Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryOTCompliance

IEC 62443

IEC 62443 is the standard series for the cybersecurity of industrial automation and control systems (IACS). Parts, the three roles, and how it is used in practice.

Updated This page as Markdown

In short

IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems (IACS), developed by ISA99 and IEC TC 65. It addresses three roles, asset owner, system integrator and product supplier, with separate parts: 62443-2-1 for security programmes, 62443-3-2 for risk assessment with zones and conduits, 62443-3-3 for system requirements and security levels, 62443-4-1 for secure development and 62443-4-2 for component requirements.

What is IEC 62443?

IEC 62443 is the series of international standards for the cybersecurity of industrial automation and control systems (IACS): PLCs, DCS, SCADA, HMIs, industrial networks, the machines and plants built from them, and the organisations that operate, integrate and supply them. It started as ISA-99 in the United States and is maintained jointly by the ISA99 committee and IEC Technical Committee 65, which is why you see it written as ISA/IEC 62443. IEC designated it a horizontal standard in 2021, so sector standards build on it instead of reinventing it.

The series is organised around three roles. The asset owner runs the plant and owns the risk. The system integrator designs and commissions the automation solution. The product supplier develops the components. Each role gets its own parts, and the parts fit together: a component’s security capabilities (4-2) are chosen to meet a system’s requirements (3-3), which follow from the risk assessment of the zones (3-2), which the asset owner’s security programme (2-1) demands.

Where is it defined?

IEC publishes the parts; ISA sells the same texts as ANSI/ISA-62443. The ones that matter most:

  • IEC 62443-1-1: terminology, concepts and models, including zones, conduits and security levels.
  • IEC 62443-2-1: requirements for the asset owner’s security programme (revised 2024).
  • IEC 62443-2-4: requirements for integration and maintenance service providers.
  • IEC 62443-3-2 (2020): security risk assessment for system design, the method for partitioning into zones and conduits and assigning target security levels.
  • IEC 62443-3-3 (2013): system security requirements organised under seven foundational requirements, with four security levels.
  • IEC 62443-4-1 (2018): secure product development lifecycle, eight practices from security management to update handling.
  • IEC 62443-4-2 (2019): technical requirements for components (embedded devices, host devices, network devices, software applications).

The seven foundational requirements run through the whole series: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, resource availability.

What it means in practice

IEC 62443 is a toolbox, and the first task is to pick the right parts. What we see in projects with machine builders and plant operators:

  • Machine builders need 4-1 and 4-2, and 3-3 for the machine as a system. Customers increasingly ask for a security level capability per component and a documented development process. The Machinery Regulation (EU) 2023/1230, applicable from 20 January 2027, adds legal pressure with its requirements on protection against corruption (Annex III, 1.1.9).
  • Operators start with 3-2. Partition the plant into zones, define conduits, assign target security levels, then compare with what the installed equipment can do. The gap list is the roadmap.
  • Testing verifies the claims. A component claiming SL 2 under 4-2 should survive a penetration test with the attacker profile of SL 2. We test PLCs, gateways and HMIs against the 4-2 requirements and plant networks against the 3-3 requirements, without downtime where the operator needs it.

Zyberum advises on and tests against IEC 62443. Certification against the series is done by schemes such as IECEE or ISASecure through accredited bodies; we are not one and prepare you for them instead.

Common misunderstandings

IEC 62443 is not one certificate for a plant. There is no “62443-certified factory”; there are certified products (4-2), certified development processes (4-1) and assessed security programmes. It is also not a replacement for ISO 27001: 27001 covers the organisation’s information security management, 62443 the automation systems and their lifecycle.

FAQ

Frequently asked questions

Which parts of IEC 62443 apply to a machine builder?

IEC 62443-4-1 for the development process, 62443-4-2 for the components you build or select, and 62443-3-3 for the machine seen as a system with a security level. Your customers, the asset owners, work with 62443-2-1 and 62443-3-2 and will ask you for the capability level of your machine and its documentation.

Is IEC 62443 mandatory?

Not as such. It is referenced by the Machinery Regulation discussions, by NIS2 guidance and by customers in procurement, and the Cyber Resilience Act covers industrial components as products with digital elements. In practice, operators of critical infrastructure and large manufacturers require it contractually, which makes it mandatory for their suppliers.

Can Zyberum certify my product to IEC 62443?

No. Certification against 62443-4-1 and 62443-4-2 is done by accredited bodies under schemes such as IECEE or ISASecure. Zyberum does the gap analysis, the security level mapping, the penetration test against the requirements and the documentation, so that the certification audit has no surprises.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab