ConsoleWorks describes recorded sessions, configuration evidence, and asset context. An OT assurance record still has to connect each consequential command with the device response and physical operating effect before reviewers can reconstruct what changed.
Cylus presents rail-specific asset discovery, threat detection, investigation context, and mitigation playbooks across rolling stock, trackside, stations, communications, and control centers. A rail operator still has to join an alert to the affected topology, service state, safety constraints, accountable owner, and authorized response.
Yokogawa presents a managed IT/OT security operations center with continuous monitoring, incident tickets, workflows, and service levels. Buyers need a site-specific handoff matrix showing who owns triage, when the plant team takes control, how operating state changes escalation, and which evidence closes the service-customer loop.
Phosphorus describes automated xIoT remediation for credentials, firmware, certificates, risky configurations, and unnecessary services. In an operating environment, safe automation still needs asset identity, engineering scope, approved preconditions, production timing, rollback, and observed process-state evidence.
Palo Alto Networks describes passive OT asset discovery, profiling, risk context, and policy controls. A device profile can inform review, but permitted communications still require validated identity, process context, zone and conduit intent, engineering constraints, approved rules, controlled change, and post-change evidence.
Binary-derived component inventory and reachability analysis can sharpen firmware review, but an asset owner still has to prove device identity, deployed version, exposure, process consequence, and change authority.
OTbase documents a contextualized OT asset inventory with device, firmware, topology, lifecycle, and vulnerability context. A firmware value becomes actionable only when it is tied to the correct physical device, acquisition method, observation time, engineering baseline, process role, exposure, approved change, and recovery evidence.
Cisco says Cyber Vision is included at no extra cost with selected industrial switches and a Network Advantage license. Commercial inclusion can change the buying path, but it does not establish that sensors are activated, correctly placed, healthy, current, authorized, or observing the site and protocols an owner depends on.
Dragos completed its Phosphorus acquisition on June 1 and described continued support, near-term device intelligence, and a unified experience to follow. Ownership and integration are separate evidence states.
OPSWAT documents removable-media inspection for critical environments. A scan result still needs file identity, approved purpose, target scope, custody, change control, and site authorization.
DeNexus presents industrial cyber-risk quantification and vulnerability prioritization in financial terms. Expected loss can help compare scenarios, but it does not replace the site-specific engineering analysis needed to understand process consequence or authorize a change to an operating asset.
TXOne's registered products URL currently resolves to a deployment-architecture page that identifies Stellar as endpoint protection for OT and ICS environments. Endpoint security can support a defense layer, but only authorized operations, control engineering, and safety processes can establish whether the physical process is in a defined safe state.
Dragos documents OT asset visibility, vulnerability management, threat detection, and response capabilities. An observed inventory and communication map can inform architecture review, but it cannot decide the approved security zones, conduits, trust boundaries, safety constraints, or change plan for a live industrial system.
Claroty documents a platform that uses cyber-physical-system visibility to define and recommend network policies that teams can monitor, refine, and enforce through existing firewalls, switches, or network-access controls. The recommendation is security analysis; production change authority remains a separate operational decision.
Microsoft documents Defender for IoT for cyber-physical asset discovery, vulnerability management, and threat detection. An alert can support investigation, but isolating an operational asset still requires verified process context and the site's engineering, safety, operations, and change authority.
Nozomi Networks presents asset visibility, anomaly detection, and threat analysis for OT and IoT environments. An anomaly can focus investigation, but accountable operations and security leaders still have to decide whether observed behavior is expected change, degraded operation, policy breach, or a declared incident.
runZero presents active and passive discovery, asset correlation, topology, criticality context, and exposure intelligence across heterogeneous environments. Discovery can create a stronger candidate inventory, but accountable operations and engineering owners still have to resolve identity, function, criticality, lifecycle state, and authority for each OT asset.
Dispel documents zero-trust remote access, vendor session control, identity controls, isolation, and audit records for industrial environments. Those controls can govern how a person reaches an OT asset, but they do not approve the maintenance task, establish a safe plant state, or transfer engineering and operating authority.
