Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
26 criteria
baselineWhat OT/ICS-specific protocols does the platform natively parse and understand (Modbus, DNP3, S7comm, EtherNet/IP, BACnet, etc.), and how many are supported out of the box versus requiring custom parsers?
baselineDescribe the asset-discovery methodology for OT environments — passive network monitoring only, or does it include active scanning — and what is the documented safety record for active scanning on fragile legacy control systems?
baselineHow does the platform handle IT/OT network segmentation validation — can it verify that Purdue Model boundaries are actually enforced, not just documented?
baselineWhat is the vulnerability intelligence source for OT-specific CVEs (ICS-CERT/CISA advisories, vendor PSIRTs), and how quickly are newly disclosed ICS vulnerabilities correlated against the discovered asset inventory?
baselineDetail anomaly detection for OT-specific attack patterns (unauthorized PLC logic changes, abnormal command sequences) versus generic IT-style network anomaly detection repurposed for OT.
baselineDoes the platform provide risk scoring specific to safety-instrumented systems (SIS) and safety-critical assets, distinguishing them from general OT assets?
baselineExplain deployment architecture for air-gapped or highly segmented OT networks — can the platform operate fully on-prem/offline, and how are updates/signatures delivered without direct internet access?
baselineWhat incident response capability exists specific to OT — can the platform support safe isolation of a compromised OT asset without disrupting physical process operations?
baselineWhat is the pricing model — per asset, per site, or a flat enterprise tier — and how does cost scale for a large industrial customer with many geographically distributed facilities, each with its own asset population?
baselineDoes the platform map coverage to OT-specific compliance frameworks (IEC 62443, NERC CIP) with audit-ready reporting, and can it demonstrate compliance-relevant evidence (e.g., asset inventory completeness, network segmentation validation) directly to an auditor?
baselineDescribe the vendor/systems-integrator ecosystem for deployment support — does the vendor have established partnerships with OT integrators experienced in the customer's specific industrial processes, or does deployment rely entirely on the vendor's own limited field team?
baselineWhat OT-specific threat intelligence feed does the platform use (distinct from general IT threat intel), covering known ICS-targeting malware families and threat actor groups specifically focused on industrial environments?
baselineDetail monitoring for third-party/vendor remote-access into OT environments (a common real-world OT breach vector — a contractor's remote-access credentials being compromised) — is this a native monitored capability or entirely out of scope?
baselineIs a named incident-response retainer with genuine OT/ICS expertise available (distinct from a generic IT incident-response team applying IT playbooks to an OT environment), and what is the team's track record of real OT-specific incident engagements?
baselineWhat is the platform's false-positive rate specifically in an OT context, given that a false alarm triggering an unnecessary safety shutdown or production halt has a much higher real-world cost than a false alarm in a typical IT environment?
baselineExplain deployment consistency for a large multi-site industrial customer — can detection quality and asset coverage be maintained uniformly across many distributed facilities with varying levels of IT/OT network maturity, or does quality degrade at less-mature sites?
baselineComplete the OT Cybersecurity Systems Specification requirements (TVE spreadsheet Sheet 2A), covering High-Level, Functional, User Interface, Integration, System Security, Environmental, and Testing/Validation Requirements for the proposed OT security technology.
baselineFor each of the five Representative Architectures (Separate OT-IT, One-Way Data Flow, No DMZ, DMZ, and DMZ with Segmentation), articulate relevant design considerations and deployment strategies, and depict where the proposed technology is placed within the architecture, marking up the provided architecture diagrams.
baselineDemonstrate the technology's ability to detect and respond to adversarial cyber activity on OT networks in the energy sector through a collective defense approach.
baselineDemonstrate how the technology utilizes artificial intelligence to identify anomalies, reduce false positives, and update OT asset information.
baselineDemonstrate the technology's advanced analytics capability to enable the user to identify systems that have been compromised and pinpoint where.
baselineDemonstrate how the technology increases system resilience in energy delivery control systems or components.
