# OT Coalition Urges CISA to Issue Directive

The Operational Technology Cybersecurity Coalition (OTCC) is urging the Cybersecurity and Infrastructure Security Agency (CISA) to issue a binding operational directive setting minimum operational technology (OT) security requirements for federal civilian agencies. The proposal calls for agencies to inventory and protect OT, assign accountable officials, and apply consistent security practices. The Government Accountability Office found that only 7 of 22 reviewed agencies fully inventoried networked OT and IoT devices. CISA has not announced a directive, solicitation, contract, or funding opportunity, so any procurement impact depends on whether the agency adopts the proposal.

- If adopted, the directive could generate agency demand for OT asset discovery, network segmentation, identity and remote-access controls, configuration management, incident readiness, and backup and recovery services.
- Contractors serving federal civilian agencies can assess how their OT cybersecurity capabilities align with the coalition’s proposed focus areas; the signals identify no procurement timeline or contract value.
- The reported inventory gap indicates a potential implementation need, but the coalition’s request is advocacy—not a current mandatory requirement for agencies or contractors.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 08, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- Government Accountability Office (GAO)
- Office of Management and Budget (OMB)

### Vendors
- Elisity ()

### Key Quotes
> Second, it sends a very strong signal to the private sector that, ‘This is what we think is important: As an OT partner, owner or operator or critical infrastructure owner or operator, [this is what] you should ask other providers to do.’
> — Michael Garcia, Policy Director, Operational Technology Cybersecurity Coalition

> Clear ownership for addressing cybersecurity risks settles in advance how priorities and resource constraints are resolved. A directive can force an agency to put a name on that responsibility, and that alone would do more than another round of guidance.
> — Dave Williams, OT Security Leader, Elisity

> Guidance alone hasn’t closed that gap. A binding operational directive would give every agency a clear, enforceable baseline and give CISA the visibility to make sure it actually gets done.
> — Tatyana Bolton, Executive Director of the Operational Technology Cybersecurity Coalition

### Sources
- [OTCC urges CISA to implement mandatory OT cybersecurity requirements for federal agencies | news | MSSP Alert](https://www.msspalert.com/news/otcc-urges-cisa-to-implement-mandatory-ot-cybersecurity-requirements-for-federal-agencies) - MSSP Alert
- [
		OT Cyber Coalition calls on CISA to issue binding directive establishing federal OT cybersecurity requirements - Industrial Cyber	](https://industrialcyber.co/industrial-cyber-attacks/ot-cyber-coalition-calls-on-cisa-to-issue-binding-directive-establishing-federal-ot-cybersecurity-requirements) - Industrial Cyber
- [Here’s how experts think CISA should tell agencies to protect OT | CyberScoop](https://cyberscoop.com/cisa-ot-cybersecurity-directive) - CyberScoop