Utilities · OT security and cyber compliance

The CISO chose you, then audited you as a supplier.

You sell OT monitoring, vulnerability management, ISMS or CIP compliance tools to utilities. The CISO or ISMS officer owns the need, and dated duties under NIS2, the EnWG and NERC CIP fund the work between incidents. The utility’s supplier review applies to you too, and in Germany a missing ISMS certificate can stop the award.

Typical deal
€25–250k a year in DACH Illustrative
Sales cycle (DACH tender)
About 9 months Illustrative
Buying group (departmental)
4–6 people Illustrative

Updated 5 October 2026 · Based on Panelhop research, October 2026

The short answer

How do OT security vendors sell to utilities?

OT security and compliance vendors sell to utilities when a rule or an incident sets the date: NERC CIP and AWIA in the US, NIS2 and EnWG duties for German Stadtwerke and DSOs. The CISO or CIP manager owns the need; IT, operations and procurement decide too. Vendors should reach every seat early and have supplier evidence ready.

OT security and cyber compliance · How a deal really moves

OT deals stall at everyone but the CISO. The consultant picks the tool, then your evidence pack stalls. The same deal, with every seat in early. Operations in before the proof, supplier review from discovery.

One Stadtwerk or US utility, 4–6 people (6–12 above €100k) and about 9 months for a DACH tender, by our estimate.

What opens a deal

  • Cyber incident at a peer: Security
  • Germany’s NIS2 law: Regulation · DE
  • EnWG ISMS certification: Regulation · DE
  • NERC CIP-015 monitoring: Regulation · US
  • AWIA recertification: Regulation · US

Signal Desk · weekly: In-market accounts, scored and mapped

Your buyer and who decides

A Stadtwerk or US utility

Stadtwerke, DSOs, IOUs and water systems

Panel Check · coverage baselined

  • CISO or ISMS officer, can Veto: Audit findings and penalties.
  • CIP compliance manager, can Veto: A violation traced to a missing control.
  • Managing director, can Veto: An incident that takes billing or control systems offline.
  • IT leadership, can Veto: Another console nobody has time to watch.
  • Control room and ops: A tool that interrupts live operations.
  • Procurement, can Veto: A challenge to the award.

How the deal moves

  1. Trigger

  2. Gap analysis

    Where it stalls
    The gap-analysis consultant picks the tool
    With Panelhop: Leak Fix
    Security consultants mapped as seats on every target account
  3. Budget and scope Typical time: 3–12 months

  4. Tender Typical time: 1–3 months

    Where it stalls
    Out at suitability: no German references
    With Panelhop: Panel Check
    Stadtwerke tiered by the German references and partners you can show
  5. Proof Typical time: 1–3 months

    Where it stalls
    Control room objects after security chose
    With Panelhop: Leak Fix
    Operations and IT engaged on the opportunity before the proof begins
  6. Supplier review Typical time: 1–3 months

    Where it stalls
    Your own evidence pack holds up the award
    With Panelhop: Leak Fix
    A supplier-review task opened at discovery, with an owner and due date
  7. Award and rollout

  8. Renewal and audits

Panel Ops · monthly: Scores and plays tuned against the baseline

Illustrative Source: Stages, seats, triggers and stalls from Panelhop research, October 2026; the services as described on the Services page. Note: Durations, panel sizes and cycle lengths are Panelhop estimates from our research, not measurements.

At a glance

Typical deal€25–250k a year in DACH Illustrative
Sales cycle (DACH tender)About 9 months Illustrative
Buying group (departmental)4–6 people Illustrative
MotionRegulation-dated purchases and tenders, plus emergency buys after incidents

Source: Panelhop research, October 2026. Note: Values marked Illustrative are Panelhop estimates from our research, not measurements.

OT security deals stall on the vendor’s own evidence.

Where do OT security deals get lost?

OT security deals are lost between incidents, at the suitability check and in the utility’s review of the vendor itself. Late security review was a likely bottleneck for 8 of 20 utility vendors Panelhop analysed. Yet none of the 20 publishes, on the pages we read, a pre-filled CIP-013 questionnaire, an SBOM or NIS2 supplier evidence.

Exhibit 1

Where the pipeline leaks: 4 points across 8 stages.

  1. Your OT pipeline follows the last incident

    What you see
    New OT security deals cluster in the months after each incident.
    Why it happens
    The regulatory dates that fund security work between incidents aren’t tracked per account.

    Stage Trigger

  2. A strong product is excluded at suitability

    What you see
    Your bid is excluded at the suitability stage despite a strong product.
    Why it happens
    No reference programme with existing German energy customers.

    Stage Tender

  3. The control room objects after security chose

    What you see
    A late objection that the monitoring tool could disturb control systems.
    Why it happens
    The deal ran through the security team alone.

