ISA/IEC 62443 – Security for Industrial Automation and Control Systems (IACS)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
ISA/IEC 62443 is a series of standards that defines requirements and processes for securing industrial automation and control systems (IACS) throughout their lifecycle. It covers the hardware, software, and networks behind distributed control systems, programmable logic controllers, SCADA, and related operational technology, and it is the only consensus-based cybersecurity standard series developed specifically for automation and control applications.
The series is developed jointly by the ISA99 committee of the International Society of Automation (ISA) and Working Group 10 of IEC Technical Committee 65. ISA publishes each part as ISA-62443-x-y and the International Electrotechnical Commission (IEC) publishes the identical text as IEC 62443-x-y. In 2021 IEC designated the series a horizontal standard, meaning it applies across industries rather than to one sector. It binds through procurement, regulation, and certification: asset owners cite it in requirements, regulators reference it for critical infrastructure, and conformity assessment programs such as ISASecure and IECEE certify against it.
Organizations implement the series according to their role. Asset owners build a security program under IEC 62443-2-1, segment plants into zones and conduits and assign target security levels under IEC 62443-3-2, and specify system requirements from IEC 62443-3-3. Integrators and service providers follow IEC 62443-2-4, while product suppliers adopt the secure development lifecycle in IEC 62443-4-1 and design components to the technical requirements in IEC 62443-4-2.
Why it Matters
Industrial control systems run physical processes where a security failure can mean a safety incident, an environmental release, or a plant outage rather than a data breach alone. IEC 62443 gives asset owners, integrators, and product suppliers one shared set of requirements that respects the realities of operational technology, such as long asset lifetimes and availability-first priorities.
Key benefits include:
- Purpose-built for operational technology
Requirements account for legacy equipment, real-time constraints, and safety interlocks that IT-centric standards do not address.
- Shared responsibility across the supply chain
Separate parts define what asset owners, integrators, and product suppliers must each deliver, so obligations are clear in procurement and contracts.
- Risk-based security levels
Zones, conduits, and security levels SL 1 to SL 4 let organizations match protection to the consequence of compromise instead of applying one blanket standard.
- Regulatory and certification recognition
The series is a horizontal IEC standard referenced by critical infrastructure regulation and certifiable through ISASecure and IECEE programs.
- Lifecycle coverage
Requirements span secure product development, system integration, operation, patching, and maintenance rather than a single point-in-time assessment.
How it Works
The series is organized in four groups. The General group (62443-1-x) defines terminology, concepts, and models. The Policies and Procedures group (62443-2-x) sets program requirements for asset owners (2-1), service providers (2-4), and patch management (2-3). The System group (62443-3-x) covers security technologies (3-1), risk assessment and system design with zones and conduits (3-2), and system security requirements and security levels (3-3). The Component group (62443-4-x) specifies the secure product development lifecycle (4-1) and technical requirements for components (4-2). Seven foundational requirements run through the system and component parts: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability.
Implementation begins with an asset inventory and a risk assessment that partitions the system into zones and conduits and assigns each a target security level. The organization then selects and documents controls to reach that level, establishes the governance, training, and incident response practices required by 62443-2-1, and writes conformance requirements into supplier and integrator contracts. Ongoing activities include patch management, periodic reassessment, and, where certification is sought, audits of products, development processes, or sites by an accredited certification body.
Within SmartSuite, teams maintain the IEC 62443 requirements as a control library organized by part and foundational requirement, record each zone and conduit with its target and achieved security level, and link controls to the assets, suppliers, and owners that satisfy them. Evidence, test results, patch records, and supplier certifications attach to the same records, and dashboards show security-level attainment and open gaps for each zone.
Key Elements
- Zones and conduits
Logical groupings of assets with shared security requirements and the communication channels between them, defined in IEC 62443-3-2 to scope risk and controls.
- Security levels SL 1 to SL 4
Graduated protection targets from casual or coincidental violation up to sophisticated, well-resourced attackers, applied per zone and per component.
- Seven foundational requirements
The requirement categories that structure the system (3-3) and component (4-2) parts, from identification and authentication control to resource availability.
- Asset owner security program (IEC 62443-2-1)
Policy, organizational, and procedural requirements for operating an IACS securely, revised in 2024 with a maturity model for evaluating each requirement.
- System security requirements (IEC 62443-3-3)
