Regulatory Framework – OT Security Standard

IEC 62443
OT and ICS Security

IEC 62443 is the international standard series for operational technology and industrial control system security. It defines security levels, zone and conduit design, and cybersecurity management system requirements for OT environments. Unlike IT security frameworks, it is built for environments where operational continuity is as critical as confidentiality.

Standard Overview

Standard Type

International Standard Series – ISA/IEC

Certification Available

Yes – product level via accredited labs and system level via scheme bodies

Applicable To

OT asset owners, system integrators, component manufacturers

Security Levels

SL 1 to SL 4 defined by risk assessment per zone

Key Regulatory Connection

NIS2 Article 21 – implementation provides direct evidence

What It Is

Understanding
IEC 62443

IEC 62443 is a series of international standards developed by ISA and adopted by IEC that address cybersecurity for industrial automation and control systems. It is structured across four series covering general concepts, policies and procedures, system level security, and component level security.

Unlike IT security frameworks, IEC 62443 is designed specifically for environments where availability and operational continuity are primary constraints. Security controls must be implemented without disrupting the physical processes the OT systems control.

IEC 62443 defines Security Levels from SL 1 through SL 4. Risk assessment per zone determines the target security level, which then drives control selection. This risk-proportionate approach means that not every zone in a facility needs the same level of protection.

NIS2 compliance for energy and manufacturing essential entities is significantly supported by IEC 62443. The CSMS requirements map to NIS2 Article 21 risk management measures. The zone and conduit model supports network security measures. The supplier requirements support Article 21 supply chain measures.

Important Distinction

IEC 62443 certification is issued by independent accredited testing laboratories and scheme bodies. We help you build the compliant OT security programme and prepare for that assessment. We do not issue the certification. The accredited body does after reviewing your implementation.

NIS2 Overlap

IEC 62443-2-1 CSMS supports NIS2 Art.21 risk management. IEC 62443-2-4 supplier requirements support Art.21(d) supply chain measures. IEC 62443-3-3 system requirements support Art.21 network and system security measures. One programme can serve both frameworks.

Standard Structure

How IEC 62443
is organised.

IEC 62443 is not one document. It is a series of standards structured across four categories, each addressing a different audience and scope of obligation.

IEC 62443-1-x

General

Foundational concepts, terminology, security level model, and CSMS concept used across the entire series. Provides the common language for all other standards.

All audiences

IEC 62443-2-x

Policies and Procedures

CSMS requirements for asset owners (62443-2-1) and security requirements for service providers and system integrators (62443-2-4). Governs the management and supply chain layer.

Asset owners and integrators

IEC 62443-3-x

System Level

Security risk assessment per zone (62443-3-2) and system security requirements across seven foundational requirements at each security level (62443-3-3).

System design and assessment

IEC 62443-4-x

Component Level

Secure product development lifecycle for manufacturers (62443-4-1) and technical security requirements for individual components seeking certification (62443-4-2).

Product manufacturers

Who It Applies To

Which organisations
IEC 62443 covers.

OT Asset Owner

Energy and Utility Operators

Grid operators, generators, water utilities, and pipeline operators with ICS and SCADA environments. IEC 62443-2-1 CSMS and IEC 62443-3-2 risk assessment are the primary applicable standards. NIS2 Article 21 creates a parallel compliance driver for most EU operators.

System Integrator

Industrial System Builders

Engineering firms who design, install, and maintain OT systems. IEC 62443-2-4 defines the security requirements they must demonstrate as suppliers. Asset owners increasingly require 62443-2-4 compliance as a procurement condition under NIS2 Article 21(d).

Component Manufacturer

OT Product Manufacturers

OT component and device manufacturers seeking IEC 62443-4-2 product certification through accredited testing laboratories. Product certification is increasingly a requirement for supply into critical infrastructure procurement in the EU and North America.

Key Standards in the Series

What each standard
actually requires.

These are the most frequently applicable IEC 62443 standards for critical infrastructure operators, integrators, and manufacturers. References use the correct IEC 62443 standard numbering, not article notation which applies to directives and regulations.

IEC 62443-2-1

Cybersecurity Management System for Asset Owners

Asset owners must establish, implement, document, and maintain a CSMS covering security policy, risk management, implementation, monitoring, and continuous improvement. This is the governance backbone for all other IEC 62443 requirements. Without a CSMS, zone and conduit controls lack the management framework to sustain them.

