Security standard

IEC 62443

IEC 62443 is a series of security standards for industrial automation and control systems (IACS/OT): production lines, power grids, water utilities and building systems. It sets separate requirements for the asset owner, the integrator and the product supplier, and the level of protection is matched to the real risk of the process.

Start assessmentRead about the standard
0
controls in Guardiso
0
free-test questions
PL · EN
two languages

What is IEC 62443?

IEC 62443 is a series, not a single standard. The documents fall into four groups: general (terminology and concepts), asset owner policies and procedures, system requirements, and component requirements. The same series therefore speaks differently to a plant operating an installation, to a systems integrator and to a controller manufacturer.

The most widely used parts are 62443-2-1 (the asset owner security management system), 62443-3-2 (risk assessment and partitioning of the installation into zones and conduits), 62443-3-3 (system requirements with security levels) and 62443-4-1 with 62443-4-2 (secure product development lifecycle and requirements for the components themselves).

Who does it apply to?

Manufacturing plants, energy, water and district heating utilities, critical infrastructure operators, automation integrators and manufacturers of controllers, drives and SCADA systems. In Poland the need usually comes from two directions at once: the national cybersecurity act requirements for essential service operators, and industrial customers asking about control network security during procurement.

The device manufacturer and the plant operator are responsible for different parts of the series. The manufacturer demonstrates a secure development process and component robustness; the operator is responsible for network segmentation, service accounts, controller configuration backups and event response. The split of these roles is explicit in the series and is worth mirroring in contracts.

Zones, conduits and security levels

The starting point is partitioning the installation into zones (groups of assets with common security requirements) and conduits (controlled connections between zones). The target security level is set per zone, not for the whole plant at once. A power unit control room and an office network therefore need not meet the same requirements.

Security levels describe who the zone must withstand: SL 1 protection against casual violation, SL 2 against simple intentional action with low resources, SL 3 against a methodical attack by someone with control systems knowledge, SL 4 against an adversary with extensive resources and time. The asset owner picks the target level based on consequences for the process, people and the environment.

What we do in Guardiso

Once the standard is switched on you get the full set of requirements broken down into tasks with an owner and a deadline, a register of zones and conduits to fill in, mapping to requirements you already meet under ISO 27001 or the national cybersecurity act, and a place for auditor evidence. Artificial intelligence prepares draft content; a human approves it.

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUISO 21434Automotive
Browse all 30 standards