Utilities · OT security and cyber compliance
The CISO chose you, then audited you as a supplier.
You sell OT monitoring, vulnerability management, ISMS or CIP compliance tools to utilities. The CISO or ISMS officer owns the need, and dated duties under NIS2, the EnWG and NERC CIP fund the work between incidents. The utility’s supplier review applies to you too, and in Germany a missing ISMS certificate can stop the award.
- Typical deal
- €25–250k a year in DACH Illustrative
- Sales cycle (DACH tender)
- About 9 months Illustrative
- Buying group (departmental)
- 4–6 people Illustrative
Updated 5 October 2026 · Based on Panelhop research, October 2026
At a German Stadtwerk or a US registered entity4–6 people Illustrative
The short answer
How do OT security vendors sell to utilities?
OT security and compliance vendors sell to utilities when a rule or an incident sets the date: NERC CIP and AWIA in the US, NIS2 and EnWG duties for German Stadtwerke and DSOs. The CISO or CIP manager owns the need; IT, operations and procurement decide too. Vendors should reach every seat early and have supplier evidence ready.
OT security and cyber compliance · How a deal really moves
OT deals stall at everyone but the CISO. The consultant picks the tool, then your evidence pack stalls. The same deal, with every seat in early. Operations in before the proof, supplier review from discovery.
One Stadtwerk or US utility, 4–6 people (6–12 above €100k) and about 9 months for a DACH tender, by our estimate.
What opens a deal
- Cyber incident at a peer: Security
- Germany’s NIS2 law: Regulation · DE
- EnWG ISMS certification: Regulation · DE
- NERC CIP-015 monitoring: Regulation · US
- AWIA recertification: Regulation · US
Signal Desk · weekly: In-market accounts, scored and mapped
Your buyer and who decides
A Stadtwerk or US utility
Stadtwerke, DSOs, IOUs and water systems
Panel Check · coverage baselined
- CISO or ISMS officer, can Veto: Audit findings and penalties.
- CIP compliance manager, can Veto: A violation traced to a missing control.
- Managing director, can Veto: An incident that takes billing or control systems offline.
- IT leadership, can Veto: Another console nobody has time to watch.
- Control room and ops: A tool that interrupts live operations.
- Procurement, can Veto: A challenge to the award.
How the deal moves
Trigger
Gap analysis
- Where it stalls
- The gap-analysis consultant picks the tool
- With Panelhop: Leak Fix
- Security consultants mapped as seats on every target account
Budget and scope Typical time: 3–12 months
Tender Typical time: 1–3 months
- Where it stalls
- Out at suitability: no German references
- With Panelhop: Panel Check
- Stadtwerke tiered by the German references and partners you can show
Proof Typical time: 1–3 months
- Where it stalls
- Control room objects after security chose
- With Panelhop: Leak Fix
- Operations and IT engaged on the opportunity before the proof begins
Supplier review Typical time: 1–3 months
- Where it stalls
- Your own evidence pack holds up the award
- With Panelhop: Leak Fix
- A supplier-review task opened at discovery, with an owner and due date
Award and rollout
Renewal and audits
Panel Ops · monthly: Scores and plays tuned against the baseline
Illustrative Source: Stages, seats, triggers and stalls from Panelhop research, October 2026; the services as described on the Services page. Note: Durations, panel sizes and cycle lengths are Panelhop estimates from our research, not measurements.
At a glance
| Typical deal | €25–250k a year in DACH Illustrative |
|---|---|
| Sales cycle (DACH tender) | About 9 months Illustrative |
| Buying group (departmental) | 4–6 people Illustrative |
| Motion | Regulation-dated purchases and tenders, plus emergency buys after incidents |
Source: Panelhop research, October 2026. Note: Values marked Illustrative are Panelhop estimates from our research, not measurements.
OT security deals stall on the vendor’s own evidence.
Where do OT security deals get lost?
OT security deals are lost between incidents, at the suitability check and in the utility’s review of the vendor itself. Late security review was a likely bottleneck for 8 of 20 utility vendors Panelhop analysed. Yet none of the 20 publishes, on the pages we read, a pre-filled CIP-013 questionnaire, an SBOM or NIS2 supplier evidence.
Where the pipeline leaks: 4 points across 8 stages.
Your OT pipeline follows the last incident
- What you see
- New OT security deals cluster in the months after each incident.
- Why it happens
- The regulatory dates that fund security work between incidents aren’t tracked per account.
Stage Trigger
A strong product is excluded at suitability
- What you see
- Your bid is excluded at the suitability stage despite a strong product.
- Why it happens
- No reference programme with existing German energy customers.
Stage Tender
The control room objects after security chose
- What you see
- A late objection that the monitoring tool could disturb control systems.
- Why it happens
- The deal ran through the security team alone.
