Regulatory Pressure
EOS Modus · OT Governance, Risk & Compliance

Know What You Own. Prove You Can Defend It.

Most operators cannot answer an auditor's first question with confidence. EOS Modus turns the OT estate into structured, living data, then answers CAF, NIS2, IEC 62443 and NIST CSF from one control set, instead of four parallel spreadsheets and a fortnight of copy and paste.

The Problem

OT Compliance Is Being Done Three Times Over

Not because teams are careless, but because the tooling was never built for operational technology. IT GRC platforms assume an estate that patches on a Tuesday. OT does not work like that.

01 · Ground Truth
Nobody Owns The Register
The asset inventory exists in six versions, and none of them is current.

Vendor documentation is years old. The commissioning spreadsheet was last touched by an engineer who left in 2021. The OEM has a list, but it is theirs, not yours, and it stops at the turbine.

Every compliance question that follows inherits that uncertainty, so the answers are hedged and the evidence is thin.

02 · Duplication
Four Frameworks, One Estate
CAF, NIS2, IEC 62443 and NIST CSF ask overlapping questions in different words.

The same control gets evidenced separately for each, by different people, at different times, against different versions of the truth. Findings contradict each other and nobody can say which is right.

The effort is real. The assurance it produces is not proportionate to it.

03 · Evidence
The Audit Scramble
Six weeks of preparation to answer questions the data should already answer.

Ofgem, an insurer, a board committee, or an incoming OFTO asks for the position. What follows is archaeology, chasing screenshots, emails and half-remembered decisions across three organisations.

The pack gets built, the audit passes, and eleven months later the whole exercise starts again from zero.

The Approach

Everything Hangs Off One Register

EOS Modus does not start with a questionnaire. It starts with the estate.

M1 · The Spine

Asset Register & Configuration Management

Every control system, zone, asset, data flow, access record and third-party connection in scope, held as structured data rather than a spreadsheet. Vendor, model, firmware, location, owner, criticality, and the conduit it sits behind.

Nothing else in Modus works without it. That is deliberate. A risk register that does not resolve to a real asset is an opinion, and a control that cannot name what it protects will not survive an audit. Build the spine once, keep it current through change control, and every other module inherits ground truth for free.

NCSC CAF B1 IEC 62443-2-1 NIST CSF ID.AM NIS2 Art. 21
The Module Map

Fourteen Modules On Top Of The Spine

Take them in any order. Most operators start with the register and the framework mapping, then add depth where the regulator is looking hardest.

All fifteen modules in detail →
Coverage

One Control Set, Every Framework

Evidence a control once. Modus maps it to every framework and standard that asks for it, and shows you where the genuine gaps are rather than where the paperwork is thin.

Who It's For

Built For Operators, Not Auditors

EOS Modus is designed to be run by the team that owns the estate. If your OT compliance position lives in a consultant's laptop, this is the alternative.

Offshore Wind
Operators & OFTOs
Energy & Utilities
Generation & networks
Data Centres
Genuine OT estates
Wider CNI
Water, transport, ports

Start With The Register

EOS Modus is in development with a small group of operators shaping the module set. If you are carrying an OT compliance obligation and the current approach is not scaling, we would like to talk.