Advantage Through Knowledge and Experience
Home › OT Security Consulting
OT Security · DACH Region & International · 2026

OT Security Consulting –
Industrial Security Without Compromise.

IEC 62443, ISO 27001, TISAX ISA, CADIS and NIS2 interlock with one another. CONSUVATION GmbH brings all standards together – for a coherent security concept for your OT environment – in the DACH region and internationally.

74% Increase in Attacks on OT
6 Relevant Standards Frameworks
25+ Years of OT Expertise
Free Initial Consultation → View Standards Overview
IEC 62443 Certified
ISO 27001 Expertise
TISAX ISA
CADIS Consulting Partner
NIS2 / Critical Infrastructure
DACH Region & International

Quick Check

Which OT Standards Apply to Your Company?

30-second quick check – free & without registration

Standards Relevance Check

References IEC 62443 Based on Official Standards As of: June 2026 Reviewed by CONSUVATION Experts

What Is OT Security?

Short Answer

OT security refers to the protection of Operational Technology – i.e. control and automation systems such as SCADA, PLCs and DCS – from cyberattacks and outages.

Unlike classic IT, OT environments prioritise the availability of physical processes above all else – an attack can endanger not just data, but machinery, facilities and human lives.

Several standards govern OT security – ISO 27001, IEC 62443, TISAX, CADIS, NIS2 and KRITIS – and interlock with one another. CONSUVATION helps you keep an overview and meet all requirements efficiently.

Standards & Frameworks

ISO 27001, IEC 62443, TISAX, CADIS – and How They Relate

OT security is not a single standard – it's an ecosystem of standards that build on one another. CONSUVATION knows them all and integrates them into a coherent concept for your facility.

🏛️

Base Standard · ISMS

ISO/IEC 27001:2022

ISO 27001 is the foundation for all other standards. It defines the overarching information security management system (ISMS) – and is directly referenced or assumed as a basis by TISAX, CADIS and NIS2. For OT operators, an ISO 27001-compliant ISMS is the most efficient entry point into all other standards.

Foundation for: IEC 62443 · TISAX · CADIS
⚙️

OT Standard · Core Standard

IEC 62443 – Industrial Cybersecurity

IEC 62443 is the international OT standard. It defines security zones, channels and security levels (SL 1–4) specifically for SCADA, PLCs and DCS. CADIS references IEC 62443 directly for its OT module. NIS2 names IEC 62443 as a recognised technical implementation path. No other standard goes as deep into OT technology.

Referenced by: CADIS · NIS2 · KRITIS
🚗

Automotive · VDA / ENX

TISAX ISA – Automotive OT

TISAX combines ISO 27001 Annex A with automotive-specific requirements. TISAX ISA (current) brings a decisive step: explicit focus on the IT and OT availability of suppliers. Production facilities are therefore now a direct subject of assessment – OT security is no longer optional, but a TISAX requirement.

Includes: OT Availability · Based on: ISO 27001
🛡️

DEKRA Assessment Procedure · Defence

CADIS – Defence Industry Suppliers

CADIS (Cybersecurity Assessment for Defence Industry Suppliers) is the first European assessment procedure for defence industry suppliers – developed by DEKRA Certification. It examines 14 modules, including OT security according to IEC 62443 explicitly. Referenced standards: ISO 27001, IEC 62443, NIST CSF, BSI C5, NIS2 and GDPR. CONSUVATION is an official CADIS consulting partner.

References: IEC 62443 · ISO 27001 · NIS2 · BSI C5
🇪🇺

EU Regulation · Since Dec. 2025

NIS2 Directive (German Implementation Act)

The NIS2 Directive obliges operators of essential and important entities – including OT operators – to implement cybersecurity measures. Technically recognised implementation path: IEC 62443 and ISO 27001. Mandatory since 6 December 2025 for critical infrastructure operators and industrial companies from 50 employees / €10 million in revenue across 18 sectors.

Technical Basis: IEC 62443 · ISO 27001
🏗️

German Regulation · BSI

Critical Infrastructure / BSI IT-Grundschutz

The German Critical Infrastructure Ordinance obliges operators of critical infrastructure in Germany. BSI IT-Grundschutz provides OT-specific modules for ICS/SCADA. Since December 2025, the German NIS2 implementation act has significantly expanded these requirements – the BSI registration deadline expired on 6 March 2026.

Basis: BSI-Grundschutz · IEC 62443 · NIS2

Cross-Connections

How the Standards Interlock

Your company often needs to satisfy several standards simultaneously. We show you the synergies – and help you avoid duplicate work.

ISO 27001 → IEC 62443

ISO 27001 covers the management system. IEC 62443 provides the OT-technical requirements. Together they form a complete ISMS with OT depth – without duplicate work.

