AuditXYZ

Compliance Framework

IEC 62443 Series: Industrial Automation and Control Systems Security (IEC 62443)

IEC 62443 is the global standard for industrial automation and control system cybersecurity. This guide covers security levels, zones and conduits, roles, certification, and OT security implementation.

$75,000–$750,0006–18 monthsAudit Required2024 (ongoing updates to individual parts)
Issuing BodyInternational Electrotechnical Commission (IEC) / ISA
First Published2009-01-01
Latest Version2024 (ongoing updates to individual parts)
Typical Cost$75,000–$750,000
Typical Timeline6–18 months
Audit RequiredYes
Audit FrequencyCertification by accredited bodies (e.g., ISASecure, TUV). Recertification periods depend on the specific part and certification scheme.
Geographyglobal

IEC 62443: Industrial Automation Cybersecurity Guide

IEC 62443 is the comprehensive international standard series for cybersecurity of Industrial Automation and Control Systems (IACS). Applicable across all industrial sectors including manufacturing, energy, water treatment, transportation, and building automation, IEC 62443 provides a defense-in-depth framework that addresses security requirements for asset owners, system integrators, and component suppliers throughout the industrial system lifecycle. As OT/IT convergence accelerates and industrial cyberattacks multiply, IEC 62443 has become the essential reference for anyone responsible for securing operational technology.

What IEC 62443 Is and Who Issues It

IEC 62443 is published jointly by the International Electrotechnical Commission (IEC) and ISA (International Society of Automation, formerly the Instrumentation, Systems, and Automation Society). The standard series consolidates and builds on ISA-99 standards originally developed by ISA's Industrial Automation and Control Systems Security Committee.

The standard series addresses a fundamental challenge in industrial cybersecurity: traditional IT security frameworks and practices are insufficient for OT environments where system availability and safety take precedence over confidentiality, where proprietary protocols and legacy equipment create unique vulnerabilities, and where the physical consequences of a security failure can be catastrophic. IEC 62443 was designed by industrial security practitioners specifically for this environment.

Regulatory uptake of IEC 62443 is accelerating globally. The EU's NIS2 Directive and the EU Cyber Resilience Act (CRA) reference IEC 62443 for OT and critical infrastructure operators. US CISA has referenced IEC 62443 in its guidance for industrial control system security. Many industrial customers now contractually require IEC 62443 conformance from system integrators and component suppliers, effectively making it a market requirement in sectors from pharmaceuticals to oil and gas.

Who Needs IEC 62443 Compliance

IEC 62443 applies to three primary roles in the industrial ecosystem, and the applicable standard parts differ by role.

Asset owners (factories, utilities, process plants, critical infrastructure operators) use IEC 62443 to establish and manage IACS security programs. Their primary reference is the Part 2 series (policies and procedures) and Part 3 series (system requirements). Asset owners define target security levels for their systems and are responsible for ensuring their systems achieve and maintain those levels.

System integrators (engineering companies, systems integrators, automation specialists) use IEC 62443 to design and deploy secure industrial systems. Their primary reference is Part 3-2 (security risk assessment for system design) and Part 3-3 (system security requirements and security levels). Integrators must design systems that achieve the target security levels specified by asset owners.

Component suppliers (PLC manufacturers, SCADA software vendors, industrial network equipment makers, industrial IoT device makers) use IEC 62443 to develop secure products. Their primary reference is Part 4-1 (secure product development lifecycle requirements) and Part 4-2 (technical security requirements for IACS components).

As OT cybersecurity regulations tighten globally, IEC 62443 compliance is increasingly mandated by industrial customers and regulators. Pharmaceutical manufacturers subject to FDA 21 CFR Part 11 increasingly reference IEC 62443 for manufacturing systems. Oil and gas operators globally are requiring IEC 62443 conformance from automation system suppliers. The EU Cyber Resilience Act will require IEC 62443-4-1 compliance for connected industrial products sold in Europe.

