OT & UTILITIES
What Is IEC 62443?
DEFINITION
IEC 62443 is a series of international standards for securing industrial automation and control systems, developed through ISA and published by the IEC. It defines security requirements for asset owners, service providers, and product suppliers, organized around zones, conduits, and four security levels. It is the most widely referenced OT security standard across manufacturing, energy, utilities, and other industrial sectors.
IEC 62443 is a multi-part series of standards for the security of industrial automation and control systems (IACS), developed through ISA as ISA/IEC 62443 and published by the International Electrotechnical Commission. It assigns requirements to three roles: asset owners who operate industrial environments, service providers who integrate and maintain them, and product suppliers who build the components. Core concepts include zones and conduits for network segmentation and four security levels (SL 1 through SL 4) that scale defenses to the sophistication of the expected attacker.
Unlike NERC CIP, IEC 62443 is not a regulation. It is a voluntary standard that functions as the common language of OT security across manufacturing, energy, water, pharmaceuticals, and building automation, and it increasingly appears in procurement requirements, insurance questionnaires, and regulatory guidance worldwide.
The practical implication for an industrial operator is that IEC 62443 provides a ready-made reference architecture for a defensible OT program: risk assessment per 62443-3-2, system security requirements per 62443-3-3, and component expectations per 62443-4-2. Buyers can also require 62443 certifications from vendors instead of writing custom security specifications into every contract.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →