Cybersecurity
DETAIL

ISA/IEC 62443 – Security for Industrial Automation and Control Systems (IACS)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

ISA/IEC 62443 is a series of standards that defines requirements and processes for securing industrial automation and control systems (IACS) throughout their lifecycle. It covers the hardware, software, and networks behind distributed control systems, programmable logic controllers, SCADA, and related operational technology, and it is the only consensus-based cybersecurity standard series developed specifically for automation and control applications.

The series is developed jointly by the ISA99 committee of the International Society of Automation (ISA) and Working Group 10 of IEC Technical Committee 65. ISA publishes each part as ISA-62443-x-y and the International Electrotechnical Commission (IEC) publishes the identical text as IEC 62443-x-y. In 2021 IEC designated the series a horizontal standard, meaning it applies across industries rather than to one sector. It binds through procurement, regulation, and certification: asset owners cite it in requirements, regulators reference it for critical infrastructure, and conformity assessment programs such as ISASecure and IECEE certify against it.

Organizations implement the series according to their role. Asset owners build a security program under IEC 62443-2-1, segment plants into zones and conduits and assign target security levels under IEC 62443-3-2, and specify system requirements from IEC 62443-3-3. Integrators and service providers follow IEC 62443-2-4, while product suppliers adopt the secure development lifecycle in IEC 62443-4-1 and design components to the technical requirements in IEC 62443-4-2.

Why it Matters

Industrial control systems run physical processes where a security failure can mean a safety incident, an environmental release, or a plant outage rather than a data breach alone. IEC 62443 gives asset owners, integrators, and product suppliers one shared set of requirements that respects the realities of operational technology, such as long asset lifetimes and availability-first priorities.

Key benefits include:

  • Purpose-built for operational technology

Requirements account for legacy equipment, real-time constraints, and safety interlocks that IT-centric standards do not address.

  • Shared responsibility across the supply chain

Separate parts define what asset owners, integrators, and product suppliers must each deliver, so obligations are clear in procurement and contracts.

  • Risk-based security levels

Zones, conduits, and security levels SL 1 to SL 4 let organizations match protection to the consequence of compromise instead of applying one blanket standard.

  • Regulatory and certification recognition

The series is a horizontal IEC standard referenced by critical infrastructure regulation and certifiable through ISASecure and IECEE programs.

  • Lifecycle coverage

Requirements span secure product development, system integration, operation, patching, and maintenance rather than a single point-in-time assessment.

How it Works

The series is organized in four groups. The General group (62443-1-x) defines terminology, concepts, and models. The Policies and Procedures group (62443-2-x) sets program requirements for asset owners (2-1), service providers (2-4), and patch management (2-3). The System group (62443-3-x) covers security technologies (3-1), risk assessment and system design with zones and conduits (3-2), and system security requirements and security levels (3-3). The Component group (62443-4-x) specifies the secure product development lifecycle (4-1) and technical requirements for components (4-2). Seven foundational requirements run through the system and component parts: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability.

Implementation begins with an asset inventory and a risk assessment that partitions the system into zones and conduits and assigns each a target security level. The organization then selects and documents controls to reach that level, establishes the governance, training, and incident response practices required by 62443-2-1, and writes conformance requirements into supplier and integrator contracts. Ongoing activities include patch management, periodic reassessment, and, where certification is sought, audits of products, development processes, or sites by an accredited certification body.

Within SmartSuite, teams maintain the IEC 62443 requirements as a control library organized by part and foundational requirement, record each zone and conduit with its target and achieved security level, and link controls to the assets, suppliers, and owners that satisfy them. Evidence, test results, patch records, and supplier certifications attach to the same records, and dashboards show security-level attainment and open gaps for each zone.

Key Elements

  • Zones and conduits

Logical groupings of assets with shared security requirements and the communication channels between them, defined in IEC 62443-3-2 to scope risk and controls.

  • Security levels SL 1 to SL 4

Graduated protection targets from casual or coincidental violation up to sophisticated, well-resourced attackers, applied per zone and per component.

  • Seven foundational requirements

The requirement categories that structure the system (3-3) and component (4-2) parts, from identification and authentication control to resource availability.

  • Asset owner security program (IEC 62443-2-1)

Policy, organizational, and procedural requirements for operating an IACS securely, revised in 2024 with a maturity model for evaluating each requirement.

  • System security requirements (IEC 62443-3-3)

Technical control system requirements for each foundational requirement, tiered by capability security level.

  • Secure product development lifecycle (IEC 62443-4-1)

Process requirements for suppliers covering security requirements, secure design, implementation, testing, defect management, and update handling.

  • Component technical requirements (IEC 62443-4-2)

Security capabilities required of embedded devices, network components, host devices, and software applications used in an IACS.

Framework Scope

IEC 62443 applies to industrial automation and control systems in any sector, including energy and utilities, oil and gas, chemicals, water, manufacturing, transportation, and building automation. It addresses asset owners who operate these systems, integrators and service providers who design and maintain them, and product suppliers who build their components, and it covers the full lifecycle from product development through operation and decommissioning.

