IEC 62443, the technical reference
It is not a law: it is the series of standards that defines how industrial security should be done. When an auditor, customer or insurer wants to assess your plant, this is the benchmark they use.
The IEC 62443 series divides responsibilities among three roles: the asset owner (you, if you operate the plant), the integrator that designs and installs the systems, and the component manufacturer. Each part of the series addresses one of them, which is why trying to “comply with all of 62443” is a common misunderstanding: parts 2-1, 3-2 and 3-3 are the ones that primarily apply to a plant.
Its central tool is zones and conduits: grouping assets by criticality and strictly controlling what passes between groups. Its scale consists of security levels (SL 1 to 4), which grade defences according to the attacker you want to protect against, from a lucky amateur to a well-resourced professional group.
| Requirement | What it means in OT |
|---|---|
| 62443-2-1 — Security programme (CSMS) | The management system: policy, roles, inventory, risk management and continual improvement applied to OT. It is the umbrella for everything else. |
| 62443-3-2 — Risk assessment and system partitioning | Define zones and conduits on the actual network and assign each zone its target security level (SL-T). This requires knowing the real flows, not those shown on the original project drawing. |
| 62443-3-3 — System requirements by SL | The catalogue of technical requirements each zone must meet according to its target SL: authentication, integrity, restricted data flow, event logging and availability. |
| SL 1–4 levels | SL1 protects against mistakes and casual attackers; SL2 against attackers using simple means; SL3 against attackers with means and motivation; and SL4 against groups with extensive resources. Choosing the SL is a business decision, not a technical one. |
| 62443-2-4 — Requirements a integradores | What contracts should require from anyone installing or maintaining systems: access management, trained personnel and test environments. Useful as a procurement appendix. |
| 62443-4-1 and 4-2 — Product manufacturers | Secure development lifecycle and technical component requirements. If you manufacture products, this is your part of the series and the precursor to the CRA. |
We use 62443 as a design and verification tool, not as paperwork:
- OT assessment — evaluates your position against 2-1 and provides the inventory assumed by 3-2.
- IT/OT segmentation — puts 3-2 into practice: zones, conduits and a target SL for each zone.
- IT and OT ethical hacking — verifies that the SL achieved is the one declared, something paperwork cannot demonstrate.
- For manufacturers — 4-1 and 4-2: secure development and component certification, also a route towards CRA compliance.