Regulatory Framework – OT Security Standard

IEC 62443 Compliance
for OT and ICS Security

IEC 62443 is the international standard series for operational technology (OT) and industrial control system (ICS) cybersecurity. Our IEC 62443 compliance consulting helps asset owners, system integrators and product manufacturers assess security requirements, define security levels, strengthen OT security controls and prepare for certification or customer assessments. The approach is designed for industrial environments where safety, availability and operational continuity matter alongside confidentiality.

Standard Overview

Standard Type

International Standard Series – ISA/IEC

Certification Available

Yes – product level via accredited labs and system level via scheme bodies

Applicable To

OT asset owners, system integrators, component manufacturers

Security Levels

SL 1 to SL 4 defined by risk assessment per zone

Key Regulatory Connection

NIS2 Article 21 – implementation provides direct evidence

What It Is

Understanding
IEC 62443

IEC 62443 is a series of international standards developed by ISA and adopted by IEC that address cybersecurity for industrial automation and control systems. It is structured across four series covering general concepts, policies and procedures, system level security, and component level security.

Unlike IT security frameworks, IEC 62443 is designed specifically for environments where availability and operational continuity are primary constraints. Security controls must be implemented without disrupting the physical processes the OT systems control.

IEC 62443 defines Security Levels from SL 1 through SL 4. Risk assessment per zone determines the target security level, which then drives control selection. This risk-proportionate approach means that not every zone in a facility needs the same level of protection.

NIS2 compliance for energy and manufacturing essential entities is significantly supported by IEC 62443. The CSMS requirements map to NIS2 Article 21 risk management measures. The zone and conduit model supports network security measures. The supplier requirements support Article 21 supply chain measures.

Important Distinction

IEC 62443 certification is issued by independent accredited testing laboratories and scheme bodies. We help you build the compliant OT security programme and prepare for that assessment. We do not issue the certification. The accredited body does after reviewing your implementation.

NIS2 Overlap

IEC 62443-2-1 CSMS supports NIS2 Art.21 risk management. IEC 62443-2-4 supplier requirements support Art.21(d) supply chain measures. IEC 62443-3-3 system requirements support Art.21 network and system security measures. One programme can serve both frameworks.

Standard Structure

How the IEC 62443
security framework is organised.

IEC 62443 is not one document. It is a series of standards structured across four categories, each addressing a different audience and scope of obligation.

IEC 62443-1-x

General

Foundational concepts, terminology, security level model, and CSMS concept used across the entire series. Provides the common language for all other standards.

All audiences

IEC 62443-2-x

Policies and Procedures

CSMS requirements for asset owners (62443-2-1) and security requirements for service providers and system integrators (62443-2-4). Governs the management and supply chain layer.

Asset owners and integrators

IEC 62443-3-x

System Level

Security risk assessment per zone (62443-3-2) and system security requirements across seven foundational requirements at each security level (62443-3-3).

System design and assessment

IEC 62443-4-x

Component Level

Secure product development lifecycle for manufacturers (62443-4-1) and technical security requirements for individual components seeking certification (62443-4-2).

Product manufacturers

Who It Applies To

Who needs
IEC 62443 compliance.

OT Asset Owner

Energy and Utility Operators

Grid operators, generators, water utilities, and pipeline operators with ICS and SCADA environments. IEC 62443-2-1 CSMS and IEC 62443-3-2 risk assessment are the primary applicable standards. NIS2 Article 21 creates a parallel compliance driver for most EU operators.

System Integrator

Industrial System Builders

Engineering firms who design, install, and maintain OT systems. IEC 62443-2-4 defines the security requirements they must demonstrate as suppliers. Asset owners increasingly require 62443-2-4 compliance as a procurement condition under NIS2 Article 21(d).

Component Manufacturer

OT Product Manufacturers

OT component and device manufacturers seeking IEC 62443-4-2 product certification through accredited testing laboratories. Product certification is increasingly a requirement for supply into critical infrastructure procurement in the EU and North America.

Key Standards in the Series

IEC 62443 standards
and security requirements.

These are the most frequently applicable IEC 62443 standards for critical infrastructure operators, integrators, and manufacturers. References use the correct IEC 62443 standard numbering, not article notation which applies to directives and regulations.

IEC 62443-2-1

Cybersecurity Management System for Asset Owners

Asset owners must establish, implement, document, and maintain a CSMS covering security policy, risk management, implementation, monitoring, and continuous improvement. This is the governance backbone for all other IEC 62443 requirements. Without a CSMS, zone and conduit controls lack the management framework to sustain them.

Asset Owner

IEC 62443-3-2

Security Risk Assessment for System Design

Structured risk assessment to identify threats, vulnerabilities, and consequences for each zone and conduit. The output determines the target security level per zone, which then drives control selection under IEC 62443-3-3. The assessment must be documented and periodically reviewed.

Required

IEC 62443-3-3

System Security Requirements and Security Levels

System-level security requirements across seven foundational requirements: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability. Requirements escalate from SL 1 through SL 4 per zone.

Required

IEC 62443-2-4

Security Requirements for Service Providers

Defines the security capabilities that system integrators and service providers must demonstrate when working in OT environments. Asset owners must verify supplier compliance. Increasingly required as a contractual condition in critical infrastructure supply chains under NIS2 Article 21(d).

