EDIH, EEN, Interreg: the platform for European programmes.Find out more

Maturity · Critical and industrial infrastructure security

The security of your industrial sites, measured site by site and turned into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Maturity · Critical and industrial infrastructure security

Industrial security governanceN1 → N5
Asset knowledge and mappingN1 → N5
Architecture, zones and conduitsN1 → N5
Access management and remote maintenanceN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Industrial security governance6484
Asset knowledge and mapping5379
Architecture, zones and conduits6182
Access management and remote maintenance3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • Cetim
  • Aerospace Valley
  • Cap'Tronic
  • IMT Mines Alès
  • Pôle SCS
  • Pôle Optitec

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Critical and industrial infrastructure security framework (IEC 62443, NIS2, CER directive) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism, one level, the level above, and the action linking the two, that turns a finding into a trajectory.

Is remote maintenance access granted to external contractors controlled and logged?

  1. N1

    No formal control. Access has been opened over the course of various projects, with no inventory or known end date.

  2. N2

    A procedure exists and named accounts are created, but access remains permanent and monitoring depends on the team that requested it.

  3. N3

    Access is named, opened on request for a limited period and recorded in a register maintained by the site. Sessions are logged.

  4. N4

    Requests are approved by the installation manager, sessions are monitored in real time and the register is reviewed at every industrial security committee.

  5. N5

    Access rules are adjusted based on incidents and changes to the equipment base, with documented tracking of revisions and an enforceable notification clause for integrators.

Action to move from L2 to L3

Introduce dated requests for opening remote maintenance access, with automatic closure at expiry, and add the review of the external access register to the agenda of the monthly maintenance meeting.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurement

What this framework covers

Critical and industrial infrastructure security is not just about the cybersecurity of automation networks. It brings together segmentation between IT and industrial systems, control over remote maintenance access, the inventory of controllers and control equipment, the physical safety of technical enclosures, detection of events on OT networks, operational continuity and recovery, and finally the management of contractors working on production lines. IEC 62443 structures the control systems part, while NIS2 and the directive on the resilience of critical entities add governance and notification obligations.

In practice, oversight runs up against the reality of the sites. Installations feature different generations of equipment, lifespans of twenty years or more, and rare shutdown windows. Three questions kept coming up without a documented answer in most industrial groups. Who holds the up to date inventory of controllers, drives and supervision workstations, and how often is it refreshed? How is remote maintenance access for integrators opened, logged and closed? What actually happens if a supervision system becomes unavailable in the middle of a production run?

One common confusion deserves clearing up: industrial security and functional safety do not overlap. Safety protects people and the environment from an installation failure, with its own safety integrity level requirements. Security, in the sense of this framework, protects the installation from intentional acts or external events. The two intersect, particularly when a cybersecurity measure touches a safety instrumented function, but they involve different people and different evidence. Many organisations handle both in the same committee without distinguishing the decisions.

A compliance audit concludes with a binary finding: the requirement is met or it is not. The maturity assessment answers a different question. What level of control does each site actually have, how much dispersion exists between business units, and what specific action moves a practice from documented to applied. The score per theme and the target generate the gap, the gap generates the action plan, and AI groups these actions into a prioritised roadmap, reusable to prepare for a regulatory audit.

The framework is ready to use in Datamensio and remains adaptable. You adjust the themes to your operations, whether continuous process, manufacturing or networks, and AI refines the questions and levels using the CMMI method. It can also build a tailored version from your own documents: industrial security policy, zone and conduit diagrams, integration specifications.

Reference standard: Critical and industrial infrastructure security framework (IEC 62443, NIS2, CER directive)

The themes assessed

  • Industrial security governance

    Policy applicable to control systems, roles between IT and automation, arbitration of exceptions, alignment with functional safety.

  • Asset knowledge and mapping

    Inventory of controllers, supervision systems, drives and network equipment, criticality of functions, flow mapping, update frequency.

  • Architecture, zones and conduits

    Separation between IT and industrial networks, zone segmentation, conduit filtering, handling of gateways and engineering workstations.

  • Access management and remote maintenance

    Accounts for internal and external staff, authentication, opening and closing of remote access, traceability of maintenance sessions.

  • Physical security of installations

    Access control to technical rooms and cabinets, protection of power and communication points, video surveillance, handling of visitors and subcontractors.

  • Change and update management

    Configuration and controller programme management, backups and restoration, applicable patches, testing before return to service, shutdown windows.

  • Event detection and handling

    Monitoring of industrial networks, escalation of anomalies to the security team, qualification, response procedures suited to a production environment.

  • Continuity and recovery of operations

    Fallback modes, degraded operation, expected recovery times per line, exercises, availability of spare parts and programme backups.

  • Supply chain and integrators

    Contractual requirements, qualification of equipment suppliers, acceptance of new installations, notification obligations for contractors.

  • Skills and continuous improvement

    Training of automation engineers and operations teams, lessons learned after incidents, indicators, comparison of sites over time.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this assessment deliver NIS2 compliance or IEC 62443 certification?

No. Datamensio measures the maturity of your practices and prepares you for the deadline. Regulatory compliance is a matter for the competent authority, and product or organisational certification is a matter for accredited bodies. The assessment gives you the current state, the gaps and the trajectory.

What is the difference between this assessment and an industrial security audit?

An audit checks whether requirements are met and concludes with a gap. The assessment places each practice on a progressive scale and indicates the action that moves it up a level. It is conducted without any intervention on the installations, based on declared practices and supporting evidence.

How long does the assessment take?

The short version can be completed in a single working session. The full version, run collaboratively with automation engineers, maintenance and the security team, generally takes one to two weeks, most of the time being spent on data collection at the sites.

Can several sites be compared with each other?

Yes. Pilot lets you assess sites against the same framework, compare theme scores across business units and track progress against previous campaigns. A cross-site roadmap consolidates the action plans of several sites.

Can the framework be adapted to our sector?

Yes. You can adjust the themes, questions and levels, or start from your own documents: the AI builds a version tailored to continuous process, manufacturing or network operations, refining the levels using the CMMI method.

Do you need automation expertise to answer?

The questions focus on management practices, not equipment configurations. Some require input from an automation engineer or the maintenance manager: the collaborative mode allows these questions to be assigned to the right person.

How is the action plan costed?

Every gap between the score and the target generates an action. The service catalogue matches a solution to each action, with its cost, timeframe and expected impact on the score, making the budget trade-off open for discussion in committee.

Where is the data hosted?

In France, with OVH, backed up at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.

Take your first measurement