TroutTrout

IEC 62443 is not one standard. It is a series, and most of it is not aimed at you.

The series runs to more than a dozen documents split across four groups, and which ones apply depends entirely on whether you operate a plant, integrate one, or build the equipment. This guide covers the structure, security levels, zones and conduits, what certification actually certifies, and where the standard stops short of telling you what to deploy.

Last updated:

What is IEC 62443?

IEC 62443 is a series of international standards for the cybersecurity of industrial automation and control systems, developed by the ISA99 committee and published jointly as ISA/IEC 62443. It is not a single document. The series is organised into four groups: general concepts, policies and procedures for the operator, system-level technical requirements, and component-level requirements for the products themselves. Its defining idea is that security is a shared responsibility split across three roles, and that you segment a plant into zones connected by conduits, then assign each zone a target security level based on the risk it carries.

That structure is why generic advice about the standard is usually useless. A plant operator, a system integrator and a PLC vendor each answer to different parts of the series, and the requirements are not interchangeable.

The series

The four parts, and which one applies to you

Document numbers follow the pattern 62443-X-Y, where X is the group. Knowing the group tells you immediately whether a document is your problem.

Group
62443-1-x
Covers
Terminology, concepts and models. The shared vocabulary the rest of the series depends on.
Written for
Everyone, once.
The parts you will actually meet
1-1 concepts and models.
Group
62443-2-x
Covers
Policies and procedures. How the operating organisation runs a security programme, and what it demands of service providers.
Written for
Asset owners and service providers.
The parts you will actually meet
2-1 security programme, 2-4 requirements for service providers.
Group
62443-3-x
Covers
System-level security. Risk assessment, zone and conduit design, and the technical requirements a whole control system must meet.
Written for
Asset owners and system integrators.
The parts you will actually meet
3-2 risk assessment and zone design, 3-3 system security requirements and security levels.
Group
62443-4-x
Covers
Component-level security. How a product is developed securely, and what technical capabilities the product itself must provide.
Written for
Product suppliers.
The parts you will actually meet
4-1 secure development lifecycle, 4-2 technical requirements for components.
THE SERIES AT A GLANCE1-xGENERAL1-1 Concepts and models1-2 Master glossary1-3 System conformance metrics1-4 Lifecycle and use cases2-xPOLICIES2-1 Security programme2-2 Programme ratings2-3 Patch management2-4 Service provider reqs3-xSYSTEM3-1 Security technologies3-2 Risk, zones, conduits3-3 System security reqs4-xCOMPONENT4-1 Secure development4-2 Component security reqsNUMBERING IS 62443-GROUP-PART. THE GROUP TELLS YOU WHOSE PROBLEM IT IS.

If you operate a plant, 3-2 and 3-3 are the two you will spend real time in. 4-2 matters to you only as a procurement filter: it is the part you cite when asking a vendor what their device can actually do.

Shared responsibility

Three roles, and why that matters more than it sounds

The series deliberately refuses to put security on any single party. Most confusion about what 62443 requires comes from reading a requirement written for one role as though it applied to another.

Asset owner

The organisation that operates the plant. Owns the security programme, the risk assessment, the zone and conduit design, and the target security levels. Answers primarily to 2-1, 3-2 and 3-3.

System integrator

Whoever designs and commissions the control system. Has to deliver a system that meets the security level the asset owner set, and to work within the zone design rather than around it. Answers to 2-4 and 3-3.

Product supplier

The vendor of the PLC, drive, switch or software. Has to develop securely under 4-1 and ship components whose capabilities meet 4-2. Cannot be made responsible for how the product is deployed.

This split is why a device advertised as 62443-certified does not make a plant compliant, and why a plant cannot be compliant purely by buying certified equipment. The parts address different questions and neither substitutes for the other.

Security levels

SL 0 to SL 4, defined by who you are defending against

Security levels are the mechanism people most often get backwards. They are not a maturity score for your organisation. Each level is defined by the capability of the adversary it is meant to stop, and you assign one per zone, not one per site.

