24/7 incident response phone: 24/7 incident response · +34 902 540 891

IEC 62443, the technical reference

It is not a law: it is the series of standards that defines how industrial security should be done. When an auditor, customer or insurer wants to assess your plant, this is the benchmark they use.

The IEC 62443 series divides responsibilities among three roles: the asset owner (you, if you operate the plant), the integrator that designs and installs the systems, and the component manufacturer. Each part of the series addresses one of them, which is why trying to “comply with all of 62443” is a common misunderstanding: parts 2-1, 3-2 and 3-3 are the ones that primarily apply to a plant.

Its central tool is zones and conduits: grouping assets by criticality and strictly controlling what passes between groups. Its scale consists of security levels (SL 1 to 4), which grade defences according to the attacker you want to protect against, from a lucky amateur to a well-resourced professional group.

IEC 62443 · The parts that apply to you
RequirementWhat it means in OT
62443-2-1 — Security programme (CSMS)The management system: policy, roles, inventory, risk management and continual improvement applied to OT. It is the umbrella for everything else.
62443-3-2 — Risk assessment and system partitioningDefine zones and conduits on the actual network and assign each zone its target security level (SL-T). This requires knowing the real flows, not those shown on the original project drawing.
62443-3-3 — System requirements by SLThe catalogue of technical requirements each zone must meet according to its target SL: authentication, integrity, restricted data flow, event logging and availability.
SL 1–4 levelsSL1 protects against mistakes and casual attackers; SL2 against attackers using simple means; SL3 against attackers with means and motivation; and SL4 against groups with extensive resources. Choosing the SL is a business decision, not a technical one.
62443-2-4 — Requirements a integradoresWhat contracts should require from anyone installing or maintaining systems: access management, trained personnel and test environments. Useful as a procurement appendix.
62443-4-1 and 4-2 — Product manufacturersSecure development lifecycle and technical component requirements. If you manufacture products, this is your part of the series and the precursor to the CRA.
How to address it

We use 62443 as a design and verification tool, not as paperwork:

  • OT assessment — evaluates your position against 2-1 and provides the inventory assumed by 3-2.
  • IT/OT segmentation — puts 3-2 into practice: zones, conduits and a target SL for each zone.
  • IT and OT ethical hacking — verifies that the SL achieved is the one declared, something paperwork cannot demonstrate.
  • For manufacturers — 4-1 and 4-2: secure development and component certification, also a route towards CRA compliance.
Titanium · Legal information
Titanium · Legal information
Titanium · Legal information