Protect · Compliance & Audit
The audit evidence builds itself while you work.
Every detection, approval, baseline change and segmentation check already produces evidence. Synaptic OT maps it to the controls your regulator asks about and packages it for the auditor.
Why it matters
Audits stop being projects
Generate a per-framework evidence pack on demand instead of collecting screenshots for weeks.
Records nobody can quietly edit
The audit log is HMAC-chained row by row. A changed or deleted row breaks the chain at verification.
Retention set by regulation
Retention windows follow NERC CIP-007-6, NIST 800-92 and ISO 27001 by default, with per-site overrides such as five years for water utilities.
framework IEC 62443-3-3 SR 3.3 security functionality verification compliant SR 5.2 zone boundary protection partial 2 open violations SR 6.1 audit log accessibility compliant SR 2.8 auditable events attested by plant manager
Illustrative values
Capabilities
What's included
Compliance & Audit is part of the full Synaptic OT suite. One licence covers every capability on this site.
Seven frameworks mapped
NESA (UAE IA), IEC 62443-3-2, IEC 62443-3-3, IEC 61511, NERC CIP, NIST SP 800-82r3 and NIS2.
Live control scorecard
Each control is bound to the evidence the platform already keeps: logic diffs, conduit violations, maintenance records, audit logs, asset inventory and human attestations.
Auditor evidence pack
Executive summary, control scorecard, forensic manifests, signed violations and the asset register in one bundle with a Merkle root.
Tamper-evident audit log
HMAC-chained per tenant, with a verification endpoint and viewer for administrators.
Automatic retention
A daily worker applies retention by data type and logs every deletion. Audit evidence is never cascade-deleted.
Watermarked exports
Every exported report carries a tenant hash and timestamp, so forwarded copies can be traced.
Global coverage
Compliance by region
One platform for operators in Europe, the Gulf, India and North America. Each entry says plainly whether it is built in, supported through evidence the platform already produces, or on our roadmap.
- MappedControl vocabulary built into the product: scorecard and/or auditor evidence pack.
- Supported via evidenceNo dedicated scorecard yet. Synaptic OT produces the evidence this regime asks for, such as attack detection, logging, incident records and segmentation, mapped through IEC 62443 and NIS2.
- RoadmapA native mapping is planned. Not available today.
International
- IEC 62443-3-2Mapped
Risk assessment, zones and conduits. Scored against your declared zones, conduits and signed violations.
- IEC 62443-3-3Mapped
System security requirements. Scored against logic diffs, audit log and asset inventory.
- IEC 61511Mapped
Functional safety for process industries. Included in auditor evidence packs.
- ISO/IEC 27001Supported via evidence
Audit logging and retention follow ISO 27001 by default. Native control scorecard on the roadmap.
European Union
- NIS2 DirectiveMapped
Annex control families scored: risk management, incident handling, business continuity, supply chain, effectiveness and cyber hygiene.
- CER Directive (critical entities resilience)Supported via evidence
Incident detection, records and evidence that support resilience obligations for critical entities.
- GDPR and data sovereigntySupported via evidence
OT data and project files stay on your site. Fully air-gapped deployments never contact us.
Germany
- KRITIS: attack detection requirement (BSI Act)Supported via evidence
Critical infrastructure operators must run systems for attack detection. Synaptic OT provides passive OT attack detection, logging and incident evidence.
- BSI guidance on attack detection systemsRoadmap
Native mapping to the BSI orientation guidance is planned.
United Kingdom
- NIS Regulations and NCSC CAFSupported via evidence
Evidence for CAF objectives on security monitoring, event detection and incident response.
- NCSC CAF native mappingRoadmap
Outcome-by-outcome CAF scorecard planned.
Gulf
- UAE IA (NESA)Mapped
Included in auditor evidence packs.
- Saudi NCA OTCCSupported via evidence
OT monitoring, logging, segmentation and incident evidence mapped through IEC 62443.
- NCA OTCC native scorecardRoadmap
Control-by-control mapping planned.
India
- CERT-In directionsSupported via evidence
Incident records and log retention that support reporting and retention obligations.
- CEA cyber security guidelines (power sector)Supported via evidence
Monitoring, segmentation and audit evidence for power utilities.
- CERT-In and CEA native scorecardsRoadmap
Planned.
North America
- NERC CIPMapped
Scored, with event-log retention aligned to CIP-007-6.
- NIST SP 800-82r3Mapped
OT security guidance families scored.
- AWIA 2018 (water)Mapped
Five-year retention applied automatically for water-sector sites.
- NIST CSF 2.0Roadmap
Native function and category mapping planned.
Using Synaptic OT does not by itself make an organisation compliant. It produces monitoring, records and evidence that assessors review against your obligations.
Questions
Asked by OT and security teams
Does using Synaptic OT make us compliant?
No product can make you compliant on its own. Synaptic OT produces the monitoring, records and evidence these frameworks ask for, and maps them to controls so your assessor can review them quickly.
Which regulations does Synaptic OT support around the world?
Seven frameworks are built in: NIS2 (EU), IEC 62443-3-2 and 62443-3-3, IEC 61511, NERC CIP, NIST SP 800-82r3 and UAE IA (NESA). For regimes such as Germany’s KRITIS attack-detection requirement, the UK NIS Regulations and NCSC CAF, the EU CER Directive, Saudi NCA OTCC and India’s CERT-In and CEA guidelines, the platform produces the evidence they ask for through its IEC 62443 and NIS2 mappings. Native scorecards for several of these are on the roadmap. See the compliance-by-region table on this page.
Does Synaptic OT help with NIS2?
Yes. NIS2 is mapped in the product: its risk-management, incident-handling, business-continuity, supply-chain and cyber-hygiene control families are scored against evidence the platform already keeps, and auditor packs can be generated for it.
Works with
See it on your own traffic.
Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.