Compass

OT cybersecurity risk assessment & maturity mapping
This tool uses a representative, illustrative set of controls based on NIST SP 800-82 Rev. 3 (via tailored NIST SP 800-53 control families) and IEC 62443 (Foundational Requirements plus security program elements from 62443-2-1). It is not a complete, verbatim reproduction of either standard and should not substitute for the official standards in a certification-grade audit.

Assessment details

This information appears on your final report.

Lightly adjusts wording (e.g. "OT systems" → "pipeline SCADA") and, if you've entered figures, enables benchmark comparison on the final report.

Choose a standard

You'll assess against one standard per session. Run it again later with the other standard to compare.

NIST SP 800-82 Rev. 3

18 control families tailored for OT (Access Control, Incident Response, Configuration Management, and others), 36 representative controls total.

IEC 62443

7 Foundational Requirements plus 2 security-program elements from 62443-2-1, 25 representative controls total.

Scoring options

Optional — leave off if you just want a straightforward equal-weighted score.

0 of 0 controls scored

1 — Initial
Ad hoc or undocumented. Where it happens, it depends on individual effort rather than a defined process.
2 — Managed
Performed, but reactively and inconsistently. Some documentation may exist but isn't consistently applied across sites or systems.
3 — Defined
A documented, standardized process is approved and consistently applied organization-wide, with clear roles and responsibilities.
4 — Quantitatively Managed
The practice is measured. Metrics are collected and reviewed regularly against defined targets.
5 — Optimizing
Continuously improved based on measured performance, and proactively adapted as threats, technology, or the environment change.

Detailed results — every control

Full scoring detail behind the final report, including notes and N/A exclusions.

GroupIDControlCSF FunctionMaturityATT&CK ICSSuggested remediationNotes

Final report

Maturity by control group

Native groupings from the chosen standard.

Maturity mapped to NIST CSF 2.0

Each control's group maps to one CSF function; scores are averaged per function. Dashed ring = target maturity (Level 3).

Control heatmap

Every scored control, colored by maturity. Hover a cell for detail.

1 · Initial 3 · Defined 5 · Optimizing N/A or unscored

Maturity distribution

How many scored controls landed at each level.

Risk quadrant

Maturity vs. criticality — the upper-left is your priority zone.

NIST CSF 2.0 function scores

FunctionControls mappedAverage maturityGap vs. target (3.0)Industry benchmarkVs. benchmark

Where to focus

Lowest-scoring controls, with suggested remediation and the related MITRE ATT&CK for ICS technique.

    Highest-scoring controls (strengths)

      Maturity is self-assessed on a 1-5 scale (CMMI-style). CSF function averages reflect a group-level mapping designed for this tool; treat them as a directional view of program maturity, not an official NIST or ISA crosswalk. Controls marked N/A are excluded from all averages.
      Load two or more saved Compass assessment files (from the Save button on any assessment) to combine or compare them. Every mode works off the shared NIST CSF 2.0 mapping, so files from different standards, sites, or assessors can still be brought together.

      Assessment A

      Nothing loaded yet.

      Assessment B

      Nothing loaded yet.