Stage Proof
The award waits on your own SBOM and ISMS
- What you see
- The OT security contract waits on your SBOM, ISMS certificate or questionnaire answers.
- Why it happens
- No evidence pack is ready before the utility asks for it.
Stage Supplier review
Dated rules and peer incidents open OT security deals.
What triggers a utility to buy OT security software?
A utility buys OT security software when a regulation sets a date or an incident at a peer makes the risk real. Germany’s NIS2 law, NERC CIP and AWIA all publish their dates, so a vendor can plan around them.
The 5 events that open or close the window for a deal.
Security
Cyber incident at a utility or a peer
- What happens
- Ransomware or an OT intrusion takes a utility’s billing or control systems offline.
- Where to spot it
- CISA, EPA and WaterISAC advisories, and local news.
- Window
- Emergency spend and stricter supplier reviews follow, from immediately to 6 months after the incident, by Panelhop’s estimate.
Regulation
Germany’s NIS2 law
- What happens
- Germany’s NIS2 implementation law has applied since 6 December 2025 to about 29,500 entities, with registration, reporting and risk management duties.
- Where to spot it
- BSI guidance and German tender aggregators.
- Window
- Ongoing; Stadtwerke have already tendered vulnerability management software since the law took effect.
Regulation
EnWG IT security duties
- What happens
- German network operators must run a certified ISMS for systems that affect network operation, under the EnWG security catalogue.
- Where to spot it
- BNetzA’s IT-Sicherheitskatalog and each operator’s certification audits.
- Window
- Each certification and surveillance audit.
Regulation
NERC CIP-015 network monitoring
- What happens
- NERC’s CIP-015 standard adds internal network security monitoring, due for high impact systems and medium impact control centres by 1 October 2028, and for remaining medium impact systems with external routable connectivity by 1 October 2030.
- Where to spot it
- FERC orders, NERC implementation plans and NERC’s list of US effective dates.
- Window
- Utilities need monitoring and asset inventory budgets approved well before the first date.
Regulation
AWIA recertification
- What happens
- US community water systems serving more than 3,300 people must review their risk and resilience assessment at least once every 5 years.
- Where to spot it
- EPA’s AWIA certification deadline tables.
- Window
- Systems serving 3,301–49,999 people certify emergency response plans by 31 December 2026.
Your buyer also audits you as a supplier.
Who signs off on OT security software at a utility?
OT security software is signed off by the CISO or ISMS officer, IT, procurement and the managing director, with control-room staff as daily users. The same security team then reviews you as a supplier under its own CIP-013 or NIS2 duties. Some of these seats apply only in the US or Germany, so one departmental deal usually involves 4–6 people, by Panelhop’s estimate.
A departmental OT security deal involves 4–6 people from these seats, depending on whether the buyer is a German Stadtwerk or a US registered entity.
At a German Stadtwerk or a US registered entity: 4–6 people
CISO or ISMS officer
Can Veto
CISO · Informationssicherheitsbeauftragter · ISMS-Verantwortlicher
- Cares about
- Evidence ready for the next audit.
- Worries about
- Audit findings and penalties.
CIP compliance manager
Can Veto
CIP Senior Manager · NERC Compliance Manager
- Cares about
- CIP evidence that stands up in an audit.
- Worries about
- A violation traced to a missing control.
Managing director
Can Veto
Geschäftsführer · General Manager
- Cares about
- Showing the board and the regulator that the duties are met.
- Worries about
- An incident that takes billing or control systems offline in public.
IT leadership
Can Veto
IT-Leiter · CIO
- Cares about
- Fit with existing security tools and IT service providers.
- Worries about
- Another console nobody has time to watch.
Control room and operations
Leiter Netzleitstelle · SCADA Coordinator · Operations Manager
- Cares about
- Monitoring that never affects control-system uptime.
- Worries about
- A tool that interrupts live operations.
Procurement
Can Veto
Einkauf · Vergabestelle · Purchasing Agent
- Cares about
- A compliant procedure with comparable bids.
- Worries about
- A challenge to the award.
External IT service provider
Municipal IT service provider · System integrator
- Cares about
- Tools it can run for several utilities at once.
- Worries about
- A product it can’t support across its clients.
Security owns the need; operations has to live with it.
Who buys OT security software at a utility?
OT security and compliance tools are bought by the CISO, OT security lead or ISMS officer, with IT and operations as co-owners of anything that touches control systems. Germany’s NIS2 law has applied to about 29,500 entities since 6 December 2025, and energy and water operators are among them. A typical DACH deal runs about €80k a year, by Panelhop’s estimate.
