BLOG

Author
Denrich Sananda

Date
23-07-2026

Industrial Cybersecurity

How to Choose a Data Diode Vendor: A Buyer's Guide for OT and ICS

Selecting a data diode vendor looks straightforward until the evaluation begins. Every supplier claims hardware enforced one way transfer, and at the level of the marketing material the products appear interchangeable. They are not. The differences that determine whether a deployment succeeds sit in areas that are easy to overlook during a first pass: the assurance level of the diode core, the breadth of native protocol support, the realistic throughput under your actual data profile, and whether anyone will answer the phone when a transfer stops at two in the morning.

This guide sets out the criteria that matter when choosing a data diode vendor for an OT or ICS environment, along with the questions worth putting to every supplier on your shortlist.

 

Why Vendor Choice Matters More Than It Appears

A data diode is not a commodity appliance. It sits at one of the most consequential boundaries in the facility, it is expected to run for a decade or more, and replacing it once deployed is disruptive. Three practical realities make the choice consequential:

  • The diode is only part of the product. The hardware enforces direction, but the proxies and application connectors determine whether your specific data actually crosses successfully. Two products with identical hardware can differ enormously in how much engineering effort deployment requires.
  • Assurance levels are not equivalent. A device certified to a recognised standard by an independent body carries a different weight in an audit than one whose one way claim rests on vendor assertion alone.
  • Support becomes the deciding factor over time. Once the appliance is in production, the relationship that matters is the one that responds when something changes in your environment.

 

Criterion 1: Certification and Assurance Level

Independent certification is the clearest way to distinguish genuine hardware enforcement from a software product marketed as unidirectional. Ask which certifications the diode core itself holds, not the surrounding software or the company's quality management system.

Certifications worth asking about include Common Criteria evaluation with a stated Evaluation Assurance Level, national scheme approvals such as ANSSI certification in France, and NATO approval for defence contexts. The relevant question is not simply whether a certificate exists but what precisely was evaluated and to what level.

Match the assurance level to your risk. A facility protecting a safety instrumented system or operating within critical national infrastructure has a stronger case for the highest evaluated levels than a site exporting production metrics for reporting purposes. Paying for assurance you do not need is a waste; discovering you needed it during an audit is worse.

 

Question to ask

Which certification does the diode hardware itself hold, at what assurance level, and can you provide the certification report rather than a summary?

 

Criterion 2: Protocol and Application Support

This is where deployments most often go wrong, and it is the criterion that separates a two week installation from a six month project.

A data diode cannot pass a normal TCP session, so every supported data flow requires an application aware proxy on each side. If the vendor has already built a connector for your historian, your control system, and your protocols, the deployment is a configuration exercise. If they have not, someone has to develop and validate it, and that work sits on your project timeline.

Build a list of every data flow you intend to send across the boundary before contacting vendors, and check each one specifically. Typical requirements include:

  • Plant historian replication, for example between PI systems or to a cloud historian
  • Control system data from platforms such as Emerson, Honeywell, Yokogawa, Siemens, or GE
  • OPC UA and OPC DA
  • Modbus TCP and other industrial protocols in use at the site
  • Syslog and security event forwarding to a SIEM or SOC platform
  • File and folder transfer, including scheduled batch exports
  • Database replication for reporting
  • Video streams where surveillance data crosses the boundary

Ask each vendor to confirm which of your flows are supported by an existing, deployed connector, which would need configuration work, and which would need new development. The answers will separate the shortlist quickly.

 

Criterion 3: Throughput and Headroom

Data diode appliances are typically offered in throughput tiers ranging from around one gigabit per second up to twenty five gigabits per second and beyond. Selecting a tier is not simply a matter of matching today's average volume.

Consider peak rather than average load, since batch exports, historian backfills after an outage, and video streams create bursts well above the steady state. Consider growth as well, because a diode installed today is likely to still be in service when the site has added instrumentation, expanded monitoring, or begun sending data to an analytics platform. Reasonable headroom at the point of purchase is far cheaper than replacing the appliance in three years.

Ask vendors for throughput figures measured with the proxy layer active and with a data profile resembling yours, not raw optical link capacity. The two numbers can differ substantially.

 

Criterion 4: Hardware Enforcement, Verified

Some products described as data diodes enforce direction in software or firmware rather than in hardware. These may be adequate for lower risk boundaries, but they do not offer the property that makes a diode valuable, which is that the return path cannot exist regardless of software state.

Ask the vendor to explain specifically how directionality is enforced at the component level. In a genuine hardware enforced diode, the answer describes an optical arrangement in which the transmit side has no receiver and the receive side has no transmitter. Our article on how a data diode works covers this design and the protocol break it creates.

 

Red flag

If a vendor cannot clearly explain which physical component is absent from each side of the device, treat the one way claim as unverified until they can.

