What XIRIQ is and is not

XIRIQ is assessment support tooling for OT cybersecurity frameworks. It gives you a structured way to work through a framework, record honest judgements, keep evidence references organised and produce a clear report.

What it is

  • A structured workspace for assessing against the UK NCSC CAF v4.0, NIS2 and IEC 62443-3-3.
  • A record of your judgements: every status you set is yours, with room for notes and justification.
  • An evidence register that cites your documents without storing them.
  • A report generator that presents results the way each framework intends, including no invented CAF score.

What it is not

XIRIQ is not assurance, audit or certification. Completing an assessment here does not mean a regulator, certification body or customer has accepted anything. The judgements in the report are the assessor's own, and the report says so. Framework wording in the app is paraphrased for assessment support; verify against the source standard or legislation before formal use.

Who it is for

Engineers and security leads who need to understand their current position against a framework, prepare for a regulator conversation, or track improvement between reviews. If you need formal certification, XIRIQ helps you prepare for it; it does not replace it.

Can't find what you need? Browse the Resources articles or use the feedback button inside the app.