Level
SL 0
Protects against
No specific requirement.
Adversary profile
No protection is claimed for the zone.
Level
SL 1
Protects against
Casual or coincidental violation.
Adversary profile
An operator error, a misrouted cable, an accident. No intent.
Level
SL 2
Protects against
Intentional violation using simple means.
Adversary profile
Low resources, generic skills, low motivation. Opportunistic, commodity malware.
Level
SL 3
Protects against
Intentional violation using sophisticated means.
Adversary profile
Moderate resources, ICS-specific skills, moderate motivation. Someone who understands your protocols.
Level
SL 4
Protects against
Intentional violation using sophisticated means with extended resources.
Adversary profile
Extended resources, ICS-specific skills, high motivation. Effectively a state-level actor.

The distinction that decides whether an audit goes well

The standard separates SL-T, the target level you assign a zone from its risk, from SL-C, the level a component or system is capable of, and SL-A, the level actually achieved once it is deployed and configured. Most estates have a documented SL-T and no measured SL-A, and the gap between them is where findings come from. Buying an SL 3 capable device and deploying it with defaults gives you SL-C 3 and SL-A 1.

THE GAP AN ASSESSMENT FINDSSL 0SL 1SL 2SL 3SL 4SL-T TARGETassigned to the zone from risk3SL-C CAPABLEwhat the component could do3SL-A ACHIEVEDwhat the deployment actually delivers1THIS DELTA IS THE FINDINGAN SL 3 CAPABLE DEVICE DEPLOYED WITH DEFAULTS ON A FLAT NETWORK GIVES YOU SL-C 3 AND SL-A 1.CERTIFICATION ANSWERS THE MIDDLE BAR. ONLY DEPLOYMENT ANSWERS THE BOTTOM ONE.
Zones and conduits

How zones and conduits actually work

Zones and conduits are the core of 62443-3-2, and the part that most directly changes what a network looks like. A zone is a grouping of assets that share a security level requirement. A conduit is the controlled path between two zones, and it is a thing you design, not a gap you leave.

Zones are drawn by risk, not by function

This is the most common mistake, and it is why Purdue levels are only a first draft of a zone model. Two devices at the same level, on the same VLAN, doing the same kind of work, belong in different zones if a compromise of one has consequences the other does not carry.

Every conduit is explicit and documented

If two zones communicate, that path is a conduit with a stated purpose, a stated protocol set, and controls of its own. A path nobody designed is not a conduit, it is a finding.

Conduits carry a security level too

A conduit between two SL 3 zones has to be capable of SL 3. A high-integrity zone reached over an undefended path is not a high-integrity zone; it is a well-documented assumption.

Safety systems are their own zone, always

A safety instrumented system shares no zone with basic process control, regardless of how the network is wired. This is one of the few places the standard is close to prescriptive.

ZONES, CONDUITS, AND THE PATHS NOBODY DESIGNEDENTERPRISE ZONESL 1ERPMAILOFFICE ITOPERATIONS ZONESL 2HISTORIANMESENG WSCONTROL ZONESL 3PLCHMIDRIVESSAFETY ZONESL 3SISSAFETY PLCCONDUITCONDUITCONDUITVENDOR VPN · ENTERPRISE STRAIGHT TO CONTROLNOT A CONDUIT. NOBODY DESIGNED IT, SO NOTHING GOVERNS IT.A CONDUIT BETWEEN TWO SL 3 ZONES MUST ITSELF BE CAPABLE OF SL 3.A PATH NOBODY DESIGNED IS NOT A CONDUIT. IT IS A FINDING.

The design work is not usually the obstacle. Most teams can draw a defensible zone model in a workshop. The obstacle is enforcing it on a plant where re-addressing equipment means downtime nobody will authorise.

