Skip to content
Baza wiedzy

IEC 62443 for Manufacturing: The OT/ICS Cybersecurity Standard Explained

IEC 62443 is the international standard for OT/ICS security. Learn about the standard structure, SL1-SL4 security levels, requirements for asset owners and integrators, and a factory implementation plan.

What is IEC 62443?

IEC 62443 is a series of international standards developed by ISA (International Society of Automation) and adopted by IEC (International Electrotechnical Commission). It defines cybersecurity requirements for Industrial Automation and Control Systems (IACS) — meaning SCADA, DCS, PLC systems and the entire industrial automation infrastructure.

Unlike ISO 27001, which is a generic information security standard, IEC 62443 was designed specifically for OT environments, accounting for their specifics: availability priority, legacy systems, patching constraints, industrial protocols and physical safety.

Structure of the IEC 62443 standard

The standard consists of four document groups:

Series 1: General

  • IEC 62443-1-1 — terminology and concepts
  • IEC 62443-1-2 — glossary of terms
  • IEC 62443-1-3 — cybersecurity metrics
  • IEC 62443-1-4 — IACS security lifecycle

Series 2: Policies & Procedures

  • IEC 62443-2-1 — requirements for an IACS cybersecurity management system (for asset owners)
  • IEC 62443-2-4 — requirements for integration and maintenance service providers

Series 3: System

  • IEC 62443-3-2 — risk assessment and zone/conduit design
  • IEC 62443-3-3 — system security requirements and SL levels

Series 4: Component

  • IEC 62443-4-1 — product development process requirements (secure development lifecycle)
  • IEC 62443-4-2 — technical security requirements for components

Zones and conduits — the foundation of OT segmentation

The key concept in IEC 62443 is dividing the OT network into zones and conduits (communication channels). Each zone groups assets with similar security levels, and conduits define controlled communication paths between zones.

In the context of the Purdue model, this means:

  • Enterprise Zone (Level 4-5) — IT networks, ERP, email
  • DMZ Zone (Level 3.5) — historian, intermediary servers
  • Manufacturing Zone (Level 3) — MES, batch management
  • Control Zone (Level 2) — SCADA/HMI, engineering workstations
  • Field Zone (Level 0-1) — PLC, RTU, sensors, actuators

Each conduit between zones must have defined:

  • Allowed protocols and ports
  • Communication direction
  • Control mechanisms (firewall, data diode, IDS)
  • Monitoring procedures

Security Levels (SL)

IEC 62443 defines four security levels:

SL 1 — Protection against accidental violations

Basic safeguards: user authentication, basic access control, event logging. Suitable for non-critical auxiliary processes.

SL 2 — Protection against intentional attack with simple means

Stronger authentication, network segmentation, monitoring, vulnerability management. Recommended minimum for a typical factory.

SL 3 — Protection against sophisticated attacks

MFA, advanced IDS/IPS, OT communication encryption, continuous monitoring, incident response. For critical production lines and defense manufacturing.

SL 4 — Protection against state-sponsored attacks

Highest level — air-gapping, advanced cryptography, dedicated SOC. For top-category critical infrastructure.

How to choose the right SL for your factory?

The process begins with risk assessment (IEC 62443-3-2):

  1. Identify assets and their criticality
  2. Analyze industry-specific threats
  3. Determine target SL for each zone
  4. Gap analysis — compare current state with target SL
  5. Remediation plan with prioritization

IEC 62443 requirements for asset owners (factories)

Series 2-1 defines requirements for organizations operating IACS systems:

Cybersecurity management

  • IACS cybersecurity policy approved by management
  • Designated OT security responsible (not only IT!)
  • Budget for OT cybersecurity
  • Regular policy reviews and updates

Personnel management

  • Cybersecurity training for OT operators and engineers
  • Verification of personnel with access to critical systems
  • Onboarding/offboarding procedures for OT access

Asset management

  • Complete OT device inventory with firmware/OS versions
  • Criticality classification
  • Lifecycle management — replacement plan for legacy systems

Incident management

  • OT-specific IR plan
  • Escalation procedures accounting for physical safety
  • Regular exercises and plan tests

Relationship between IEC 62443 and NIS2

Implementing IEC 62443 significantly facilitates NIS2 compliance in the OT area:

NIS2 RequirementIEC 62443 Coverage
Risk managementIEC 62443-3-2 (risk assessment, zones/conduits)
Incident handlingIEC 62443-2-1 (IACS incident management)
Business continuityIEC 62443-2-1 (IACS business continuity)
Supply chain securityIEC 62443-2-4 (integrator requirements)
Procurement securityIEC 62443-4-2 (component requirements)
MonitoringIEC 62443-3-3 (system requirements, monitoring)

IEC 62443 implementation plan for a factory

Step 1: Current state audit

An OT/ICS security audit includes asset inventory, network mapping, segmentation assessment and gap identification against IEC 62443 requirements.

Step 2: Risk assessment and zone definition

Following IEC 62443-3-2: zone and conduit identification, target SL determination for each zone, threat analysis.

Step 3: Gap analysis and roadmap

Comparing current state with target SL requirements. Action prioritization — segmentation and monitoring first, then hardening of individual zones.

Step 4: Technical implementation

Deploying industrial firewalls, segmentation, OT monitoring, access control. SOC as a Service provides monitoring without building an in-house team.

Step 5: Processes and training

Policies, IR procedures, personnel training, supplier management.

Step 6: Continuous improvement

Regular audits, OT penetration testing, risk assessment updates, tracking new threats.

Want to assess your factory’s IEC 62443 compliance? Schedule an OT security audit — we will identify gaps and prepare an implementation plan.


Cybersecurity for Your Industry

Learn more about cybersecurity in your industry:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist