Article

Five Updated Standards Shaping the Current OT Cybersecurity Landscape

Driven by heightened geopolitical tensions, supply chain vulnerabilities, and the rapid convergence of IT and OT networks, governments and standard-setting bodies such as NIST and ISA have pivoted from voluntary, static guidance to mandatory, resilience-based standards. These are significant regulatory changes from the old practice that shape the current OT cybersecurity.

1. Hardware Regulations Mandating "Secure-by-Design"

In the past, voluntary safety guidelines or best practice were encouraged. However, global governments are implementing aggressive regulatory frameworks targeting critical infrastructure. Mandates are forcing industrial operators to prove their compliance posture before spinning up new infrastructure. Instead of bolting security onto legacy machinery after the fact to save cost, the trend centers on buying and deploying "Secure-by-Design" equipment. Industrial asset owners make cybersecurity compliance a strict condition of procurement, forcing automation vendors to build secure cryptographic identities directly into physical hardware at the factory level.

  • Sources & Frameworks:
    • ISA/IEC 62443 Series (Industrial Automation): The definitive international standard governing the secure development lifecycle (Part 4-1) and technical components (Part 4-2) of industrial automation products. 
    • NIST Special Publication 800-82 Revision 3: The Guide to Operational Technology (OT) Security, which expanded its scope from traditional Industrial Control Systems (ICS) to all cyber-physical environments, establishing tailored compliance baselines for OT systems.

2. Mandatory Asset Visibility and Lifecycle Tracking

Historically, industrial sites maintained poor inventories of legacy programmable logic controllers (PLCs), remote terminal units (RTUs), and edge devices due to fears that active scanning would crash fragile physical processes. Regulatory frameworks such as NIST SP 800-82 (Revision 3) and NERC CIP-002-7-Cyber Security have shifted asset tracking from a best-practice suggestion to an explicit compliance requirement. Agencies now require critical infrastructure operators to maintain rigorous, dynamically updated hardware taxonomies and comprehensive life-cycle replacement plans to mitigate technical debt.

3. Industrial Zero Trust: Demolishing "Implicit Trust"

In old versions of OT architectures, it was assumed that if a device was physically inside the plant and only connected to the local network, it was safe. However, the rise of smart, remote field devices widely open the physical perimeter. Because of this, OT networks are migrating toward Industrial Zero Trust architectures. To roll out innovative edge computing without violating compliance baselines, every smart meter, sensor, and PLC must cryptographically authenticate its identity using Public Key Infrastructure (PKI) before it is allowed to transmit telemetry or receive operational commands.

4. Securing the "Sneakernet" and Remote Vendor Access

Even the most sophisticated, compliant, cloud-monitored factory floor can be brought down by a third-party maintenance vendor plugging a compromised laptop or USB drive directly into a physical machine. Therefore, NERC CIP Standards (CIP-003 to CIP-013) provide mandated standards to regulate transient assets and unmanaged remote access methods. For example, one of solutions that the industry is using to accommodate the convenience of remote vendor diagnostics (innovation) without violating compliance, facilities are installing hardware-enforced data diodes (which allow data to flow out to the cloud, but prevent external commands from flowing in) and physical, sandboxed sanitization kiosks that thoroughly vet removable media before it ever enters the production zone.

This isn't limited to the electric grid, either. TSA has issued parallel mandatory directives for pipeline and rail operators (requiring hard segmentation between IT and OT networks, multi-factor authentication for any remote access, and continuous monitoring) precisely because vendor remote-diagnostic connections are one of the most common ways attackers reach the OT environment. Under active directives SD Pipeline-2021-02F and SD Pipeline-2021-01G, designated pipeline owners must also report cyber incidents to CISA within 12 hours, conduct annual penetration testing, and undergo independent third-party assessments. TSA has proposed converting these directives into a permanent federal rule (Docket TSA-2022-0001), though that rulemaking is still pending.

  • Sources & Frameworks:
    • NERC CIP Standards (CIP-003 to CIP-013): Enforced by the North American Electric Reliability Corporation, these regulations strictly mandate how transient cyber assets (like vendor laptops and thumb drives) and interactive remote access must be authorized, logged, and sanitized before interacting with bulk power systems.
    • FERC Order 919 approved updated CIP-002-7 through CIP-013-3 (virtualization-focused), effective May 26, 2026, mandatory by July 1, 2028.
    • TSA Security Directives – Pipeline & Rail Cybersecurity: Mandatory directives for TSA-designated hazardous liquid and natural gas pipeline operators, and passenger/freight rail carriers, requiring IT/OT network segmentation, MFA for remote access, 12-hour incident reporting to CISA, and annual independent security assessments. Enforced directly by TSA; a permanent regulation is in progress but not yet final.

5. Upstream Supply Chain and SBOM Mandates then not

Asset owners are requiring vendors to supply a Software Bill of Materials (SBOM) — essentially an ingredient list for software. When engineers want to introduce a new digital twin or predictive analytics platform, compliance teams can scan the SBOM to catch hidden vulnerabilities before the software touches the operational network. Worth noting: at the U.S. federal level, this requirement has become less prescriptive than it once was. Executive Order 14306 (June 2025) and OMB Memorandum M-26-05 (January 2026) rolled back the government-wide SBOM and self-attestation mandates that followed EO 14028, replacing them with a risk-based approach where individual agencies now decide whether to require SBOMs contractually. The EU, by contrast, has moved in the opposite direction, hardening its SBOM requirements through the Cyber Resilience Act.

  • Sources & Frameworks:
    • U.S. Executive Order 14028 (Improving the Nation's Cybersecurity): Enforces strict requirements for securing the software supply chain, heavily penalizing vendors that do not provide transparent SBOMs for software used in federal and critical infrastructure. The order's text remains in effect, but its enforcement mechanism has since been loosened — EO 14306 (2025) and OMB M-26-05 (2026) rescinded the mandatory attestation and centralized SBOM validation requirements, leaving SBOM provision to individual agency discretion rather than a blanket mandate.
    • EU NIS2 Directive, Article 21 (Cybersecurity risk-management measures): Explicitly links compliance to the security of supply chains and the relationships between essential entities and their direct providers.
    • EU Cyber Resilience Act (CRA): Requires manufacturers of hardware and software products with digital elements sold in the EU to produce a machine-readable SBOM (CycloneDX or SPDX format) and report actively exploited vulnerabilities within 24 hours. Enforced by national market surveillance authorities; fines up to €15 million or 2.5% of global turnover.

Upcoming mandates 

CISA is working on finalizing new CIRCIA regulations in late 2026. This may require 72-hour incident reporting / 24-hour ransomware-payment reporting across 16 critical infrastructure sectors. According to CISA, this regulation would allow f

Thao Le-Vasicek
VP of Operations