Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
CPS is broader than classic OT; look for named asset-class coverage with per-class protocol depth, not an OT product relabeled 'CPS.'
Active scanning has crashed real controllers; strong answers lead passive-first with a documented safety record for any active techniques.
In CPS, consequence is physical — look for process-impact-aware risk models, not raw CVSS lists that rank a lab thermostat above a safety controller.
Look for enforcement through your existing network stack plus continuous validation — recommendations without enforcement integration leave the gap open.
Third-party remote maintenance is the top CPS intrusion path; strong answers offer brokered, recorded, per-session-approved access rather than shared VPN accounts.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Much of a CPS fleet can't be patched; look for compensating-control workflows (segmentation, monitoring) with residual-risk tracking, not patch-centric workflows that dead-end.
Look for CPS-native detections mapped to ATT&CK for ICS, not IT NDR heuristics applied to industrial traffic.
CPS buyers are usually regulation-driven; look for named-framework evidence reports, not a generic compliance dashboard.
Look for transparent, predictable per-site/per-facility scaling economics; CPS deployments often span many distributed sites with real budget-risk implications if pricing isn't clear upfront.
A compromised medical device or building safety system carries physical-safety risk that a generic IT IR team may not be equipped to handle safely — ask specifically about physical-safety-aware response expertise and a real engagement track record.
CPS environments (a hospital, a smart building, a fleet depot) often require deep sector-specific operational knowledge — a mature integrator ecosystem indicates a more scalable, lower-risk deployment path.
The cost asymmetry of false positives is far higher for CPS (a false alarm can disrupt patient care or building safety systems) than in IT — a vendor should have a CPS-context-aware answer, not a generic IT-derived accuracy figure.
A vendor should give an honest answer about whether facilities with less-mature network infrastructure get materially weaker coverage — a common real-world gap for large multi-site organizations.
Trend-over-time reporting is a distinct capability from a real-time dashboard — confirm this exists as a maintained, exportable report, particularly relevant given the regulatory reporting burden common in CPS-heavy sectors (healthcare, critical infrastructure).
Look for specific data-residency options; a vendor offering only a single-region SaaS with no on-prem/regional processing option may not meet regulatory requirements for the most sensitive CPS environments.
Correlating cyber and physical-security signals is an emerging, valuable capability for CPS environments where the two domains genuinely intersect — a vendor should clarify whether this integration is real or the two domains remain fully siloed.