Shape

Service · Industrial cybersecurity

OT assessment and hardening: IEC 62443 and NIS2 readiness

Know where your industrial site stands on security and what to fix first, without stopping production.

Pricing
Fixed price, on quotation
Typical duration
2 to 4 weeks depending on scope
Who it is for
Industrial SMEs and mid-caps · Water and energy sites

Who it is for

  • Industrial SMEs and mid-caps
  • Water and energy sites
  • Food and beverage
  • Any site likely to fall within NIS2 scope

Why now

  1. The French Resilience Act transposing NIS2 is debated in plenary session on 7 October 2026: obligations will follow publication of the decrees.
  2. OT incidents have physical consequences: downtime, worker safety, product quality.
  3. People who understand both a PLC and an industrial firewall are scarce.

Deliverables

What we deliver

  • Map of OT assets and flows (PLCs, HMIs, SCADA, remote access)
  • Zones and conduits per IEC 62443-3-2
  • Risk analysis and target security levels
  • Segmentation and hardening recommendations
  • Review of remote access and maintenance accounts
  • Prioritised roadmap aligned with NIS2 expectations

Method

How the engagement runs

  1. 1

    Scoping

    Scope, production constraints, contacts, site access rules.

  2. 2

    On-site collection

    Visit, inventory, passive network captures, interviews with production, maintenance and IT.

  3. 3

    Analysis

    Zones and conduits, risk analysis, gap against IEC 62443 and expected NIS2 measures.

  4. 4

    Report-out

    Report, prioritised roadmap and presentation to management.

Example

Sample deliverable

Typical table of contents of the OT assessment report

Example
  1. 01Executive summary
  2. 02Scope and method
  3. 03Asset and flow map
  4. 04Zones, conduits and target security levels
  5. 05Priority risks and scenarios
  6. 063, 6 and 12-month action plan

Typical structure of a deliverable, shown for illustration. Actual content is specific to each site or product.

FAQ

Frequently asked questions

Does the assessment require a production stop?

No. Collection relies on observation, interviews and passive network captures. Any active checks are planned with you, outside production if needed.

What is the difference between IEC 62443 and NIS2?

IEC 62443 is a family of technical standards for securing automation systems. NIS2 is an EU legal obligation requiring risk-management measures. IEC 62443 is a recognised way to meet NIS2 expectations on the OT side.

What happens after the assessment?

You can implement the roadmap with your teams or integrators, or have us deliver all or part of it: segmentation, hardening, monitoring.

A regulatory deadline is coming up?

Let’s talk about your site or product. One call is enough to know where to start.

Shape