Services

IEC 62443 — the technical framework for plant and product

IEC 62443 (more precisely ISA/IEC 62443) is the internationally authoritative series of standards for the cybersecurity of industrial automation and control systems. Unlike general information-security standards, it is built for industry: for controllers that run for decades, for scarce maintenance windows, and for the primacy of availability and plant safety. For manufacturing and automation it is the common denominator — in operation as much as in the product.

Why the standard matters for you

Two developments turn IEC 62443 from optional into expected. First, more and more industrial customers and tenders require evidence against 62443 before they will buy a machine or component. Second, the standard directly supports your regulatory evidence: it provides the technical substance behind NIS2 measures and CRA requirements. Mastering 62443 therefore meets a customer expectation and spares you duplicate work on the other obligations at the same time.

How the series is structured — briefly

The series is divided into parts that address different roles. Part 62443-2-1 describes the security management system for operators. Part 62443-3-3 defines the system requirements for an automation solution. Two parts are central for manufacturers: 62443-4-1 sets out a secure product development process, and 62443-4-2 describes the technical requirements for individual components such as controllers or devices. A single family of standards thus covers both worlds — the operated plant and the shipped product.

Protection levels and zones

Two concepts sit at the heart of the standard. Protection levels (termed "Security Level", SL 1 to SL 4) describe the kind of attacker a system must withstand — from accidental error to a targeted, well-resourced adversary. The zone model divides a plant into bounded areas (zones) and controlled transitions (conduits). Instead of protecting everything equally, each area is assigned the protection level it genuinely needs. That makes security both affordable and defensible.

For operators — assessing the plant

For operators we assess the running environment against the standard: an inventory of all components, a review of zones and transitions, and an evaluation of remote access and the separation between office and control networks. The result is a target picture with a protection level per zone and a prioritised path towards it.

For manufacturers — securing the product

For manufacturers, 62443-4-1 and 4-2 are the technical foundation of your CRA conformity. We help you establish a secure development process and test your components against the standard's requirements. An abstract regulation thus becomes a concrete, auditable product development process.

How we work

We begin with an assessment (evaluating the current state against the relevant parts of the standard), map the findings to protection levels, produce a prioritised action plan and, if you wish, support implementation through to the security architecture. Our principle throughout: recommendations must be implementable on the plant floor and in the product, not only on paper.

Why us

You work directly with a consultant who commands the standard through the ISA/IEC 62443 (IC32) qualification and has applied it across 11 OT audits — and who at the same time provides the regulatory framing for management and the authorities.

IEC 62443 or ISO 27001 — which do we need?

The two standards complement each other; they do not compete. ISO/IEC 27001 orders the organisation and the management system; IEC 62443 addresses the technical security of automation and products. Anyone operating control systems or making connected devices cannot avoid 62443 — ISO 27001 alone falls short here. In practice we build both so that they reinforce each other: the management system provides the organisational frame, the 62443 assessment the technical substance. The result is evidence that satisfies both the authorities and your customers.

Typical findings in practice

In almost every environment we find the same patterns: flat networks with no effective separation between office and control, remote-maintenance access without strong authentication, default passwords in components, no clear picture of one's own assets, and logs that nobody reviews. None of these findings is exotic — and that is exactly why clear prioritisation closes them effectively. The standard helps you not to attempt everything at once, but to raise each zone to the protection level it truly needs.

Effort and process

Effort depends on the size and complexity of your environment or product portfolio. An initial assessment already gives a reliable picture within a few days; the path to the target architecture is then taken in stages, aligned to your maintenance windows and your development schedule. You receive a traceable basis for every step — not a blanket verdict, but prioritised, justified measures.

When an assessment is especially worthwhile

An IEC 62443 assessment is particularly valuable when customers or tenders demand evidence, when you bring a new connected product to market, when a plant is modernised or connected, or when NIS2 and CRA obligations are due anyway. In each of these cases the standard creates a common, auditable yardstick — and spares you answering the same question afresh for every counterpart.

Further reading: Product Security & CRA · OT Security Assessment · Manufacturing & Automation

Request an IEC 62443 assessment

A free intro call, no commitment, a reply within 24 hours.