Asset Owner

IEC 62443-3-2

Security Risk Assessment for System Design

Structured risk assessment to identify threats, vulnerabilities, and consequences for each zone and conduit. The output determines the target security level per zone, which then drives control selection under IEC 62443-3-3. The assessment must be documented and periodically reviewed.

Required

IEC 62443-3-3

System Security Requirements and Security Levels

System-level security requirements across seven foundational requirements: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability. Requirements escalate from SL 1 through SL 4 per zone.

Required

IEC 62443-2-4

Security Requirements for Service Providers

Defines the security capabilities that system integrators and service providers must demonstrate when working in OT environments. Asset owners must verify supplier compliance. Increasingly required as a contractual condition in critical infrastructure supply chains under NIS2 Article 21(d).

Supply Chain

IEC 62443-4-1

Secure Product Development Lifecycle

Security practices that product manufacturers must embed in their development lifecycle. Covers security requirements management, secure design, secure implementation, verification and validation, defect management, patch management, and end-of-life provisions. Prerequisite for 62443-4-2 certification.

Manufacturer

IEC 62443-4-2

Technical Security Requirements for Components

Product-level technical security requirements for OT components. Manufacturers seeking IEC 62443-4-2 certification must demonstrate these controls through assessment by an independent accredited testing laboratory. This is a formal certification process, not a self-declaration.

Manufacturer

Security Level Model

Four levels of protection.

IEC 62443 does not require uniform security across every system. Risk assessment per zone determines the target security level. Controls are implemented to reach that target. Over-engineering is as problematic as under-engineering in OT environments.

SL 1

Basic Protection

Protection against casual or unintentional violation. Assumes the threat actor has generic skills, low resources, and low motivation targeting the system.

Typical: Low-criticality auxiliary systems

SL 2

Intentional Violation

Protection against intentional violation using simple means with IACS-specific skills and moderate resources. The most common target security level for operational OT environments.

Typical: Most energy grid OT environments

SL 3

Sophisticated Attack

Protection against sophisticated attacks using OT-specific knowledge and substantial resources. Assumes entity-specific targeting with high motivation.

Typical: Critical generation and transmission

SL 4

State-Level Threat

Protection against intentional violation by a nation-state level threat actor with extended resources and maximum motivation. Applied to the most critical national infrastructure.

Typical: National critical infrastructure

How KairosVector Helps

From gap assessment
to evidenced compliance.

We follow the KairosVector Method for every IEC 62443 engagement. Each phase is detailed below with what happens, what we do, and exactly what you receive at the end of that phase.

Phase 01 – Assess

OT Environment Baseline

We map your OT landscape against IEC 62443 requirements. Every zone is assessed for its current security level versus the target security level required by risk. NIS2 Article 21 obligations are scoped in parallel.

Output: Gap Report and Security Level Baseline per zone

Phase 02 – Design

Zone and Conduit Design

We design your zone and conduit boundary architecture with security level targets defined per zone from the risk assessment. The CSMS programme blueprint covers all IEC 62443-2-1 management system requirements.

Output: Zone and Conduit Design Document

Phase 03 – Deploy

CSMS Implementation

The CSMS is implemented alongside your operations and IT teams. Policies are written for your specific environment and asset profile. Evidence collection is built into the operation of controls from day one.

Output: Operating CSMS and Policies

Phase 04 – Demonstrate

Certification and Audit Readiness

We prepare you for IEC 62443 system assessment or product certification through accredited bodies. For product manufacturers seeking IEC 62443-4-2 certification, we manage the accredited laboratory interface.

Output: Evidence Pack and Certification

Phase 05 – Defend

Ongoing OT Resilience

IEC 62443 compliance is not a one-time exercise. OT environments change as new assets are added, NIS2 guidance evolves, and annual surveillance is required. Retainer engagement keeps your CSMS current.

Output: Continuous Compliance

Phase 01 – OT Environment Baseline

We map your OT landscape against IEC 62443 requirements. Every zone is assessed for its current security level versus the target security level required by risk.

What We Do

  • OT asset inventory and network topology mapping
  • IEC 62443-2-1 CSMS maturity gap assessment
  • IEC 62443-3-2 risk assessment per zone
  • Current versus target security level analysis per zone

Deliverable

IEC 62443 gap report with security level baseline per zone, maturity rating.

