# Security Level (IEC 62443)

> A Security Level (SL) in IEC 62443 describes the strength of attacker a system or component must resist: SL 1 casual or coincidental violation, SL 2 intentional attack with simple means and low resources, SL 3 sophisticated means with moderate resources and IACS-specific skills, SL 4 sophisticated means with extended resources. Levels are set per zone as a target (SL-T), claimed by products as a capability (SL-C) and measured after implementation as achieved (SL-A). They are vectors across seven foundational requirements, not one number.

Security Levels in IEC 62443 rate the attacker a zone or component must withstand, from SL 1 to SL 4. Target, capability and achieved levels (SL-T, SL-C, SL-A).

Source: https://zyberum.com/glossary/security-level-iec-62443 · Updated: 2026-10-07

## What is a Security Level?

A Security Level is IEC 62443's measure for how much protection a zone, system or component provides, expressed as the kind of attacker it is designed to withstand. IEC 62443-3-3 defines four levels, plus SL 0 for no specific requirement:

- **SL 1**: protection against casual or coincidental violation, such as operator mistakes or untargeted malware.
- **SL 2**: protection against intentional violation using simple means with low resources, generic skills and low motivation. The opportunistic attacker with public tools.
- **SL 3**: protection against intentional violation using sophisticated means with moderate resources, IACS-specific skills and moderate motivation.
- **SL 4**: protection against intentional violation using sophisticated means with extended resources, IACS-specific skills and high motivation. State-level capability.

A level is not a single number. Each level is a vector across the seven foundational requirements, for example SL 2 for identification and authentication control but SL 3 for restricted data flow, written as a vector such as (2,2,2,3,3,2,2). Each requirement in 62443-3-3 and 62443-4-2 is marked with the level from which it applies, so a target of SL 2 selects a specific set of requirements and enhancements.

## Where is it defined?

The concept is introduced in IEC 62443-1-1 and made operational in three parts. IEC 62443-3-2 describes how the risk assessment assigns a **target security level (SL-T)** to each zone and conduit. IEC 62443-3-3 lists the system requirements per level and defines the **achieved security level (SL-A)**, measured after the system is built. IEC 62443-4-2 defines the **capability security level (SL-C)** a component can provide when configured correctly, which product certificates attest. The logic is: the zone needs SL-T, the chosen components must offer an SL-C at least as high, and the commissioned system is checked to reach SL-A.

Security levels are different from the **maturity levels** (ML 1 to 4) in IEC 62443-2-4 and 62443-4-1, which rate how well a process is performed, not how strong the technology is.

## What it means in practice

What security levels look like in projects:

- **SL 2 is the usual target, SL 3 for the critical zones.** Most production zones end up at SL 2; safety systems, zones with remote access and zones feeding critical processes often get SL 3. SL 4 is rare, and much legacy equipment cannot reach SL 2 at all.
- **Capability is not achievement.** A PLC with an SL 2 certificate configured with the default password and open Modbus is running at SL 0. SL-A depends on configuration, network design and operation.
- **Compensating controls are allowed.** When a legacy controller cannot meet a requirement, 62443-3-2 lets you meet it at zone or conduit level, for example with an industrial firewall in the conduit. Document it.
- **Testing shows the real level.** We map our OT and component penetration tests to the attacker profile of the target level: at SL 2, public tools and protocol defaults; at SL 3, custom protocol fuzzing, firmware analysis and lateral movement. Where the test succeeds, the achieved level is lower than the target.

## Common misunderstandings

A security level is not a risk rating of the plant, and SL 4 is not "the best": the level follows from the risk assessment, and over-specifying costs money without benefit. A certificate for SL 2 on a component says nothing about the plant it sits in. And levels are per zone, not per company; a single site typically has several.

## FAQ

**Which security level should my plant or product aim for?**

The one the risk assessment under IEC 62443-3-2 produces for each zone. Most production zones end up at SL 2; safety systems, remote access paths and zones feeding critical processes often need SL 3. For a product, ask your customers which target levels their zones have and design the capability (SL-C) to match.

**What is the difference between SL-T, SL-C and SL-A?**

SL-T is the target level a zone or conduit needs, set in the risk assessment. SL-C is the capability a component or system can provide when configured correctly, which is what product certificates attest. SL-A is the level actually achieved in the installed, configured and operated system. A component with SL-C 2 in a badly configured network can have an SL-A of 0.

**Are security levels the same as maturity levels?**

No. Security levels rate the technical protection against an attacker profile. Maturity levels (ML 1 to 4) in IEC 62443-2-4 and 62443-4-1 rate how consistently a process is performed, from initial to improving. A supplier can have a mature process and still ship components with a low capability level, or the reverse.

## Sources

- [IEC 62443-3-3:2013 System security requirements and security levels](https://webstore.iec.ch/en/publication/7033)
- [IEC 62443-3-2:2020 Security risk assessment for system design](https://webstore.iec.ch/en/publication/30727)
- [IEC 62443-4-2:2019 Technical security requirements for IACS components](https://webstore.iec.ch/en/publication/34421)
- [ISA: The ISA/IEC 62443 Series of Standards](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards)

## Related

- [IEC 62443](https://zyberum.com/glossary/iec-62443)
- [Zones and conduits](https://zyberum.com/glossary/zones-and-conduits)
- [PLC (Programmable Logic Controller)](https://zyberum.com/glossary/plc)
- [IEC 62443 vs ISO 27001: Plant Security or Information Security Management?](https://zyberum.com/compare/iec-62443-vs-iso-27001)
- [OT Penetration Testing Without Downtime: How It Is Done](https://zyberum.com/insights/ot-pentest-without-downtime)
- [IEC 62443 for plants that must keep running.](https://zyberum.com/iec-62443)

---
Zyberum GmbH. Canonical page: https://zyberum.com/glossary/security-level-iec-62443
