Skip to main content

IEC 62443

IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems (operational technology, OT). Its core concepts are segmentation into zones and conduits and the four security levels SL1 to SL4, which grade the required protection against attackers of varying strength. Where ISO/SAE 21434 addresses the vehicle, IEC 62443 covers industrial control systems, automation systems, energy supply and critical infrastructure.

Who does IEC 62443 apply to?

The series of standards addresses all roles in the industrial environment: the component manufacturer supplying devices and software, the system integrator building plants from them, and the asset owner operating the plant. For each role, dedicated parts of the standard define the appropriate requirements — from organisational management systems to technical product properties.

Zones and conduits

The fundamental principle of IEC 62443 is segmentation: assets with similar protection needs are grouped into zones, and communication between zones runs via controlled conduits. This creates a defensible architecture instead of a flat network, often oriented around the Purdue model of manufacturing levels. Each zone and each conduit receives its own protection level, derived from the risk — not imposed uniformly.

Security levels SL1 to SL4

Security levelProtection against
SL1accidental or unintentional misuse
SL2intentional attacks with simple means
SL3organised attackers with moderate resources
SL4state-level attackers with high effort

Important: the security level is not a single value but a vector across seven foundational requirements — such as access control, data integrity and availability. The same zone can receive different levels for different requirements.

The most important parts of the standard

  • IEC 62443-2-1: requirements for the asset owner’s security management system.
  • IEC 62443-3-3: system security requirements and security levels.
  • IEC 62443-4-1: requirements for a secure product development lifecycle.
  • IEC 62443-4-2: technical requirements for individual components.

IEC 62443 in practice: one methodology for multiple evidence worlds

Many manufacturers today face several standards at once: a supplier building control units for vehicles and for industrial plants must serve ISO/SAE 21434 and IEC 62443 in parallel — and the EU Cyber Resilience Act sits as a horizontal regulation above both. The good news: the methodological basis is related. All three work risk-based, require security across the lifecycle and rely on a structured threat analysis. Anyone who sets up their risk assessment properly and reusably once produces the evidence from a single model instead of maintaining three separate documentation worlds.

Frequently asked questions

What is the difference between IEC 62443 and ISO/SAE 21434?
ISO/SAE 21434 applies to road vehicles and their components, IEC 62443 to industrial automation and operational technology. The methodological basis is related: both work risk-based, require security across the entire lifecycle and rely on a structured threat analysis. Anyone manufacturing both — for example control units for vehicles and plants — faces both standards at the same time.
What do the security levels SL1 to SL4 mean?
Four levels: from SL1 (protection against accidental or unintentional misuse) to SL4 (protection against state-level attackers with high effort). The security level is not a single value but a vector across seven foundational requirements and is derived per zone and conduit from the risk.
How does IEC 62443 relate to the Cyber Resilience Act?
The CRA sits as a horizontal EU regulation above the sector-specific standards. Anyone who sets up their risk assessment methodology properly once serves IEC 62443, ISO/SAE 21434 and the CRA from a single model instead of maintaining separate evidence worlds.

Related terms

Reviewed by Dirk Leopold, Executive Vice President Digital Engineering on July 20, 2026