Critical Infrastructure
Resilience for CNI and OT environments — from NCA-ECC and OTCC to IEC 62443 and AESCSF — where a control failure is measured in outages, not records.
- SectorsEnergy, water, transport, health, telecoms, finance
- AnchorsIEC 62443 · NCA OTCC · AESCSF / SOCI · NCA-ECC
- ScoringMaturity engines with all-or-nothing and weakest-link rules
- EvidenceNetwork posture from NSPM, rule by rule
Critical Infrastructure
Critical infrastructure security is where information security meets engineering. Operational technology — the controllers, HMIs and safety systems that run a plant or a grid — was built to be available for decades, not patched every month, and the frameworks written for it reflect that: IEC 62443's zones and conduits, Saudi Arabia's OTCC for operators of industrial control systems, Australia's AESCSF for the energy sector and the SOCI obligations behind it.
These frameworks score differently from an ISO clause list, and the difference matters. AESCSF's maturity indicator levels are all-or-nothing: a single unmet practice holds the whole level back. SAMA's cyber framework reports the weakest applicable subdomain, not the average. A dashboard that averages these into a comfortable percentage misreports the regulator's own arithmetic.
GRCLens implements each framework's scoring rules as written — pinned by tests, so a catalogue update cannot quietly soften them — and keeps NSPM's network evidence beside the assessment, so segmentation is shown from the firewall rulebase rather than asserted from a diagram.
What the platform does for CNI and OT
IEC 62443 as a catalogue framework
The asset-owner programme and the seven foundational requirements of IEC 62443-3-3, assessed control by control with evidence, on the same model as the rest of the library.
OTCC, in Arabic and English
NCA's Operational Technology Cybersecurity Controls with the official Arabic text of every control, domain and objective, and domain-by-domain assessment paging.
AESCSF maturity as the regulator scores it
MIL-1 to MIL-3 with the all-or-nothing rule enforced, SOCI risk-management-programme obligations mapped alongside, and the annual self-assessment exported.
Weakest-link reporting
Where a framework's own rule is the minimum, not the mean, the banner shows the minimum — and says which subdomain is holding it there.
Network posture as evidence
NSPM's rulebase analysis, segmentation findings and device compliance held as evidence beside the controls that require segmentation.
CIRMP under the SOCI Act
The Critical Infrastructure Risk Management Program document with its eleven prescribed sections, control statuses under the 2026 Enhanced Rules, a readiness check and Word/PDF export — kept apart from the AESCSF score, because they are different deliverables.
How it shows up in a tenant
These frameworks are enabled per tenant like any other; these are the screens they add.
Maturity dashboards
OTCC, AESCSF, SAMA and Essential Eight with each framework's own scoring rule and its Arabic where the regulator publishes it.
IEC 62443 assessment
The asset-owner programme and the 62443-3-3 foundational requirements, with evidence per control.
NSPM
Devices, rules, objects, risk, topology and compliance for the network that carries the OT traffic.
CIRMP
The SOCI Act Part 2A programme document, drafted section by section with a readiness check before export.
Frameworks in this discipline
ISA/IEC 62443 Industrial Automation and Control Systems Security
Evidence industrial cybersecurity against ISA/IEC 62443 — from the security programme to the seven foundational requirements for control systems.
Open the framework page →AESCSF & SOCI Act CIRMP Obligations (Australia)
Evidence AESCSF maturity and SOCI Act risk-management obligations for Australian critical infrastructure — one assessment, board-ready reporting.
Open the framework page →NCA Essential Cybersecurity Controls
Assess, evidence and report against the Kingdom's Essential Cybersecurity Controls — in Arabic or English, hosted in your own environment.
Open the framework page →Network Security Policy Management (NSPM)
Govern firewalls and network policy operationally — device inventory, rule-base analysis, findings and compliance checks in one workspace.
Open the framework page →Australian Protective Security Policy Framework (PSPF)
Assess protective security maturity across the PSPF domains — governance, risk, information, technology, personnel and physical security.
Open the framework page →New Zealand Protective Security Requirements (PSR)
Assess and evidence the Protective Security Requirements across GOVSEC, PERSEC, INFOSEC and PHYSEC — ready for annual PSR assurance reporting.
Open the framework page →Critical Infrastructure
Why does the AESCSF score drop to a lower level when one practice is unmet?
Because that is the framework's rule: a maturity indicator level is achieved only when every practice at that level is met. GRCLens applies the rule as published rather than averaging, and the demo data is shaped and tested to show it.
Is OTCC available in Arabic?
Yes. The OTCC catalogue carries NCA's official Arabic for every domain, subdomain, objective and control, alongside the English, and the assessment can be completed in either.
How is network segmentation evidenced?
Through NSPM, which analyses firewall rulebases and device configurations; its findings are held as evidence in the tenant beside the IEC 62443, OTCC and PCI DSS controls that require segmentation, so the evidence is the live rulebase rather than a network diagram.
Deep expertise across the disciplines that matter

Score OT the way the regulator does
A walkthrough of the OTCC and AESCSF assessments, the IEC 62443 zone model and NSPM's segmentation evidence, on a demo tenant shaped like your estate.