baselineDemonstrate autonomous defense solutions deployed at remote endpoints to protect against in-band and out-of-band attacks, including hardware, firmware, or software that protects, defends, or hardens deployed OT.
baselineDemonstrate the ability to deliver anonymized, aggregated threat data to a separate platform for collective analysis and information sharing.
baselineDescribe the Vendor's flexibility with respect to lightweight contracts and simple invoice/payment options intended to facilitate speedy deployments of OT cybersecurity technologies across the utility sector, and the ease of use and simplicity of the Vendor's proposed Deployment Execution Strategies and Methods.
baselineProvide Industrial Control Systems Security Review/Assessment.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat OT/ICS-specific protocols does the platform natively parse and understand (Modbus, DNP3, S7comm, EtherNet/IP, BACnet, etc.), and how many are supported out of the box versus requiring custom parsers?Answer key — what a strong answer shows
Look for a specific protocol list and clarity on native vs. custom-built support; generic 'OT visibility' claims without named protocols are a red flag.
RFPDescribe the asset-discovery methodology for OT environments — passive network monitoring only, or does it include active scanning — and what is the documented safety record for active scanning on fragile legacy control systems?Answer key — what a strong answer shows
Passive-only is safer for fragile OT gear; if active scanning is offered, look for a real safety track record and opt-in controls, since a scan that crashes a PLC is a serious operational risk.
RFIHow does the platform handle IT/OT network segmentation validation — can it verify that Purdue Model boundaries are actually enforced, not just documented?Answer key — what a strong answer shows
Look for active validation against real traffic/flows, not just a static policy review.
RFIWhat is the vulnerability intelligence source for OT-specific CVEs (ICS-CERT/CISA advisories, vendor PSIRTs), and how quickly are newly disclosed ICS vulnerabilities correlated against the discovered asset inventory?Answer key — what a strong answer shows
Strong answers name ICS-CERT/CISA advisories specifically and state a correlation latency, not just 'we track vulnerabilities.'
RFPDetail anomaly detection for OT-specific attack patterns (unauthorized PLC logic changes, abnormal command sequences) versus generic IT-style network anomaly detection repurposed for OT.Answer key — what a strong answer shows
Look for OT-native detection logic built for control-system semantics, not a generic NDR product with an OT label bolted on.
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
RFIDoes the platform provide risk scoring specific to safety-instrumented systems (SIS) and safety-critical assets, distinguishing them from general OT assets?Answer key — what a strong answer shows
Safety-critical systems warrant distinct, higher-priority risk treatment — a vendor with no answer likely treats all OT assets uniformly.
RFPExplain deployment architecture for air-gapped or highly segmented OT networks — can the platform operate fully on-prem/offline, and how are updates/signatures delivered without direct internet access?Answer key — what a strong answer shows
Look for a genuine offline/air-gapped deployment mode with a documented update mechanism, not an assumption of cloud connectivity.
RFIWhat incident response capability exists specific to OT — can the platform support safe isolation of a compromised OT asset without disrupting physical process operations?Answer key — what a strong answer shows
Isolating an OT asset carelessly can halt a physical process — look for OT-aware response actions, not IT-style automatic quarantine.
RFIWhat is the pricing model — per asset, per site, or a flat enterprise tier — and how does cost scale for a large industrial customer with many geographically distributed facilities, each with its own asset population?Answer key — what a strong answer shows
Look for transparent, predictable per-site/per-facility scaling economics; OT deployments often span many distributed sites, and unclear multi-site pricing creates real budget risk.
RFIDoes the platform map coverage to OT-specific compliance frameworks (IEC 62443, NERC CIP) with audit-ready reporting, and can it demonstrate compliance-relevant evidence (e.g., asset inventory completeness, network segmentation validation) directly to an auditor?Answer key — what a strong answer shows
Native OT-framework compliance mapping and audit-ready reporting are a distinct, higher-value capability than generic IT-compliance reporting repurposed for OT — ask for the specific frameworks supported.
