STAR Registry Listing for
OTNOS Platform
OTNOS Platform
The OTNOS Platform is a multi-tenant SaaS for OT vulnerability management. It continuously ingests security advisories from 160+ industrial vendors and public sources, enriches them with exploitation intelligence (CISA KEV, EPSS), and matches them against each customer's asset inventory to produce risk-based, actionable remediation priorities.
Capabilities include per-tenant asset and vulnerability views, digest and instant notifications (email, signed webhooks, SIEM/SOAR and Power Automate integrations), a documented REST API, role-based access control with MFA and SSO, tenant isolation verified by automated tests on every deployment, and audit logging. Reporting supports IEC 62443, NIS2, and EU CRA obligations.
The service is hosted in ISO 27001-certified data centers in Germany; all customer data is processed in the EU. Security controls are described in the attached CAIQ v4 self-assessment.

Listed Since: 09/06/2026
STAR Level 1

CAIQ Self-assessment v4.0.3
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Created or renewed 6 days ago, on September 06, 2026.