Skip to content
Zyberum Cyber Security Firm
Menu

IEC 62443

IEC 62443 for plants that must keep running.

The standard for industrial cybersecurity has parts for operators, integrators and manufacturers. We help you find the parts that apply to you, implement them without stopping production, and test whether they hold.

  • Operators: 62443-2-1, 3-2, 3-3
  • Manufacturers: 62443-4-1, 4-2
  • Tested in the lab, not in production

In short

IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems. It defines requirements for plant operators (62443-2-1, 3-2, 3-3), system integrators (2-4, 3-3) and component manufacturers (4-1 for secure development, 4-2 for component requirements), and uses zones, conduits and security levels SL 1 to SL 4. Zyberum provides risk assessments, gap analyses, component security tests and secure development processes according to IEC 62443.

For operators

Securing a running plant

Risk assessment (3-2)

Asset inventory, zones and conduits, and target security levels for each zone.

Segmentation (3-3)

Network architecture, firewalls and remote access designed so an office incident stays in the office.

Security programme (2-1)

Roles, patching, backup, incident handling and supplier requirements for the plant.

For manufacturers

Building secure components

Component testing (4-2)

Penetration tests of devices, firmware and interfaces against the component requirements and your target security level.

Secure development (4-1)

Threat modelling, secure coding, security testing and vulnerability handling in your development process.

Secure development

CRA readiness

IEC 62443-4-1 and 4-2 cover much of what the Cyber Resilience Act demands from industrial products.

CRA compliance

How we work

Safe for production

Industrial systems run for decades and must not fail. We use passive analysis on live systems, agree every active test with your operations team, and move attacks that could cause trouble into the lab or a maintenance window.

You get measures ordered by their effect on safety and availability, not by chapter number.

  • PLCs, RTUs, HMIs, SCADA and DCS
  • Profinet, Modbus, OPC UA, S7
  • Remote maintenance and IIoT gateways
  • Evidence for NIS2 and customer audits

FAQ

IEC 62443 FAQ

Which part of IEC 62443 applies to us?

Operators start with 62443-2-1 and 3-2. System integrators work with 2-4 and 3-3. Manufacturers of components need 4-1 for their development process and 4-2 for the product requirements.

What are security levels?

Security levels SL 1 to SL 4 describe the strength of attacker a zone or component must resist, from casual misuse (SL 1) to attackers with extensive resources and specific knowledge (SL 4).

Can a component be certified?

Yes, by accredited certification bodies under schemes such as IECEE or ISASecure. We prepare you: gap analysis, fixes and a test against the requirements before the certification lab sees the product.

Get started

One hour on IEC 62443 for your plant or product, free

We clarify which parts of the standard apply to you and what the sensible first step is.

  • Operator, integrator or manufacturer: what applies
  • Your target security level and the gap to it
  • First steps that do not interrupt production
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usFree IEC 62443 consultation

Pick a time that suits you

Open in a new tab