IEC 62443 explained for asset owners

Updated 15 September 2026 · 8 minute read

IEC 62443 is the international series of standards for the security of industrial automation and control systems. It is long, it is written for three different audiences at once, and most of it will never apply to you. This guide picks out the parts an asset owner needs.

How the series is organised

The series is split into four groups. The general parts (62443-1-x) set the vocabulary and concepts. The policies and procedures parts (62443-2-x) describe the security programme an asset owner runs and what a service provider must do. The system parts (62443-3-x) cover risk assessment, system design and the technical requirements of a control system. The component parts (62443-4-x) are for product suppliers: secure development and product requirements.

An asset owner lives mostly in 62443-2-1 (your security programme), 62443-3-2 (risk assessment and the design of zones and conduits) and 62443-3-3 (the system requirements at each security level). The rest is how you hold your integrators and vendors to account.

Zones and conduits

The central idea is to divide the control system into zones: groups of assets that share the same security requirements because they do the same job and face the same consequences if compromised. A safety system, a turbine controller and an engineering workstation are not the same zone.

A conduit is the communication path between zones. Every conduit is a place where a control can be applied: a firewall, a data diode, a jump host, a protocol filter. Segmentation in 62443 terms is deciding the zones, drawing the conduits and enforcing them.

Security levels

Each zone gets a target security level from 1 to 4. The levels describe the adversary the zone must resist: casual or accidental misuse at level 1; an intentional attacker with low resources and generic skills at level 2; a sophisticated attacker with moderate resources and control-system skills at level 3; a highly resourced, state-level attacker at level 4.

The target level is set by consequence. A zone whose compromise could hurt someone or stop a plant for weeks needs a higher level than a reporting historian. 62443-3-3 then lists the technical requirements a system needs to meet each level, grouped under seven foundational requirements: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability.

What an assessment produces

  • A zone and conduit model of your estate, with each zone's target security level and the reason for it.
  • A gap analysis: the achieved level of each zone against its target, requirement by requirement.
  • A risk register that ties each gap to a consequence in the plant, not just a control name.
  • A prioritised programme: the changes, the order, and what each one buys you.

How it fits the other frameworks

IEC 62443 is a control-system standard, not a governance framework. It sits comfortably under a programme framework such as AESCSF, the NIST Cybersecurity Framework or ISO/IEC 27001, and it is the vocabulary most OT regulators use when they talk about segmentation and trust levels. India's Bureau of Indian Standards has adopted the series as Indian Standards, and the CEA power sector regulations' requirement to segment OT by trust level is a zone-and-conduit design by another name.

Sources
  • IEC 62443 series, in particular parts 1-1, 2-1, 3-2 and 3-3

Questions we get asked

Can we be certified to IEC 62443?
Products and service providers can be certified against the component and service parts. Asset owners generally are not certified; they assess and improve against the series. An assessment report from an independent party is what most boards and regulators want to see.
Do we need to reach security level 3 everywhere?
No. Levels are set per zone by consequence. Many plants end up with a small number of high-level zones and a larger number at level 1 or 2. Spending the effort where the consequence is highest is the point.

Want this applied to your plant?

Tell us the site, the systems and the regulator. A consultant will reply, not a sales queue.