Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryOT

Security Level (IEC 62443)

Security Levels in IEC 62443 rate the attacker a zone or component must withstand, from SL 1 to SL 4. Target, capability and achieved levels (SL-T, SL-C, SL-A).

Updated This page as Markdown

In short

A Security Level (SL) in IEC 62443 describes the strength of attacker a system or component must resist: SL 1 casual or coincidental violation, SL 2 intentional attack with simple means and low resources, SL 3 sophisticated means with moderate resources and IACS-specific skills, SL 4 sophisticated means with extended resources. Levels are set per zone as a target (SL-T), claimed by products as a capability (SL-C) and measured after implementation as achieved (SL-A). They are vectors across seven foundational requirements, not one number.

What is a Security Level?

A Security Level is IEC 62443’s measure for how much protection a zone, system or component provides, expressed as the kind of attacker it is designed to withstand. IEC 62443-3-3 defines four levels, plus SL 0 for no specific requirement:

  • SL 1: protection against casual or coincidental violation, such as operator mistakes or untargeted malware.
  • SL 2: protection against intentional violation using simple means with low resources, generic skills and low motivation. The opportunistic attacker with public tools.
  • SL 3: protection against intentional violation using sophisticated means with moderate resources, IACS-specific skills and moderate motivation.
  • SL 4: protection against intentional violation using sophisticated means with extended resources, IACS-specific skills and high motivation. State-level capability.

A level is not a single number. Each level is a vector across the seven foundational requirements, for example SL 2 for identification and authentication control but SL 3 for restricted data flow, written as a vector such as (2,2,2,3,3,2,2). Each requirement in 62443-3-3 and 62443-4-2 is marked with the level from which it applies, so a target of SL 2 selects a specific set of requirements and enhancements.

Where is it defined?

The concept is introduced in IEC 62443-1-1 and made operational in three parts. IEC 62443-3-2 describes how the risk assessment assigns a target security level (SL-T) to each zone and conduit. IEC 62443-3-3 lists the system requirements per level and defines the achieved security level (SL-A), measured after the system is built. IEC 62443-4-2 defines the capability security level (SL-C) a component can provide when configured correctly, which product certificates attest. The logic is: the zone needs SL-T, the chosen components must offer an SL-C at least as high, and the commissioned system is checked to reach SL-A.

Security levels are different from the maturity levels (ML 1 to 4) in IEC 62443-2-4 and 62443-4-1, which rate how well a process is performed, not how strong the technology is.

What it means in practice

What security levels look like in projects:

  • SL 2 is the usual target, SL 3 for the critical zones. Most production zones end up at SL 2; safety systems, zones with remote access and zones feeding critical processes often get SL 3. SL 4 is rare, and much legacy equipment cannot reach SL 2 at all.
  • Capability is not achievement. A PLC with an SL 2 certificate configured with the default password and open Modbus is running at SL 0. SL-A depends on configuration, network design and operation.
  • Compensating controls are allowed. When a legacy controller cannot meet a requirement, 62443-3-2 lets you meet it at zone or conduit level, for example with an industrial firewall in the conduit. Document it.
  • Testing shows the real level. We map our OT and component penetration tests to the attacker profile of the target level: at SL 2, public tools and protocol defaults; at SL 3, custom protocol fuzzing, firmware analysis and lateral movement. Where the test succeeds, the achieved level is lower than the target.

Common misunderstandings

A security level is not a risk rating of the plant, and SL 4 is not “the best”: the level follows from the risk assessment, and over-specifying costs money without benefit. A certificate for SL 2 on a component says nothing about the plant it sits in. And levels are per zone, not per company; a single site typically has several.

FAQ

Frequently asked questions

Which security level should my plant or product aim for?

The one the risk assessment under IEC 62443-3-2 produces for each zone. Most production zones end up at SL 2; safety systems, remote access paths and zones feeding critical processes often need SL 3. For a product, ask your customers which target levels their zones have and design the capability (SL-C) to match.

What is the difference between SL-T, SL-C and SL-A?

SL-T is the target level a zone or conduit needs, set in the risk assessment. SL-C is the capability a component or system can provide when configured correctly, which is what product certificates attest. SL-A is the level actually achieved in the installed, configured and operated system. A component with SL-C 2 in a badly configured network can have an SL-A of 0.

Are security levels the same as maturity levels?

No. Security levels rate the technical protection against an attacker profile. Maturity levels (ML 1 to 4) in IEC 62443-2-4 and 62443-4-1 rate how consistently a process is performed, from initial to improving. A supplier can have a mature process and still ship components with a low capability level, or the reverse.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab