The Cognisec IEC 62443 Engine is a purpose-built threat modelling platform. Three dedicated panels โ Asset Owner, Service Provider, and Risk Dashboard โ give every stakeholder exactly what they need. FR-based risk computation, Security Level determination, and control derivation โ all automated.
The Asset Owner defines and manages the entire IACS topology. Register every device and conduit, model threats against each, compute FR-based risk indices, and determine target Security Levels โ all in a structured, automated workflow aligned to IEC 62443-3-2.
Add all IACS assets โ PLCs, HMIs, historians, switches, field devices โ and all conduits (network connections) between them. Capture IEC 62443 security properties for each asset including zone assignment, criticality, and existing security measures.
For each device and conduit, assess threats across all 7 Foundational Requirements (FR1โFR7). Map threat likelihood and consequence to compute a per-FR risk index โ deterministic, not subjective.
The engine automatically derives the Target Security Level (SL-T) for each zone and conduit based on computed risk scores โ fully aligned to IEC 62443-3-2 methodology. No manual SL guesswork.
For each device and conduit, receive a mapped set of IEC 62443 security controls required to achieve the Target SL. Know exactly what needs to be implemented โ and what gap remains.
Visual grid mapping current security posture against Target SL requirements across every asset and FR domain. Instantly see what controls are missing and what risks remain open.
Target SL Computed
Threat Assessment
The Service Provider โ the OT integrator, system integrator, or maintenance contractor โ receives the Target SL requirements and implements the controls needed to achieve them. The Service Provider Panel guides them through the full implementation and evidence submission workflow.
See all devices and conduits assigned to you, along with the specific IEC 62443 controls required to achieve the Target SL on each one. Your work is clearly defined.
Record the security controls implemented on each device and conduit. Mark controls as implemented, partially implemented, or not applicable โ with justification.
Upload evidence of implementation โ configuration exports, test reports, certificates, site photographs โ against each control. Track submission status in real time.
Import large asset lists and connection topologies using our pre-formatted Excel manifest. Dropdown validation prevents import errors.
Receive feedback on rejected submissions, update your implementation records, and resubmit โ all within the same workflow. Full submission history retained.


The Risk Dashboard gives Asset Owners a real-time, consolidated view of risk posture across all assets, conduits, zones, and FR domains. Every risk index, every Security Level gap, every open control โ visible in one place. The single source of truth for IEC 62443 compliance status.
View computed risk scores for every device and conduit across all 7 Foundational Requirements (FR1โFR7). Filter by FR domain, zone, risk level, or asset type to focus where it matters most.
For every zone and conduit, see current SL versus Target SL. Instantly identify where SL-T has not been achieved and what controls remain outstanding.
Track the implementation status of every assigned control across every asset. See what is implemented, what is pending, and what is overdue โ in real time.
Visual matrix mapping current implementation against Target SL requirements. Missing controls flagged instantly across every FR domain and asset.
Export risk summary, SL status, and control implementation reports to CSV or Excel. Share with management, auditors, or regulators at any time.
FR Risk Indices
SL Status
Built specifically for IEC 62443 threat modelling. No bloat. No generic GRC features. Every feature serves one purpose โ automated, FR-based risk computation and Security Level determination.
FR1โFR7 pre-embedded. Threat and risk assessment structured per FR domain for every device and conduit โ from day one.
Register all IACS assets (PLCs, HMIs, switches, field devices) and conduits with full IEC 62443 security properties and zone assignments.
Automated Target Security Level determination per zone and conduit based on FR-specific risk indices โ aligned to IEC 62443-3-2.
Structured threat assessment per device and conduit across all 7 FRs. Likelihood ร consequence risk computation โ objective and repeatable.
For each asset, the engine maps the IEC 62443 controls required to achieve the Target SL. Know exactly what needs to be implemented.
Real-time risk indices per FR domain across all devices and conduits. Filter by zone, FR, risk level or asset type.
Import large IACS topologies โ devices and conduits โ using downloadable Excel manifests with built-in IEC 62443 validation.
Service Providers upload implementation evidence against each control. Track status, receive feedback, and resubmit โ all in-platform.
Every action logged permanently. Timestamped, user-attributed, and non-repudiable. Admissible in regulatory proceedings.
Every client gets their own isolated subdomain โ ibm.iec.cognisecsecurity.com. Complete data separation from other clients.
Data never leaves European Union servers. Full GDPR compliance built in. Not a US platform with EU add-ons.
Visual matrix mapping current control implementation against Target SL requirements across every asset and FR domain.
No implementation project. No consulting fees. No 6-month onboarding. Start your 30-day trial and be live today.
Select a plan, enter details and credit card. 30-day trial begins immediately. No charges until trial ends.
Add all IACS devices and conduits. Assign zones, capture security properties. Import in bulk via Excel or add individually.
Assess threats per device and conduit across all 7 FRs. The engine computes FR-based risk indices and determines Target Security Levels automatically.
Service Providers implement assigned controls and upload evidence. Monitor SL achievement on the Risk Dashboard. Gap Analysis coming soon.
We are seeking motivated partners to represent the Cognisec IEC 62443 Engine across industrial sectors globally. If you work in OT security, industrial consulting or ICS โ let's talk.