Multi-Framework Compliance
Track assessments across NERC CIP, IEC 62443, NIST 800-82, IEC 61511, CMMC 2.0, and more — all in one Command Center.
Manage compliance assessments, track incidents, and generate audit documentation for all your industrial clients — across every major OT/ICS framework. No spreadsheets. No manual tracking. Assessment-ready documentation in one click. Designed for multi-client consulting practices.
Request AccessA purpose-built platform for industrial cybersecurity professionals managing multiple clients.
Track assessments across NERC CIP, IEC 62443, NIST 800-82, IEC 61511, CMMC 2.0, and more — all in one Command Center.
Log and manage OT/ICS incidents across your client portfolio, and look up vendor/product vulnerabilities without scanning live OT networks.
Draft executive briefs, audit reports, and gap analyses with AI using assessment data, subject to consultant review.
Review CISA KEV information and NVD ICS advisories; verify deadlines and obligations with official sources.
Review your authorized clients' assessment and risk metrics from a single dashboard.
Covers SCADA, ICS, DCS, PLCs, RTUs, SIS, BAS — the complete operational technology spectrum with Purdue Model visualization.
OT Comply cut our assessment documentation time by 60%. The AI report generation alone is worth the entire subscription.
Marcus Rodriguez, Senior OT Security Consultant
Finally a platform that understands the difference between NERC CIP and IEC 62443. Our audit prep went from weeks to days.
Sarah Chen, Director of ICS Compliance, Gulf Coast Energy
The ATT&CK for ICS mapping and CVE scanning give our clients a level of insight they've never had before.
James Whitfield, Principal Consultant, Nordic Grid Security
OT Comply is a multi-tenant compliance management platform designed specifically for OT/ICS cybersecurity consultants and consulting firms. It helps you manage compliance assessments, track incidents, generate AI-powered audit reports, monitor asset vulnerabilities, manage SBOM per device, and build post-quantum cryptography inventories across all your industrial clients — covering SCADA, ICS, DCS, PLCs, RTUs, SIS, and BAS systems — from a single portfolio dashboard.
OT Comply supports client assessments across frameworks such as CMMC 2.0 and NIST CSF. Other catalogs, including NERC CIP, ISA/IEC 62443, IEC 61511 and ISO/IEC 27001, require authorized or licensed content before scored assessment. NIST SP 800-82, SP 800-160 Vols. 1 and 2, and SP 800-161 are guidance overlays, not scored certifications. Custom authorized catalogs can also be imported.
In an assessment, select NIST SP 800-160 Vol. 1 for secure systems engineering, Vol. 2 for cyber resilience, or SP 800-161 for supply-chain risk management. Record engineering lifecycle decisions and scenarios, client-scoped supplier risks, and inherited or shared responsibilities, with links to existing evidence and remediation. These are guidance and traceability tools, not independent scored certifications.
The PQC Inventory records known cryptographic algorithms across a client's documented OT assets, using vendor datasheets, firmware changelogs and protocol specifications without scanning OT devices. It classifies recorded algorithms against NIST and NSA guidance, suggests post-quantum alternatives where applicable and estimates Harvest-Now-Decrypt-Later exposure based on asset context. AI can help extract candidate algorithms from vendor text; consultants should verify its findings.
No. OT Comply is a documentation-driven platform by design. Asset inventories, SBOM entries, cryptographic inventories, and compliance assessments are all built from vendor documentation, network diagrams, firmware changelogs, and consultant knowledge — not live scanning. This is intentional: most OT environments cannot safely support network scanning or agent installation on safety-critical systems.
OT Comply uses AI to draft gap analyses, remediation suggestions, and audit reports from assessment data. Where supported, results stream in the platform; response times vary, and consultants must review drafts before use. Document-driven assessment can recommend control statuses with citations from uploaded policies and procedures, and can reuse unchanged document results on rerun. AI assistance is also available for incident triage and extracting algorithm references from vendor materials.
OT Comply focuses on operational technology: it uses Purdue-level asset context, supports OT-focused assessments where catalogs are authorized, includes ATT&CK for ICS mapping, offers vendor/product vulnerability lookups and a documentation-based cryptography inventory, and is designed for consultants managing multiple clients.
Yes — the Command Center helps authorized consultants manage multiple clients with assessment status, risk metrics, alerts, engagement timelines, and evidence management. Available features and client limits depend on your access and plan.
The inventory supports documented SCADA servers, HMIs, PLCs, RTUs, DCS controllers, SIS systems and BAS devices, organized by Purdue level. You can import CycloneDX SBOMs and compare their components with available CISA KEV and NVD vulnerability data, then use SSVC-based prioritization. Vendor/product/firmware lookups do not scan live OT devices or guarantee complete vulnerability coverage.
Yes — the Evidence Bundle feature generates a single ZIP per framework with one click. Each bundle contains a machine-readable manifest, an executive narrative, the full control register, an exception register, the incident log, and every linked evidence file pulled from secure object storage. Bundles are pre-formatted for NERC CIP, TSA Pipeline, EU NIS2, and other major OT audit programs, and are retained for 90 days with audit-trail metadata. Packages support attestation workflows, not formal certification.
Bundles include SHA-256 file hashes. When signing is configured and succeeds, the manifest is signed with Ed25519 and contains a reference to the previous package for the client. A signature is included only on successfully signed packages. A trusted RFC 3161 timestamp and its verification request are included only if a configured timestamp authority's response passes certificate-chain, policy, signature, imprint and nonce verification; otherwise the package clearly states no trusted timestamp was issued. Reviewers can verify a signed package using its manifest and the public key at /api/audit-packages/signing-key. Any framework crosswalk is for reference and does not itself establish compliance.
From the Audit Package tab, click Share to create a time-bounded download link (default 72 hours, configurable). The link is an HMAC-signed token validated against a server-side hash and rate-limited; auditors download the package without a Replit or Clerk account. Every download is logged with timestamp and IP, and you can revoke a link instantly from the same dialog.
Supported AI workflows can tokenize recognized IP addresses, MAC addresses, emails, control IDs, and known asset names before a request leaves the server, with configurable patterns and redaction audit traces. The server keeps mappings for restoring tokenized values when needed. This does not detect every kind of sensitive information; review documents before uploading them or requesting AI analysis.
The AI/Cloud Vendor Risk Registry is client-scoped: authorized users select a client before viewing or editing its provider records. It tracks provider details such as attestation status, DPA information, data residency, OT-data sensitivity, renewal dates, owner, and risk rating. Product-assurance supplier and shared-responsibility records can link only to vendors owned by the same client.
The tabletop generator produces framework-aligned exercises (IEC 62443, NERC CIP, NIST 800-82, etc.) grounded in the client's actual assets, network zones, and conduits — not generic templates. You pick a scenario type (ransomware, supply-chain, insider, physical) and difficulty, and the AI streams a complete exercise in real time: scenario background, objectives, participant roles, a timed inject timeline with decision points, discussion questions, expected actions, success criteria, hotwash questions, and explicit mapping of injects to specific framework controls.
Every PCAP configuration audit run is persisted as a snapshot. The drift forensics view diffs the two most recent snapshots and highlights exactly what changed: added or removed firewall rules, new or resolved findings, zone additions and deletions. An optional AI narrative explains the change in plain language — what drifted, why it matters, and which controls or attack paths it affects. It lets consultants answer the regulator's favourite question: 'what changed since the last audit?'
Access to OT Comply requires approval. Sign up to request access or contact us to arrange a guided demo; approval timing varies.