Overview
ISA/IEC 62443 is a family of standards and technical reports for securing industrial automation and control systems, developed by the ISA99 committee and published by the IEC. It's organized in 4 groups. The general parts cover terms and models, the policies and procedures parts cover asset owner and service provider programs, the system parts cover risk assessment and system requirements, and the component parts cover secure product development and technical requirements for components.
The series treats security as a shared job across roles. Asset owners run a security program and assess risk, integrators and service providers bring defined capabilities, and product suppliers build components to a secure development life cycle. Systems are divided into zones of assets with similar risk, linked by conduits that carry communication, and each zone gets a target security level from SL 1 to SL 4. Higher levels resist stronger attackers. Requirements are grouped under 7 foundational requirements, from identification and authentication to resource availability.
Parts are revised on their own schedules. ANSI/ISA-62443-2-1-2024 updated the asset owner program requirements, ISA-TR62443-2-2-2025 added guidance on a protection scheme, and IEC lists IEC 62443-3-3:2013 as the current edition of the system requirements. Certification is available through ISASecure, which requires certification bodies accredited to ISO/IEC 17065, and through the IECEE scheme. In Canada, IEC 62443 sits alongside NERC CIP for the electricity sector and guidance from the Canadian Centre for Cyber Security on operational technology.
Who it applies to in Canada
Asset owners, system integrators, service providers, and product suppliers involved with industrial automation and control systems (IACS) and other operational technology. It's used in energy, utilities, oil and gas, manufacturing, water, transportation, and building systems.
Canadian utilities, pipelines, mines, and manufacturers specify IEC 62443 when buying control systems and services, and Canadian OT vendors use certification to sell into those markets and abroad. The Canadian Centre for Cyber Security has warned that threats to operational technology are a national security issue for Canada's critical infrastructure.
Controls at a glance
The series is organized in 4 groups of parts, and its system and component requirements are built on 7 foundational requirements and 4 security levels.
General (62443-1-x)
- Shared terms, concepts, and reference models
- IACS roles, such as asset owner and supplier
- Security levels, zones, and conduits as core concepts
ISA-62443-1-1-2007 and IEC TS 62443-1-1 are the base documents.
Policies and procedures (62443-2-x)
- Security program requirements for IACS asset owners (2-1)
- Protection scheme for evaluating IACS security (2-2)
- Patch management in the IACS environment (2-3)
- Security program requirements for IACS service providers (2-4)
System (62443-3-x)
- Security technologies for IACS (3-1)
- Risk assessment for system design (3-2)
- Partition the system into zones and conduits (3-2)
- System security requirements and security levels (3-3)
Component (62443-4-x)
- Secure product development life cycle for suppliers (4-1)
- Technical security requirements for IACS components (4-2)
- Requirements for software, embedded, host, and network devices
Foundational requirements (7)
- Identification and authentication control
- Use control
- System integrity
- Data confidentiality
- Restricted data flow
- Timely response to events
- Resource availability
Security levels (SL 1 to SL 4)
- SL 1 protects against casual or accidental violation
- SL 2 resists intentional attacks with simple means
- SL 3 resists sophisticated attacks with moderate resources
- SL 4 resists sophisticated attacks with extended resources
- Target, capability, and achieved levels are compared per zone
Zones and conduits
- Group assets with shared security requirements into zones
- Define conduits for communication between zones
- Assign a target security level to each zone
- Document zone and conduit requirements for designers
Secure development practices (4-1)
- Security management of the development process
- Specifying security requirements
- Secure by design and secure implementation
- Security verification and validation testing
- Managing security issues and security updates
- Security guidelines for product users
Certification and assessment
Products, systems, and supplier development processes are certified against specific parts, for example ISASecure CSA against 62443-4-2, SSA against 62443-3-3, and SDLA against 62443-4-1. ISASecure also offers assessment of asset owner and integrator programs against parts 2-1, 2-4, 3-2, and 3-3. Asset owners usually show conformance through independent assessments and procurement requirements.
Dates to know
- 2013-08
- IEC 62443-3-3:2013 published, system security requirements and security levels
- 2024
- ANSI/ISA-62443-2-1-2024 issued, updating asset owner security program requirements
- 2025
- ISA-TR62443-2-2-2025 issued on the IACS security protection scheme
Resources
Official texts and free tools for IEC 62443. Links open the publisher’s site.
- ISA/IEC 62443 series of standards, ISA
- IEC 62443 overview, IEC Systems Committee on Smart Energy
- IEC 62443-3-3:2013, IEC
- ISASecure certification programs, ISA Security Compliance Institutetool
- ISA Global Cybersecurity Alliance, ISAguidance
- Cyber threat bulletin on operational technology, Canadian Centre for Cyber Securityguidance
- Industrial control systems, US Cybersecurity and Infrastructure Security Agencyguidance
Need help? Browse the directory or read the guides.
References
- ISA/IEC 62443 series of standards, ISA
- IEC 62443 overview, IEC Systems Committee on Smart Energy
- ISASecure certification programs, ISA Security Compliance Institute
- Cyber threat bulletin on operational technology, Canadian Centre for Cyber Security
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.