    Stage Proof

  4. The award waits on your own SBOM and ISMS

    What you see
    The OT security contract waits on your SBOM, ISMS certificate or questionnaire answers.
    Why it happens
    No evidence pack is ready before the utility asks for it.

    Stage Supplier review

Source: Panelhop research, October 2026.

Dated rules and peer incidents open OT security deals.

What triggers a utility to buy OT security software?

A utility buys OT security software when a regulation sets a date or an incident at a peer makes the risk real. Germany’s NIS2 law, NERC CIP and AWIA all publish their dates, so a vendor can plan around them.

Exhibit 2 Illustrative

The 5 events that open or close the window for a deal.

  • Security

    Cyber incident at a utility or a peer

    What happens
    Ransomware or an OT intrusion takes a utility’s billing or control systems offline.
    Where to spot it
    CISA, EPA and WaterISAC advisories, and local news.
    Window
    Emergency spend and stricter supplier reviews follow, from immediately to 6 months after the incident, by Panelhop’s estimate.
  • Regulation

    Germany’s NIS2 law

    What happens
    Germany’s NIS2 implementation law has applied since 6 December 2025 to about 29,500 entities, with registration, reporting and risk management duties.
    Where to spot it
    BSI guidance and German tender aggregators.
    Window
    Ongoing; Stadtwerke have already tendered vulnerability management software since the law took effect.
  • Regulation

    EnWG IT security duties

    What happens
    German network operators must run a certified ISMS for systems that affect network operation, under the EnWG security catalogue.
    Where to spot it
    BNetzA’s IT-Sicherheitskatalog and each operator’s certification audits.
    Window
    Each certification and surveillance audit.
  • Regulation

    NERC CIP-015 network monitoring

    What happens
    NERC’s CIP-015 standard adds internal network security monitoring, due for high impact systems and medium impact control centres by 1 October 2028, and for remaining medium impact systems with external routable connectivity by 1 October 2030.
    Where to spot it
    FERC orders, NERC implementation plans and NERC’s list of US effective dates.
    Window
    Utilities need monitoring and asset inventory budgets approved well before the first date.
  • Regulation

    AWIA recertification

    What happens
    US community water systems serving more than 3,300 people must review their risk and resilience assessment at least once every 5 years.
    Where to spot it
    EPA’s AWIA certification deadline tables.
    Window
    Systems serving 3,301–49,999 people certify emergency response plans by 31 December 2026.
Source: Panelhop research, October 2026; BSI (Bundesamt für Sicherheit in der Informationstechnik); U.S. Environmental Protection Agency; NERC (North American Electric Reliability Corporation). Note: Timings are Panelhop estimates from our research, not measurements.

Your buyer also audits you as a supplier.

Who signs off on OT security software at a utility?

OT security software is signed off by the CISO or ISMS officer, IT, procurement and the managing director, with control-room staff as daily users. The same security team then reviews you as a supplier under its own CIP-013 or NIS2 duties. Some of these seats apply only in the US or Germany, so one departmental deal usually involves 4–6 people, by Panelhop’s estimate.

Exhibit 3 Illustrative

A departmental OT security deal involves 4–6 people from these seats, depending on whether the buyer is a German Stadtwerk or a US registered entity.

At a German Stadtwerk or a US registered entity: 4–6 people

  1. CISO or ISMS officer

    Can Veto

    CISO · Informationssicherheitsbeauftragter · ISMS-Verantwortlicher

    Cares about
    Evidence ready for the next audit.
    Worries about
    Audit findings and penalties.
  2. CIP compliance manager

    Can Veto

    CIP Senior Manager · NERC Compliance Manager

    Cares about
    CIP evidence that stands up in an audit.
    Worries about
    A violation traced to a missing control.
  3. Managing director

    Can Veto

    Geschäftsführer · General Manager

    Cares about
    Showing the board and the regulator that the duties are met.
    Worries about
    An incident that takes billing or control systems offline in public.
  4. IT leadership

    Can Veto

    IT-Leiter · CIO

    Cares about
    Fit with existing security tools and IT service providers.
    Worries about
    Another console nobody has time to watch.
  5. Control room and operations

    Leiter Netzleitstelle · SCADA Coordinator · Operations Manager

    Cares about
    Monitoring that never affects control-system uptime.
    Worries about
    A tool that interrupts live operations.
  6. Procurement

    Can Veto

    Einkauf · Vergabestelle · Purchasing Agent

    Cares about
    A compliant procedure with comparable bids.
    Worries about
    A challenge to the award.
  7. External IT service provider

    Municipal IT service provider · System integrator

    Cares about
    Tools it can run for several utilities at once.
    Worries about
    A product it can’t support across its clients.
Source: Panelhop research, October 2026. Note: The panel size is a Panelhop estimate from our research, not a measurement.

Security owns the need; operations has to live with it.

Who buys OT security software at a utility?

OT security and compliance tools are bought by the CISO, OT security lead or ISMS officer, with IT and operations as co-owners of anything that touches control systems. Germany’s NIS2 law has applied to about 29,500 entities since 6 December 2025, and energy and water operators are among them. A typical DACH deal runs about €80k a year, by Panelhop’s estimate.

What vendors of this type sell

  • OT network monitoring and asset inventory
  • Vulnerability and patch management for OT
  • ISMS tooling and audit evidence for ISO 27001 and the IT-Sicherheitskatalog
  • NERC CIP compliance management
  • Supplier risk and questionnaire management
  • Backup and incident response for billing and control systems

Which utilities buy it

  • US registered entities under NERC CIP: IOUs, large public power and G&Ts
  • German Stadtwerke and DSOs under NIS2 and the EnWG
  • US community water systems under AWIA
  • Austrian and Swiss network operators

OT security deals run from trigger to supplier review.

How does an OT security deal move at a utility?

An OT security deal moves from a regulatory or incident trigger through gap analysis, budget, tender and proof, then a review of the vendor itself as a supplier. That last step is where many deals stall.

Exhibit 4 Illustrative

Stage by stage: what you do, what the utility does, and what changes at the 4 stages where deals stall.

StageWhat you doWhat the utility doesTodayWith Panelhop
TriggerPublishes guidance on the new duty or the latest incident.Registers under NIS2, recertifies under AWIA or reacts to a peer’s incident.Pipeline depends on the latest incident.Peer incidents, registrations and deadlines scored weekly per account, each with a brief for your rep. Signal Desk In-market accounts, weekly
Gap analysisOffers a gap review or audit support.Maps duties to gaps, often with a consultant ahead of the certification audit.The consultant’s shortlist arrives as a surprise. Stalls: The consultant picks the tool. The consultant who runs a utility’s gap analysis often shortlists the tools that will close the gaps.Security consultants mapped as seats on every target account. Leak Fix We build the fixes
Budget and scope Typical time: 3–12 months, or immediately after an incidentSizes the deal to the utility’s control systems and sites.Funds it from the security budget, the capital plan or emergency spend after an incident.Every utility gets the same offer.Draft tiers by regulatory exposure and control-system scope, from your closed-won and closed-lost data. Panel Check GTM audit · 2–3 weeks
Tender Typical time: 1–3 monthsAnswers SektVO, city or framework tenders with references and certificates.Sets suitability criteria such as recent comparable references and ISO 27001.Bids go to tenders your references can’t pass. Stalls: Excluded at suitability. DACH tenders often ask for recent comparable German energy references, so a vendor with only US or UK references can be out before scoring.Target Stadtwerke tiered by the German energy references and integrator partners you can show, before the tender opens. Panel Check GTM audit · 2–3 weeks
Proof Typical time: 1–3 monthsRuns a proof on a test network or with passive monitoring.Operations and IT test it against uptime and integration needs.The proof starts with the security team alone. Stalls: Operations not in the room. A tool chosen by security without control-room input meets objections when it touches live systems.Operations and IT engaged on the opportunity before the proof begins. Leak Fix We build the fixes
Supplier review Typical time: 1–3 monthsProves its own ISMS, SBOM and incident notification process.Reviews the vendor under its own NIS2 or CIP-013 supply-chain duties.Your evidence pack is assembled after the request. Stalls: Your own evidence is the blocker. In Germany, a provider operating in-scope systems for a network operator may need its own certified ISMS, and a missing certificate stops the award.A supplier-review task opened at discovery, with a named owner and a due date. Leak Fix We build the fixes
Award and rolloutDeploys sensors or agents and trains the team.Signs after any standstill period and starts operating the tool.Sales commitments on sensors and sites stay with the rep.A handoff document from the deal, with the audit dates each renewal depends on. Leak Fix We build the fixes
Renewal and auditsRenews ahead of each audit or plan review.Reviews the supplier again on each plan cycle.Renewals are handled by whoever remembers.Renewal tasks timed to each customer’s audit and plan cycle, checked in the weekly signal review. Panel Ops We run it monthly
Source: Panelhop research, October 2026. Note: Typical times are Panelhop estimates from our research, not measurements.

Track the dates between incidents, and start the review early.

How does Panelhop change an OT security pipeline?

Panelhop changes an OT security pipeline by tracking regulatory dates and peer incidents per account, mapping operations and IT before the proof and opening your supplier review at discovery. Your reps own every first touch, and your security team still owns the evidence.

