Skip to content
Zyberum Cyber Security Firm
Menu
ComparisonsCompliance

IEC 62443 vs ISO 27001: Plant Security or Information Security Management?

ISO 27001 certifies an organisation's security management system. IEC 62443 secures industrial automation, from plant to PLC. Where they overlap and who needs which.

Updated This page as Markdown

In short

ISO/IEC 27001 is a management-system standard: it tells any organisation how to run information security as a process, with a risk assessment, 93 Annex A controls and a worldwide-recognised certificate. IEC 62443 is a family of standards for industrial automation and control systems: it adds what ISO 27001 lacks for plants: zones and conduits, Security Levels, requirements for PLC firmware and secure development at the supplier. Operators of office IT need ISO 27001; operators and makers of machines and plants need IEC 62443, usually in addition. Zyberum helps implement both and tests against them; accredited bodies certify.

What is the difference?

ISO/IEC 27001 describes how an organisation manages information security; IEC 62443 describes how to secure an industrial automation and control system and the components it is built from. The first is one standard, applies to any organisation, and is organised around a management cycle: context, leadership, risk assessment, treatment, Annex A controls, internal audit, management review. The second is a series of standards for a specific domain, organised around roles: the asset owner who runs the plant (62443-2-1), the integrator or service provider who builds and maintains it (2-4), and the product supplier who makes the controllers and software (4-1 for the process, 4-2 for the component), with the system requirements in 3-3 and the risk assessment with zones and conduits in 3-2.

Their protection goals differ. ISO 27001 starts from confidentiality, integrity and availability of information. IEC 62443 starts from the plant: availability and the safety of people and equipment come first, a controller must keep running, and a control that interrupts a process is a risk in itself. That is why IEC 62443 has seven foundational requirements and Security Levels SL 1 to 4 that express how capable an attacker a zone has to withstand, while ISO 27001 leaves the strength of each control to the risk owner.

Side by side

ISO/IEC 27001IEC 62443
What it coversThe information security management system of an organisation: policies, roles, risk assessment, 93 controls in Annex A (organisational, people, physical, technological), continual improvementIndustrial automation and control systems: risk assessment with zones and conduits, Security Levels, technical system and component requirements, secure development lifecycle, security programmes for operators and service providers
What it does not coverTechnical requirements for controllers, field devices and industrial protocols; safety; the specific constraints of plants that cannot be patched or restartedOffice IT, HR processes, legal and contractual controls, the management cycle beyond the plant; it assumes a management system exists
Who is addressedAny organisation, from a software start-up to a hospital to an OEM; often demanded by customers and insurersAsset owners of plants, system integrators, and product suppliers of PLCs, drives, HMIs, industrial software and machines
Implementation timeSix to eighteen months to a certifiable ISMS for a mid-sized companySix to twelve months for a plant risk assessment and segmentation programme; one to two years to bring a product development process to 4-1 and a component to 4-2
Typical costImplementation support 20,000 to 80,000 euros for a mid-sized company, certification audit several thousand to tens of thousands per cycle; typical ranges for Germany and the EU, not an offerPlant risk assessment and OT penetration test 12,000 to 25,000 euros per site; 4-1 process assessment and 4-2 component evaluation often five-figure sums per product; not an offer
Recurring dutiesYearly surveillance audits, recertification every three years, internal audits, management reviewReassessment of zones after changes, patch and vulnerability management per 2-3 and 4-1, re-evaluation of components after major releases
Required byCustomer contracts and tenders, TISAX in automotive (based on ISO 27001 controls), insurers, NIS2 Art. 21 in practice as the recognised way to show a management systemOEM and operator specifications for machines and components, NIS2 for operators of plants in practice, the Machinery Regulation and the CRA via harmonised standards for industrial products
OutputCertificate from an accredited body with a scope statement, statement of applicability, risk registerZone and conduit model with target Security Levels, requirement traceability per 3-3 or 4-2, process evidence per 4-1, and where wanted a certificate per product or process

Choose ISO 27001 when

  • You are an organisation whose risk is in information and IT: software vendor, service provider, engineering office, hospital administration, OEM headquarters. ISO 27001 is the right frame and the one your customers will ask for.
  • Customers, tenders or insurers require a certificate. No IEC 62443 certificate replaces ISO 27001 in a supplier questionnaire.
  • You need a management system that also carries NIS2, TISAX or GDPR duties. ISO 27001 provides the process skeleton; the others add controls.

Choose IEC 62443 when

  • You run a plant, a utility network, a building automation system or a production line. ISO 27001 does not tell you how to segment a Profinet network or what a PLC has to withstand; IEC 62443 does.
  • You build machines, controllers, industrial software or components for them. Customers increasingly specify 62443-4-1 for your process and 4-2 or 3-3 with a Security Level for your product, and the CRA will push in the same direction.
  • You integrate or service plants. IEC 62443-2-4 is written for you, and operators under NIS2 will ask for it.
  • Your risk is availability and safety, not confidentiality. The IEC 62443 risk method and Security Levels map onto that; the ISO 27001 controls do not.

For anyone building or running industrial systems, IEC 62443 is the better choice for the plant and the product, even with an ISO 27001 certificate on the wall.

Both together

The combination is the normal case for an industrial company: ISO 27001 as the management system for the whole organisation, with the plant in scope, and IEC 62443 as the technical standard inside that scope for the OT network and the products. The ISMS risk assessment delegates the plant to a 62443-3-2 assessment; the Annex A controls on access, logging and vulnerability management are implemented in OT following 3-3 and 2-3; and one development process serves both A.8.25 to A.8.29 and IEC 62443-4-1.

Zyberum helps machine builders and operators with IEC 62443 risk assessments, Security Level targets, 4-1 and 4-2 gap analyses and OT penetration tests, and supports ISO 27001 implementations where the plant is in scope. We are not a certification body: audits and certificates come from accredited bodies, and our work is to make sure you pass them and that the plant is secure in reality, not just on paper.

FAQ

Frequently asked questions

We are ISO 27001 certified. Does that cover our production network?

Only if the production network is in the scope of the ISMS and the risk assessment treated it seriously, and even then the Annex A controls say nothing about safety-related availability, 20-year-old controllers that cannot be patched, or protocols without authentication. IEC 62443-3-2 and 3-3 give you the method for exactly that: zones and conduits, a target Security Level per zone and technical requirements that fit a plant. Most plants certified under ISO 27001 have the OT network out of scope or treated as one asset.

Can a company get "IEC 62443 certified"?

Not as a whole. Certifications exist for specific parts and roles: a product supplier's development process against IEC 62443-4-1, a component against 4-2, a system against 3-3, a service provider against 2-4, and an operator's programme against 2-1. Certificates come from accredited bodies under schemes such as IECEE. Zyberum prepares you for these assessments and tests the products and systems, but does not certify.

Which one do NIS2 and the CRA expect?

Neither law names a standard. NIS2 Art. 21 asks for proportionate, state-of-the-art measures, and ISO 27001 is the usual way to show that for the organisation, with IEC 62443 for the plant. The CRA will rely on harmonised standards for products; for industrial components, IEC 62443-4-1 and 4-2 are the obvious candidates, and manufacturers who already follow them will have less to do.

Sources

Related pages

Get started

Not sure which test you need?

Describe your product or environment in a 15-minute call. You get a clear recommendation and, if you want one, a fixed-price offer.

  • A recommendation, not a sales pitch
  • Scope and effort estimate on the spot
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usGet a recommendation

Pick a time that suits you

Open in a new tab