IEC 62443 is the leading international standard series for securing Industrial Automation and Control Systems (IACS). Developed by the International Electrotechnical Commission with the ISA99 committee, it defines how to protect the systems that run physical processes, where a breach threatens safety and uptime, not just data. Rather than one checklist, it is a set of documents that split the job across the asset owner, the system integrator, and the product supplier.
How is IEC 62443 structured?
The series is organized into four groups so each audience reads the part that applies to them:
- General: common terms, concepts, and models used across the standard.
- Policies and Procedures (62443-2-x): the security program the asset owner runs, including patch and program management.
- System (62443-3-x): system-level design, most notably 62443-3-2 for risk assessment and 62443-3-3 for the foundational system security requirements.
- Component (62443-4-x): secure development for product suppliers (62443-4-1) and technical security requirements for individual devices (62443-4-2).
What are zones, conduits, and security levels?
These are the two ideas that make IEC 62443 practical. You divide the system into zones, groups of assets that share security requirements, and control every path between them through defined conduits. Each zone gets a target Security Level, SL 1 through SL 4, scaled to the threat it faces: SL 1 guards against casual or accidental misuse, SL 4 against a well-resourced attacker with IACS-specific skills. Segmenting into zones and conduits is the same instinct behind network segmentation and microsegmentation, applied to the plant.
Who needs to comply with IEC 62443?
Anyone building, integrating, or running industrial control systems: manufacturers, energy and water utilities, transportation, and the vendors that sell into them. It is voluntary in most places but increasingly cited by regulators. In the EU it underpins how operators approach NIS2, and product suppliers pursue 62443-4-1 and 62443-4-2 certification because their customers now ask for it in procurement.
How is IEC 62443 different from NIST 800-82 or NERC CIP?
They overlap but serve different roles. IEC 62443 is a horizontal, international standard for any IACS, structured around zones, conduits, and security levels. NIST 800-82 is U.S. guidance for securing OT and maps closely to it. NERC CIP is narrower and mandatory: enforceable rules for the North American bulk electric system with audits and penalties. Many operators use IEC 62443 as the engineering blueprint and a regulation like NERC CIP or NIS2 as the legal driver.

