation
From 20 January 2027 machinery must protect safety-related control systems against corruption, including cyber attack.
Read the page →
CER · Wwke
CER / Wwke
Physical and operational resilience of critical entities; the Dutch Wwke enters into force together with the Cbw.
Read the page →

The law sets the date. The method is ready.

Whichever regime brought you here, it starts with a demonstrable risk analysis. Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.

See how the method runs →