Certification

What certification proves, and what it does not

Certification against 62443 is real, but it certifies narrower things than the marketing around it suggests. Three separate things get certified, and they are frequently conflated.

Product certification

A component or system is assessed against 4-2 or 3-3 and its development process against 4-1. Schemes include ISASecure and IECEE. This proves the product is capable of a security level. It says nothing about your plant.

Process certification

A supplier's or integrator's development or service process is assessed, typically under 4-1 or 2-4. This proves the organisation works in a defined way, not that any given deployment is secure.

Personnel certification

Individuals pass ISA's certificate programme, for example the risk assessment or design specialist tracks. This is a qualification for a person, not for a site.

There is no plant certificate

An operating site is not certified against 62443 the way a factory is certified against ISO 9001. Asset owners demonstrate conformity through assessment against 2-1, 3-2 and 3-3, usually via a third-party audit against a defined scope. Anyone offering to certify your plant is describing an assessment.

On cost, the honest answer is that the question hides three different budgets: buying the documents from IEC or ISA, paying for an assessment, and the remediation the assessment finds. The third is almost always the largest by a wide margin, and it is the one that is never quoted.

In context

IEC 62443 against the frameworks it gets confused with

These are frequently presented as alternatives. They are not. They answer different questions and most regulated operators end up touching more than one.

Framework
ISO/IEC 27001
What it governs
An information security management system. Organisational, information-centric, certifiable for an organisation.
Relationship to 62443
Complementary, not competing. 27001 governs how you manage security; 62443 governs the technical and procedural specifics of an industrial control system. A 27001-certified company can run a plant with no 62443 controls at all.
Framework
NIST CSF 2.0
What it governs
A voluntary framework of outcomes across govern, identify, protect, detect, respond, recover.
Relationship to 62443
Higher level and sector-neutral. CSF tells you which outcomes to pursue; 62443 tells you what that means for an IACS specifically. They map cleanly onto each other.
Framework
NIST SP 800-82r3
What it governs
Guidance for securing operational technology, published by NIST for a mostly US audience.
Relationship to 62443
Closest in subject matter. 800-82r3 explicitly references 62443 and reads as guidance where 62443 reads as requirements. Many teams use 800-82 to understand and 62443 to specify.
Framework
NIS2
What it governs
EU law imposing risk-management and reporting duties on essential and important entities.
Relationship to 62443
A legal obligation rather than a technical standard. NIS2 says you must manage risk appropriately; 62443 is one of the most defensible ways to show an industrial operator has done so.
Framework
NERC CIP
What it governs
Mandatory, enforceable regulation for the North American bulk electric system.
Relationship to 62443
Regulation with penalties, scoped to one sector. 62443 is voluntary and cross-sector. Utilities in scope for CIP often use 62443 concepts to organise work CIP then audits.
Where Access Gate fits

Closing the gap between the zone model and the network

62443 tells you to segment into zones and to control every conduit. It does not tell you how to do that on a plant where the equipment cannot be re-addressed, patched or taken offline, which is precisely where most zone models stop being real. This is the gap between SL-T on paper and SL-A on the network.

Zones without re-addressing anything

The appliance connects to the network you already have rather than cutting into it, and you steer the flows you want protected through it, one asset at a time. The zone boundary becomes something you enforce rather than something you rewire.

Conduits that are actually controlled

Each path between zones is terminated and inspected, with an explicit allow per protocol and per identity. That is a conduit in the sense 3-2 means it, rather than a firewall rule that documents an assumption.

Identification and use control, FR1 and FR2

3-3 opens with identification and authentication control and use control. Named identity per session against assets that have no user model of their own is the requirement most legacy estates cannot meet on their own.

Evidence that closes SL-A, not just SL-T

Every session is recorded with identity, asset, protocol and time. That is what turns a documented target level into a measured achieved level, which is the thing an assessment actually asks you to show.

