Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
AI is changing fast. Behavioral security helps you keep up. Join Darktrace’s September 22 broadcast to see how →

CSA STAR Registry

Security, Trust, Assurance, and Risk Registry

Listings for OTNOS

Listings for OTNOS

OTNOS is an OT vulnerability intelligence platform for industrial environments. The SaaS service continuously collects security advisories from more than 160 OT vendors and public sources (CISA ICS, CERT feeds), enriches them with exploitation data (KEV, EPSS), and matches them to each customer's asset inventory, so operators of plants and industrial networks know within hours which of their devices are affected and what to do first.

The platform provides risk-based prioritization, digest and instant alerting (email, webhooks, SIEM/SOAR integration), API access, and compliance-oriented reporting aligned with IEC 62443, NIS2, and the EU Cyber Resilience Act. Alongside the platform, OTNOS offers vendor-independent OT security services across the IEC 62443 lifecycle: risk assessments, secure network design, product qualification, and configuration hardening.

OTNOS is operated from Germany with all customer data processed in EU data centers, GDPR-aligned, with security practices documented in this CAIQ self-assessment.

OTNOS Platform

The OTNOS Platform is a multi-tenant SaaS for OT vulnerability management. It continuously ingests security advisories from 160+ industrial vendors and pu...

Listed Since: 2026-09-06

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).