IEC 62443 vs ISO 27001: Plant Security or Information Security Management?
ISO 27001 certifies an organisation's security management system. IEC 62443 secures industrial automation, from plant to PLC. Where they overlap and who needs which.
Updated This page as Markdown
In short
ISO/IEC 27001 is a management-system standard: it tells any organisation how to run information security as a process, with a risk assessment, 93 Annex A controls and a worldwide-recognised certificate. IEC 62443 is a family of standards for industrial automation and control systems: it adds what ISO 27001 lacks for plants: zones and conduits, Security Levels, requirements for PLC firmware and secure development at the supplier. Operators of office IT need ISO 27001; operators and makers of machines and plants need IEC 62443, usually in addition. Zyberum helps implement both and tests against them; accredited bodies certify.
What is the difference?
ISO/IEC 27001 describes how an organisation manages information security; IEC 62443 describes how to secure an industrial automation and control system and the components it is built from. The first is one standard, applies to any organisation, and is organised around a management cycle: context, leadership, risk assessment, treatment, Annex A controls, internal audit, management review. The second is a series of standards for a specific domain, organised around roles: the asset owner who runs the plant (62443-2-1), the integrator or service provider who builds and maintains it (2-4), and the product supplier who makes the controllers and software (4-1 for the process, 4-2 for the component), with the system requirements in 3-3 and the risk assessment with zones and conduits in 3-2.
Their protection goals differ. ISO 27001 starts from confidentiality, integrity and availability of information. IEC 62443 starts from the plant: availability and the safety of people and equipment come first, a controller must keep running, and a control that interrupts a process is a risk in itself. That is why IEC 62443 has seven foundational requirements and Security Levels SL 1 to 4 that express how capable an attacker a zone has to withstand, while ISO 27001 leaves the strength of each control to the risk owner.
Side by side
| ISO/IEC 27001 | IEC 62443 | |
|---|---|---|
| What it covers | The information security management system of an organisation: policies, roles, risk assessment, 93 controls in Annex A (organisational, people, physical, technological), continual improvement | Industrial automation and control systems: risk assessment with zones and conduits, Security Levels, technical system and component requirements, secure development lifecycle, security programmes for operators and service providers |
| What it does not cover | Technical requirements for controllers, field devices and industrial protocols; safety; the specific constraints of plants that cannot be patched or restarted | Office IT, HR processes, legal and contractual controls, the management cycle beyond the plant; it assumes a management system exists |
| Who is addressed | Any organisation, from a software start-up to a hospital to an OEM; often demanded by customers and insurers | Asset owners of plants, system integrators, and product suppliers of PLCs, drives, HMIs, industrial software and machines |
| Implementation time | Six to eighteen months to a certifiable ISMS for a mid-sized company | Six to twelve months for a plant risk assessment and segmentation programme; one to two years to bring a product development process to 4-1 and a component to 4-2 |
| Typical cost | Implementation support 20,000 to 80,000 euros for a mid-sized company, certification audit several thousand to tens of thousands per cycle; typical ranges for Germany and the EU, not an offer | Plant risk assessment and OT penetration test 12,000 to 25,000 euros per site; 4-1 process assessment and 4-2 component evaluation often five-figure sums per product; not an offer |
| Recurring duties | Yearly surveillance audits, recertification every three years, internal audits, management review | Reassessment of zones after changes, patch and vulnerability management per 2-3 and 4-1, re-evaluation of components after major releases |
| Required by | Customer contracts and tenders, TISAX in automotive (based on ISO 27001 controls), insurers, NIS2 Art. 21 in practice as the recognised way to show a management system | OEM and operator specifications for machines and components, NIS2 for operators of plants in practice, the Machinery Regulation and the CRA via harmonised standards for industrial products |
| Output | Certificate from an accredited body with a scope statement, statement of applicability, risk register | Zone and conduit model with target Security Levels, requirement traceability per 3-3 or 4-2, process evidence per 4-1, and where wanted a certificate per product or process |
Choose ISO 27001 when
- You are an organisation whose risk is in information and IT: software vendor, service provider, engineering office, hospital administration, OEM headquarters. ISO 27001 is the right frame and the one your customers will ask for.
- Customers, tenders or insurers require a certificate. No IEC 62443 certificate replaces ISO 27001 in a supplier questionnaire.
- You need a management system that also carries NIS2, TISAX or GDPR duties. ISO 27001 provides the process skeleton; the others add controls.
Choose IEC 62443 when
- You run a plant, a utility network, a building automation system or a production line. ISO 27001 does not tell you how to segment a Profinet network or what a PLC has to withstand; IEC 62443 does.
