OT DEFENSEREVIEW

Intelligence for systems that move the physical world.

2026 research note

Authority-to-control crosswalk

A source-linked map from selected NIST, CISA, ISA/IEC 62443, NERC CIP, TSA, EU, DOE, MITRE, and IAEA records to operating responsibilities and evidence.

OT DEFENSE REVIEWAuthority-to-control crosswalkMethod and limitations included
Executive summary

A source-linked map from selected NIST, CISA, ISA/IEC 62443, NERC CIP, TSA, EU, DOE, MITRE, and IAEA records to operating responsibilities and evidence.

The maintained dataset joins 45 organization records, 26 normalized capabilities, 10 operating models, 19 authority records, and 10 operating domains. Counts describe the research corpus; they are not a market-size or quality score.

The authority records

NIST SP 800-82 Rev. 3

United States federal guidance with broad voluntary use · Final; NIST has begun a Rev. 4 pre-draft process. NIST describes OT topologies, threats, vulnerabilities, safeguards, and risk-management considerations while recognizing performance, reliability, and safety requirements.

NIST SP 800-82 Rev. 4 pre-draft

United States federal publication process · Pre-draft comment period closed February 23, 2026; no Rev. 4 draft or final is inferred. NIST initiated revision work to align the OT guide with current frameworks, standards, practices, and threat conditions and asked whether dynamic resources should replace several appendices.

NIST CSF 2.0

Global voluntary use; organization-specific adoption · Final. CSF 2.0 organizes cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond, and Recover and can be applied alongside OT-specific guidance.

ISA/IEC 62443-2-1:2024

International voluntary standard; applicability depends on adoption, contract, certification, or authority · Published. Part 2-1 defines security-program requirements for asset owners across governance, risk, implementation, maintenance, and continuous improvement of IACS security.

IEC PAS 62443-2-2:2025

International voluntary technical specification · Published and valid. The specification provides guidance for developing, validating, operating, and maintaining a set of technical, physical, and process security measures for IACS facilities.

ISA/IEC 62443-3-2

International voluntary standard · Published. Part 3-2 addresses system-level risk assessment and the use of zones, conduits, and target security levels in IACS design.

ISA/IEC 62443-3-3

International voluntary standard · Published. Part 3-3 defines system security requirements and security levels for industrial automation and control systems.

ISA/IEC 62443-4-1

International voluntary standard · Published. Part 4-1 defines secure-development-lifecycle requirements for IACS product suppliers.

IEC 62443-4-2

International voluntary standard · Published. Part 4-2 defines technical security requirements for IACS components using the foundational requirements and security-level framework.

CISA CPGs

United States critical-infrastructure guidance · Current guidance; users should verify the live CISA record. CISA publishes a prioritized set of cybersecurity practices intended to reduce common and consequential risks across critical-infrastructure sectors.

Joint OT asset inventory guidance

Cross-national guidance for OT owners and operators · Published. The joint guide describes a regularly updated OT asset inventory and taxonomy tied to function and criticality as a foundation for risk, vulnerability, architecture, and incident-response work.

CISA Secure by Demand for OT

Cross-national guidance for OT digital-product buyers · Published. The guide presents security considerations and questions for OT buyers addressing product configuration, logging, identity, updates, vulnerability handling, support, and secure-by-design behavior.

CISA primary OT mitigations

United States critical-infrastructure guidance · Published. The fact sheet calls attention to exposed OT connectivity and prioritizes defensive actions for owners and operators facing intentional targeting.

NERC CIP-015-1

Applicable registered entities and BES cyber systems within the approved scope · Approved by FERC Order No. 907; implementation dates and applicability require the controlling standard and implementation plan. CIP-015-1 requires documented processes for internal network security monitoring of specified high- and medium-impact BES cyber-system environments, including data feeds, anomaly detection, evaluation, and evidence.

TSA Pipeline-2021-02F

TSA-designated United States hazardous-liquid, natural-gas pipeline, and LNG owner/operators in stated scope · The published directive states it expired May 2, 2026; a successor status is not established in this seed record. The directive continued performance-based requirements covering cyber risk assessment, plans, architecture, access, monitoring, incident response, testing, and related evidence for notified pipeline operators.

EU Cyber Resilience Act

European Union and products with digital elements within scope · In force with staged application. The CRA establishes horizontal cybersecurity requirements for products with digital elements, including design, vulnerability handling, economic-operator, conformity, reporting, and market-surveillance provisions.

NIS2

EU Member State implementations and entities within scope · In force; national law and supervision vary. NIS2 establishes cybersecurity risk-management, reporting, governance, supervision, and supply-chain requirements across essential and important entities.

