IEC 62443
IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems (operational technology, OT). Its core concepts are segmentation into zones and conduits and the four security levels SL1 to SL4, which grade the required protection against attackers of varying strength. Where ISO/SAE 21434 addresses the vehicle, IEC 62443 covers industrial control systems, automation systems, energy supply and critical infrastructure.
Who does IEC 62443 apply to?
The series of standards addresses all roles in the industrial environment: the component manufacturer supplying devices and software, the system integrator building plants from them, and the asset owner operating the plant. For each role, dedicated parts of the standard define the appropriate requirements — from organisational management systems to technical product properties.
Zones and conduits
The fundamental principle of IEC 62443 is segmentation: assets with similar protection needs are grouped into zones, and communication between zones runs via controlled conduits. This creates a defensible architecture instead of a flat network, often oriented around the Purdue model of manufacturing levels. Each zone and each conduit receives its own protection level, derived from the risk — not imposed uniformly.
Security levels SL1 to SL4
| Security level | Protection against |
|---|---|
| SL1 | accidental or unintentional misuse |
| SL2 | intentional attacks with simple means |
| SL3 | organised attackers with moderate resources |
| SL4 | state-level attackers with high effort |
Important: the security level is not a single value but a vector across seven foundational requirements — such as access control, data integrity and availability. The same zone can receive different levels for different requirements.
The most important parts of the standard
- IEC 62443-2-1: requirements for the asset owner’s security management system.
- IEC 62443-3-3: system security requirements and security levels.
- IEC 62443-4-1: requirements for a secure product development lifecycle.
- IEC 62443-4-2: technical requirements for individual components.
IEC 62443 in practice: one methodology for multiple evidence worlds
Many manufacturers today face several standards at once: a supplier building control units for vehicles and for industrial plants must serve ISO/SAE 21434 and IEC 62443 in parallel — and the EU Cyber Resilience Act sits as a horizontal regulation above both. The good news: the methodological basis is related. All three work risk-based, require security across the lifecycle and rely on a structured threat analysis. Anyone who sets up their risk assessment properly and reusably once produces the evidence from a single model instead of maintaining three separate documentation worlds.


