Customer Evaluation Checklist¶
This checklist turns a product demonstration into a structured industrial evaluation. It is intended for joint use by the asset owner, operations, control engineering, maintenance, OT cybersecurity, and deployment teams.

Figure — Evaluation checklist aligns to Raymon operations and assurance capabilities.
Industrial scope¶
- Representative plant area and use case are identified.
- Equipment, controllers, masters, outstations, PLCs, RTUs, or IEDs are identified.
- Consequential points, registers, commands, values, and sequences are documented.
- Normal, maintenance, startup, recovery, and emergency behavior is understood.
- Local process interlocks and safety responsibilities are documented separately.
Users and access¶
- Human, vendor, engineering, service, and machine identities in scope are identified.
- Required equipment and operations are assigned to each role or user.
- The approved access period and source context are defined.
- L2Proxy Connect or standalone enforcement is selected for each path.
- Required North-South and East-West flows and protected access domains are documented.
- Every consequential inter-domain flow crosses an identified enforcement point.
- Session closure and access revocation responsibilities are agreed.
Protocol and policy qualification¶
- Required protocol portfolio and parser coverage are confirmed.
- Equipment and point mappings are verified against representative traffic.
- Record, Allow, and Block behavior is approved for each policy outcome.
- Stateful timing, replay, duplicate, timeout, and recovery behavior is tested where applicable.
- Normal and violation test cases are retained as regression evidence.
Operations and resilience¶
- Traffic direction, capacity, latency expectations, and deployment topology are confirmed.
- Segmentation default policy, communication exceptions, and lateral-movement containment are approved.
- Failure posture, bypass, rollback, and recovery procedures are approved.
- Policy owner, service owner, and change-approval authority are named.
- Monitoring is completed before blocking where operational risk requires it.
- Connect and standalone service health responsibilities are assigned.
Evidence and integration¶
- Required user, session, equipment, operation, verdict, and metadata fields are agreed.
- Event retention, partitioning, backup, access, and deletion requirements are defined.
- Normalized event terminology is reviewed by operations and engineering.
- Investigation, reporting, SIEM, or long-term evidence integrations are identified.
- Sensitive identity and industrial asset information is handled under customer policy.
Acceptance decision¶
| Decision | Owner | Required evidence |
|---|---|---|
| Industrial use case accepted | Asset owner / operations | Approved scope and operating assumptions |
| Equipment model accepted | Control or protection engineering | Verified points, limits, commands, and mappings |
| Policy accepted | Operations and OT cybersecurity | Reviewed normal and violation outcomes |
| Deployment accepted | Network and service owner | Topology, performance, resilience, and rollback evidence |
| Production activation approved | Change authority | Completed tests, ownership, monitoring, and support plan |
Continue with Capability Status and Product Boundaries.