Regulatory Framework – OT Security Standard
IEC 62443
OT and ICS Security
International Standard Series for Operational Technology
IEC 62443 is the international standard series for operational technology and industrial control system security. It defines security levels, zone and conduit design, and cybersecurity management system requirements for OT environments. Unlike IT security frameworks, it is built for environments where operational continuity is as critical as confidentiality.
Standard Overview
Standard Type
International Standard Series – ISA/IEC
Certification Available
Yes – product level via accredited labs and system level via scheme bodies
Applicable To
OT asset owners, system integrators, component manufacturers
Security Levels
SL 1 to SL 4 defined by risk assessment per zone
Key Regulatory Connection
NIS2 Article 21 – implementation provides direct evidence
What It Is
Understanding
IEC 62443
IEC 62443 is a series of international standards developed by ISA and adopted by IEC that address cybersecurity for industrial automation and control systems. It is structured across four series covering general concepts, policies and procedures, system level security, and component level security.
Unlike IT security frameworks, IEC 62443 is designed specifically for environments where availability and operational continuity are primary constraints. Security controls must be implemented without disrupting the physical processes the OT systems control.
IEC 62443 defines Security Levels from SL 1 through SL 4. Risk assessment per zone determines the target security level, which then drives control selection. This risk-proportionate approach means that not every zone in a facility needs the same level of protection.
NIS2 compliance for energy and manufacturing essential entities is significantly supported by IEC 62443. The CSMS requirements map to NIS2 Article 21 risk management measures. The zone and conduit model supports network security measures. The supplier requirements support Article 21 supply chain measures.
Important Distinction
IEC 62443 certification is issued by independent accredited testing laboratories and scheme bodies. We help you build the compliant OT security programme and prepare for that assessment. We do not issue the certification. The accredited body does after reviewing your implementation.
NIS2 Overlap
IEC 62443-2-1 CSMS supports NIS2 Art.21 risk management. IEC 62443-2-4 supplier requirements support Art.21(d) supply chain measures. IEC 62443-3-3 system requirements support Art.21 network and system security measures. One programme can serve both frameworks.
Standard Structure
How IEC 62443
is organised.
IEC 62443 is not one document. It is a series of standards structured across four categories, each addressing a different audience and scope of obligation.
IEC 62443-1-x
General
Foundational concepts, terminology, security level model, and CSMS concept used across the entire series. Provides the common language for all other standards.
All audiences
IEC 62443-2-x
Policies and Procedures
CSMS requirements for asset owners (62443-2-1) and security requirements for service providers and system integrators (62443-2-4). Governs the management and supply chain layer.
Asset owners and integrators
IEC 62443-3-x
System Level
Security risk assessment per zone (62443-3-2) and system security requirements across seven foundational requirements at each security level (62443-3-3).
System design and assessment
IEC 62443-4-x
Component Level
Secure product development lifecycle for manufacturers (62443-4-1) and technical security requirements for individual components seeking certification (62443-4-2).
Product manufacturers
Who It Applies To
Which organisations
IEC 62443 covers.
OT Asset Owner
Energy and Utility Operators
Grid operators, generators, water utilities, and pipeline operators with ICS and SCADA environments. IEC 62443-2-1 CSMS and IEC 62443-3-2 risk assessment are the primary applicable standards. NIS2 Article 21 creates a parallel compliance driver for most EU operators.
System Integrator
Industrial System Builders
Engineering firms who design, install, and maintain OT systems. IEC 62443-2-4 defines the security requirements they must demonstrate as suppliers. Asset owners increasingly require 62443-2-4 compliance as a procurement condition under NIS2 Article 21(d).
Component Manufacturer
OT Product Manufacturers
OT component and device manufacturers seeking IEC 62443-4-2 product certification through accredited testing laboratories. Product certification is increasingly a requirement for supply into critical infrastructure procurement in the EU and North America.
Key Standards in the Series
What each standard
actually requires.
These are the most frequently applicable IEC 62443 standards for critical infrastructure operators, integrators, and manufacturers. References use the correct IEC 62443 standard numbering, not article notation which applies to directives and regulations.
IEC 62443-2-1
Cybersecurity Management System for Asset Owners
Asset owners must establish, implement, document, and maintain a CSMS covering security policy, risk management, implementation, monitoring, and continuous improvement. This is the governance backbone for all other IEC 62443 requirements. Without a CSMS, zone and conduit controls lack the management framework to sustain them.