Technical control system requirements for each foundational requirement, tiered by capability security level.
- Secure product development lifecycle (IEC 62443-4-1)
Process requirements for suppliers covering security requirements, secure design, implementation, testing, defect management, and update handling.
- Component technical requirements (IEC 62443-4-2)
Security capabilities required of embedded devices, network components, host devices, and software applications used in an IACS.
Framework Scope
IEC 62443 applies to industrial automation and control systems in any sector, including energy and utilities, oil and gas, chemicals, water, manufacturing, transportation, and building automation. It addresses asset owners who operate these systems, integrators and service providers who design and maintain them, and product suppliers who build their components, and it covers the full lifecycle from product development through operation and decommissioning.
Framework Objectives
The series aims to make automation and control systems electronically secure without compromising the safety and availability that industrial operations depend on.
Establish a common vocabulary and model for IACS security shared by owners, integrators, and suppliers.
Require a documented, risk-based security program for asset owners operating industrial systems.
Segment systems into zones and conduits with target security levels proportional to risk.
Define technical security capabilities for systems and components at each security level.
Embed security into product development through a certifiable secure development lifecycle.
Support conformity assessment and certification so that security claims can be independently verified.
Framework in Context
IEC 62443 is the operational technology counterpart to ISO/IEC 27001: many organizations run an ISO/IEC 27001 information security management system for enterprise IT and apply IEC 62443 to plant and control networks. NIST SP 800-82 references it as the primary OT standard, the EU Cyber Resilience Act and NIS2 point toward it for products and essential entities in industrial sectors, NERC CIP and national OT regulations such as Saudi Arabia's OTCC-1 align with its concepts, and the NIST Cybersecurity Framework and NIST SP 800-53 are commonly mapped to it for cross-domain programs.
Common Framework Mappings
IEC 62443 is commonly mapped to enterprise security standards and to sector regulations so that a single OT security program can demonstrate compliance across frameworks.
Mapped frameworks include:
IEC 62443-4-2
ISO 27001:2022
NIST CSF 2.0
NIST 800-53 Rev. 5
NIST 800-82 Rev. 3 Moderate OT
NERC CIP
EU CRA
NIS2 (EU 2022/2555)
OTCC-1:2022
ISO/IEC 27019
- ClassificationCategoryCybersecurityDomainCybersecurityFramework FamilyISO Industry Standards
- Regulatory ContextTypeStandardLegal InstrumentStandardSectorCritical InfrastructureIndustryCritical Infrastructure
- Region / PublisherRegionGlobalRegion DetailInternationalPublisherInternational Electrotechnical Commission (IEC) with the International Society of Automation (ISA)
- VersioningVersionSeries; current parts 2007–2025 (IEC 62443-2-1:2024 latest revision)Effective Date2024 (IEC 62443-2-1 edition 2)Issue Date2007 (IEC TS 62443-1-1)
- AdoptionAdoption ModelIndustry RequirementImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: No
Each part of IEC 62443 is a copyrighted standard purchased from the IEC Webstore or from ISA, and the text is not included with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports IEC 62443 Series
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Teams track zones, conduits, and target security levels alongside the IEC 62443-2-1, 3-3, 4-1, and 4-2 requirements, with supplier certifications and patch records linked to the assets they cover.
IEC 62443 Requirements Library
Hold the requirements of parts 2-1, 2-4, 3-3, 4-1, and 4-2 as structured records grouped by foundational requirement and security level.
Ownership, Cadence, and Accountability
Assign each requirement and each zone to an owner with review dates so security programs stay current across sites.
Evidence Collection and Audit Trail
Attach configuration evidence, test reports, and supplier certificates to requirements with timestamps for certification audits.
Security Level Testing
Record target and achieved security levels per zone and track verification results against IEC 62443-3-3 requirements.
Risk and Supplier Alignment
Link zone risk assessments and supplier or integrator obligations under 62443-2-4 and 4-1 to the controls they support.
OT Security Reporting
Report security-level attainment, open gaps, and patch status by plant, zone, and supplier for leadership and auditors.
Related frameworks

IEC 62443-4-2 specifies technical security requirements for industrial automation and control system components to protect them from cyber threats.

NIST SP 800-82 Rev. 3 (Moderate OT Overlay) guides securing industrial control and operational technology systems with moderate-impact cybersecurity controls.

NERC CIP is a set of cybersecurity and operational standards to protect bulk electric system infrastructure and ensure grid reliability.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

The EU Cyber Resilience Act mandates cybersecurity requirements for products with digital elements sold in the EU to reduce vulnerabilities.

NIS2 establishes mandatory cybersecurity and incident-reporting requirements to strengthen resilience across essential and important EU organizations.
Frequently Asked Questions For IEC 62443 Series
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
