ISA/IEC 62443 · assessment & assurance for OT estates

Align your OT estate
to IEC 62443.
Prove it with evidence.

ZeroGap OT turns a plant, site or whole estate into a governed IEC 62443 model: zones and conduits drawn the moment you define them, a Cybersecurity Requirements Specification in one click, component evidence assessed against IEC 62443-4-2 and readiness tracked against approved targets — with an audit trail a regulator can follow.

Self-hosted. Offline-capable. Know your gaps, show your evidence.

Inside ZeroGap OT

From a blank system
to a defensible assessment.

Follow one water treatment system through ten stages. Explore the screens, decisions and outputs that connect your architecture to your evidence.

01 / 10
ZeroGapOTWater Treatment SCADA / WorkspaceIllustrative data
Workspace / Water Treatment SCADA

IACS Workspace

Define scope, zones, conduits, assets, target vectors and controlled documents.

+ Create system

Water Treatment SCADA

Version 1

Control and monitoring of treatment, chemical dosing and treated-water storage.

Reference
SYS-01
Lifecycle state
Operational
Intended use
Operate the treatment process safely within the site boundary.
ZonesConduitsAssetsDocuments

Start with your system boundaries

Define zones to group assets with shared security requirements.

Stage 1 · Workspace

Start with the system you need to understand.

Create the system under consideration, describe its intended use and define its scope. This is the main workspace your zones, conduits, assets and documents belong to.

WHAT YOU TAKE FORWARD

A named, scoped system that gives every later assessment its context.

Guided interface examples based on the current application, using fictional data. Use the stage buttons, arrow keys or swipe the explanation to explore. No assessment data is submitted.

Regulatory alignment

The standard regulators
ask you to show.

Operators of essential services are asked the same question by regulators, NIS-style regimes, customers and insurers: can you demonstrate your industrial control systems are secured to a recognised standard? ISA/IEC 62443 is that standard. ZeroGap makes the answer a governed record rather than a slide.

01

Regulations recorded with the system

Every system under consideration carries its applicable regulations, policies, sites, tolerable-risk criteria and risk-assessment references. They travel into the CRS and every governed report, so the regulatory context is never reconstructed after the fact.

02

Claims you can defend

Seven foundational requirements stay independent. Machine findings are proposals; human decisions carry reviewer, rationale and independent approval. ZeroGap never averages a compliance score and never asserts an achieved security level it cannot evidence.

03

Evidence an auditor can verify

Checksum-verified evidence, a tamper-evident audit chain and a cryptographic audit export with SHA-256 integrity proofs. Reports snapshot the exact review state, policy version and evidence cut-off behind each result.

IEC 62443-3-2
Zones, conduits, ZCR drawings and the Cybersecurity Requirements Specification.
IEC 62443-3-3
System requirements FR 1 to FR 7, seven-part SL-T vectors and zone readiness.
IEC 62443-4-2
Component assessment of PLCs, HMIs, network devices and software against CR 1 to CR 7.

Zones & conduits · instant

Drawn the moment
you define them.

Add a zone or conduit and it is on the drawing. ZeroGap generates the ISA/IEC 62443-3-2 zone-and-conduit drawing from the recorded model — with trust boundaries, protocols, permitted flows and each zone's SL-T target — so the architecture, the requirements and the drawing never drift apart.

  • Guided creation. References auto-suggested from names. Trust boundaries, external connections, direction and protocols captured per conduit.
  • Targets on the drawing. Approved and draft seven-part SL-T vectors shown against each zone, with asset placement.
  • Export anywhere. PDF, high-resolution PNG, native Draw.io, Mermaid markup and a full ZCR matrix as CSV/Excel.
Zone & conduit drawingSYS-01 · ZCR 6.3Illustrative
Illustrative zone-and-conduit drawingAn enterprise network connects through a trust boundary to a DMZ and historian zone, which connects to a process control zone and a safety instrumented zone. Each zone shows its seven-part target security level.Enterprise networkEXTERNAL · UNTRUSTEDTRUST BOUNDARYCN-01 · HTTPS · inbound onlyDMZ / Historian zoneZN-DMZ-02 · DATA COLLECTIONSL-T2 2 2 1 2 2 2CN-02 · OPC UACN-04 · Modbus/TCPProcess Control ZoneZN-PCZ-03 · CLOSED-LOOP CONTROLSL-T2 2 2 1 2 2 2PLC-04HMI-02SW-11+9CN-03Safety Instrumented ZoneZN-SIS-01 · SIS BOUNDARYSL-T · DRAFT3 3 3 2 2 2 3SIS-01SIS-02
Generated from the recorded system. Targets are design targets, not achieved levels.
IEC 62443-3-2 ZCR 6 · DRAFT FOR REVIEW

