Security Level (IEC 62443)
Security Levels in IEC 62443 rate the attacker a zone or component must withstand, from SL 1 to SL 4. Target, capability and achieved levels (SL-T, SL-C, SL-A).
Updated This page as Markdown
In short
A Security Level (SL) in IEC 62443 describes the strength of attacker a system or component must resist: SL 1 casual or coincidental violation, SL 2 intentional attack with simple means and low resources, SL 3 sophisticated means with moderate resources and IACS-specific skills, SL 4 sophisticated means with extended resources. Levels are set per zone as a target (SL-T), claimed by products as a capability (SL-C) and measured after implementation as achieved (SL-A). They are vectors across seven foundational requirements, not one number.
What is a Security Level?
A Security Level is IEC 62443’s measure for how much protection a zone, system or component provides, expressed as the kind of attacker it is designed to withstand. IEC 62443-3-3 defines four levels, plus SL 0 for no specific requirement:
- SL 1: protection against casual or coincidental violation, such as operator mistakes or untargeted malware.
- SL 2: protection against intentional violation using simple means with low resources, generic skills and low motivation. The opportunistic attacker with public tools.
- SL 3: protection against intentional violation using sophisticated means with moderate resources, IACS-specific skills and moderate motivation.
- SL 4: protection against intentional violation using sophisticated means with extended resources, IACS-specific skills and high motivation. State-level capability.
A level is not a single number. Each level is a vector across the seven foundational requirements, for example SL 2 for identification and authentication control but SL 3 for restricted data flow, written as a vector such as (2,2,2,3,3,2,2). Each requirement in 62443-3-3 and 62443-4-2 is marked with the level from which it applies, so a target of SL 2 selects a specific set of requirements and enhancements.
Where is it defined?
The concept is introduced in IEC 62443-1-1 and made operational in three parts. IEC 62443-3-2 describes how the risk assessment assigns a target security level (SL-T) to each zone and conduit. IEC 62443-3-3 lists the system requirements per level and defines the achieved security level (SL-A), measured after the system is built. IEC 62443-4-2 defines the capability security level (SL-C) a component can provide when configured correctly, which product certificates attest. The logic is: the zone needs SL-T, the chosen components must offer an SL-C at least as high, and the commissioned system is checked to reach SL-A.
Security levels are different from the maturity levels (ML 1 to 4) in IEC 62443-2-4 and 62443-4-1, which rate how well a process is performed, not how strong the technology is.
What it means in practice
What security levels look like in projects:
- SL 2 is the usual target, SL 3 for the critical zones. Most production zones end up at SL 2; safety systems, zones with remote access and zones feeding critical processes often get SL 3. SL 4 is rare, and much legacy equipment cannot reach SL 2 at all.
- Capability is not achievement. A PLC with an SL 2 certificate configured with the default password and open Modbus is running at SL 0. SL-A depends on configuration, network design and operation.
- Compensating controls are allowed. When a legacy controller cannot meet a requirement, 62443-3-2 lets you meet it at zone or conduit level, for example with an industrial firewall in the conduit. Document it.
- Testing shows the real level. We map our OT and component penetration tests to the attacker profile of the target level: at SL 2, public tools and protocol defaults; at SL 3, custom protocol fuzzing, firmware analysis and lateral movement. Where the test succeeds, the achieved level is lower than the target.
Common misunderstandings
A security level is not a risk rating of the plant, and SL 4 is not “the best”: the level follows from the risk assessment, and over-specifying costs money without benefit. A certificate for SL 2 on a component says nothing about the plant it sits in. And levels are per zone, not per company; a single site typically has several.
FAQ
Frequently asked questions
Which security level should my plant or product aim for?
The one the risk assessment under IEC 62443-3-2 produces for each zone. Most production zones end up at SL 2; safety systems, remote access paths and zones feeding critical processes often need SL 3. For a product, ask your customers which target levels their zones have and design the capability (SL-C) to match.
What is the difference between SL-T, SL-C and SL-A?
SL-T is the target level a zone or conduit needs, set in the risk assessment. SL-C is the capability a component or system can provide when configured correctly, which is what product certificates attest. SL-A is the level actually achieved in the installed, configured and operated system. A component with SL-C 2 in a badly configured network can have an SL-A of 0.
Are security levels the same as maturity levels?
No. Security levels rate the technical protection against an attacker profile. Maturity levels (ML 1 to 4) in IEC 62443-2-4 and 62443-4-1 rate how consistently a process is performed, from initial to improving. A supplier can have a mature process and still ship components with a low capability level, or the reverse.
Sources
Related pages
- GlossaryIEC 62443IEC 62443 is the standard series for the cybersecurity of industrial automation and control systems (IACS). Parts, the three roles, and how it is used in practice.
- GlossaryZones and conduitsZones and conduits are the IEC 62443 model for segmenting industrial systems: groups of assets with common security requirements and the controlled links between them.
- GlossaryPLC (Programmable Logic Controller)A PLC is the industrial computer that runs the control logic of a machine or process. How PLCs work, which standards apply and where their security typically fails.
- ComparisonsIEC 62443 vs ISO 27001: Plant Security or Information Security Management?ISO 27001 certifies an organisation's security management system. IEC 62443 secures industrial automation, from plant to PLC. Where they overlap and who needs which.
- InsightsOT Penetration Testing Without Downtime: How It Is DoneHow to test a plant without stopping production: passive analysis, test benches and twins, what belongs in a maintenance window, what is never done on a live plant.
- ServicesIEC 62443 for plants that must keep running.IEC 62443 for operators and manufacturers: risk assessment with zones and conduits, security levels, component tests to 62443-4-2 and secure development.
