CSRAS 62443 is our own desktop software that lifts IEC/ISA 62443 OT risk assessment out of scattered spreadsheets into a living visual model of the plant. Draw zones and conduits once; security levels, residual risk, compliance and attack paths are computed automatically.

Control systems were designed decades ago, before the internet reached the plant floor. Regulation (IEC 62443, NIS2) now demands structure — yet most assessments still run on error-prone spreadsheets.
Once-isolated plant networks are now connected to the enterprise. A single foothold can halt production or endanger the safety system (SIS).
IEC 62443 is becoming the reference for industrial security; regimes like NIS2 push asset owners toward auditable, standards-aligned assessment.
The method is sound, but running it in Excel is slow, brittle and hand-maintained. When the plant changes, the assessment falls behind.
Design, analyse, simulate, prove. Each step feeds the next; when the plant changes, the whole assessment updates itself.
Drag device symbols into zones and conduits; Purdue levels are inherited automatically. The plant's real structure lives in one visual model — the single source of truth for the assessment.

From inherent to residual risk; SL-A achieved against SL-T for every zone and asset, an overall compliance score, and the single highest-value action. The decision, up top.

Drop a threat at any entry point, pick an attacker level (SL-1→SL-4) and see how far it reaches. Choke-point analysis tells you exactly which conduit to harden.

Per-asset SL-T ↔ SL-A vectors across all seven foundational requirements (FR1–FR7), with the exact gap to close. One click produces executive risk-report, audit-checklist and attack-report PDFs.

Every step of the IEC 62443 workflow, from inventory to mitigation — connected, traceable and visual end to end.
Drag-and-drop device symbols; Purdue levels are inherited automatically and every crossing becomes a conduit.
See the plant live across levels L0–L4; the architecture and network schematic stay in sync with the design.
Drop a threat, pick an SL-1→SL-4 attacker, see reached assets and choke-point nodes; test controls with what-if.
SL-A against SL-T across FR1–FR7; plain and vulnerability-adjusted variants, and the exact gap to close.
Impact × likelihood matrix, inherent→residual risk and an overall compliance score from the ICSS network score.
Every IACS asset with its type, Purdue level and zone; vulnerability findings (VA) recorded with the SRs they affect.
All requirements and enhancements (CR/RE), with Min SL and a component-type (NDR/EDR/HDR/CR/SAR) matrix.
Map threat scenarios to ICS-specific attack techniques; each is linked to FRs, typical assets and likely consequences.
A configurable, step-by-step target-security-level wizard for ZCR-6; a separate SL-T per FR.
Every SR you tick is recorded with a rationale — traceable audit evidence, including which MITRE technique it prevents.
Executive risk report, per-plant compliance checklist and an attack report with remediation — no manual formatting.
Switch language at runtime (Turkish/English); protected by machine-bound online licensing.
CSRAS assigns each zone a target-level vector (SL-T) — one value per FR1–FR7. The level rises with the strength of attacker the defence must resist; the difference to the SL-A reached by existing controls is the gap to close.
The screens below are captured from the live application on a real assessment. Click to enlarge; drag to browse.








The model turns straight into documents with no manual formatting — charts for the board, a checklist for the auditor, an attack analysis for the engineer.
An executive, chart-heavy IEC 62443 risk report: KPIs, risk matrix, inherent→residual risk, FR compliance and recommendations.
A per-plant auditor checklist: for every zone, conduit and asset, SRs posed as Yes/No/Partial questions for the responsible owner.
What was compromised and why, remediation via recommended SRs, and the choke-point nodes that slow an attacker down the most.
CSRAS follows the IEC/ISA 62443-3-2 ZCR workflow exactly: SuC definition, high-level risk (HLCRA), zone & conduit split, detailed risk (DCRA) mapped to MITRE ATT&CK for ICS, an SL-T vector per zone, and gap-closing mitigation.
Let us walk you through CSRAS 62443 live on a demo model of your plant — from zone & conduit design to a board-ready report.