Tenable documents asset inventory, exposure prioritization, configuration-change detection, network monitoring, and remediation guidance for cyber-physical systems. In an operating environment, the finding still has to pass asset-owner, engineering, safety, production, vendor, change-control, and recovery review before anyone changes the device or network.
The published TSA directive states an effective period ending May 2, 2026. Its controls remain useful historical evidence, but current applicability requires a current TSA instrument and operator-specific authority—not a stale vendor mapping.
NIST SP 1800-45 documents three secure remote-access reference designs demonstrated with commercial technologies in a lab. The guide can sharpen architecture and acceptance questions, but it does not authorize a connection to a live water or wastewater control environment.
Waterfall documents a hardware-enforced one-way transfer architecture with software that replicates OT data for external use. That boundary can serve a defined conduit, but it does not design every zone, identity, remote-access path, exception, monitoring control, or recovery decision.
NIST Cybersecurity Framework 2.0 provides a taxonomy of cybersecurity outcomes across six functions, including the added Govern function. The framework can structure an OT program and its evidence, but it does not prescribe a safe control design, determine site-specific risk, or prove that an industrial system is secure or compliant.
Directive (EU) 2022/2555 establishes staged reporting duties for significant incidents, but the operating clock depends on entity scope, national transposition, competent authority, awareness, significance, and the facts of the incident.
The approved reliability standard gives covered bulk-power entities a concrete operating test for internal network telemetry, anomaly detection, evaluation, escalation, and retained records. Applicability still depends on the controlling standard and entity facts.
The IAEA guidance covers computer security for nuclear-facility instrumentation and control across design, operation, maintenance, supporting environments, and decommissioning. That scope is broader than a point-in-time device inventory.
CISA presents the Cross-Sector Cybersecurity Performance Goals as prioritized, voluntary practices for critical infrastructure. They can organize an improvement record, but they do not certify a facility, replace sector requirements, or prove control effectiveness.
ISA describes shared responsibility across asset owners, product suppliers, integrators, and service suppliers while assigning different requirements across the 62443 series. A product mapping or certificate cannot transfer the facility's operating, engineering, safety, and risk decisions.
NIST treats an accurate OT asset inventory as important to risk management while warning that collection methods can affect the environment being observed. Passive, active, automated, and manual approaches have different evidence gaps and operational consequences, so discovery authority must be bounded before a tool is run.
The current C2M2 organizes more than 350 IT and OT cybersecurity practices across ten domains and three maturity levels. Asset owners still need practice-level evidence, scope, and accountable targets before a maturity result can guide investment.
Notified-body provisions began applying in June 2026 and vulnerability-reporting provisions follow in September, while the regulation's general application remains December 2027.
The June 2026 announcement would combine OT threat detection, asset intelligence, firmware analysis, services, and a large integrator—creating immediate product-boundary, data, neutrality, and roadmap questions.
The April 2026 close moves a major cyber-asset intelligence platform inside ServiceNow and puts asset identity, exposure, workflow, data use, packaging, and remediation ownership on the diligence agenda.
The provider's annual report supplies threat, vulnerability, ransomware, assessment, and incident-response observations—but its populations and methods must remain attached to every reported number.
The release spans multiple Siemens and Schneider Electric product families and demonstrates why asset identity, version, vendor guidance, exposure, process consequence, and maintenance feasibility must stay connected.
The joint guide raises the baseline from a discovered device list to a maintained inventory and taxonomy connected to function, criticality, risk, architecture, and response.
Order No. 907 creates a concrete network-data, anomaly-detection, evaluation, escalation, and evidence decision for covered bulk-power-system environments.
The May 2025 fact sheet emphasizes internet exposure, credentials, remote access, segmentation, inventory, monitoring, and recovery without turning public guidance into a site-specific response plan.
IEC PAS 62443-2-2:2025 organizes technical, physical, and process measures as a maintained protection scheme rather than a disconnected catalog of security products.
The guide puts secure configuration, identity, logging, vulnerability handling, updates, support, and buyer evidence into product selection rather than leaving them for post-purchase remediation.