What vendors of this type sell
- OT network monitoring and asset inventory
- Vulnerability and patch management for OT
- ISMS tooling and audit evidence for ISO 27001 and the IT-Sicherheitskatalog
- NERC CIP compliance management
- Supplier risk and questionnaire management
- Backup and incident response for billing and control systems
Which utilities buy it
- US registered entities under NERC CIP: IOUs, large public power and G&Ts
- German Stadtwerke and DSOs under NIS2 and the EnWG
- US community water systems under AWIA
- Austrian and Swiss network operators
OT security deals run from trigger to supplier review.
How does an OT security deal move at a utility?
An OT security deal moves from a regulatory or incident trigger through gap analysis, budget, tender and proof, then a review of the vendor itself as a supplier. That last step is where many deals stall.
Stage by stage: what you do, what the utility does, and what changes at the 4 stages where deals stall.
| Stage | What you do | What the utility does | Today | With Panelhop |
|---|---|---|---|---|
| Trigger | Publishes guidance on the new duty or the latest incident. | Registers under NIS2, recertifies under AWIA or reacts to a peer’s incident. | Pipeline depends on the latest incident. | Peer incidents, registrations and deadlines scored weekly per account, each with a brief for your rep. Signal Desk In-market accounts, weekly |
| Gap analysis | Offers a gap review or audit support. | Maps duties to gaps, often with a consultant ahead of the certification audit. | The consultant’s shortlist arrives as a surprise. Stalls: The consultant picks the tool. The consultant who runs a utility’s gap analysis often shortlists the tools that will close the gaps. | Security consultants mapped as seats on every target account. Leak Fix We build the fixes |
| Budget and scope Typical time: 3–12 months, or immediately after an incident | Sizes the deal to the utility’s control systems and sites. | Funds it from the security budget, the capital plan or emergency spend after an incident. | Every utility gets the same offer. | Draft tiers by regulatory exposure and control-system scope, from your closed-won and closed-lost data. Panel Check GTM audit · 2–3 weeks |
| Tender Typical time: 1–3 months | Answers SektVO, city or framework tenders with references and certificates. | Sets suitability criteria such as recent comparable references and ISO 27001. | Bids go to tenders your references can’t pass. Stalls: Excluded at suitability. DACH tenders often ask for recent comparable German energy references, so a vendor with only US or UK references can be out before scoring. | Target Stadtwerke tiered by the German energy references and integrator partners you can show, before the tender opens. Panel Check GTM audit · 2–3 weeks |
| Proof Typical time: 1–3 months | Runs a proof on a test network or with passive monitoring. | Operations and IT test it against uptime and integration needs. | The proof starts with the security team alone. Stalls: Operations not in the room. A tool chosen by security without control-room input meets objections when it touches live systems. | Operations and IT engaged on the opportunity before the proof begins. Leak Fix We build the fixes |
| Supplier review Typical time: 1–3 months | Proves its own ISMS, SBOM and incident notification process. | Reviews the vendor under its own NIS2 or CIP-013 supply-chain duties. | Your evidence pack is assembled after the request. Stalls: Your own evidence is the blocker. In Germany, a provider operating in-scope systems for a network operator may need its own certified ISMS, and a missing certificate stops the award. | A supplier-review task opened at discovery, with a named owner and a due date. Leak Fix We build the fixes |
| Award and rollout | Deploys sensors or agents and trains the team. | Signs after any standstill period and starts operating the tool. | Sales commitments on sensors and sites stay with the rep. | A handoff document from the deal, with the audit dates each renewal depends on. Leak Fix We build the fixes |
| Renewal and audits | Renews ahead of each audit or plan review. | Reviews the supplier again on each plan cycle. | Renewals are handled by whoever remembers. | Renewal tasks timed to each customer’s audit and plan cycle, checked in the weekly signal review. Panel Ops We run it monthly |
Track the dates between incidents, and start the review early.
How does Panelhop change an OT security pipeline?
Panelhop changes an OT security pipeline by tracking regulatory dates and peer incidents per account, mapping operations and IT before the proof and opening your supplier review at discovery. Your reps own every first touch, and your security team still owns the evidence.
What we baseline and report
- Target accounts with a dated regulatory trigger in the CRM, against the baseline
- OT opportunities with operations and IT engaged before the proof
- Days from verbal award to signature, tracked against the baseline
Other vendor types in utilities.
What other vendors sell to utilities?
The same utilities buy from these vendor types too, through different panels and pipelines.
- Vendor type
Customer information and billing systems
CIS, billing, portals and rate engines for US public power, co-ops, IOUs and water utilities, UK water companies and German Stadtwerke.
Read the pipeline - Vendor type
AMI, meter data management and analytics
Smart meter networks, head-end systems, MDM and analytics for municipal, co-op and investor-owned utilities and German meter operators.