ISMSOT TechnologyZone Model

ISO 27001 → TISAX ISA

TISAX builds on ISO 27001 Annex A. Companies that already have ISO 27001 reach TISAX with significantly less effort. TISAX ISA adds OT availability as a new mandatory field for production facilities.

AutomotiveVDAOT Availability

IEC 62443 → CADIS

CADIS references IEC 62443 directly for its OT security module. An IEC 62443-compliant environment is the strongest lever for a successful CADIS assessment in the defence supply chain.

DefenceDEKRA14 Modules

NIS2 → IEC 62443 + ISO 27001

NIS2 requires appropriate security measures but does not name specific tools. IEC 62443 + ISO 27001 are the internationally recognised evidence for NIS2 compliance in OT environments.

NIS2EU LawCompliance

CADIS → ISO 27001 + NIS2 + GDPR

CADIS Module 1 is based on ISO 27001. Module 12 covers GDPR. Module 14 addresses NIS2 obligations. Companies that pass CADIS fulfil substantial parts of all three requirement frameworks simultaneously.

ISMSGDPRNIS2

TISAX ISA → OT Security

With TISAX ISA, TISAX expands its scope to production environments. Automotive suppliers with OT facilities must now include these in the security assessment – a direct link to IEC 62443.

TISAX ISAProductionOEM Requirement

What Applies to Your Company?

The Most Important OT Security Obligations at a Glance

Different obligations apply depending on industry and company size. Here are the four most common scenarios.

IEC 62443

Secure OT Systems

Zone model, security levels (SL 1–4), network segmentation, asset management, patch management for SCADA, PLCs and DCS – without stopping production.

ISO 27001

Build an ISMS

Establish an information security management system, conduct risk analysis, document security policies and embed them in OT environments – as the foundation for all other standards.

TISAX ISA

Demonstrate OT Availability

For automotive suppliers: include OT facilities in the TISAX assessment, demonstrate availability and security requirements, complete Assessment Level 2 or 3.

CADIS

Pass the 14-Module Assessment

Complete all relevant CADIS modules – including OT security per IEC 62443, supply chain management, GDPR and NIS2. CONSUVATION supports you as an official consulting partner.

€10 Million
Max. NIS2 Fine (§ 65 BSIG)

Implementation Checklist

What Must OT Operators Implement?

📋 Organisational Measures

  • 🏛️Build an ISMS according to ISO 27001 or extend it to cover OT
  • 📜Conduct a risk analysis according to IEC 62443-3-2
  • 📋Complete BSI registration (German NIS2 implementation act, deadline: 6 March 2026 – overdue)
  • 👤Train management in OT cybersecurity (§ 38 BSIG)
  • 🤝Review supply chain security (CADIS Module 5)
  • 📞Implement an OT incident reporting process (24h / 72h)
  • 🚗Plan a TISAX assessment (TISAX ISA) for OT facilities
  • 🛡️CADIS applicability analysis: which modules apply?

🔧 Technical Measures (IEC 62443)

  • 🌐Zone model and network segmentation (IT / OT / DMZ)
  • 📦OT asset inventory (all SCADA, PLCs, HMIs)
  • 🔐Access control and identity management for OT
  • 🔒Encryption and secure protocols (OPC UA, etc.)
  • 💾OT backup management and business continuity plan
  • 🔍Vulnerability management and patch processes for legacy systems
  • 🧪OT penetration testing (without stopping production)
  • 📡Set up OT monitoring and anomaly detection

Services

OT Security Consulting From a Single Source

From initial analysis to assessment readiness – across standards, without operational disruption, with senior consultants.

01

OT Security Audit & Assessment

Complete inventory according to IEC 62443-3-2: assets, network architecture, vulnerabilities, risks – without operational disruption.

IEC 62443ISO 27001

02

IEC 62443 Consulting & Compliance

Gap analysis, zone definition and implementation of measures for operators, integrators and manufacturers – fully documented and auditable.

IEC 62443Zones & Conduits

03

ISO 27001 ISMS – OT Extension

Build or extend your ISMS with OT-specific modules – as the foundation for TISAX, CADIS, NIS2 and critical infrastructure requirements in one integrated project.

ISO 27001ISMS

04

TISAX ISA – OT Preparation

Consulting on TISAX certification under TISAX ISA – with a focus on the new OT availability requirements for automotive suppliers.

TISAXTISAX ISAAutomotive

05

CADIS Assessment Preparation

As an official CADIS consulting partner, we guide you through all 14 modules of the DEKRA assessment procedure – from applicability analysis to assessment readiness.

CADISDEKRADefence

06

NIS2 & Critical Infrastructure for OT Operators

Applicability assessment, measures planning, BSI registration and incident reporting integration for OT operators across 18 sectors.

