IT/OT gateway and data connector
Reads data out of controllers and pushes it to the business system or a cloud dashboard; the conduit between the plant and the office made into a box.
How the register reads it
| Also called | edge gateway, IoT gateway, ERP connector |
|---|---|
| Family | Process and line control |
| What a wrong action costs | line. A write path into a controller that nobody meant to create. |
| Zone class and SL-T | business SL-T 3 by default (2 for the class, raised one because the class is reached remotely by default). It is the boundary: it belongs in the DMZ on the business side, reading from the plant and never writing to it. Never above 3; the paste may state its own zone name and SL-T. |
| Networked by default | Yes. It exists to be on two networks. |
| Remote access by default | Yes. Dashboard and gateway suppliers commonly reach it remotely; the paste decides. |
| Behaviour by default | fixed. Configured. |
| Machinery Regulation | A controller, a server or a sensor that is not itself a machine or a safety component carries no Machinery Regulation row; the machine it controls does. |
| Vendor cloud | The fleet or the model is usually managed from a vendor cloud: ISO 27001 control 5.23 attaches where ISO 27001 is ticked, and the runtime attestation row asks what the vendor can send back. |
| Safety references |
|
What each regime attaches, and who it binds
49 clauses across 4 regimes, on the class defaultsShown on a register for the regimes you tick; with none ticked, the IEC 62443 asset-owner rows are the default. The CRA row is informational on every connected asset. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
IEC 62443
Binds Part 2-1 binds the asset owner; Part 3-2 is the owner's zoning and risk assessment; Part 3-3 is what the owner specifies for the system. Part 2-4 binds the service provider and Parts 4-1 and 4-2 the product supplier, so those rows are rendered as what to ask. Source framework: IEC 62443.
| Asset owner duty | On every asset (Part 2-1) IEC 62443 2-1 AC · 2-1 BCP · 2-1 CSMS · 2-1 IR · 2-1 MOC · 2-1 NSEG · 2-1 PHY · 2-1 PM · 2-1 RA · 2-1 TRN Whatever the zone, these ten programme duties are the owner's for every asset in the system under consideration. |
|---|---|
| Asset owner duty | System requirements to specify for the site business zone (Part 3-3) IEC 62443 3-3 SR 1.1 · 3-3 SR 2.1 · 3-3 SR 5.2 · 3-3 SR 6.1 An asset on the business side of the boundary is inside the CRS for what it can reach across it: identification, use control, the zone boundary and accessible logs. |
| Asset owner duty | Added where the asset is on a network IEC 62443 3-3 SR 3.1 · 3-3 SR 5.2 · 3-3 SR 6.2 Communication integrity, a monitored zone boundary and continuous monitoring attach the moment the asset is reachable. |
| Asset owner duty | Added where the asset is reached remotely IEC 62443 2-1 AC · 3-3 SR 1.1 · 3-3 SR 6.1 The remote account, its authentication and the record of its sessions are the owner's. |
| Ask the integrator | Part 2-4 binds the service provider, not the owner IEC 62443 2-4 SP-01 · 2-4 SP-02 · 2-4 SP-03 · 2-4 SP-04 · 2-4 SP-05 · 2-4 SP-06 The owner owes none of these rows; the owner asks the integrator and the maintenance provider for the evidence of each before commissioning and at every substantial change. |
| Ask the supplier | Part 4-1 binds the supplier, not the owner IEC 62443 4-1 DM · 4-1 SG · 4-1 SUM The owner asks the maker of the controller or the machine for the hardening guide, the vulnerability handling process and the signed update channel. |
| Ask the supplier | Part 4-2 binds the supplier: a networked component IEC 62443 4-2 CR-1-1 · 4-2 EDR-3-10 For a networked controller the owner also asks for signed firmware with rollback protection and user authentication on the component. |
NIST SP 800-82 Rev 3
Binds guidance addressed to the operator of the OT environment: it binds nobody in law and is what most OT security programmes are assessed against. Source framework: NIST SP 800-82 Rev 3.