 

Criterion 5: Deployment, Integration, and Operational Fit

The best specified appliance still has to work inside your plant. Practical considerations that shape day to day experience include:

  • Form factor and environment. Rack space, power draw, thermal profile, and whether the device is rated for the physical conditions where it will sit.
  • High availability. Whether redundant pairs are supported, and how failover behaves for in flight transfers.
  • Monitoring and alerting. Since the receive side cannot acknowledge, you need clear visibility that expected data is arriving and prompt alerting when a stream stops. Ask how this integrates with your existing monitoring tools.
  • Management interface. How the appliance is configured and maintained, and whether management access itself introduces a path you need to secure.
  • Change handling. What is involved when a new data flow needs to be added after go live, which will happen.

 

Criterion 6: Support Model and Local Presence

Support is routinely underweighted during evaluation and routinely decisive afterwards. Establish clearly who you will actually be dealing with once the purchase is complete.

Questions worth answering before signing: Is support provided by the manufacturer directly or through a partner? What are the guaranteed response times, and do they cover the hours your plant operates? Is there engineering capability in your region or does every escalation cross several time zones? Who performs commissioning, and are they familiar with industrial environments rather than only with the product?

For operators in North America in particular, a supplier with local delivery and engineering presence removes a meaningful category of project risk, both during deployment and across the service life of the appliance.

 

Criterion 7: Compliance and Standards Alignment

Your diode deployment will eventually be examined by an auditor. Ask each vendor how their product supports the frameworks that apply to you, whether that is IEC 62443 zone and conduit requirements, NERC CIP, NIS2, or sector specific directives. Our regulatory playbooks cover these frameworks and what they require at network boundaries.

A capable vendor will be able to explain how the appliance supports a Security Level 3 or Security Level 4 conduit and what documentation they provide to evidence it. A vendor who has not encountered these questions before is telling you something useful about their experience in industrial environments.

 

Vendor Evaluation Checklist

Use these questions with every supplier on your shortlist. Ask for written answers, since the differences between vendors become much clearer on paper.

Area

Question to ask

Certification

Which certification does the diode hardware hold, at what assurance level, and can you share the report?

Enforcement

Which physical component is absent from each side of the device to prevent reverse flow?

Protocols

Which of our specific data flows are supported by an existing deployed connector today?

Throughput

What throughput is achieved with the proxy layer active on a data profile like ours?

Availability

Are redundant pairs supported, and what happens to in flight data during failover?

Monitoring

How do we confirm data is arriving, and how does alerting integrate with our existing tools?

Deployment

Who performs commissioning, and what is the realistic timeline for our flow list?

Change

What is involved in adding a new data flow after go live, and what does it cost?

Support

Who provides support, in which region, with what guaranteed response times?

Lifecycle

What is the expected product lifespan and the committed security support period?

Compliance

How does the product support IEC 62443 Security Level 3 or 4 conduits, and what evidence do you provide?

 

Warning Signs During Evaluation

  • The vendor cannot describe the physical enforcement mechanism in specific terms
  • Throughput figures are quoted for the optical link rather than measured through the proxy layer
  • Protocol support is described as available rather than as already deployed at other sites
  • No independent certification exists for the diode core itself
  • Support is routed entirely through a distributor with no engineering capability in your region
  • The vendor has no experience with the compliance framework that applies to your sector

 

Frequently Asked Questions

How much does a data diode cost?

Pricing varies considerably with throughput tier, assurance level, redundancy, and the number of application connectors required. Because these are configured to the deployment, most vendors quote against a defined requirement rather than publishing list prices. Preparing your data flow list and throughput requirement before approaching vendors will produce far more comparable quotes.

How long does a data diode deployment take?

Where the vendor already has connectors for your systems, deployment is typically a matter of weeks including commissioning and validation. Where new connector development is required, timelines extend substantially, which is why the protocol support question should be settled early.

Can one data diode serve multiple data flows?

Yes. A single appliance normally carries several concurrent flows, for example historian replication, syslog forwarding, and scheduled file transfer, provided the aggregate throughput sits within the appliance's capacity and connectors exist for each flow.

Should we buy from the manufacturer or a regional partner?

Either can work well. What matters is where the engineering capability sits. A regional partner with genuine deployment and support expertise often delivers a better outcome than a distant manufacturer relationship, particularly for commissioning and ongoing change work.

 

Where Arista Cyber Fits

Arista Cyber delivers, deploys, and supports the OWA data diode appliance range across North America, built around a certified optical diode core with native connectors for the industrial systems already installed in most plants. We combine OT cybersecurity and functional safety expertise, which matters where diodes protect boundaries around safety instrumented systems.

If you are earlier in the process, our explanation of what a data diode is covers the fundamentals, and our comparison of data diodes and firewalls sets out where each control belongs in an industrial architecture.

 

Evaluating data diode vendors?

Bring us your data flow list and we will tell you honestly what is straightforward and what is not.

Explore OWA Data Diode Appliances