top of page
Image by Evgeni Tcherkasski

OT Cybersecurity Engineer — Certified Professional License

A professional license for experienced practitioners who engineer defensible, measurable, and reviewable cybersecurity for operational technology and cyber-physical systems

What is the CPL?

The OT Cybersecurity Engineer Certified Professional License

What the license represents

The OTE CPL recognizes experienced practitioners who can translate operational mission, physical-process consequences, safety and reliability constraints, cybersecurity risk, and credible threats into defensible architectures, engineering requirements, security controls, validation criteria, and recovery capabilities for operational technology and industrial cyber-physical systems.

A professional who earns this license can define OT system boundaries; establish asset and dependency baselines; model industrial levels, zones, conduits, trust boundaries, data flows, and remote-access paths; analyze cyber-physical risk; engineer segmentation, identity, secure administration, hardening, monitoring, and recovery controls; coordinate changes with operations, controls, safety, maintenance, integrators, and suppliers; and verify that protections work within operational constraints.

The license represents the demonstrated ability to make and explain sound OT cybersecurity engineering decisions, connect requirements to implementation and evidence, document trade-offs and residual risk, and communicate clearly with technical, operational, safety, and business stakeholders. The occupational scope aligns directly with the NICE Operational Technology Cybersecurity Engineering Work Role DD-WRL-009 and is evaluated through ISAUnited's D10S evidence discipline.

What Will I Receive?

Your Professional Licensing Certification

Your certification is the official record that you have satisfied the qualification and assessment requirements for the OT Cybersecurity Engineer CPL. It displays your name, professional designation, issue date, and unique License ID.

The license is valid for three years and can be independently verified through the ISAUnited public credential registry at

/isaunited-verify-credentials

CPL-OT ENG_cert_pic.png

Your CPCA Professional Stamp

The personalized OTE Stamp is a professional mark issued to each license holder. It identifies the holder by name and signifies demonstrated capability to analyze, design, integrate, validate, sustain, and communicate cybersecurity protections for operational technology and cyber-physical systems.

Authorized use of the CPCA Stamp

The OTE Stamp may be applied to OT cybersecurity architecture packages, system-context and consequence profiles, zones-and-conduits diagrams, remote-access and segmentation designs, engineering control and traceability plans, verification and validation records, resilience and recovery plans, technical reports, and engineering decision memoranda prepared, reviewed, or approved by the license holder within the holder's authorized role.

Use of the stamp signifies professional accountability for the OT cybersecurity engineering work and adherence to ISAUnited licensing requirements and its Code of Ethics. It does not constitute professional-engineering licensure, organizational or regulatory approval, control-room or plant-operating authority, process-safety or electrical authorization, acceptance of risk, or permission to change a live facility unless the responsible organization has separately granted that authority.

CPL-OT_stamp_blk_pic.png

Who is this CPL For?

Designed for Experienced Practitioners

The OTE CPL is intended for cybersecurity, automation, controls, industrial-network, and technology professionals who design, review, integrate, validate, or guide cybersecurity for operational environments. Candidates do not need to already hold the title of OT Cybersecurity Engineer, but should have a strong technical foundation and practical experience with OT or industrial systems, security architecture, cyber-physical risk, engineering controls, change coordination, validation, resilience, and technical decision-making.

NOTE: The CPL is a professional-level credential and is not intended as an entry-level cybersecurity certification.

OT Cybersecurity and ICS Security Engineers
 

Professionals responsible for engineering, integrating, validating, or sustaining cybersecurity across industrial control systems and other operational technologies.

Collaborative Computer Work

Controls Automation and Industrial Network Professionals

Controls engineers, automation specialists, system integrators, industrial network engineers, and related practitioners whose work includes secure architecture, access, communications, lifecycle change, or recovery.

Architects Reviewing Plans

Senior Cybersecurity Engineers Architects and Technical Leaders

Experienced enterprise cybersecurity practitioners moving into OT or already responsible for industrial architecture, secure integration, remote access, control selection, technical reviews, and implementation guidance.

Image by Firosnv. Photography

Industrial Cybersecurity Specialists Consultants and Program Leads

Practitioners who assess, improve, or govern cybersecurity across energy, water, manufacturing, oil and gas, transportation, buildings, life sciences, food and agriculture, mining, defense, space, and other cyber-physical environments

Office employee

Why Should I Earn it?