- You build machines, controllers, industrial software or components for them. Customers increasingly specify 62443-4-1 for your process and 4-2 or 3-3 with a Security Level for your product, and the CRA will push in the same direction.
- You integrate or service plants. IEC 62443-2-4 is written for you, and operators under NIS2 will ask for it.
- Your risk is availability and safety, not confidentiality. The IEC 62443 risk method and Security Levels map onto that; the ISO 27001 controls do not.
For anyone building or running industrial systems, IEC 62443 is the better choice for the plant and the product, even with an ISO 27001 certificate on the wall.
Both together
The combination is the normal case for an industrial company: ISO 27001 as the management system for the whole organisation, with the plant in scope, and IEC 62443 as the technical standard inside that scope for the OT network and the products. The ISMS risk assessment delegates the plant to a 62443-3-2 assessment; the Annex A controls on access, logging and vulnerability management are implemented in OT following 3-3 and 2-3; and one development process serves both A.8.25 to A.8.29 and IEC 62443-4-1.
Zyberum helps machine builders and operators with IEC 62443 risk assessments, Security Level targets, 4-1 and 4-2 gap analyses and OT penetration tests, and supports ISO 27001 implementations where the plant is in scope. We are not a certification body: audits and certificates come from accredited bodies, and our work is to make sure you pass them and that the plant is secure in reality, not just on paper.
FAQ
Frequently asked questions
We are ISO 27001 certified. Does that cover our production network?
Only if the production network is in the scope of the ISMS and the risk assessment treated it seriously, and even then the Annex A controls say nothing about safety-related availability, 20-year-old controllers that cannot be patched, or protocols without authentication. IEC 62443-3-2 and 3-3 give you the method for exactly that: zones and conduits, a target Security Level per zone and technical requirements that fit a plant. Most plants certified under ISO 27001 have the OT network out of scope or treated as one asset.
Can a company get "IEC 62443 certified"?
Not as a whole. Certifications exist for specific parts and roles: a product supplier's development process against IEC 62443-4-1, a component against 4-2, a system against 3-3, a service provider against 2-4, and an operator's programme against 2-1. Certificates come from accredited bodies under schemes such as IECEE. Zyberum prepares you for these assessments and tests the products and systems, but does not certify.
Which one do NIS2 and the CRA expect?
Neither law names a standard. NIS2 Art. 21 asks for proportionate, state-of-the-art measures, and ISO 27001 is the usual way to show that for the organisation, with IEC 62443 for the plant. The CRA will rely on harmonised standards for products; for industrial components, IEC 62443-4-1 and 4-2 are the obvious candidates, and manufacturers who already follow them will have less to do.
Sources
- ISO/IEC 27001:2022 Information security management systems: Requirements
- IEC: Understanding IEC 62443 (overview of the series)
- IEC 62443-3-3:2013 System security requirements and security levels
- IEC 62443-4-1:2018 Secure product development lifecycle requirements
- Directive (EU) 2022/2555 (NIS2), Art. 21 risk-management measures
Related pages
- GlossaryIEC 62443IEC 62443 is the standard series for the cybersecurity of industrial automation and control systems (IACS). Parts, the three roles, and how it is used in practice.
- GlossaryISO/IEC 27001ISO/IEC 27001 is the international standard for an information security management system (ISMS). What it requires, what Annex A covers, where pentests fit in.
- GlossarySecurity Level (IEC 62443)Security Levels in IEC 62443 rate the attacker a zone or component must withstand, from SL 1 to SL 4. Target, capability and achieved levels (SL-T, SL-C, SL-A).
- GlossaryZones and conduitsZones and conduits are the IEC 62443 model for segmenting industrial systems: groups of assets with common security requirements and the controlled links between them.
- ComparisonsISO/SAE 21434 vs IEC 62443: Vehicle or Plant, and What If Your Product Is Both?ISO/SAE 21434 covers cybersecurity engineering for vehicles and ECUs, IEC 62443 covers industrial automation. Differences, overlaps and products that sit in between.
- For your industryCybersecurity for Machine Builders: Machinery Regulation, CRA and IEC 62443What machine builders must do for cybersecurity: Machinery Regulation 2027, Cyber Resilience Act, IEC 62443, the typical attack surface and a sensible first project.
- ServicesIEC 62443 for plants that must keep running.IEC 62443 for operators and manufacturers: risk assessment with zones and conduits, security levels, component tests to 62443-4-2 and secure development.
