TroutTrout

Find the parts of IEC 62443 that apply to you. Most of the series is written for vendors and integrators.

The series has more than a dozen documents in four groups. Which ones apply depends on your role: you operate a plant, integrate one, or build the equipment. This guide covers the structure, security levels, zones and conduits, and what certification proves.

Last updated:

What is IEC 62443?

IEC 62443 is a series of international standards for securing industrial automation and control systems. The ISA99 committee developed it, and IEC and ISA publish it jointly as ISA/IEC 62443. The series has four groups: general concepts, policies and procedures for the operator, system-level requirements, and component-level requirements for products. Security is a shared responsibility across three roles. You split a plant into zones linked by conduits. Then you give each zone a target security level based on its risk.

That structure is why generic advice about the standard is usually useless. A plant operator, a system integrator and a PLC vendor each answer to different parts of the series, and the requirements are not interchangeable.

The series

Four groups of documents, each for a different role.

Document numbers follow the pattern 62443-X-Y, where X is the group. Knowing the group tells you immediately whether a document is your problem.

Group
62443-1-x
Covers
Terminology, concepts and models. The shared vocabulary the rest of the series depends on.
Written for
Everyone, once.
The parts you will actually meet
1-1 concepts and models.
Group
62443-2-x
Covers
Policies and procedures. How the operating organisation runs a security programme, and what it demands of service providers.
Written for
Asset owners and service providers.
The parts you will actually meet
2-1 security programme, 2-4 requirements for service providers.
Group
62443-3-x
Covers
System-level security. Risk assessment, zone and conduit design, and the technical requirements a whole control system must meet.
Written for
Asset owners and system integrators.
The parts you will actually meet
3-2 risk assessment and zone design, 3-3 system security requirements and security levels.
Group
62443-4-x
Covers
Component-level security. How a product is developed securely, and what technical capabilities the product itself must provide.
Written for
Product suppliers.
The parts you will actually meet
4-1 secure development lifecycle, 4-2 technical requirements for components.
THE SERIES AT A GLANCE1-xGENERAL1-1 Concepts and models1-2 Master glossary1-3 System conformance metrics1-4 Lifecycle and use cases2-xPOLICIES2-1 Security programme2-2 Programme ratings2-3 Patch management2-4 Service provider reqs3-xSYSTEM3-1 Security technologies3-2 Risk, zones, conduits3-3 System security reqs4-xCOMPONENT4-1 Secure development4-2 Component security reqsNUMBERING IS 62443-GROUP-PART. THE GROUP TELLS YOU WHOSE PROBLEM IT IS.

If you operate a plant, 3-2 and 3-3 are the two you will spend real time in. 4-2 matters to you only as a procurement filter: it is the part you cite when asking a vendor what their device can actually do.

Shared responsibility

Three roles share the security work.

The series does not put security on a single party. Most confusion comes from reading a requirement written for one role as if it applied to another.

Asset owner

The organisation that operates the plant. Owns the security programme, the risk assessment, the zone and conduit design, and the target security levels. Answers primarily to 2-1, 3-2 and 3-3.

System integrator

Whoever designs and commissions the control system. Has to deliver a system that meets the security level the asset owner set, and to work within the zone design rather than around it. Answers to 2-4 and 3-3.

Product supplier

The vendor of the PLC, drive, switch or software. Has to develop securely under 4-1 and ship components whose capabilities meet 4-2. Cannot be made responsible for how the product is deployed.

This split is why a device advertised as 62443-certified does not make a plant compliant, and why a plant cannot be compliant purely by buying certified equipment. The parts address different questions and neither substitutes for the other.

Security levels

SL 0 to SL 4 are set by attacker capability.

Security levels are often misread as a maturity score for the organisation. Each level is defined by the capability of the attacker it must stop. You assign one level per zone, and a site has several zones.

Level
SL 0
Protects against
No specific requirement.
Adversary profile
No protection is claimed for the zone.
Level
SL 1
Protects against
Casual or coincidental violation.
Adversary profile
An operator error, a misrouted cable, an accident. No intent.
Level
SL 2
Protects against
Intentional violation using simple means.
Adversary profile
Low resources, generic skills, low motivation. Opportunistic, commodity malware.
Level
SL 3
Protects against
Intentional violation using sophisticated means.
Adversary profile
Moderate resources, ICS-specific skills, moderate motivation. Someone who understands your protocols.
Level
SL 4
Protects against
Intentional violation using sophisticated means with extended resources.
Adversary profile
Extended resources, ICS-specific skills, high motivation. Effectively a state-level actor.

The distinction that decides whether an audit goes well

The standard separates SL-T, the target level you assign a zone from its risk, from SL-C, the level a component or system is capable of, and SL-A, the level actually achieved once it is deployed and configured. Most estates have a documented SL-T and no measured SL-A, and the gap between them is where findings come from. Buying an SL 3 capable device and deploying it with defaults gives you SL-C 3 and SL-A 1.

