Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
AI is changing fast. Behavioral security helps you keep up. Join Darktrace’s September 22 broadcast to see how →

STAR Registry Listing for

OTNOS Platform

OTNOS Platform

OTNOS Platform

The OTNOS Platform is a multi-tenant SaaS for OT vulnerability management. It continuously ingests security advisories from 160+ industrial vendors and public sources, enriches them with exploitation intelligence (CISA KEV, EPSS), and matches them against each customer's asset inventory to produce risk-based, actionable remediation priorities.

Capabilities include per-tenant asset and vulnerability views, digest and instant notifications (email, signed webhooks, SIEM/SOAR and Power Automate integrations), a documented REST API, role-based access control with MFA and SSO, tenant isolation verified by automated tests on every deployment, and audit logging. Reporting supports IEC 62443, NIS2, and EU CRA obligations.

The service is hosted in ISO 27001-certified data centers in Germany; all customer data is processed in the EU. Security controls are described in the attached CAIQ v4 self-assessment.

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about OTNOS Platform
Listed Since: 09/06/2026

STAR Level 1

Cloud Controls Matrix

CAIQ Self-assessment v4.0.3

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

Created or renewed 6 days ago, on September 06, 2026.