Asset Owner
IEC 62443-3-2
Security Risk Assessment for System Design
Structured risk assessment to identify threats, vulnerabilities, and consequences for each zone and conduit. The output determines the target security level per zone, which then drives control selection under IEC 62443-3-3. The assessment must be documented and periodically reviewed.
Required
IEC 62443-3-3
System Security Requirements and Security Levels
System-level security requirements across seven foundational requirements: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability. Requirements escalate from SL 1 through SL 4 per zone.
Required
IEC 62443-2-4
Security Requirements for Service Providers
Defines the security capabilities that system integrators and service providers must demonstrate when working in OT environments. Asset owners must verify supplier compliance. Increasingly required as a contractual condition in critical infrastructure supply chains under NIS2 Article 21(d).
Supply Chain
IEC 62443-4-1
Secure Product Development Lifecycle
Security practices that product manufacturers must embed in their development lifecycle. Covers security requirements management, secure design, secure implementation, verification and validation, defect management, patch management, and end-of-life provisions. Prerequisite for 62443-4-2 certification.
Manufacturer
IEC 62443-4-2
Technical Security Requirements for Components
Product-level technical security requirements for OT components. Manufacturers seeking IEC 62443-4-2 certification must demonstrate these controls through assessment by an independent accredited testing laboratory. This is a formal certification process, not a self-declaration.
Manufacturer
Security Level Model
Four levels of protection.
IEC 62443 does not require uniform security across every system. Risk assessment per zone determines the target security level. Controls are implemented to reach that target. Over-engineering is as problematic as under-engineering in OT environments.
SL 1
Basic Protection
Protection against casual or unintentional violation. Assumes the threat actor has generic skills, low resources, and low motivation targeting the system.
Typical: Low-criticality auxiliary systems
SL 2
Intentional Violation
Protection against intentional violation using simple means with IACS-specific skills and moderate resources. The most common target security level for operational OT environments.
Typical: Most energy grid OT environments
SL 3
Sophisticated Attack
Protection against sophisticated attacks using OT-specific knowledge and substantial resources. Assumes entity-specific targeting with high motivation.
Typical: Critical generation and transmission
SL 4
State-Level Threat
Protection against intentional violation by a nation-state level threat actor with extended resources and maximum motivation. Applied to the most critical national infrastructure.
Typical: National critical infrastructure
How KairosVector Helps
From gap assessment
to evidenced compliance.
We follow the KairosVector Method for every IEC 62443 engagement. Each phase is detailed below with what happens, what we do, and exactly what you receive at the end of that phase.
Phase 01 – Assess
OT Environment Baseline
We map your OT landscape against IEC 62443 requirements. Every zone is assessed for its current security level versus the target security level required by risk. NIS2 Article 21 obligations are scoped in parallel.
Output: Gap Report and Security Level Baseline per zone
Phase 02 – Design
Zone and Conduit Design
We design your zone and conduit boundary architecture with security level targets defined per zone from the risk assessment. The CSMS programme blueprint covers all IEC 62443-2-1 management system requirements.
Output: Zone and Conduit Design Document
Phase 03 – Deploy
CSMS Implementation
The CSMS is implemented alongside your operations and IT teams. Policies are written for your specific environment and asset profile. Evidence collection is built into the operation of controls from day one.
Output: Operating CSMS and Policies
Phase 04 – Demonstrate
Certification and Audit Readiness
We prepare you for IEC 62443 system assessment or product certification through accredited bodies. For product manufacturers seeking IEC 62443-4-2 certification, we manage the accredited laboratory interface.
Output: Evidence Pack and Certification
Phase 05 – Defend
Ongoing OT Resilience
IEC 62443 compliance is not a one-time exercise. OT environments change as new assets are added, NIS2 guidance evolves, and annual surveillance is required. Retainer engagement keeps your CSMS current.
Output: Continuous Compliance
Phase 01 – OT Environment Baseline
We map your OT landscape against IEC 62443 requirements. Every zone is assessed for its current security level versus the target security level required by risk.
What We Do
- OT asset inventory and network topology mapping
- IEC 62443-2-1 CSMS maturity gap assessment
- IEC 62443-3-2 risk assessment per zone
- Current versus target security level analysis per zone
Deliverable
IEC 62443 gap report with security level baseline per zone, maturity rating.