Read the pipeline - Vendor type
Grid operations and DER management software
ADMS, OMS, SCADA, DERMS and flexibility platforms for US IOUs, co-ops and public power, British DNOs and European DSOs.
Read the pipeline - Vendor type
Asset, GIS and field workforce platforms
Network GIS, asset management, joint use, vegetation and mobile workforce software for electric, gas and water utilities.
Read the pipeline
The words your buyers use, defined.
What do terms like “NERC CIP” and “CIP-013” mean?
Plain definitions of the terms that come up when you sell OT security and cyber compliance to utilities.
- NERC CIP
- North America’s mandatory cybersecurity standards for entities that own or operate bulk electric system assets. Many small distribution-only utilities fall outside them.
- CIP-013
- NERC’s supply-chain risk management standard. Registered entities must plan how they manage vendor cyber risk, so suppliers face questionnaires and evidence requests before contract.
- NIS2
- The EU directive on network and information security. Germany’s implementation law, in force since 6 December 2025, covers energy and water operators among about 29,500 entities.
- ISMS
- Information security management system: the documented processes an organisation uses to manage security risk, usually certified to ISO 27001.
- IT-Sicherheitskatalog
- The Bundesnetzagentur’s security catalogue under Germany’s Energy Industry Act (EnWG). It requires grid operators to run a certified ISMS for systems that affect network operation.
- SBOM
- Software bill of materials: a list of the components inside a software product. Utilities ask suppliers for one during security review to check for known vulnerabilities.
Answers before your next utility deal.
What do vendors of OT security and cyber compliance ask about selling to utilities?
How do you sell OT security software to utilities?
OT security software is sold to utilities around dated duties and incidents. Track each target utility’s regulatory exposure, such as NERC CIP, Germany’s NIS2 law, EnWG duties or AWIA. Map the CISO, IT, operations and procurement before the tender, and have your own supplier evidence ready, because utilities review OT vendors as suppliers too.
What security documents do utilities ask software vendors for?
Utilities ask software vendors for a completed supply-chain questionnaire, SOC 2 or ISO 27001 reports, a software bill of materials and terms for vulnerability disclosure and incident notification. US registered entities ask under NERC CIP-013. In Germany, a vendor operating in-scope systems for a network operator may need its own certified ISMS. Having these ready shortens the utility’s review.
What does NIS2 mean for vendors selling to Stadtwerke?
NIS2 means in-scope Stadtwerke must manage cyber risk across their suppliers, so vendors selling to Stadtwerke face stricter security checks. Germany’s NIS2 law has applied since 6 December 2025 to about 29,500 entities. It also creates demand for ISMS, OT monitoring and vulnerability management tools, and Stadtwerke have already tendered vulnerability management software.
How do you win Stadtwerke tenders without German energy references?
To win Stadtwerke tenders without German energy references, build a reference programme with the first German customers, partner with an established integrator or start with smaller contracts below the tender threshold. Suitability criteria often ask for recent comparable references and certificates such as ISO 27001, and a vendor without them can be excluded before scoring.
Do cyber incidents at utilities create sales opportunities?
Cyber incidents at utilities do open buying windows: emergency spend on OT security, backup and resilient billing often follows within 6 months, by Panelhop’s estimate, and supplier reviews tighten across the sector. But an OT security pipeline that waits for incidents is erratic. Vendors selling to utilities do better tracking regulatory dates per account between incidents.
How long does it take to sell OT security software to a Stadtwerk?
Selling OT security software to a Stadtwerk takes about 9 months for a tender by Panelhop’s estimate, within a range of 4–18 months. Smaller deals below the tender threshold take about 3 months, by the same estimate. Budget approval alone can take an estimated 3–12 months, unless an incident releases emergency spend. The Stadtwerk’s review of the vendor as a supplier then adds an estimated 1–3 months, so OT security vendors should open it at discovery.
Where the numbers come from.
Sources
Sourced figures link to their source below. Figures marked Illustrative, and figures given as estimates, are inferred from Panelhop research. Vendors appear only as types, never by name.
- BSI (Bundesamt für Sicherheit in der Informationstechnik), Cybersicherheitsrecht: NIS-2-Umsetzungsgesetz ab morgen in Kraft (2025)
- U.S. Environmental Protection Agency, AWIA Section 2013/SDWA Section 1433: Risk and Resilience Assessments and Emergency Response Plans (2026)
- NERC (North American Electric Reliability Corporation), FAQ for Reliability Standard CIP-015-2 (Project 2025-02 Internal Network Security Monitoring) (2025)
- NERC (North American Electric Reliability Corporation), Standards, Compliance, and Enforcement Bulletin, February 2–8, 2026 (2026)
- Panelhop research, October 2026: our analysis of the vendors, buying panels, pipelines and triggers for OT security and cyber compliance in utilities, from public sources. Vendor names are not published.
