ADVISE / Regulations & standards

Connect requirements to operational resilience.

Establish what applies and translate requirements into controls, responsibilities and evidence. NIS2, CRA and IEC 62443 address different roles; meeting applicable requirements and checking that controls work both need attention.

Explore the Security Assessment

Start with applicability and role

NIS2

Organisation and risk management

Assess scope and national implementation. Connect risk, supply-chain security and incident handling to accountable management.

CRA

Product and lifecycle

For products in scope: risk assessment, vulnerability handling, support and evidence across the product lifecycle.

IEC 62443

Requirements matched to your role

Distinguish asset owners, service providers and product developers. Part 4-1 addresses development processes; part 4-2 addresses component security capabilities.

From requirement to evidence

  • Establish scope, role and relevant obligations
  • Review existing controls and evidence gaps
  • Assign priorities and accountable owners
  • Implement technical and organisational improvements
  • Validate operation and maintain evidence

No blanket compliance promise

Legislation and voluntary standards are different. Applicability and assessment depend on your role, product and environment. Our support is not a certificate, and one control does not establish complete compliance.

NIS2 — European Commission · CRA — European Commission · IEC 62443-4-1 · IEC 62443-4-2

Where is your operation still vulnerable?

Where is your operation still vulnerable? Examine critical dependencies, protective controls and recovery preparations. Agree the scope, project price and a practical next step before work begins.

Discuss an assessment