OT cybersecurity risk assessment & maturity mapping
This tool uses a representative, illustrative set of controls based on NIST SP 800-82 Rev. 3 (via tailored NIST SP 800-53 control families) and IEC 62443 (Foundational Requirements plus security program elements from 62443-2-1). It is not a complete, verbatim reproduction of either standard and should not substitute for the official standards in a certification-grade audit.
Assessment details
This information appears on your final report.
Lightly adjusts wording (e.g. "OT systems" → "pipeline SCADA") and, if you've entered figures, enables benchmark comparison on the final report.
Choose a standard
You'll assess against one standard per session. Run it again later with the other standard to compare.
NIST SP 800-82 Rev. 3
18 control families tailored for OT (Access Control, Incident Response, Configuration Management, and others), 36 representative controls total.
IEC 62443
7 Foundational Requirements plus 2 security-program elements from 62443-2-1, 25 representative controls total.
Scoring options
Optional — leave off if you just want a straightforward equal-weighted score.
0 of 0 controls scored
1 — Initial
Ad hoc or undocumented. Where it happens, it depends on individual effort rather than a defined process.
2 — Managed
Performed, but reactively and inconsistently. Some documentation may exist but isn't consistently applied across sites or systems.
3 — Defined
A documented, standardized process is approved and consistently applied organization-wide, with clear roles and responsibilities.
4 — Quantitatively Managed
The practice is measured. Metrics are collected and reviewed regularly against defined targets.
5 — Optimizing
Continuously improved based on measured performance, and proactively adapted as threats, technology, or the environment change.
Detailed results — every control
Full scoring detail behind the final report, including notes and N/A exclusions.
Group
ID
Control
CSF Function
Maturity
ATT&CK ICS
Suggested remediation
Notes
Final report
Maturity by control group
Native groupings from the chosen standard.
Maturity mapped to NIST CSF 2.0
Each control's group maps to one CSF function; scores are averaged per function. Dashed ring = target maturity (Level 3).
Control heatmap
Every scored control, colored by maturity. Hover a cell for detail.
1 · Initial3 · Defined5 · OptimizingN/A or unscored
Maturity distribution
How many scored controls landed at each level.
Risk quadrant
Maturity vs. criticality — the upper-left is your priority zone.
NIST CSF 2.0 function scores
Function
Controls mapped
Average maturity
Gap vs. target (3.0)
Industry benchmark
Vs. benchmark
Where to focus
Lowest-scoring controls, with suggested remediation and the related MITRE ATT&CK for ICS technique.
Highest-scoring controls (strengths)
Load two or more saved Compass assessment files (from the Save button on any assessment) to combine or compare them. Every mode works off the shared NIST CSF 2.0 mapping, so files from different standards, sites, or assessors can still be brought together.
Assessment A
Nothing loaded yet.
Assessment B
Nothing loaded yet.
NIST CSF 2.0 comparison
Overlaid maturity by function. Dashed ring = target maturity (Level 3).
Function-by-function detail
Function
A average
B average
Delta (B − A)
Load individual assessor files
Load 2 or more assessments of the same facility, ideally on the same standard — one file per team member.
Team-averaged maturity by NIST CSF 2.0
Where assessors disagreed most
Widest spread between assessor scores — worth a team discussion.
Control
Scores
Spread
Load site assessments
Load one file per facility/site. Sites can use different standards — the rollup happens on the shared CSF mapping.
Enterprise rollup — NIST CSF 2.0
Per-site overall scores
Standalone view — each site's own maturity, unaveraged.
Site
Standard
Overall
Site × CSF heatmap
Each cell is one site's average maturity for that function.
1 · Initial3 · Defined5 · OptimizingNo data
Sites ranked by overall maturity
Function spread across sites
Range (min–max) of site averages per CSF function.
Load assessments over time
Load 2 or more assessments of the same facility from different dates, ideally the same standard.