THE GAP AN ASSESSMENT FINDSSL 0SL 1SL 2SL 3SL 4SL-T TARGETassigned to the zone from risk3SL-C CAPABLEwhat the component could do3SL-A ACHIEVEDwhat the deployment actually delivers1THIS DELTA IS THE FINDINGAN SL 3 CAPABLE DEVICE DEPLOYED WITH DEFAULTS ON A FLAT NETWORK GIVES YOU SL-C 3 AND SL-A 1.CERTIFICATION ANSWERS THE MIDDLE BAR. ONLY DEPLOYMENT ANSWERS THE BOTTOM ONE.
Zones and conduits

How zones and conduits work.

Zones and conduits are the core of 62443-3-2. They are the part that most directly changes what a network looks like. A zone groups assets that share a security level requirement. A conduit is the controlled path between two zones, and you design it on purpose.

Zones are drawn by risk, not by function

This is the most common mistake, and it is why Purdue levels are only a first draft of a zone model. Two devices at the same level, on the same VLAN, doing the same kind of work, belong in different zones if a compromise of one has consequences the other does not carry.

Every conduit is explicit and documented

If two zones communicate, that path is a conduit with a stated purpose, a stated protocol set, and controls of its own. A path nobody designed is not a conduit, it is a finding.

Conduits carry a security level too

A conduit between two SL 3 zones has to be capable of SL 3. A high-integrity zone reached over an undefended path is not a high-integrity zone; it is a well-documented assumption.

Safety systems are their own zone, always

A safety instrumented system shares no zone with basic process control, regardless of how the network is wired. This is one of the few places the standard is close to prescriptive.

ZONES, CONDUITS, AND THE PATHS NOBODY DESIGNEDENTERPRISE ZONESL 1ERPMAILOFFICE ITOPERATIONS ZONESL 2HISTORIANMESENG WSCONTROL ZONESL 3PLCHMIDRIVESSAFETY ZONESL 3SISSAFETY PLCCONDUITCONDUITCONDUITVENDOR VPN · ENTERPRISE STRAIGHT TO CONTROLNOT A CONDUIT. NOBODY DESIGNED IT, SO NOTHING GOVERNS IT.A CONDUIT BETWEEN TWO SL 3 ZONES MUST ITSELF BE CAPABLE OF SL 3.A PATH NOBODY DESIGNED IS NOT A CONDUIT. IT IS A FINDING.

The design work is not usually the obstacle. Most teams can draw a defensible zone model in a workshop. The obstacle is enforcing it on a plant where re-addressing equipment means downtime nobody will authorise.

Certification

What IEC 62443 certification proves.

Certification against 62443 is real, but it covers narrower things than its marketing suggests. Three separate things get certified, and people often confuse them.

Product certification

A component or system is assessed against 4-2 or 3-3 and its development process against 4-1. Schemes include ISASecure and IECEE. This proves the product is capable of a security level. It says nothing about your plant.

Process certification

A supplier's or integrator's development or service process is assessed, typically under 4-1 or 2-4. This proves the organisation works in a defined way, not that any given deployment is secure.

Personnel certification

Individuals pass ISA's certificate programme, for example the risk assessment or design specialist tracks. This is a qualification for a person, not for a site.

There is no plant certificate

An operating site is not certified against 62443 the way a factory is certified against ISO 9001. Asset owners demonstrate conformity through assessment against 2-1, 3-2 and 3-3, usually via a third-party audit against a defined scope. Anyone offering to certify your plant is describing an assessment.

On cost, the honest answer is that the question hides three different budgets: buying the documents from IEC or ISA, paying for an assessment, and the remediation the assessment finds. The third is almost always the largest by a wide margin, and it is the one that is never quoted.

In context

How IEC 62443 relates to other frameworks.

These are often presented as alternatives. They answer different questions, and most regulated operators use more than one.

Framework
ISO/IEC 27001
What it governs
An information security management system. Organisational, information-centric, certifiable for an organisation.
Relationship to 62443
Complementary, not competing. 27001 governs how you manage security; 62443 governs the technical and procedural specifics of an industrial control system. A 27001-certified company can run a plant with no 62443 controls at all.
Framework
NIST CSF 2.0
What it governs
A voluntary framework of outcomes across govern, identify, protect, detect, respond, recover.
Relationship to 62443
Higher level and sector-neutral. CSF tells you which outcomes to pursue; 62443 tells you what that means for an IACS specifically. They map cleanly onto each other.
Framework
NIST SP 800-82r3
What it governs
Guidance for securing operational technology, published by NIST for a mostly US audience.
Relationship to 62443
Closest in subject matter. 800-82r3 explicitly references 62443 and reads as guidance where 62443 reads as requirements. Many teams use 800-82 to understand and 62443 to specify.
Framework
NERC CIP
What it governs
Mandatory, enforceable regulation for the North American bulk electric system.
Relationship to 62443
Regulation with penalties, scoped to one sector. 62443 is voluntary and cross-sector. Utilities in scope for CIP often use 62443 concepts to organise work CIP then audits.
Where Access Gate fits

Enforce zones without redesigning the network.