Demonstrate Applied OT Cybersecurity Engineering Capabilities

The OTE gives experienced professionals a way to demonstrate that they can perform OT cybersecurity engineering work in a realistic Cyber Capstone. It recognizes applied judgment - how you interpret physical-process consequences, define boundaries, analyze cyber-physical risk, engineer zones and conduits, protect remote access, select controls, coordinate operational change, plan validation and recovery, and communicate residual risk - not just knowledge recall.

Demonstrate Applied Capability

Show that you can analyze, design, integrate, validate, sustain, and communicate OT cybersecurity through connected professional work products and defensible evidence.

 

Strengthen Your Professional Credibility

Use the OTE designation and professional stamp to identify your demonstrated OT cybersecurity engineering capability, judgment, and accountability.

 

Make Your Achievement Verifiable

Give employers, clients, asset owners, and professional peers a unique License ID they can confirm through the ISAUnited public credential registry.

 

Support Your Career Development

Document your readiness for OT cybersecurity engineering, ICS security engineering, industrial cyber architecture, critical-infrastructure consulting, technical assurance, and OT security leadership opportunities.

How Can I Earn It?

Two ways to earn your license.

Earn CPL

Path 1 — Attend ISAU Academy (recommended)

Learn the method, then earn the license:

  1. Enroll in the Pro Bundle (course + ebook + one evaluation)

  2. Complete the self-paced modules (knowledge checks; non-heavy)

  3. Submit your capstone portfolio (principles, models, methods in use)

  4. Panel review & decision (up to 14 days for course completion)

NOTE: 20 CPEs awarded automatically for course completion.

Path 2 — Direct Evaluation (for experienced practitioners)

Already fluent in the concepts and methods? Bypass the course and go straight to the cyber capstone portfolio:

  • Brief eligibility check (experience + example artifacts)

  • Cyber Capstone portfolio submission and panel review

  • Same license, same stamp, same public verification

NOTE: 0 (zero) CPEs will be awarded for not completing the course.

What Is the CPL Assessment?

A Cyber Capstone Completed Through FlexCert 30

The certification exam isn't a traditional multiple-choice, memorization-based test. Instead, you complete a real-world, scenario-based Cyber Capstone that reflects the work cybersecurity practitioners do.

You will analyze a realistic organization and technical environment, identify security requirements and design risks, develop a secure architecture, recommend risk remediation, explain your design decisions and trade-offs, and define how to validate the architecture.

What You Will Submit

Your Cyber Capstone includes five connected professional work artifacts:

  1. Architecture Context and Requirements Brief

  2. Threat Model and Design Risk Analysis

  3. Target Security Architecture Package

  4. Security Design Rationale and Implementation Guidance

  5. Architecture Validation and Executive Decision Brief

 

Complete It Through FlexCert 30

FlexCert 30 is the remote, independent format for completing your Cyber Capstone. You receive a controlled professional scenario, instructions, and submission templates, then have 30 days to develop and submit your work.

 

Complete the assessment on your own schedule without traveling to a testing center, scheduling a fixed examination appointment, or participating in live remote proctoring.

Thirty days. Independent completion. Your schedule.

How Will I Be Evaluated?

Your Cyber Capstone Artifacts Work Is the Evidence

Trained evaluators review your five Cyber Capstone artifacts as one connected architecture submission. The evaluation considers whether your requirements, threat analysis, architecture models, security controls, design decisions, validation approach, and professional communication are clear, technically sound, and consistent.

Part 1 — Technical Artifact Evaluation

This section determines whether you have passed the technical requirements of the Cyber Capstone.

 

Evaluators assess:

  • Architecture context and security requirements

  • Architecture models, data flows, and trust boundaries

  • Threat modeling and design risk analysis

  • Security patterns and control placement

  • Design decisions, trade-offs, and risk remediation

  • Technical feasibility and implementation guidance

  • Validation criteria and professional communication

Part 2 — Professional Capability Profile

We also use your submission to develop a separate Skills, Knowledge, and Abilities Capability Profile. This evidence-based profile evaluates your professional reasoning, technical judgment, disciplined practice, problem-solving, and communication across seven capability dimensions.

 

The profile shows how you performed, where you demonstrated strength, and where continued professional development may be beneficial.

 

 

Your Evaluation Outcome

After the review is completed, you receive a Defensible Capability Score Report containing your technical results, professional capability profile, evaluator findings, and licensing decision.

Candidates who successfully satisfy the technical and professional requirements are awarded the CPCA License and entered into the public credential registry.

Image by Bench Accounting

Ready to Demonstrate Your OTE Capability?

bottom of page