Cybersecurity Requirements Specification

Water Treatment SCADA · SYS-01 · v4
  1. 1
    System under considerationName, reference, lifecycle state, intended use and process under control
  2. 2
    System scopeZCR 6.2 · physical and logical scope, sites, applicable policies and regulations
  3. 3
    Zone characteristicsZCR 6.4 · purpose, boundaries, critical and essential functions
  4. 4
    Conduit characteristics and endpointsZCR 6.4 · direction, protocols, permitted flows, trust boundaries
  5. 5
    Target security level profilesIEC 62443-3-3 FR 1 to FR 7 · SL-T vectors with status and rationale
An export of recorded information. Unrecorded values are labelled missing, never generated.

CRS · one click

A requirements spec
from what you recorded.

The Cybersecurity Requirements Specification is the document IEC 62443-3-2 asks for and most OT teams assemble by hand. In ZeroGap it is a button on the system workspace. Scope, architecture, zone and conduit characteristics and the seven-element SL-T vectors, with their status and rationale, are compiled from the live model and opened for saving as PDF.

  • Honest by design. The CRS describes exactly what is recorded for that system. Nothing is padded to look complete.
  • Always current. Change a target, a boundary or a protocol and the next export reflects it — versioned against the system record.
  • An input to design. Hand it to integrators, product suppliers and internal architecture as the requirement baseline for the system.

Simplifying 62443 for OT estates

One connected path
from estate to evidence.

IEC 62443 alignment usually lives in spreadsheets, Visio files and inboxes. ZeroGap puts the model, the targets, the component assessments, the review decisions and the reports in one governed workflow — across every system, site and organisation in your estate.

01

Model the estate

Create each system under consideration with its zones, conduits and assets. References are auto-suggested; trust boundaries, protocols and permitted flows are recorded as you go.

02

Set targets, generate the CRS

Record a seven-part SL-T vector per zone and conduit with rationale and approval. Export the zone-and-conduit drawing and a draft Cybersecurity Requirements Specification instantly.

03

Assess component evidence

Run the signed IEC 62443-4-2 component assessor against uploaded, checksum-verified evidence. Findings are kept as an immutable machine baseline.

04

Review, approve, remediate

Reviewers accept, reject or override with rationale. Approvers sign off independently. Gaps get owners, due dates and implementation evidence.

05

Prove readiness

Compare demonstrated capability with approved targets per zone, then snapshot governed reports for auditors, regulators and the board.

Built for estates, not single sites

Every system and asset,
governed the same way.

Organisations hold many systems under consideration. Each keeps its own zones, conduits, assets, targets, evidence and review history, while roles, search and reporting work across the whole estate.

01

Search the whole workspace

Find any asset, vendor, model, zone or system across the estate with wildcard search, then open it in context.

02

Reassessment that keeps pace with change

Schedule first and repeat assessments per asset. A firmware change flags the device for reassessment while earlier results stay available.

03

Separation of duties by role

Assessors, reviewers, approvers, risk owners and auditors have distinct permissions. Approvers cannot approve their own decisions.

04

Controlled evidence library

Checksum-addressed documents assigned to systems and assets, with bulk assignment and a register of everything reviewers relied on.

Outputs for the work you do

The right report.
The context behind it.

Explore the current picture, document the system design or preserve an assessment for review and audit. Every governed report carries scope and provenance metadata and keeps the seven security levels independent.

LIVE INSIGHTS · PDF

Understand the current picture

A posture dashboard built from finalised reviews: approved SL-T comparisons, findings by requirement, defence-in-depth indicators and inventory drill-downs, exportable with its scope and filters.

A live snapshot of the workspace.
REQUIREMENTS SPECIFICATION · PDF

Document the system design

The CRS and zone-and-conduit drawing with target profiles, derived requirements, open specification actions and asset placement.

An input to security architecture and design.
GOVERNED REPORTS · PDF / CSV / JSON

Preserve the assessment record

Thirteen governed report types plus the CRS, generated from a snapshot of the approved review state by a dedicated worker.

Immutable snapshots with recorded review and approval state.

Controlled by your organisation

Your estate.
Your infrastructure.

ZeroGap OT is a licensed, self-hosted platform. Your deployment holds the system model, evidence, review history and reports — on your network, including fully disconnected sites.

Offline assessment
Deterministic assessment is the default and supports disconnected environments. Signed offline licences, releases and backups need no registry.
Optional AI review
AI use is licence- and policy-controlled. When enabled, configured providers may receive assessment evidence; when disabled, nothing leaves your deployment.
Controlled access
Organisation-scoped permissions, MFA, revocable sessions and a tamper-evident audit chain support accountable working.