NIS2Critical InfrastructureBSI

07

OT Penetration Testing

Controlled attack simulation against SCADA, PLCs and industrial networks – without stopping production, with evidence for TISAX and CADIS assessors.

IEC 62443CADIS Module 3

08

Training & Awareness

OT security training for technicians, operators and management – IEC 62443 fundamentals, CADIS preparation, TISAX awareness, NIS2 management training (§ 38 BSIG).

ISO 27001 A.6§ 38 BSIG

Frequently Asked Questions

OT Security – Frequently Asked Questions

What is OT security consulting?
OT security consulting covers the analysis, assessment and protection of Operational Technology (SCADA, PLCs, DCS) according to standards such as IEC 62443 and ISO 27001. Unlike IT security, the availability of physical processes comes first.
What is the relationship between ISO 27001 and IEC 62443?
ISO 27001 provides the overarching ISMS foundation – policies, risk management, governance. IEC 62443 specialises this for industrial control systems with concrete zone models and security levels. Implemented together, they form a complete and audited OT security concept.
What changed for TISAX with TISAX ISA?
TISAX ISA places an explicit focus on the IT and OT availability of suppliers. Production facilities and manufacturing environments are now a direct subject of the TISAX assessment – OT security per IEC 62443 is no longer optional, but mandatory.
What is CADIS and who is affected by it?
CADIS (Cybersecurity Assessment for Defence Industry Suppliers) is the DEKRA assessment procedure for defence industry suppliers. It examines 14 modules – including OT security – and references IEC 62443, ISO 27001, NIS2 and GDPR. All companies in the defence industry supply chain are affected.
How exactly are CADIS and IEC 62443 connected?
CADIS references IEC 62443 directly as the technical standard for OT security in the defence sector. An IEC 62443-compliant OT environment therefore satisfies substantial CADIS modules in advance. CONSUVATION guides you from IEC 62443 implementation through to CADIS assessment readiness in one integrated project.
Does NIS2 also apply to OT operators?
Yes. NIS2 covers operators of essential and important entities – including energy, manufacturing, water, healthcare and other sectors. OT systems are explicitly included within the scope of protection. Recognised implementation path: IEC 62443 in conjunction with ISO 27001.

Our OT Security Solutions

From Analysis to Assessment Readiness

CONSUVATION guides you the whole way – from selecting the right standards to passing the assessment.

Management System

OT Management System

Turnkey OT information security management system, fully tailored to IEC 62443 and ISO 27001. Includes all documents, processes and evidence for TISAX, CADIS and NIS2.

Learn More →
Documentation

OT Handbook

Practical handbook for OT security implementation – clearly prepared for management and OT staff. With concrete action guidance, checklists and template documents according to IEC 62443 and ISO 27001.

Download Now →
Training

OT Training

Tailored OT security training for management, OT technicians and employees. IEC 62443 fundamentals, CADIS preparation, TISAX awareness and NIS2 management training – certified and verifiable.

Request Training →

Our Expertise

Experienced Experts – No Junior Consultants

CONSUVATION exclusively employs experienced senior consultants. With more than 25 years of experience in information security and industrial cybersecurity, we are among the pioneers of the industry.

Our experts were among the first certified BS 7799 auditors – the British standard considered the direct predecessor of today's ISO 27001. They combine this foundational knowledge with current practical experience in IEC 62443, TISAX and CADIS.

As an official CADIS consulting partner and active members of ISO working groups, we bring insider knowledge that flows directly into your OT security implementation.

Our Tool: OT Correlation Matrix

CONSUVATION has developed its own correlation matrix for OT security requirements, mapping all relevant standards – IEC 62443, ISO 27001, TISAX ISA, CADIS, NIS2 and BSI-Grundschutz. This allows us to identify synergies and overlaps immediately and produce a complete gap analysis in the shortest possible time – without duplicate work, with maximum standards coverage.

25+
Years of Experience
BS 7799
First ISO Auditors
ISO
Working Group Members
100%
Senior Consultants

ISO 27001 · IEC 62443

Consultants, auditors & ISO working group members – deep first-hand standards knowledge, from the BS 7799 era to today

TISAX ISA

Many years of experience in the automotive industry – VDA ISA, Assessment Level 2 & 3, including new OT availability requirements

CADIS – Official Consulting Partner

Specialised expertise in defence cybersecurity – practice-proven across all 14 CADIS modules

CISA · CISM · CRISC · CGEIT

Our consultants hold the most renowned international ISACA certifications – from IT audit to IT governance

Take Action Now

Ready to Secure Your OT Environment in Line With Standards?

Get advice from an experienced CONSUVATION consultant – free of charge and without obligation.

Download OT Security Checklist (PDF) Request a Consultation
CONSUVATION GmbH · Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com