Documents You Receive

  • Gap Assessment Report
  • Security Level Baseline Map
  • Board-ready Executive Summary

Phase 02 – Zone and Conduit Design

We design your zone and conduit boundary architecture with security level targets defined per zone from the risk assessment. The CSMS programme blueprint covers all IEC 62443-2-1 management system requirements. Controls are sequenced by operational impact so your plant does not stop while you secure it.

What We Do

  • Zone and conduit boundary definition and documentation
  • Security level target assignment per zone (SL 1 to SL 4)
  • CSMS programme blueprint covering IEC 62443-2-1
  • OT-specific policy framework structure definition
  • IEC 62443-2-4 supplier requirement specification
  • Budget and resource plan with realistic timelines

Deliverable

Zone and conduit design document with security level targets, CSMS programme blueprint, and supplier security requirements.

Documents You Receive

  • Zone and Conduit Design Document
  • CSMS Programme Blueprint
  • Security Level Target Matrix
  • Supplier Requirements Specification

Phase 03 – CSMS Implementation

The CSMS is implemented alongside your operations and IT teams. Policies are written for your specific environment and asset profile, not adapted from generic templates. Evidence collection is built into the operation of controls from day one, not treated as an audit preparation activity that happens afterwards.

What We Do

  • IEC 62443-2-1 CSMS policy and procedure development
  • Technical control implementation support per zone
  • IEC 62443-3-3 security requirement fulfilment per SL target
  • Training for OT engineers, IT/OT bridge teams, and management

Deliverable

Operating CSMS with implemented controls, OT security policy suite, trained personnel, and evidence collection framework.

Documents You Receive

  • OT Security Policy Suite
  • CSMS Implementation Records
  • Training Completion Evidence
  • Evidence Collection Framework

Phase 04 – Certification and Audit Readiness

We prepare you for IEC 62443 system assessment or product certification through accredited bodies. For product manufacturers seeking IEC 62443-4-2 certification, we manage the accredited laboratory interface.

What We Do

  • Pre-assessment simulation against applicable IEC 62443 standards
  • Evidence pack assembly and completeness review
  • Accredited laboratory liaison for product certification
  • Gap closure before formal accredited body assessment

Deliverable

Certification readiness package for submission to accredited body.

Documents You Receive

  • IEC 62443 Evidence Package
  • Accredited Body Submission
  • Certification Confirmation

Phase 05 – Ongoing OT Resilience

IEC 62443 compliance is not a one-time exercise. OT environments change as new assets are added, and annual surveillance is required. Retainer engagement keeps your CSMS current, your evidence organised, and your security levels maintained as your environment develops.

What We Do

  • Annual CSMS review and update
  • New asset classification and zone assignment
  • Quarterly OT risk register review
  • Incident response plan maintenance and tabletop exercises

Deliverable

Continuous OT compliance posture through retainer engagement. CSMS stays current and evidence remains audit-ready.

Documents You Receive

  • Annual CSMS Review Report
  • Updated Risk Register
  • Regulatory Intelligence Briefings
  • Incident Response Plan

NIS2

The regulatory connection – IEC 62443 and NIS2 personal liability

IEC 62443 is not a regulatory requirement but NIS2 is. Under NIS2 Article 20, management bodies of essential entities face personal liability for inadequate cybersecurity measures. IEC 62443 gives you documented, auditable evidence across the three core Article 21 obligations: risk management, network and system security, and supply chain controls. One programme. One evidence base. Direct protection against personal liability.

Related

Connected frameworks
and services.

Service

OT Security and IEC 62443

Full engagement service for OT security programme design, CSMS implementation, and IEC 62443 compliance support.

Explore →

Regulation

NIS2 Directive

IEC 62443 CSMS and zone requirements directly support NIS2 Article 21 measures for essential entities in energy and manufacturing.

Read more →

Regulation

EU Cyber Resilience Act

IEC 62443-4-2 is a harmonised standard supporting CRA Annex I essential requirements for connected OT product manufacturers.

Read more →

Ready to assess your IEC 62443 compliance posture?

Not sure where you sit against IEC 62443 requirements? Start with our OT Security Baseline Review a structured initial engagement that gives you a security level map of your environment and your top three compliance gaps.

You leave with:

  • Your current security level baseline
  • Your top three gap priorities
  • A recommended programme approach
Scroll to Top