| Asset owner duty | The OT overlay on every asset SP 800-82 GOV-3 · HOST-4 · HOST-6 · IR-1 · MON-2 SP 800-82 is guidance for the operator of the OT environment: an inventory that holds firmware and location, safety and security run together, change and patch management, and an incident plan with OT scenarios. |
|---|---|
| Asset owner duty | Network architecture where the asset is on a network SP 800-82 ARCH-1 · ARCH-2 · NET-1 Zones and conduits, an industrial DMZ between the plant and the office, and deny-by-default rules between zones. |
| Asset owner duty | Remote access where the asset is reached remotely SP 800-82 RA-1 · RA-2 A brokered, authenticated, recorded, time-bounded path; vendor accounts named individually and enabled just in time. |
The EU Cyber Resilience Act
Binds manufacturers, importers and distributors of products with digital elements; never the owner using them. Source framework: the EU Cyber Resilience Act.
| Ask the supplier | From the application date (the CRA binds manufacturers) CRA Art. 13 and Annex I · Art. 69, 70, 71 A connected controller or machine with digital elements is a product with digital elements; the manufacturer owes the essential cybersecurity requirements, a support period with security updates and vulnerability handling. The owner asks for the support period and the update channel. Informational: the owner owes no CRA clause. |
|---|
ISO/IEC 27001:2022
Binds the organisation that holds the certificate, through the Annex A controls it declared applicable. Source framework: ISO/IEC 27001:2022.
| Asset owner duty | Supplier and change controls on every asset ISO 27001 5.19 · 5.20 · 5.22 · 8.32 The integrator and the maintenance provider are suppliers; the change to a machine is a change. |
|---|---|
| Asset owner duty | Network controls where the asset is on a network ISO 27001 5.21 · 8.9 · 8.20 · 8.21 · 8.22 Network security, the services on it, segregation and a secure configuration baseline attach to any connected asset; the ICT supply chain control attaches to what the supplier delivers into it. |
| Asset owner duty | Where a fleet or model is managed from a vendor cloud ISO 27001 5.23 A fleet manager or a model service hosted by the vendor is a cloud service: acquisition, use and exit are governed. |
The EU AI Act
A fixed-program machine is not an AI system: it does not infer from input how to generate its output and it does not learn or re-plan at runtime. No AI Act row attaches to it; the Machinery Regulation and IEC 62443 do.
Runtime attestation: what to ask the supplier for
Signed firmware and updates with rollback protection, an attested boot or integrity check the controller reports, and behaviour logs that can be read off the device. The register asks; it does not say the supplier provides any of it. CRA Art. 13 and Annex I IEC 62443 3-3 SR 3.3 · 3-3 SR 3.4 · 4-1 SUM · 4-2 EDR-3-10
Ask the integrator
- Whether it can write to any controller, and if so which
- What it sends out and where
- Who can reach it from the office and from the vendor
Findings this class can raise
- Flat network: networked assets with no zone named
Networked assets whose zone or network column is blank, spread across two or more zone classes. Either the zones exist and the register cannot see them, or they do not: the zone and conduit sheet is the first thing an assessor asks for, and it cannot be drawn from this paste. - No change record on an adaptive or networked asset
An adaptive or networked asset with no commissioning date and no last-change date. Management of change is the control every regime here shares; a register that cannot say when the asset last changed cannot say whether the last change was reviewed. - End of support or unpatched
The paste says the asset is out of support, unpatched or at end of life, or its commissioning year is older than the support threshold in the preamble. The asset owner's row is patch management with a recorded risk acceptance for what cannot be patched; the supplier's row is what to ask about updates and the support period. - Vendor share at or above a third
One vendor behind a third or more of the assets, or behind every asset in a zone class. Concentration is often the right engineering choice; the regimes ask that the dependence be recorded and the supplier relationship managed, not avoided. The register names the share and never rates the vendor.
Do this for every asset on your floor
Paste the list and get this classification for every asset at once, with the zone and SL-T, the behaviour, the connectivity, the findings and the obligation rows per regime. Eight assets free, no account.
Build my cell register