prEN 40000-1-2 §6.4 · STRIDE · ETSI TS 102 165-1IEC/EN 62443 · MITRE ATT&CK for ICS · D3FEND

Threat modeling, guided by AI.

Two assessments in one workspace: STRIDE threat models for connected products, scored per ETSI TS 102 165-1, and IEC/EN 62443 risk analysis for industrial and OT environments — zones and conduits, ICS threats and target security levels. The assistant drafts, scores and explains every step.

Product threat modeling

For connected products and embedded devices, aligned to prEN 40000-1-2 §6.

  • · STRIDE enumeration per asset
  • · ETSI TS 102 165-1 likelihood × impact scoring
  • · MITRE EMB3D threat and mitigation catalogue
  • · Risk register, criteria, treatment and §6.x coverage report
Start a product modelAbout product threat modeling

OT risk analysis (IEC/EN 62443)

For plants, utilities and industrial control systems, following the 62443-3-2 flow.

  • · Asset inventory by Purdue level with C/I/A ratings
  • · Zones & conduits, initial and detailed risk
  • · Threats from MITRE ATT&CK for ICS, countermeasures from D3FEND
  • · Target Security Levels per foundational requirement, plus sign-off log
Start an OT assessmentAbout IEC 62443 risk analysis

How it works

1
Describe the system

Paste a product description or a site and process overview. The assistant interviews you for what is missing.

2
Let the assistant draft and score

Scope, assets, zones, threats and risk ratings are proposed for you — you review and adjust.

3
Export the report

A print-ready assessment report with the full risk register, treatment decisions and review log.

AI chat input

Paste a product description. The assistant interviews you for missing context.

STRIDE per asset

Spoofing, Tampering, Repudiation, Info disclosure, DoS, Elevation — grouped by asset.

ETSI risk scoring

Likelihood × Impact (1–5), with residual risk once mitigations are in place.

Zones & conduits

Group OT assets into zones by Purdue level and document every conduit between them.

ATT&CK for ICS threats

Pick ICS techniques from the MITRE matrix, or let the assistant propose the relevant ones.

Target Security Levels

SL-T 1–4 per zone across the seven foundational requirements of 62443-3-3.

Built for EU cybersecurity regulation

Zybercomply produces the documented risk assessment that regulators and notified bodies expect to see. Use it as the evidence base for:

Cyber Resilience Act (CRA)

The CRA requires manufacturers of products with digital elements to carry out and document a cybersecurity risk assessment. Zybercomply's prEN 40000-1-2 §6 workflow delivers it.

Read the Cyber Resilience Act (CRA) guide
RED delegated act · EN 18031

Radio equipment placed on the EU market must meet the RED cybersecurity requirements. Threat models and risk registers support your EN 18031 assessment.

Read the RED delegated act guide
IEC/EN 62443 · NIS2

Operators and integrators of industrial systems can document zones, conduits and target security levels per IEC 62443-3-2, supporting NIS2 risk management duties.

Read the IEC/EN 62443 guide

Who it's for

Device manufacturers
Plant & utility operators
System integrators
Security consultancies

Simple pricing

Both modules — product threat modeling and OT risk analysis — are included in every plan. Start free with 1 product and 1 saved assessment. Upgrade to Pro at €250/month for more products, PDF export and higher AI limits.

See full pricing