Key Requirements: Zones, Conduits, and Security Levels

The most distinctive and important concepts in IEC 62443 are zones and conduits, and the associated security levels.

Zones are groupings of IACS assets that share common security requirements. Every asset in an industrial system must be assigned to a zone based on its criticality, connectivity, and risk profile. Zones are defined by the asset owner during risk assessment and represent logical security boundaries — not necessarily physical boundaries.

Conduits are logical groupings of assets that enable communication between zones. A conduit represents data flows crossing zone boundaries. Every inter-zone communication must be managed through a conduit with appropriate security controls (firewalls, deep packet inspection, data diodes, encrypted tunnels depending on the security level requirement).

Security Levels (SL 1–4) quantify the security capability required for zones and conduits.

SL 1 protects against casual or coincidental violations — typically unintentional human errors or simple equipment malfunctions. This is the baseline level for most industrial zones.

SL 2 protects against intentional violation using simple means — a low-sophistication attacker using publicly available tools and techniques with limited resources. Most industrial environments that connect to enterprise networks should target at least SL 2.

SL 3 protects against sophisticated attack using moderate resources — a skilled attacker with moderate resources using IACS-specific knowledge. This level applies to systems where a successful attack could cause significant physical harm or major operational disruption.

SL 4 protects against state-level attacks using extended resources — a nation-state or equivalent attacker with extensive resources, IACS-specific expertise, and motivation for catastrophic impact. SL 4 is reserved for the most critical national infrastructure.

The distinction between Target Security Level (SL-T) and Achieved Security Level (SL-C) is important. SL-T is what the asset owner determines the zone requires based on risk assessment. SL-C is what the system, integrator's work, or component actually achieves. The goal is SL-C meeting or exceeding SL-T.

Foundational Requirements (FRs) define seven security requirement categories that apply at each security level: identification and authentication control (IAC), use control (UC), system integrity (SI), data confidentiality (DC), restricted data flow (RDF), timely response to events (TRE), and resource availability (RA). Each FR has a set of requirements that become more stringent at higher security levels.

The Standard Series Structure

Part 1 (General) covers concepts, models, and terminology. Part 1-1 defines the models; Part 1-2 provides a master glossary; Part 1-3 covers system security compliance metrics; Part 1-4 addresses the IACS security lifecycle and use cases.

Part 2 (Policies and Procedures) addresses the security management system for asset owners. Part 2-1 specifies requirements for establishing a security program. Part 2-3 covers patch management for IACS environments. Part 2-4 specifies security requirements for IACS service providers.

Part 3 (System) covers system-level security requirements. Part 3-2 addresses security risk assessment and provides the methodology for defining zones, conduits, and target security levels. Part 3-3 defines the system security requirements (the FRs mapped to security levels).

Part 4 (Component) covers product-level security. Part 4-1 specifies secure product development lifecycle requirements for component suppliers. Part 4-2 defines technical security requirements for IACS components mapped to security levels.

The Certification Process

Certification under IEC 62443 is available through several schemes.

ISASecure is the most widely recognized industrial cybersecurity certification scheme, operating through the ISCI (ISA Security Compliance Institute). ISASecure offers certifications for component suppliers (Component Security Assurance — CSA), system integrators (System Security Assurance — SSA), and the secure development lifecycle (Security Development Lifecycle Assurance — SDLA).

TUV (including TUV SUD, TUV Rheinland, TUV Nord) offers IEC 62443 assessments and certification for both products and organizations. TUV certifications are widely recognized particularly in European industrial markets.

exida specializes in functional safety and cybersecurity for process industries, offering IEC 62443 certification services.

The certification process involves a gap assessment against the applicable IEC 62443 parts, remediation of identified gaps, and a formal assessment by the certification body. For component suppliers, Part 4-1 certification (secure development lifecycle) is typically pursued first and enables more efficient Part 4-2 (component security requirements) certification subsequently.