62443 tells you to segment into zones and control every conduit. It does not say how to do that when equipment cannot be re-addressed, patched or taken offline. That is where most zone models stop being real. It is the gap between SL-T on paper and SL-A on the network.

Build zones without re-addressing machines.

The appliance connects to the network you already have rather than cutting into it, and you steer the flows you want protected through it, one asset at a time. The zone boundary becomes something you enforce rather than something you rewire.

Control every conduit.

Each path between zones is terminated and inspected, with an explicit allow per protocol and per identity. That is a conduit in the sense 3-2 means it, rather than a firewall rule that documents an assumption.

Named identity for every session (FR1, FR2).

3-3 opens with identification and authentication control and use control. Named identity per session against assets that have no user model of their own is the requirement most legacy estates cannot meet on their own.

Record evidence for the achieved level (SL-A).

Every session is recorded with identity, asset, protocol and time. That is what turns a documented target level into a measured achieved level, which is the thing an assessment actually asks you to show.

Getting started

Where to start with IEC 62443.

The series is large, and the most common failure is never starting. Here is a workable order:

  1. 01

    Read 62443-1-1 for the vocabulary, then decide which role you are. Almost everything else follows from that one decision.

  2. 02

    If you are an asset owner, go to 3-2. Zone and conduit design with a risk assessment behind it is the foundation the rest of the series builds on.

  3. 03

    Inventory what you actually have before assigning target levels. A zone model drawn over an unknown asset list is a drawing, not a design.

  4. 04

    Assign SL-T per zone from consequence, and be willing to defend why a zone is SL 2 rather than SL 3. Uniform levels across a site are a sign nobody did the assessment.

  5. 05

    Measure SL-A against those targets on a couple of representative zones before scaling. The first measurement is usually uncomfortable and always informative.

  6. 06

    Treat 4-2 as a procurement filter from now on. It is far cheaper to require component capability at purchase than to compensate for its absence afterwards.

  7. 07

    Close the highest-consequence gaps with enforcement you can deploy without a network redesign, and keep the zone model as the thing you are steering toward.

Next step

Review your zone model with us.

Do you have a zone and conduit design the plant cannot enforce yet? We can walk through closing the SL-T to SL-A gap on your topology.

OT network security

How zone architecture gets imposed across sites without a VLAN redesign.

See the solution

Review your own zone model

A walkthrough against your estate: which conduits are undefended, which zones cannot reach their target level, and what enforcement would take.

Common questions about IEC 62443.

3-2

The part that defines zone and conduit design and the risk assessment behind it. If you operate a plant and read only one part of the series, read this one.

It is about securing industrial automation and control systems through shared responsibility. The series splits duties across three roles: asset owner, system integrator and product supplier. Each role gets its own requirements. The central technique is to divide a plant into zones of assets that share a security requirement. Explicitly designed conduits connect the zones. Each zone gets a target security level, SL 0 to SL 4, based on the attacker it must withstand.

ISO/IEC 27001 certifies an information security management system: it governs how an organisation manages security as a process, is information-centric, and applies to any sector. IEC 62443 addresses industrial automation and control systems specifically, covering technical requirements for systems and components alongside the operator's programme. They are complementary. A 27001-certified organisation can still operate a plant with no 62443 controls, and a plant meeting 62443 requirements is not thereby running a 27001 management system.

There is no single figure, because the question usually covers three separate budgets. First, obtaining the documents, which are purchased per part from IEC or ISA. Second, the assessment itself, which varies with scope, the certification scheme, and whether you are certifying a product, a process or a person. Third, the remediation the assessment identifies, which is almost always the largest cost and the one never included in a quote. Note also that operating sites are not certified in the way products are; asset owners demonstrate conformity through assessment.

The parts are copyrighted publications sold by IEC and ISA, so there is no legitimate free download of the full series. Some material is genuinely free: IEC and ISA publish overviews and blog explanations, ISA offers selected content to members, and the ISA Global Cybersecurity Alliance publishes free guidance about the standards. Copies circulating on file-sharing sites are unlicensed, and using them is a poor basis for a compliance programme.

Five levels, defined by adversary capability rather than by organisational maturity. SL 0 claims no protection. SL 1 protects against casual or coincidental violation, meaning accidents rather than intent. SL 2 protects against intentional violation using simple means, with low resources and generic skills. SL 3 protects against sophisticated means, moderate resources and ICS-specific skills. SL 4 protects against sophisticated means with extended resources and high motivation. Levels are assigned per zone, not per site.

No. Product certification under 4-2 proves a component is capable of a security level, which the standard calls SL-C. What matters at your site is SL-A, the level actually achieved once that component is deployed and configured within a zone. A device capable of SL 3 installed with default credentials on a flat network delivers far less. The roles are separate by design: a supplier cannot be responsible for your deployment, and certified equipment cannot substitute for a zone model and a security programme.