What this domain asks
The lifecycle evidence connecting industrial product design, components, firmware, provenance, secure development, vulnerabilities, updates, support, suppliers, integrators, customers, and end-of-life responsibilities.
The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.
Buyer questions
- Which exact legal entity, product, version, site, and process does a claim or certificate cover?
- Can buyers obtain and operationalize component and vulnerability information over the support period?
- How are updates authenticated, tested, distributed, installed, failed, and recovered?
- What happens when an upstream component, supplier, ownership, or support commitment changes?
- Can the organization retain product and evidence history after replacement or end of support?
Mapped workflows
Firmware, SBOM, And Component Intelligence
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for firmware, SBOM, and component intelligence within this domain.
Configuration, Baseline, And Change Monitoring
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for configuration, baseline, and change monitoring within this domain.
Compliance Mapping And Control Evidence
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for compliance mapping and control evidence within this domain.
Device And Product Software-Supply-Chain Risk
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for device and product software-supply-chain risk within this domain.
IT Security-Operations Integration And APIs
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for IT security-operations integration and APIs within this domain.
Offline And Air-Gapped Environment Support
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for offline and air-gapped environment support within this domain.
Authority context
ISA/IEC 62443-4-1
Part 4-1 defines secure-development-lifecycle requirements for IACS product suppliers.
IEC 62443-4-2
Part 4-2 defines technical security requirements for IACS components using the foundational requirements and security-level framework.
CISA Secure by Demand for OT
The guide presents security considerations and questions for OT buyers addressing product configuration, logging, identity, updates, vulnerability handling, support, and secure-by-design behavior.
EU Cyber Resilience Act
The CRA establishes horizontal cybersecurity requirements for products with digital elements, including design, vulnerability handling, economic-operator, conformity, reporting, and market-surveillance provisions.
Relevant operating models
- OT Asset Inventory And Configuration-Risk Platform
- Industrial OEM Security Portfolio
- Industrial Cyber-Risk And Governance Platform
Evidence boundary
OT Defense Review is not a regulator, standards body, certification body, control-system integrator, safety authority, engineering firm, incident-response provider, insurer, or law firm. Its records support market research and decision review; they do not establish compliance, certification, security, safety, reliability, exploitability, or fitness for a specific operational environment. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.