RFPDescribe the vendor/systems-integrator ecosystem for deployment support — does the vendor have established partnerships with OT integrators experienced in the customer's specific industrial processes, or does deployment rely entirely on the vendor's own limited field team?Answer key — what a strong answer shows
OT deployments often require deep, plant-specific operational knowledge beyond generic cybersecurity expertise — a mature integrator ecosystem indicates a more scalable, lower-risk deployment path than a small vendor-only field team.
RFIWhat OT-specific threat intelligence feed does the platform use (distinct from general IT threat intel), covering known ICS-targeting malware families and threat actor groups specifically focused on industrial environments?Answer key — what a strong answer shows
OT-targeting threats (e.g., ICS-specific malware families) require distinct threat intelligence from general IT feeds — a vendor should name a real OT-specific intelligence source rather than repurposing generic IT threat intel.
RFPDetail monitoring for third-party/vendor remote-access into OT environments (a common real-world OT breach vector — a contractor's remote-access credentials being compromised) — is this a native monitored capability or entirely out of scope?Answer key — what a strong answer shows
Third-party remote access is one of the most common real OT breach vectors — a vendor with no answer here has a significant real-world coverage gap regardless of how strong their core anomaly detection is.
RFIIs a named incident-response retainer with genuine OT/ICS expertise available (distinct from a generic IT incident-response team applying IT playbooks to an OT environment), and what is the team's track record of real OT-specific incident engagements?Answer key — what a strong answer shows
Generic IT incident responders often lack the specialized knowledge to safely respond to an OT incident without risking physical process disruption — ask specifically about OT-experienced responders and real engagement history.
RFIWhat is the platform's false-positive rate specifically in an OT context, given that a false alarm triggering an unnecessary safety shutdown or production halt has a much higher real-world cost than a false alarm in a typical IT environment?Answer key — what a strong answer shows
The cost asymmetry of false positives is far higher in OT (a false alarm can halt physical production) than in IT — a vendor should have a specific, OT-context-aware answer, not a generic IT-derived accuracy figure.
RFPExplain deployment consistency for a large multi-site industrial customer — can detection quality and asset coverage be maintained uniformly across many distributed facilities with varying levels of IT/OT network maturity, or does quality degrade at less-mature sites?Answer key — what a strong answer shows
A vendor should give an honest answer about whether facilities with less-mature IT/OT convergence get materially weaker coverage — a common real-world gap for large industrial organizations with uneven site maturity.
RFPComplete the OT Cybersecurity Systems Specification requirements (TVE spreadsheet Sheet 2A), covering High-Level, Functional, User Interface, Integration, System Security, Environmental, and Testing/Validation Requirements for the proposed OT security technology.
RFPFor each of the five Representative Architectures (Separate OT-IT, One-Way Data Flow, No DMZ, DMZ, and DMZ with Segmentation), articulate relevant design considerations and deployment strategies, and depict where the proposed technology is placed within the architecture, marking up the provided architecture diagrams.
RFPDemonstrate the technology's ability to detect and respond to adversarial cyber activity on OT networks in the energy sector through a collective defense approach.
RFPDemonstrate how the technology utilizes artificial intelligence to identify anomalies, reduce false positives, and update OT asset information.
RFPDemonstrate the technology's advanced analytics capability to enable the user to identify systems that have been compromised and pinpoint where.
RFPDemonstrate how the technology increases system resilience in energy delivery control systems or components.
RFPDemonstrate autonomous defense solutions deployed at remote endpoints to protect against in-band and out-of-band attacks, including hardware, firmware, or software that protects, defends, or hardens deployed OT.
RFPDemonstrate the ability to deliver anonymized, aggregated threat data to a separate platform for collective analysis and information sharing.
RFPDescribe the Vendor's flexibility with respect to lightweight contracts and simple invoice/payment options intended to facilitate speedy deployments of OT cybersecurity technologies across the utility sector, and the ease of use and simplicity of the Vendor's proposed Deployment Execution Strategies and Methods.
RFPProvide Industrial Control Systems Security Review/Assessment.