Framework Objectives

The series aims to make automation and control systems electronically secure without compromising the safety and availability that industrial operations depend on.

Establish a common vocabulary and model for IACS security shared by owners, integrators, and suppliers.

Require a documented, risk-based security program for asset owners operating industrial systems.

Segment systems into zones and conduits with target security levels proportional to risk.

Define technical security capabilities for systems and components at each security level.

Embed security into product development through a certifiable secure development lifecycle.

Support conformity assessment and certification so that security claims can be independently verified.

Framework in Context

IEC 62443 is the operational technology counterpart to ISO/IEC 27001: many organizations run an ISO/IEC 27001 information security management system for enterprise IT and apply IEC 62443 to plant and control networks. NIST SP 800-82 references it as the primary OT standard, the EU Cyber Resilience Act and NIS2 point toward it for products and essential entities in industrial sectors, NERC CIP and national OT regulations such as Saudi Arabia's OTCC-1 align with its concepts, and the NIST Cybersecurity Framework and NIST SP 800-53 are commonly mapped to it for cross-domain programs.

Common Framework Mappings

IEC 62443 is commonly mapped to enterprise security standards and to sector regulations so that a single OT security program can demonstrate compliance across frameworks.

Mapped frameworks include:

IEC 62443-4-2

ISO 27001:2022

NIST CSF 2.0

NIST 800-53 Rev. 5

NIST 800-82 Rev. 3 Moderate OT

NERC CIP

EU CRA

NIS2 (EU 2022/2555)

OTCC-1:2022

ISO/IEC 27019

At a Glance
ISA/IEC 62443 – Security for Industrial Automation and Control Systems (IACS)
  • Classification
    Category
    Cybersecurity
    Domain
    Cybersecurity
    Framework Family
    ISO Industry Standards
  • Regulatory Context
    Type
    Standard
    Legal Instrument
    Standard
    Sector
    Critical Infrastructure
    Industry
    Critical Infrastructure
  • Region / Publisher
    Region
    Global
    Region Detail
    International
    Publisher
    International Electrotechnical Commission (IEC) with the International Society of Automation (ISA)
  • Versioning
    Version
    Series; current parts 2007–2025 (IEC 62443-2-1:2024 latest revision)
    Effective Date
    2024 (IEC 62443-2-1 edition 2)
    Issue Date
    2007 (IEC TS 62443-1-1)
  • Adoption
    Adoption Model
    Industry Requirement
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: No

Each part of IEC 62443 is a copyrighted standard purchased from the IEC Webstore or from ISA, and the text is not included with the platform.

Framework text is licensed by its publisher and is included only where stated above.

SMARTSUITE

How SmartSuite Supports IEC 62443 Series

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

Teams track zones, conduits, and target security levels alongside the IEC 62443-2-1, 3-3, 4-1, and 4-2 requirements, with supplier certifications and patch records linked to the assets they cover.

IEC 62443 Requirements Library

Hold the requirements of parts 2-1, 2-4, 3-3, 4-1, and 4-2 as structured records grouped by foundational requirement and security level.

Ownership, Cadence, and Accountability

Assign each requirement and each zone to an owner with review dates so security programs stay current across sites.

Evidence Collection and Audit Trail

Attach configuration evidence, test reports, and supplier certificates to requirements with timestamps for certification audits.

Security Level Testing

Record target and achieved security levels per zone and track verification results against IEC 62443-3-3 requirements.

Risk and Supplier Alignment

Link zone risk assessments and supplier or integrator obligations under 62443-2-4 and 4-1 to the controls they support.

OT Security Reporting

Report security-level attainment, open gaps, and patch status by plant, zone, and supplier for leadership and auditors.

Related frameworks

IEC 62443-4-2

IEC 62443-4-2 specifies technical security requirements for industrial automation and control system components to protect them from cyber threats.

NIST 800-82 Rev.3 Moderate OT

NIST SP 800-82 Rev. 3 (Moderate OT Overlay) guides securing industrial control and operational technology systems with moderate-impact cybersecurity controls.

NERC CIP

NERC CIP is a set of cybersecurity and operational standards to protect bulk electric system infrastructure and ensure grid reliability.

ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

EU CRA

The EU Cyber Resilience Act mandates cybersecurity requirements for products with digital elements sold in the EU to reduce vulnerabilities.

NIS2 (EU 2022/2555)

NIS2 establishes mandatory cybersecurity and incident-reporting requirements to strengthen resilience across essential and important EU organizations.

OTCC-1:2022

OTCC-1:2022 defines cybersecurity controls to protect operational technology systems and critical industrial infrastructure in Saudi Arabia.

NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

ONBOARDING FAQS

Frequently Asked Questions For IEC 62443 Series

No items found.

Operationalize IEC 62443 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.