IEC 62443 platform-boundary report
For industrial (oil & gas / IEC 62443 / NERC CIP adjacent) deployments, MOD can generate a platform-boundary report from live platform metadata. It is a single admin-only endpoint that returns the report as JSON, or as a downloadable Markdown form.
Enabling, not certification. The report is report-only. It documents what the MOD platform does — its zones, conduits, egress posture, ACL state, conformance results and monitoring hooks — and it maps that evidence to the IEC 62443-3-3 security requirements (SRs) it supports. It never certifies the client's own plant, facility or OT system, and it asserts no compliance verdict or security level. Wording is always "supports control X", never "satisfies".
What it reports
- Zones. Platform components grouped into IEC 62443 zones (edge ingress,
control plane, data stores, workers, mesh), plus the live view: the manager
components, workers grouped by
network_zone, and persistent stacks (counted per zone/status — stack names are tenant data and never appear). - Conduits. The per-service port inventory (direction, protocol, TLS) plus the five standing conduits between zones: API, mesh/tailnet, S3, Vault and the database — each with its protection posture read live.
- Egress inventory. The sealed-mode switch and each egress category, with the foreign hosts each category can reach.
- ACL state. Whether the whole-tailnet default-deny policy is enforced
(
mesh.acl_enforced). - Hardening. The latest continuous-conformance (GY.C12) result per check.
- Monitoring. Whether the SIEM audit export is configured (the SIEM endpoint is a client-private host and is never included — only a boolean flag is reported).
- SR evidence mapping. Each IEC 62443-3-3 security requirement (SR.PSA, SR.DLP, SR.FUP, SR.RMA, SR.MA) with the minimum security level at which it is a minimum requirement, and the conformance check(s) whose evidence points at it.
- Gaps. Open items stated plainly (e.g.
acl_enforced=False, plaintext inbound conduits, a missing SIEM export) — observations, not verdicts.
Metadata only
The report carries no secrets, no credential values and no tenant data. The only hostnames are the platform's own components (already visible on the admin pages). Worker names and their network zone are included; stack names are not (stacks are reported as counts). The SIEM endpoint host is excluded.
How to get it
- API (JSON):
GET /v1/compliance/reports/iec62443-boundary(platform admin auth). Returns{"report": {...}}. - API (downloadable form):
GET /v1/compliance/reports/iec62443-boundary?format=md(platform admin auth). Returns the same report rendered as Markdown (Content-Type: text/markdown).
Both reads are audit-logged (COMPLIANCE_REPORT_EXPORTED) — exporting the
boundary report is itself a security-relevant event. Non-admin callers get
403.
What it is not
The report is a starting point for a client's own IEC 62443 assessment, not a substitute for one. OT-specific controls (and the actual security-level assessment of the client's plant) belong to the client and their assessors. MOD supports the platform-side controls it implements; it does not certify any installation.