What we baseline and report

  1. Target accounts with a dated regulatory trigger in the CRM, against the baseline
  2. OT opportunities with operations and IT engaged before the proof
  3. Days from verbal award to signature, tracked against the baseline

The words your buyers use, defined.

What do terms like “NERC CIP” and “CIP-013” mean?

Plain definitions of the terms that come up when you sell OT security and cyber compliance to utilities.

NERC CIP
North America’s mandatory cybersecurity standards for entities that own or operate bulk electric system assets. Many small distribution-only utilities fall outside them.
CIP-013
NERC’s supply-chain risk management standard. Registered entities must plan how they manage vendor cyber risk, so suppliers face questionnaires and evidence requests before contract.
NIS2
The EU directive on network and information security. Germany’s implementation law, in force since 6 December 2025, covers energy and water operators among about 29,500 entities.
ISMS
Information security management system: the documented processes an organisation uses to manage security risk, usually certified to ISO 27001.
IT-Sicherheitskatalog
The Bundesnetzagentur’s security catalogue under Germany’s Energy Industry Act (EnWG). It requires grid operators to run a certified ISMS for systems that affect network operation.
SBOM
Software bill of materials: a list of the components inside a software product. Utilities ask suppliers for one during security review to check for known vulnerabilities.

Answers before your next utility deal.

What do vendors of OT security and cyber compliance ask about selling to utilities?

How do you sell OT security software to utilities?

OT security software is sold to utilities around dated duties and incidents. Track each target utility’s regulatory exposure, such as NERC CIP, Germany’s NIS2 law, EnWG duties or AWIA. Map the CISO, IT, operations and procurement before the tender, and have your own supplier evidence ready, because utilities review OT vendors as suppliers too.

What security documents do utilities ask software vendors for?

Utilities ask software vendors for a completed supply-chain questionnaire, SOC 2 or ISO 27001 reports, a software bill of materials and terms for vulnerability disclosure and incident notification. US registered entities ask under NERC CIP-013. In Germany, a vendor operating in-scope systems for a network operator may need its own certified ISMS. Having these ready shortens the utility’s review.

What does NIS2 mean for vendors selling to Stadtwerke?

NIS2 means in-scope Stadtwerke must manage cyber risk across their suppliers, so vendors selling to Stadtwerke face stricter security checks. Germany’s NIS2 law has applied since 6 December 2025 to about 29,500 entities. It also creates demand for ISMS, OT monitoring and vulnerability management tools, and Stadtwerke have already tendered vulnerability management software.

How do you win Stadtwerke tenders without German energy references?

To win Stadtwerke tenders without German energy references, build a reference programme with the first German customers, partner with an established integrator or start with smaller contracts below the tender threshold. Suitability criteria often ask for recent comparable references and certificates such as ISO 27001, and a vendor without them can be excluded before scoring.

Do cyber incidents at utilities create sales opportunities?

Cyber incidents at utilities do open buying windows: emergency spend on OT security, backup and resilient billing often follows within 6 months, by Panelhop’s estimate, and supplier reviews tighten across the sector. But an OT security pipeline that waits for incidents is erratic. Vendors selling to utilities do better tracking regulatory dates per account between incidents.

How long does it take to sell OT security software to a Stadtwerk?

Selling OT security software to a Stadtwerk takes about 9 months for a tender by Panelhop’s estimate, within a range of 4–18 months. Smaller deals below the tender threshold take about 3 months, by the same estimate. Budget approval alone can take an estimated 3–12 months, unless an incident releases emergency spend. The Stadtwerk’s review of the vendor as a supplier then adds an estimated 1–3 months, so OT security vendors should open it at discovery.

Where the numbers come from.

Sources

Sourced figures link to their source below. Figures marked Illustrative, and figures given as estimates, are inferred from Panelhop research. Vendors appear only as types, never by name.

  1. BSI (Bundesamt für Sicherheit in der Informationstechnik), Cybersicherheitsrecht: NIS-2-Umsetzungsgesetz ab morgen in Kraft (2025)
  2. U.S. Environmental Protection Agency, AWIA Section 2013/SDWA Section 1433: Risk and Resilience Assessments and Emergency Response Plans (2026)
  3. NERC (North American Electric Reliability Corporation), FAQ for Reliability Standard CIP-015-2 (Project 2025-02 Internal Network Security Monitoring) (2025)
  4. NERC (North American Electric Reliability Corporation), Standards, Compliance, and Enforcement Bulletin, February 2–8, 2026 (2026)
  5. Panelhop research, October 2026: our analysis of the vendors, buying panels, pipelines and triggers for OT security and cyber compliance in utilities, from public sources. Vendor names are not published.
Next step

Find where your pipeline to utilities leaks.