Supply Chain

IEC 62443-4-1

Secure Product Development Lifecycle

Security practices that product manufacturers must embed in their development lifecycle. Covers security requirements management, secure design, secure implementation, verification and validation, defect management, patch management, and end-of-life provisions. Prerequisite for 62443-4-2 certification.

Manufacturer

IEC 62443-4-2

Technical Security Requirements for Components

Product-level technical security requirements for OT components. Manufacturers seeking IEC 62443-4-2 certification must demonstrate these controls through assessment by an independent accredited testing laboratory. This is a formal certification process, not a self-declaration.

Manufacturer

How KairosVector Helps

From gap assessment to evidence compliance.

The KairosVector approach to IEC 62443 moves from OT assessment and security design through implementation, audit readiness, and ongoing resilience.

Phase 01 – Assess

OT Environment Baseline

We map your OT landscape against IEC 62443 requirements. Every zone is assessed for its current security level versus the target security level required by risk. NIS2 Article 21 obligations are scoped in parallel.

What We Do

  • OT asset inventory and network topology mapping
  • IEC 62443-2-1 CSMS maturity gap assessment
  • IEC 62443-3-2 risk assessment per zone
  • Current versus target security level analysis per zone

Deliverable

IEC 62443 gap report with security level baseline per zone, maturity rating.

Documents You Receive

  • Gap Assessment Report
  • Security Level Baseline Map
  • Board-ready Executive Summary

IEC 62443 Compliance Consulting

A practical path from
gap assessment to implementation.

IEC 62443 compliance is most effective when the standard is translated into an evidence-based security programme. We help organisations understand their current posture, define the target security level, prioritise remediation and prepare documentation that can support internal governance, customer requirements and independent assessment.

1. Assess

Review the OT environment, zones, conduits, assets, risks, existing controls and applicable IEC 62443 requirements.

2. Prioritise

Map gaps to the target security level and prioritise remediation based on risk, operational impact and business requirements.

3. Prepare

Build the required policies, technical evidence, procedures and implementation roadmap for ongoing OT cybersecurity and assessment readiness.

Security Level Model

Four levels of protection.

IEC 62443 does not require uniform security across every system. Risk assessment per zone determines the target security level. Controls are implemented to reach that target. Over-engineering is as problematic as under-engineering in OT environments.

SL 1

Basic Protection

Protection against casual or unintentional violation. Assumes the threat actor has generic skills, low resources, and low motivation targeting the system.

Typical: Low-criticality auxiliary systems

SL 2

Intentional Violation

Protection against intentional violation using simple means with IACS-specific skills and moderate resources. The most common target security level for operational OT environments.

Typical: Most energy grid OT environments

SL 3

Sophisticated Attack

Protection against sophisticated attacks using OT-specific knowledge and substantial resources. Assumes entity-specific targeting with high motivation.

Typical: Critical generation and transmission

SL 4

State-Level Threat

Protection against intentional violation by a nation-state level threat actor with extended resources and maximum motivation. Applied to the most critical national infrastructure.

Typical: National critical infrastructure

Frequently Asked Questions

IEC 62443 compliance questions

What is IEC 62443 compliance?

IEC 62443 compliance means applying the relevant requirements from the IEC 62443 series to the organisation, industrial system or product being assessed. The applicable requirements depend on the role, system scope and target security level.

What is the difference between IEC 62443 and ISO 27001?

IEC 62443 is specifically designed for industrial automation and control systems, while ISO 27001 provides a broader information security management framework. An OT security programme may use both where their scopes overlap.

Does IEC 62443 provide certification?

Certification can be available for applicable products, processes and system-level schemes through independent assessment bodies. The exact assessment route depends on the standard, scope and certification scheme.

How does IEC 62443 support NIS2?

IEC 62443 provides OT-focused security practices that can support organisations addressing cybersecurity risk management, system security and supply-chain requirements relevant to NIS2. The mapping depends on the organisation and applicable regulatory obligations.


NIS2

The regulatory connection - IEC 62443 and NIS2 personal liability

IEC 62443 is not a regulatory requirement but NIS2 is. Under NIS2 Article 20, management bodies of essential entities face personal liability for inadequate cybersecurity measures. IEC 62443 gives you documented, auditable evidence across the three core Article 21 obligations: risk management, network and system security, and supply chain controls. One programme. One evidence base. Direct protection against personal liability.

Related

Connected frameworks
and services.

Service

OT Security and IEC 62443

Full engagement service for OT security programme design, CSMS implementation, and IEC 62443 compliance support.

Explore →

Regulation

NIS2 Directive

IEC 62443 CSMS and zone requirements directly support NIS2 Article 21 measures for essential entities in energy and manufacturing.

Read more →

Regulation

EU Cyber Resilience Act

IEC 62443-4-2 is a harmonised standard supporting CRA Annex I essential requirements for connected OT product manufacturers.

Read more →

Ready to assess your IEC 62443 compliance posture?

Not sure where you sit against IEC 62443 requirements? Start with our OT Security Baseline Review a structured initial engagement that gives you a security level map of your environment and your top three IEC 62443 compliance gaps.

You leave with:

  • Your current security level baseline
  • Your top three gap priorities
  • A recommended programme approach

Scroll to Top