Documents You Receive
- Gap Assessment Report
- Security Level Baseline Map
- Board-ready Executive Summary
Phase 02 – Zone and Conduit Design
We design your zone and conduit boundary architecture with security level targets defined per zone from the risk assessment. The CSMS programme blueprint covers all IEC 62443-2-1 management system requirements. Controls are sequenced by operational impact so your plant does not stop while you secure it.
What We Do
- Zone and conduit boundary definition and documentation
- Security level target assignment per zone (SL 1 to SL 4)
- CSMS programme blueprint covering IEC 62443-2-1
- OT-specific policy framework structure definition
- IEC 62443-2-4 supplier requirement specification
- Budget and resource plan with realistic timelines
Deliverable
Zone and conduit design document with security level targets, CSMS programme blueprint, and supplier security requirements.
Documents You Receive
- Zone and Conduit Design Document
- CSMS Programme Blueprint
- Security Level Target Matrix
- Supplier Requirements Specification
Phase 03 – CSMS Implementation
The CSMS is implemented alongside your operations and IT teams. Policies are written for your specific environment and asset profile, not adapted from generic templates. Evidence collection is built into the operation of controls from day one, not treated as an audit preparation activity that happens afterwards.
What We Do
- IEC 62443-2-1 CSMS policy and procedure development
- Technical control implementation support per zone
- IEC 62443-3-3 security requirement fulfilment per SL target
- Training for OT engineers, IT/OT bridge teams, and management
Deliverable
Operating CSMS with implemented controls, OT security policy suite, trained personnel, and evidence collection framework.
Documents You Receive
- OT Security Policy Suite
- CSMS Implementation Records
- Training Completion Evidence
- Evidence Collection Framework
Phase 04 – Certification and Audit Readiness
We prepare you for IEC 62443 system assessment or product certification through accredited bodies. For product manufacturers seeking IEC 62443-4-2 certification, we manage the accredited laboratory interface.
What We Do
- Pre-assessment simulation against applicable IEC 62443 standards
- Evidence pack assembly and completeness review
- Accredited laboratory liaison for product certification
- Gap closure before formal accredited body assessment
Deliverable
Certification readiness package for submission to accredited body.
Documents You Receive
- IEC 62443 Evidence Package
- Accredited Body Submission
- Certification Confirmation
Phase 05 – Ongoing OT Resilience
IEC 62443 compliance is not a one-time exercise. OT environments change as new assets are added, and annual surveillance is required. Retainer engagement keeps your CSMS current, your evidence organised, and your security levels maintained as your environment develops.
What We Do
- Annual CSMS review and update
- New asset classification and zone assignment
- Quarterly OT risk register review
- Incident response plan maintenance and tabletop exercises
Deliverable
Continuous OT compliance posture through retainer engagement. CSMS stays current and evidence remains audit-ready.
Documents You Receive
- Annual CSMS Review Report
- Updated Risk Register
- Regulatory Intelligence Briefings
- Incident Response Plan
NIS2
The regulatory connection – IEC 62443 and NIS2 personal liability
IEC 62443 is not a regulatory requirement but NIS2 is. Under NIS2 Article 20, management bodies of essential entities face personal liability for inadequate cybersecurity measures. IEC 62443 gives you documented, auditable evidence across the three core Article 21 obligations: risk management, network and system security, and supply chain controls. One programme. One evidence base. Direct protection against personal liability.
Related
Connected frameworks
and services.
Service
OT Security and IEC 62443
Full engagement service for OT security programme design, CSMS implementation, and IEC 62443 compliance support.
Explore →
Regulation
NIS2 Directive
IEC 62443 CSMS and zone requirements directly support NIS2 Article 21 measures for essential entities in energy and manufacturing.
Read more →
Regulation
EU Cyber Resilience Act
IEC 62443-4-2 is a harmonised standard supporting CRA Annex I essential requirements for connected OT product manufacturers.
Read more →
Ready to assess your IEC 62443 compliance posture?
Not sure where you sit against IEC 62443 requirements? Start with our OT Security Baseline Review a structured initial engagement that gives you a security level map of your environment and your top three compliance gaps.
You leave with:
- Your current security level baseline
- Your top three gap priorities
- A recommended programme approach