RiskWatch
RiskWatch International · Founded 1993 · Annapolis, MD, USA
Mid-market utility compliance platform with NERC CIP, AWIA, TSA, EPA RMP, and IEC 62443-aligned libraries in one tenant.
Summary
RiskWatch ships a compliance assessment platform built around pre-mapped control libraries for 40+ regulatory frameworks including NERC CIP-002 through CIP-015 INSM, CIP-014 R4/R5 physical security, EPA Risk Management Program (40 CFR Part 68), EPA AWIA Risk + Resilience Assessment, TSA SD-2021-02 Series F pipeline cybersecurity, NIST 800-53 r5, NIST 800-82 r3 alignment for OT/ICS, NIST 800-171, CMMC 2.0, ISO 27001:2022, IEC 62443-aligned controls, SOC 2, PCI DSS v4, HIPAA, and physical security against ASIS and CIP-014. The platform runs on a survey-based assessment engine, an evidence vault with versioning, and a cross-mapping engine that auto-detects shared controls across NERC CIP, NIST, ISO, and IEC 62443. Utility customers include investor-owned utilities, electric cooperatives, and water authorities. The product has been in the field since 1993 with federal customers (DoD, VA, DOJ, NSA per public press). Pricing is partial on the public site, but the single-tenant architecture and customer-owned data residency mean utility buyers retain full control of BES cyber-system, CEII, and AWIA data.
Strengths
- 40+ pre-built framework libraries covering NERC CIP-002 through CIP-015 INSM, CIP-014 R4/R5, EPA RMP 40 CFR Part 68, EPA AWIA RRA, TSA SD-2021-02 Series F, NIST 800-53 r5, NIST 800-82 r3 alignment, NIST 800-171, CMMC 2.0, ISO 27001:2022, IEC 62443-aligned, FERC Order 706, and FERC Order 907
- Cross-mapping engine auto-detects shared controls (NERC CIP-007 to NIST 800-53 SI-4, CIP-005 to NIST 800-82 SC-7, IEC 62443-3-3 SR-3 to NERC CIP-010) so one evidence pull satisfies multiple audits
- Physical security assessment module is in the same tenant as cyber and compliance risk, useful for CIP-014 R4/R5 critical-substation programmes and EPA RMP facility access controls
- 33-year operating history with federal and state customers; FERC-audit and PUC-audit export packs are first-class output, not a custom report build
- Survey-based assessment engine works for non-technical control owners (substation supervisors, water-plant managers, SCADA admins, pipeline operators) without a workflow-builder learning curve
- Single-tenant deployment with customer-owned data residency, an advantage for ITAR-controlled defence-utility customers, CEII data, and EU-data-locality water utilities
- Vendor risk management with BAA and SOC 2 tracking is a first-party module, useful for CIP-013-2 supply-chain and TSA Series F third-party requirements
Weaknesses
- No native OT-detection integrations at the depth of Dragos, Nozomi, or Claroty; RiskWatch ingests asset-inventory and incident data via REST API but does not run east-west INSM monitoring itself, so CIP-015 INSM compliance still requires a paired OT-detection platform
- No native FAIR / Monte-Carlo quantitative cyber-risk module that some Tier 1 IOUs require for board reporting; we deliver this via assessment scoring rather than probabilistic loss modelling
- Public pricing is opaque on the public site (we publish partial bands here; the Enterprise tier is quote-only because deployment topology varies materially for CEII and single-tenant)
- Brand awareness on G2 and Capterra in the utility-compliance cohort is lower than Archer or ServiceNow IRM; total third-party review volume sits below 100
- UI shows its operational-heritage in places; newer entrants (RegScale, Hyperproof) ship a more polished first-run experience for technical users
- Smaller integration marketplace than ServiceNow IRM or IBM OpenPages; the integration count caps at about 25 first-party connectors plus REST
Mid-market and regional utilities (200-5,000 employees: municipal utilities, electric cooperatives, water authorities, regional IOUs, gas distribution operators) running 3+ regulatory frameworks (NERC CIP + AWIA + TSA + state PUC, or NERC CIP + CIP-014 + IEC 62443 + ISO 27001) who want one tenant covering cyber, physical, and environmental compliance plus a FERC-audit response pack.
Pure OT-detection buyers who need east-west INSM monitoring on the bulk electric system as the load-bearing requirement; pair RiskWatch with Dragos, Nozomi, or Claroty for that brief. Also worst for Tier 1 IOUs that require a fully-loaded watsonx AI regulatory-change engine on day one; pair RiskWatch with IBM OpenPages for that.
Key features
- Pre-built control libraries for NERC CIP-002 through CIP-015 INSM, EPA AWIA RRA, TSA SD-2021-02 Series F, EPA RMP 40 CFR Part 68, NIST 800-53 r5, NIST 800-82 r3 alignment, NIST 800-171, CMMC 2.0, ISO 27001:2022, IEC 62443-aligned, FERC Order 706, FERC Order 907
- Cross-mapping engine auto-detects shared controls across NERC CIP, NIST, ISO, and IEC 62443
- Physical security assessment module aligned to ASIS and CIP-014 R4/R5 for critical-substation programmes
- Survey-based assessment engine for non-technical control owners
- Evidence vault with versioning and FERC-audit-ready export
- Vendor risk management with CIP-013-2 supply-chain attestation and TSA Series F third-party
- Policy management with approval and attestation workflows for state PUC and ISO/RTO evidence
- Single-tenant deployment for CEII and data-residency requirements
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Slack, Jira, Salesforce, Custom REST API for OT asset inventory ingest.
Target size
100 to 25,000 employees · US · Canada · EU · UK · AU