What is IEC 62443?
IEC 62443 is a series, not a single standard. The documents fall into four groups: general (terminology and concepts), asset owner policies and procedures, system requirements, and component requirements. The same series therefore speaks differently to a plant operating an installation, to a systems integrator and to a controller manufacturer.
The most widely used parts are 62443-2-1 (the asset owner security management system), 62443-3-2 (risk assessment and partitioning of the installation into zones and conduits), 62443-3-3 (system requirements with security levels) and 62443-4-1 with 62443-4-2 (secure product development lifecycle and requirements for the components themselves).
Who does it apply to?
Manufacturing plants, energy, water and district heating utilities, critical infrastructure operators, automation integrators and manufacturers of controllers, drives and SCADA systems. In Poland the need usually comes from two directions at once: the national cybersecurity act requirements for essential service operators, and industrial customers asking about control network security during procurement.
The device manufacturer and the plant operator are responsible for different parts of the series. The manufacturer demonstrates a secure development process and component robustness; the operator is responsible for network segmentation, service accounts, controller configuration backups and event response. The split of these roles is explicit in the series and is worth mirroring in contracts.
Zones, conduits and security levels
The starting point is partitioning the installation into zones (groups of assets with common security requirements) and conduits (controlled connections between zones). The target security level is set per zone, not for the whole plant at once. A power unit control room and an office network therefore need not meet the same requirements.
Security levels describe who the zone must withstand: SL 1 protection against casual violation, SL 2 against simple intentional action with low resources, SL 3 against a methodical attack by someone with control systems knowledge, SL 4 against an adversary with extensive resources and time. The asset owner picks the target level based on consequences for the process, people and the environment.
What we do in Guardiso
Once the standard is switched on you get the full set of requirements broken down into tasks with an owner and a deadline, a register of zones and conduits to fill in, mapping to requirements you already meet under ISO 27001 or the national cybersecurity act, and a place for auditor evidence. Artificial intelligence prepares draft content; a human approves it.
