OT cybersecurity compliance

Know exactly where your OT estate stands.

XIRIQ turns the NCSC CAF v4.0, NIS2 and IEC 62443-3-3 into a guided assessment your engineers can actually complete, then produces the gap register, dashboard and board-ready PDF report a consultancy would charge tens of thousands for.

Free during early access · No credit card · UK/EU data residency
Built for operators under UK NCSC CAF NIS2 DIRECTIVE IEC 62443-3-3
OT cybersecurity knowledge

Understand the frameworks behind your assessment.

Practical guidance on the NCSC Cyber Assessment Framework, NIS2 and IEC 62443: what they require, where they overlap, and how they apply to OT, SCADA and critical infrastructure environments.

Framework guides, comparisons and assessment-readiness articles, written for the engineers who have to answer the questions, not just the people who read the reports.

View all resources

Three frameworks. One assessment workflow.

Every requirement rewritten in plain engineering language, with the network zones, IEDs and remote-access realities of real industrial estates in mind.

UK NCSC CAF
41 outcomes

Cyber Assessment Framework

The version UK regulators assess operators of essential services against today.

  • +Full v4.0 coverage: all 41 contributing outcomes.
  • +Detailed mode assesses the CAF's own indicators of good practice.
  • +Sector overlays and regulator target profiles supported.
How XIRIQ assesses the NCSC CAF v4.0 →
NIS2
15 obligations

Directive obligations

Governance duties, the ten Article 21 risk-management measures, and the 24h / 72h / 1-month incident-reporting deadlines under Article 23.

NIS2 obligations in XIRIQ →
IEC 62443-3-3
51 requirements

System security requirements

All base requirements across FR1 to FR7, scoped automatically to your target security level (SL-T). The contractual standard on most energy projects.

IEC 62443-3-3 requirements and SL-T scoping →

From blank page to board-ready report

A structured workflow, not a chatbot. Your answers stay yours.

01

Define scope

Site, zones, target security level. The framework adapts to what is actually in scope.

02

Assess

Work through plain-language requirements. Mark implemented, partial or gap, with evidence notes.

03

See your position

Live dashboard with compliance by section and a severity-ordered gap register.

04

Issue the report

AI-drafted executive summary and a formatted PDF: referenced, paginated, review-ready.

Questions engineers actually ask

Yes. Free during early access, full functionality, no credit card. Paid team and multi-site tiers will come later; early users keep generous terms.

Run your first gap assessment today.

45 minutes from sign-up to a scored, exportable position.

Create free account