EOS Modus · Frameworks & Standards

Eight Regimes. One Control Set.

These are the regimes an OT estate in UK and European critical infrastructure is actually measured against. They overlap heavily, and they use different words for the same control. EOS Modus holds the control once and answers each of them from it.

Status current as at September 2026. Regulatory positions move, we keep this page and the ODiGE NIS Bill tracker aligned.
On getting the terms right

These things are not interchangeable, and using them loosely causes real confusion in scoping conversations. A regulation creates a legal duty. A framework gives you a structure for assessing whether you have met one. A standard tells you how to build and verify a control. A capability is a body of knowledge or a live data feed you consume. IEC 62443 is a standard, not a framework. MITRE ATT&CK and the CVE ecosystem are distinct capabilities, not the same thing. We label each one below.

NCSC Cyber Assessment Framework v4.0

Framework
The yardstick UK regulators apply to essential services, including energy.

CAF is outcome-based rather than prescriptive. It asks whether you achieve an outcome, not whether you bought a particular product. Four objectives, A to D, covering managing security risk, protecting against cyber attack, detecting events, and minimising the impact of incidents.

Version 4.0 landed in August 2025 and moved the bar in four places, a deeper expectation around understanding attacker methods and motivations, secure software development and maintenance for software used in essential services, stronger security monitoring and threat detection, and explicit coverage of AI-related risk. Operators who assessed against v3.2 and have not re-baselined are carrying an unquantified gap.

Structure
4 objectives, 14 principles, contributing outcomes assessed as achieved, partially achieved or not achieved
Current version
v4.0, published August 2025
Hardest outcome for OT
B1.a asset management, which is where M1 earns its place
Answered by M1 M5 M7 M8 M14 M15

UK Cyber Security & Resilience Bill

Legislation, in progress
The update to the UK NIS Regulations 2018, currently before the House of Lords.

Announced in the July 2024 State Opening, introduced on 12 November 2025, second reading 6 January 2026, committee stage through February, third reading in the Commons 16 June 2026, and now in Lords committee. It is not law yet, but the direction is settled enough to plan against.

The scope widens. Data centres, managed service providers, large load controllers and critical suppliers to regulated entities come into the net, alongside the existing sectors. Reporting duties increase, including compulsory ransomware reporting, and regulators gain stronger enforcement powers. Daily fines in the order of £100,000 for continued failure have been signalled by government.

For an offshore wind operator the practical question is not whether you are in scope, you almost certainly are, but whether your critical suppliers know that they now might be too.

Stage
House of Lords committee, from 1 September 2026
New in scope
Data centres, MSPs, large load controllers, critical suppliers
Enforcement
Signalled daily fines up to £100,000, plus wider regulator powers
Answered by M8 M10 M13 M15

NIS2 Directive & UK NIS Regulations

Regulation
Legal duties for essential and important entities, on both sides of the Channel.

NIS2 (EU 2022/2555) has applied since October 2024, though national transposition has been uneven and several member states arrived late. If you operate assets in Dutch, German, Danish, Belgian or Polish waters, the obligation sits with the local entity under local implementing law, which is rarely a straight copy of the directive.

The reporting clock is the part that catches operators out. An early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. Twenty four hours is not long if nobody has agreed in advance who declares an incident and who talks to the regulator.

Reporting
24h early warning, 72h notification, 1 month final report
Penalties
Up to €10M or 2% of global turnover for essential entities
Management liability
Named accountability at management-body level, a change from NIS1
Answered by M8 M10 M13 M14

IEC 62443 Series

Standard
The engineering standard for industrial automation and control system security.

A standard, not a framework. Where CAF asks whether you have understood your estate, 62443 tells you how to partition it and how to specify a control so a vendor can build and verify it. The parts that matter most in an operating offshore wind estate are 62443-2-1 for the security management system, 62443-3-2 for zone and conduit risk assessment and target security levels, and 62443-3-3 for the system requirements that follow from an SL target.

62443-3-2 is increasingly written into FEED and O&M contracts, which means the zone and conduit model stops being a consultancy artefact and becomes a contractual deliverable that has to be maintained. M3 holds it as living data for exactly that reason.

Zone & conduit
62443-3-2, tolerable risk and target security level per zone
System requirements
62443-3-3, SL 1 to SL 4 with foundational requirements
Product side
62443-4-1 and 4-2, what to demand of an OEM
Answered by M2 M3 M4 M8 M11

NIST Cybersecurity Framework 2.0

Framework
The common language, and the one your US parent or investor will ask for.

CSF 2.0 added Govern to the original five functions, so the set is now Govern, Identify, Protect, Detect, Respond and Recover. It is not a UK regulatory requirement, but it is the framework most international owners, insurers and lenders are fluent in, and it is frequently the language a board paper has to be written in.

Modus treats CSF as an output view rather than a separate programme. The controls are the same controls, presented against CSF categories for the audience that wants them that way.

Functions
Govern, Identify, Protect, Detect, Respond, Recover
Released
Version 2.0, February 2024
Typical use
Investor, insurer and group-level reporting
Answered by M8 M15

MITRE ATT&CK for ICS

Capability
Adversary behaviour, in the language of industrial control systems.

A knowledge base of the tactics and techniques observed against ICS environments, not a compliance checklist. Its value in Modus is specificity. Rather than a generic threat statement, techniques are mapped against the assets, conduits and access routes in your register that would actually carry them.

That turns the threat model into a prioritised work list, and it gives detection engineering something concrete to aim at. CAF v4.0's stronger expectation around understanding attacker methods is most readily evidenced this way.

Scope
ICS-specific tactics and techniques, distinct from Enterprise ATT&CK
Use in Modus
Technique-to-asset mapping, coverage and gap analysis
Not to be confused with
CVE and KEV, which describe vulnerabilities, not behaviour
Answered by M5 M7

CISA Known Exploited Vulnerabilities

Capability, live feed
The short list of vulnerabilities that are being exploited in the wild.

Thousands of CVEs are published every month and almost none of them are relevant to your estate. The KEV catalogue narrows the field to what is confirmed as actively exploited, which is a far more useful prioritisation signal than a CVSS score on its own.

Modus matches advisories against the asset register by vendor, product and firmware version, then flags KEV entries separately. A KEV on a device sitting behind a well-controlled conduit is a different conversation from the same KEV on an asset reachable through an OEM remote access route, and Modus can tell the difference because it knows the architecture.

Match on
Vendor, product, firmware version, from M1
Context added
Zone, conduit and reachability, from M2 to M4
Reality check
Most OT assets cannot be patched on demand, so compensating controls are the answer Modus tracks
Answered by M6 M12

Ofgem CAF & The OFTO Regime

Sector profile
How CAF is actually applied to GB energy, and what changes hands at OFTO transfer.

Ofgem applies CAF as the competent authority for the GB energy sector, with sector-specific expectations and its own assessment cycle. Generators, transmission owners and OFTOs are all in scope, with the boundary between them a recurring source of argument about who owns which control.

OFTO transfer is where an undocumented OT estate becomes expensive. Due diligence increasingly includes OT cyber evidence, and a transmission asset handed over without a credible asset register or zone model creates a liability that gets priced in. Building the register during construction is considerably cheaper than reconstructing it at transfer.

Competent authority
Ofgem, for the GB energy sector
Boundary risk
Generator, TO and OFTO control ownership at the interface
Transfer evidence
Asset register, zone model, access records, incident history
Answered by M1 M3 M14 M15

Which One Is Actually Coming For You First?

Usually it is whichever regulator, insurer or counterparty has the nearest deadline. We can map your obligations across these regimes and show you where the overlap is, which is normally more than clients expect.