{"uid":"cap_v-Ib9-PIpw44t8k2X3Gm4","slug":"ot-compliance-batch-gap-assessment-e4d1fa15","name":"OT Compliance Batch Gap Assessment","description":"Aggregate compliance-gap assessment across multiple CVEs/actors in one call. Pass items=<comma-separated, max 25> (auto-detects CVE vs actor), optional framework=<value>, entity_sector=<ENERGY|WATER|TRANSPORTATION|GOVERNMENT>. Dedupes triggered controls into one compliance_gap_severity (HIGH/MEDIUM/LOW/CLEAN) plus a remediation summary. Same compliance_mappings data as /ot/compliance — deterministic lookup, LLM only writes prose. Cheaper than N individual calls for batch triage.","url":"https://ot-intel-api.onrender.com/ot/compliance/batch","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["items"],"properties":{"items":{"type":"string","description":"Comma-separated list of CVE IDs and/or actor names, max 25, e.g. CVE-2023-38802,CVE-2024-12345,SANDWORM,XENOTIME. Each token auto-detected as a CVE ID (matches CVE-\\d{4}-\\d+) or treated as an actor name otherwise. Required."},"framework":{"type":"string","description":"Optional filter to one compliance framework. Valid values: nerc_cip, iec_62443_2_1, iec_62443_2_4, iec_62443_3_2, iec_62443_3_3, iec_62443_4_2, nist_800_82, nist_csf, cisa_cpg, nca_otcc, uae_nesa_ia. Omit (or pass 'all') to return matches across every framework."},"entity_sector":{"type":"string","description":"Optional: ENERGY, WATER, TRANSPORTATION, or GOVERNMENT. Informs the remediation summary's tone/priority framing only — does not filter which controls match."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.2","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.2/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_2MQpDZZgcSnJ_0qaFkOtN","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.2","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a single aggregated compliance-gap assessment across up to 25 CVEs and/or threat actors, returning deduplicated control gaps and a remediation summary across OT/ICS security frameworks.","exampleAgentPrompt":"Run a batch compliance gap assessment for CVE-2023-38802, CVE-2024-12345, and SANDWORM against the IEC 62443-3-3 framework for the energy sector — give me the overall severity and a remediation summary.","exampleUseCases":[{"title":"Multi-CVE compliance posture check","prompt":"I've got a list of five critical OT vulnerabilities affecting our water treatment facility—can you run a batch assessment against NIST 800-82 and tell me the overall compliance gap severity plus what controls we need to fix?"},{"title":"SOC triage for mixed threat actors","prompt":"We're tracking SANDWORM, HEXANE, and three related CVEs across our energy infrastructure. Run a single compliance check against NERC CIP to see what our combined risk profile looks like and what remediation steps matter most."},{"title":"Industrial sector compliance snapshot","prompt":"Give me one aggregated compliance gap report for CVE-2024-21111, CVE-2024-19987, CVE-2023-38802, and the RUSSIANOOLIGAN actor group—I need the overall severity under IEC 62443 for our transportation network and a plain-English summary of what we have to address."}],"resultDescription":"Returns a deduplicated compliance_gap_severity rating (HIGH/MEDIUM/LOW/CLEAN), a list of triggered compliance controls across requested frameworks, and an LLM-written remediation summary prose tailored to the specified sector. Deterministic control mappings with AI-generated narrative.","failureModes":["More than 25 items passed — API rejects with an error","Invalid CVE format causes item to be misclassified as an actor name","Unknown framework value returns an error or empty results","Invalid entity_sector value causes a validation error","Empty items parameter returns a required-field error","Network timeout on Render cold-start (free-tier hosting latency spike)"],"whenToPreferThis":"Use this endpoint when you need to assess compliance gaps for multiple CVEs or threat actors in a single call, saving cost and latency compared to N individual /ot/compliance calls. Prefer it for bulk triage workflows, SOC automation pipelines, or whenever you have a list of 2–25 mixed CVE IDs and actor names and want a single aggregated severity rating and remediation summary.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:56:04.425Z","isFirstParty":false}