Costs and Timeline

RoleEstimated CostTimeline
Component supplier (Part 4-1 SDLA)$75K–$200K6–12 months
Component supplier (Part 4-2 product cert.)$50K–$150K per product4–9 months
System integrator (SSA)$100K–$300K8–15 months
Asset owner (security program, no cert.)$150K–$750K12–18 months

Costs scale significantly with the number of product lines (for suppliers), the scope of systems (for integrators), and the size and complexity of the industrial environment (for asset owners).

NERC CIP (approximately 55% overlap) is the mandatory compliance framework for North American electric utilities. IEC 62443 and NERC CIP address similar OT security concerns but from different angles: NERC CIP is sector-specific and prescriptive; IEC 62443 is global and risk-based. Many utilities use IEC 62443 as the engineering framework underlying their NERC CIP compliance program.

ISO 27001 (approximately 40% overlap) addresses IT security management broadly. IEC 62443 addresses OT security specifically — the lower overlap reflects fundamentally different security requirements for operational technology versus information technology. Organizations often maintain separate compliance programs for their IT (ISO 27001) and OT (IEC 62443) environments.

ISO 21434 (approximately 45% overlap) addresses automotive cybersecurity engineering and shares the secure development lifecycle concepts of IEC 62443 Part 4-1, with meaningful cross-pollination between automotive and industrial cybersecurity standards.

How Automation Helps

IEC 62443 compliance generates ongoing operational requirements — security event monitoring, patch management tracking, access review documentation, vulnerability assessment records, and zone/conduit change management. Automation makes sustained compliance manageable.

LowerPlane supports IEC 62443 compliance management as part of its 50+ framework library. Its policy management, risk assessment tracking, and evidence collection capabilities are particularly valuable for asset owners managing the documentation requirements of Part 2-1 (security program) and Part 3-2 (risk assessment). Starting at $4,000 per year with a free tier. AuditXYZ rated LowerPlane 9.4/10.

Frequently Asked Questions

What is the difference between IEC 62443 and ISA-99? ISA-99 is the original ISA committee designation for the industrial cybersecurity standard series. The standards developed by ISA-99 were adopted by IEC as IEC 62443. The two designations refer to the same standards — ISA-99 is the development name and IEC 62443 is the published standard designation. When practitioners refer to "ISA/IEC 62443," they are using both designations for the same document series.

Do all four security levels apply to every industrial environment? No. Most industrial environments target SL 1 or SL 2 for the majority of their zones. SL 3 is appropriate for systems controlling processes where compromise could cause significant physical harm. SL 4 is reserved for the most critical national infrastructure. The risk assessment process (Part 3-2) determines appropriate target security levels for each zone based on the potential consequences of compromise.

How does IEC 62443 address legacy equipment that cannot be patched? Legacy systems without patching capability are a reality in industrial environments. IEC 62443 addresses this through compensating controls: network segmentation (restricting communication to and from the legacy system to only what is necessary), application whitelisting where the system can support it, enhanced monitoring of traffic to/from the legacy system, and physical access controls. The zone and conduit model is specifically designed to enable security even when individual components cannot be secured to current standards.

Is IEC 62443 applicable to building automation systems? Yes. Building automation and management systems — HVAC control, lighting control, access control, elevator management — are IACS within the scope of IEC 62443. Smart building systems have become increasingly attractive attack targets, and IEC 62443 provides a framework for securing them systematically.

How does the EU Cyber Resilience Act (CRA) affect IEC 62443? The EU CRA (effective 2024, with compliance obligations phasing in through 2027) requires manufacturers of connected products — including industrial devices — to meet cybersecurity requirements throughout the product lifecycle. IEC 62443-4-1 (secure product development lifecycle) is explicitly referenced as a standard that can demonstrate conformance with CRA requirements. Component suppliers selling connected products in Europe should prioritize Part 4-1 certification as a CRA readiness measure.

Request a IEC 62443 consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

NERC CIPMedium55%
NIST CSFMedium50%
ISO 27001Low40%

Get matched with a IEC 62443 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.