Getting started

Where to start if you are starting from nothing

The series is large enough that the most common failure is not non-compliance, it is never beginning. A workable order:

  1. 01

    Read 62443-1-1 for the vocabulary, then decide which role you are. Almost everything else follows from that one decision.

  2. 02

    If you are an asset owner, go to 3-2. Zone and conduit design with a risk assessment behind it is the foundation the rest of the series builds on.

  3. 03

    Inventory what you actually have before assigning target levels. A zone model drawn over an unknown asset list is a drawing, not a design.

  4. 04

    Assign SL-T per zone from consequence, and be willing to defend why a zone is SL 2 rather than SL 3. Uniform levels across a site are a sign nobody did the assessment.

  5. 05

    Measure SL-A against those targets on a couple of representative zones before scaling. The first measurement is usually uncomfortable and always informative.

  6. 06

    Treat 4-2 as a procurement filter from now on. It is far cheaper to require component capability at purchase than to compensate for its absence afterwards.

  7. 07

    Close the highest-consequence gaps with enforcement you can deploy without a network redesign, and keep the zone model as the thing you are steering toward.

Next step

From a zone model on paper to one on the network

If you have a zone and conduit design that the plant cannot currently enforce, we can walk through what closing the SL-T to SL-A gap looks like on your topology.

OT network security

How zone architecture gets imposed across sites without a VLAN redesign.

See the solution

Review your own zone model

A walkthrough against your estate: which conduits are undefended, which zones cannot reach their target level, and what enforcement would take.

IEC 62443 questions

3-2

The part that defines zone and conduit design and the risk assessment behind it. If you operate a plant and read only one part of the series, read this one.

It is about securing industrial automation and control systems through a shared-responsibility model. The series splits duties across three roles, asset owner, system integrator and product supplier, and gives each one its own requirements. Its central technique is to divide a plant into zones of assets that share a security requirement, connect them with explicitly designed conduits, and assign each zone a target security level from SL 0 to SL 4 based on the capability of the adversary it must withstand.

ISO/IEC 27001 certifies an information security management system: it governs how an organisation manages security as a process, is information-centric, and applies to any sector. IEC 62443 addresses industrial automation and control systems specifically, covering technical requirements for systems and components alongside the operator's programme. They are complementary. A 27001-certified organisation can still operate a plant with no 62443 controls, and a plant meeting 62443 requirements is not thereby running a 27001 management system.

There is no single figure, because the question usually covers three separate budgets. First, obtaining the documents, which are purchased per part from IEC or ISA. Second, the assessment itself, which varies with scope, the certification scheme, and whether you are certifying a product, a process or a person. Third, the remediation the assessment identifies, which is almost always the largest cost and the one never included in a quote. Note also that operating sites are not certified in the way products are; asset owners demonstrate conformity through assessment.

The parts are copyrighted publications sold by IEC and ISA, so there is no legitimate free download of the full series. Some material is genuinely free: IEC and ISA publish overviews and blog explanations, ISA offers selected content to members, and the ISA Global Cybersecurity Alliance publishes free guidance about the standards. Copies circulating on file-sharing sites are unlicensed, and using them is a poor basis for a compliance programme.

Five levels, defined by adversary capability rather than by organisational maturity. SL 0 claims no protection. SL 1 protects against casual or coincidental violation, meaning accidents rather than intent. SL 2 protects against intentional violation using simple means, with low resources and generic skills. SL 3 protects against sophisticated means, moderate resources and ICS-specific skills. SL 4 protects against sophisticated means with extended resources and high motivation. Levels are assigned per zone, not per site.

No. Product certification under 4-2 proves a component is capable of a security level, which the standard calls SL-C. What matters at your site is SL-A, the level actually achieved once that component is deployed and configured within a zone. A device capable of SL 3 installed with default credentials on a flat network delivers far less. The roles are separate by design: a supplier cannot be responsible for your deployment, and certified equipment cannot substitute for a zone model and a security programme.