home / frameworks / iec-62443

// International standards

ISA/IEC 62443 series

The ISA/IEC 62443 series sets security requirements for industrial automation and control systems across asset owners, service providers, and product suppliers. It uses zones, conduits, and security levels, and certification is available for products, systems, and development processes.

International

Overview

ISA/IEC 62443 is a family of standards and technical reports for securing industrial automation and control systems, developed by the ISA99 committee and published by the IEC. It's organized in 4 groups. The general parts cover terms and models, the policies and procedures parts cover asset owner and service provider programs, the system parts cover risk assessment and system requirements, and the component parts cover secure product development and technical requirements for components.

The series treats security as a shared job across roles. Asset owners run a security program and assess risk, integrators and service providers bring defined capabilities, and product suppliers build components to a secure development life cycle. Systems are divided into zones of assets with similar risk, linked by conduits that carry communication, and each zone gets a target security level from SL 1 to SL 4. Higher levels resist stronger attackers. Requirements are grouped under 7 foundational requirements, from identification and authentication to resource availability.

Parts are revised on their own schedules. ANSI/ISA-62443-2-1-2024 updated the asset owner program requirements, ISA-TR62443-2-2-2025 added guidance on a protection scheme, and IEC lists IEC 62443-3-3:2013 as the current edition of the system requirements. Certification is available through ISASecure, which requires certification bodies accredited to ISO/IEC 17065, and through the IECEE scheme. In Canada, IEC 62443 sits alongside NERC CIP for the electricity sector and guidance from the Canadian Centre for Cyber Security on operational technology.

Who it applies to in Canada

Asset owners, system integrators, service providers, and product suppliers involved with industrial automation and control systems (IACS) and other operational technology. It's used in energy, utilities, oil and gas, manufacturing, water, transportation, and building systems.

Canadian utilities, pipelines, mines, and manufacturers specify IEC 62443 when buying control systems and services, and Canadian OT vendors use certification to sell into those markets and abroad. The Canadian Centre for Cyber Security has warned that threats to operational technology are a national security issue for Canada's critical infrastructure.

Controls at a glance

The series is organized in 4 groups of parts, and its system and component requirements are built on 7 foundational requirements and 4 security levels.

General (62443-1-x)

  • Shared terms, concepts, and reference models
  • IACS roles, such as asset owner and supplier
  • Security levels, zones, and conduits as core concepts

ISA-62443-1-1-2007 and IEC TS 62443-1-1 are the base documents.

Policies and procedures (62443-2-x)

  • Security program requirements for IACS asset owners (2-1)
  • Protection scheme for evaluating IACS security (2-2)
  • Patch management in the IACS environment (2-3)
  • Security program requirements for IACS service providers (2-4)

System (62443-3-x)

  • Security technologies for IACS (3-1)
  • Risk assessment for system design (3-2)
  • Partition the system into zones and conduits (3-2)
  • System security requirements and security levels (3-3)

Component (62443-4-x)

  • Secure product development life cycle for suppliers (4-1)
  • Technical security requirements for IACS components (4-2)
  • Requirements for software, embedded, host, and network devices

Foundational requirements (7)

  • Identification and authentication control
  • Use control
  • System integrity
  • Data confidentiality
  • Restricted data flow
  • Timely response to events
  • Resource availability

Security levels (SL 1 to SL 4)

  • SL 1 protects against casual or accidental violation
  • SL 2 resists intentional attacks with simple means
  • SL 3 resists sophisticated attacks with moderate resources
  • SL 4 resists sophisticated attacks with extended resources
  • Target, capability, and achieved levels are compared per zone

Zones and conduits

  • Group assets with shared security requirements into zones
  • Define conduits for communication between zones
  • Assign a target security level to each zone
  • Document zone and conduit requirements for designers

Secure development practices (4-1)

  • Security management of the development process
  • Specifying security requirements
  • Secure by design and secure implementation
  • Security verification and validation testing
  • Managing security issues and security updates
  • Security guidelines for product users

Certification and assessment

Products, systems, and supplier development processes are certified against specific parts, for example ISASecure CSA against 62443-4-2, SSA against 62443-3-3, and SDLA against 62443-4-1. ISASecure also offers assessment of asset owner and integrator programs against parts 2-1, 2-4, 3-2, and 3-3. Asset owners usually show conformance through independent assessments and procurement requirements.

Dates to know

2013-08
IEC 62443-3-3:2013 published, system security requirements and security levels
2024
ANSI/ISA-62443-2-1-2024 issued, updating asset owner security program requirements
2025
ISA-TR62443-2-2-2025 issued on the IACS security protection scheme

Resources

Official texts and free tools for IEC 62443. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. ISA/IEC 62443 series of standards, ISA
  2. IEC 62443 overview, IEC Systems Committee on Smart Energy
  3. ISASecure certification programs, ISA Security Compliance Institute
  4. Cyber threat bulletin on operational technology, Canadian Centre for Cyber Security