C2M2 v2.1

Voluntary use across energy and other organizations · Published. C2M2 supports evaluation and improvement of cybersecurity capabilities across domains such as risk, assets, access, threat and vulnerability, situational awareness, response, continuity, third parties, workforce, architecture, and program management.

ATT&CK for ICS

Global defensive research resource · Maintained online knowledge base. ATT&CK for ICS organizes publicly reported adversary tactics, techniques, software, groups, mitigations, and data sources relevant to industrial control systems.

The operating-domain lens

Asset inventory, context, and lifecycle

The maintained operating record for each OT asset's identity, role, location, owner, criticality, communications, dependencies, versions, configuration, support state, exposure, and recovery relevance. The crosswalk links 9 capabilities and 3 authority records.

Network architecture, segmentation, and conduits

The design and maintained evidence for security zones, conduits, trust boundaries, routable paths, industrial DMZs, enforcement points, fail states, and allowed communication supporting physical operations. The crosswalk links 9 capabilities and 3 authority records.

Vulnerability, exposure, and remediation governance

The operating process that connects a device, product, component, vulnerability, exploit context, exposure path, process consequence, compensating control, vendor guidance, maintenance window, decision, and retained evidence. The crosswalk links 9 capabilities and 3 authority records.

Detection, investigation, and operational response

The connected defensive workflow from approved telemetry and detection content through triage, process-context review, evidence preservation, incident decision, engineering coordination, containment, recovery, and learning. The crosswalk links 8 capabilities and 3 authority records.

Remote access, identity, and third-party control

The operating domain governing who can reach which industrial resource, for which approved task, through which path, with which credential, privilege, device, time window, supervision, file flow, emergency process, and retained session evidence. The crosswalk links 7 capabilities and 3 authority records.

Endpoint, removable media, and controlled transfer

The controls and evidence for protecting constrained industrial endpoints and moving software, files, updates, logs, and operational data across security boundaries. The crosswalk links 7 capabilities and 3 authority records.

Product security and software supply chain

The lifecycle evidence connecting industrial product design, components, firmware, provenance, secure development, vulnerabilities, updates, support, suppliers, integrators, customers, and end-of-life responsibilities. The crosswalk links 6 capabilities and 4 authority records.

Resilience, recovery, and cyber-informed engineering

The integration of cybersecurity with physical mission, safety, reliability, design, spares, configuration baselines, backups, manual capability, tested restoration, and recovery decision authority. The crosswalk links 6 capabilities and 3 authority records.

Governance, authorities, and assurance

The system for identifying applicable authorities and commitments, assigning accountable roles, translating requirements into controls, collecting evidence, testing effectiveness, managing exceptions, reporting risk, and preserving change history. The crosswalk links 5 capabilities and 4 authority records.

Safety, reliability, and engineering coordination

The decision boundary connecting cyber defense with process safety, functional safety, reliability, operations, maintenance, engineering change, and physical consequence. The crosswalk links 9 capabilities and 3 authority records.

How to use the crosswalk

Determine applicability with qualified owners, identify affected records and workflows, map each expectation to an accountable decision and retained evidence, then use capability and organization pages to frame a technology evaluation. A mapping is editorial navigation—not a conformity or legal conclusion.

Methodology

  1. Define the market boundary, exclusions, operating models, and capability taxonomy before classifying organizations.
  2. Require an approved official source for organization inclusion and each documented capability.
  3. Keep authority sources, provider claims, independent observations, editorial synthesis, and unknowns in separate evidence states.
  4. Use one primary operating model per organization while retaining adjacent scope in the narrative record.
  5. Preserve source URLs, review dates, material changes, limitations, and correction history.

Limitations

  • The maintained population is substantial but not claimed to be a complete global market.
  • Official public documentation may omit available capabilities or lag product and service changes.
  • Documented positioning does not measure product depth, configured availability, independent performance, implementation effort, customer outcome, or commercial terms.
  • Authority mappings are editorial research aids and do not establish buyer-specific applicability or product conformity.
  • No organization may purchase inclusion, classification, finding, or correction outcome.

Reproducibility and updates

The report is reproduced from the provider registry, normalized facts and evidence, authority and domain records, and the publication taxonomy. A material change requires a dated source and editorial explanation. Historical values remain available through the change ledger rather than disappearing when the current record changes.

Research boundary

OT Defense Review is not a regulator, standards body, certification body, control-system integrator, safety authority, engineering firm, incident-response provider, insurer, or law firm. Its records support market research and decision review; they do not establish compliance, certification, security, safety, reliability, exploitability, or fitness for a specific operational environment.