Cofferdam product roadmap
What is coming to Cofferdam, and the order it will arrive in. Everything Cofferdam already does is on the Cofferdam page. Weighing it up against NetBox? Read the honest NetBox comparison.
What is coming, in order.
The roadmap runs left to right: in progress now, next, then later.
Select any item for more detail.
Device config drift review
Cofferdam knows the approved baseline for every device it manages and labels any device whose running configuration has moved away from it. The scheduled drift review turns that signal into a queued proposal: the fix is prepared, a person reviews and approves it, and nothing touches a device without that approval. Proposals nobody actions simply expire.
Hardware config vulnerability scanning (beta)
Matches the configuration and firmware details of your industrial hardware against known vulnerabilities and vendor advisories, including CISA KEV and ICS-CERT feeds. Findings land on the asset record next to its configuration history, so you can see what is exposed, where it sits and what changed on it. Everything runs against the inventory Cofferdam already holds; nothing probes your live plant.
External secrets: CyberArk and HashiCorp (beta)
Device credentials no longer need to live in Cofferdam at all. With external secrets, Cofferdam reads credentials from CyberArk or HashiCorp Vault at the moment they are used and never stores them. Your vault stays the single source of truth, with its own audit and rotation policies intact.
Write-back: Modbus TCP, OPC UA, Siemens S7
First-class write-back means Cofferdam can return a device to its approved configuration directly, behind the same two-person approval gate that covers every write. Modbus TCP, OPC UA and Siemens S7 are the first industrial targets.
Write-back: DNP3, IEC 104, EtherNet/IP
The deeper control protocols follow. DNP3 and IEC 104 carry select-before-operate control semantics that demand extra care, and EtherNet/IP platforms are tightly coupled to vendor tooling, so these arrive after the first wave has proven the approval and rollback path end to end.
SOCI CIRMP catalogue
The SOCI CIRMP catalogue maps Cofferdam's evidence collection and traceability matrix to the Security of Critical Infrastructure risk management program. It is the deepest of the seven catalogues Cofferdam ships, and it is delivered.
AESCSF, IEC 62443, NERC CIP catalogues
With SOCI CIRMP delivered, the same treatment moves to AESCSF, IEC 62443 and NERC CIP, framework by framework: each catalogue is worked end to end before it is promoted.
NIST SP 800-82, EU NIS2, OT configuration hardening
NIST SP 800-82, EU NIS2 and the OT configuration hardening catalogue complete the set, following the same path as the catalogues ahead of them.
HPE OneView integration (beta)
Connects Cofferdam to HPE OneView and pulls your server hardware inventory into the estate automatically, so racks reflect the iron that is actually in them. Alongside the inventory, it collects performance metrics such as power draw and temperature onto the same asset records, putting live readings next to each server's configuration history.
ServiceNow CMDB integration
Cofferdam's asset records and the ServiceNow CMDB describe the same estate, so they should agree. This integration syncs racks, devices and their relationships into ServiceNow configuration items and reads back what ServiceNow already knows, keeping change tickets and incident context pointed at hardware that actually exists. Where the two sides disagree, Cofferdam surfaces the difference instead of silently overwriting either one.
SAP S/4HANA Asset Management integration (beta)
For estates where SAP S/4HANA is the system of record for physical assets, this integration lines Cofferdam's hardware inventory up with the SAP asset master: serial numbers, locations and lifecycle status stay consistent between the plant documentation and the ERP.