What is IEC 62443?
IEC 62443 is a series of international standards developed by ISA (International Society of Automation) and adopted by IEC (International Electrotechnical Commission). It defines cybersecurity requirements for Industrial Automation and Control Systems (IACS) — meaning SCADA, DCS, PLC systems and the entire industrial automation infrastructure.
Unlike ISO 27001, which is a generic information security standard, IEC 62443 was designed specifically for OT environments, accounting for their specifics: availability priority, legacy systems, patching constraints, industrial protocols and physical safety.
Structure of the IEC 62443 standard
The standard consists of four document groups:
Series 1: General
- IEC 62443-1-1 — terminology and concepts
- IEC 62443-1-2 — glossary of terms
- IEC 62443-1-3 — cybersecurity metrics
- IEC 62443-1-4 — IACS security lifecycle
Series 2: Policies & Procedures
- IEC 62443-2-1 — requirements for an IACS cybersecurity management system (for asset owners)
- IEC 62443-2-4 — requirements for integration and maintenance service providers
Series 3: System
- IEC 62443-3-2 — risk assessment and zone/conduit design
- IEC 62443-3-3 — system security requirements and SL levels
Series 4: Component
- IEC 62443-4-1 — product development process requirements (secure development lifecycle)
- IEC 62443-4-2 — technical security requirements for components
Zones and conduits — the foundation of OT segmentation
The key concept in IEC 62443 is dividing the OT network into zones and conduits (communication channels). Each zone groups assets with similar security levels, and conduits define controlled communication paths between zones.
In the context of the Purdue model, this means:
- Enterprise Zone (Level 4-5) — IT networks, ERP, email
- DMZ Zone (Level 3.5) — historian, intermediary servers
- Manufacturing Zone (Level 3) — MES, batch management
- Control Zone (Level 2) — SCADA/HMI, engineering workstations
- Field Zone (Level 0-1) — PLC, RTU, sensors, actuators
Each conduit between zones must have defined:
- Allowed protocols and ports
- Communication direction
- Control mechanisms (firewall, data diode, IDS)
- Monitoring procedures
Security Levels (SL)
IEC 62443 defines four security levels:
SL 1 — Protection against accidental violations
Basic safeguards: user authentication, basic access control, event logging. Suitable for non-critical auxiliary processes.
SL 2 — Protection against intentional attack with simple means
Stronger authentication, network segmentation, monitoring, vulnerability management. Recommended minimum for a typical factory.
SL 3 — Protection against sophisticated attacks
MFA, advanced IDS/IPS, OT communication encryption, continuous monitoring, incident response. For critical production lines and defense manufacturing.
SL 4 — Protection against state-sponsored attacks
Highest level — air-gapping, advanced cryptography, dedicated SOC. For top-category critical infrastructure.
How to choose the right SL for your factory?
The process begins with risk assessment (IEC 62443-3-2):
- Identify assets and their criticality
- Analyze industry-specific threats
- Determine target SL for each zone
- Gap analysis — compare current state with target SL
- Remediation plan with prioritization
IEC 62443 requirements for asset owners (factories)
Series 2-1 defines requirements for organizations operating IACS systems:
Cybersecurity management
- IACS cybersecurity policy approved by management
- Designated OT security responsible (not only IT!)
- Budget for OT cybersecurity
- Regular policy reviews and updates
Personnel management
- Cybersecurity training for OT operators and engineers
- Verification of personnel with access to critical systems
- Onboarding/offboarding procedures for OT access
Asset management
- Complete OT device inventory with firmware/OS versions
- Criticality classification
- Lifecycle management — replacement plan for legacy systems
Incident management
- OT-specific IR plan
- Escalation procedures accounting for physical safety
- Regular exercises and plan tests
Relationship between IEC 62443 and NIS2
Implementing IEC 62443 significantly facilitates NIS2 compliance in the OT area:
| NIS2 Requirement | IEC 62443 Coverage |
|---|---|
| Risk management | IEC 62443-3-2 (risk assessment, zones/conduits) |
| Incident handling | IEC 62443-2-1 (IACS incident management) |
| Business continuity | IEC 62443-2-1 (IACS business continuity) |
| Supply chain security | IEC 62443-2-4 (integrator requirements) |
| Procurement security | IEC 62443-4-2 (component requirements) |
| Monitoring | IEC 62443-3-3 (system requirements, monitoring) |
IEC 62443 implementation plan for a factory
Step 1: Current state audit
An OT/ICS security audit includes asset inventory, network mapping, segmentation assessment and gap identification against IEC 62443 requirements.
Step 2: Risk assessment and zone definition
Following IEC 62443-3-2: zone and conduit identification, target SL determination for each zone, threat analysis.
Step 3: Gap analysis and roadmap
Comparing current state with target SL requirements. Action prioritization — segmentation and monitoring first, then hardening of individual zones.
Step 4: Technical implementation
Deploying industrial firewalls, segmentation, OT monitoring, access control. SOC as a Service provides monitoring without building an in-house team.
Step 5: Processes and training
Policies, IR procedures, personnel training, supplier management.
Step 6: Continuous improvement
Regular audits, OT penetration testing, risk assessment updates, tracking new threats.
Want to assess your factory’s IEC 62443 compliance? Schedule an OT security audit — we will identify gaps and prepare an implementation plan.
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
Related topics
See also:
