IEC 62443 for governance people
IEC 62443 as a system of roles and decisions: which part binds which role, the concepts a governance reader must own, and where the series gets misread.
Governance5 Sept 20269 min read
On this page
What it is
IEC 62443 is a series, not a single standard. Its parts sit in four layers: general, policies and procedures, system, and component. Three roles carry them. The asset owner operates the industrial automation and control system, the integrator builds the automation solution, the supplier develops the product 1. The system part names the same audience, adding service providers and compliance authorities 2.
Vocabulary sits in IEC TS 62443-1-1:2009, Terminology, concepts and models, a Technical Specification 3. Risk assessment for system design sits in IEC 62443-3-2:2020, the development process in IEC 62443-4-1:2018 4.
Who is in scope (decision test)
Five questions. The written answer is the record.
- Does the organisation operate an IACS? The term covers personnel, hardware and software able to affect how safely, securely and reliably an industrial process runs 5.
- Which role, and therefore which parts? The asset owner works to -2-1, establishing an IACS security programme; the integrator and service provider to IEC 62443-2-4:2023 and -3-2; the product supplier to -4-1 and -4-2. The development part binds the developer and maintainer, not the user 6.
- Is there a regulatory driver reaching OT? Article 21(2) of the NIS 2 Directive sets ten all-hazards measures covering the systems' physical environment 7. The Cyber Resilience Act reaches products with a data connection 8. No Annex III category is industrial: items enter by function, as operating systems, switches or firewalls; Annex IV names smart meter gateways 9.
- Has a zone and conduit model been done? Assets are grouped into zones and conduits, the grouping determined by risk, with safety-related assets separated 10.
- Are target security levels set and owned? A target level is set per zone or conduit, and management accountable for the process approves the assessment 11.
| Outcome | What it means | Next step |
|---|---|---|
| In scope | An IACS exists and a role is held | Fix the role, take its parts |
| Out of scope | No industrial process is affected | Record the reason; re-run after acquisitions |
| Needs specialist input | The role or plant boundary is arguable | Have engineering confirm |
The concepts a governance reader must own
| Concept | What the text says | Source |
|---|---|---|
| Zone | Assets grouped because they share security requirements; clear border, sub-zones allowed | 12 |
| Conduit | A logical group of communication channels between two or more zones | 13 |
| Security level | The effectiveness countermeasures and device properties need, from the risk assessed for that zone | 14 |
| Target, achieved, capability | The target comes from risk assessment; the achieved level reflects what is in place; capability belongs to countermeasures, devices or systems | 15 |
| The seven foundational requirements | Identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, resource availability | 16 |
| The security-level vector | One value per foundational requirement for a stated domain, not a single score | 17 |
Levels run 0 to 4 against a rising attacker, from casual violation to sophisticated means with extended resources 18. A second scale runs four maturity levels, initial to improving, read per practice 19.
The eight practices are security management, specification of security requirements, secure by design, and secure implementation. The rest are security verification and validation testing, management of security-related issues, security update management, and security guidelines 20.
Obligations by part
| Part | Who it binds | What it asks for | Artefact | Governance decision behind it |
|---|---|---|---|---|
| IEC TS 62443-1-1:2009 | Every role | Terminology, concepts and models, with reference levels from process to enterprise 21 | Glossary and reference model | Which vocabulary contracts use |
| IEC 62443-2-4:2023 | Service providers | Security programme requirements for IACS service providers 22 | Capability statement in the contract | Whether the contract names a programme |
| IEC 62443-3-2:2020 | Asset owner and integrator | Identify the system, partition it, assess risk, set the target, document requirements 23 | Requirements specification, eight sections 24 | Who owns tolerable risk |
| IEC 62443-3-3:2013 | Integrators and product suppliers | System requirements tied to the foundational requirements, defining capability levels 16 | Checklist per zone | Which target is bought against |
| IEC 62443-4-1:2018 | Product developer and maintainer | A secure development lifecycle from requirements definition to product end-of-life 25 | Process evidence, per practice | Whether selection tests process |
Dates (verified)
| Designation or date | What it is | Source |
|---|---|---|
| IEC TS 62443-1-1:2009 | Technical Specification, Edition 1.0, July 2009 | 3 |
| IEC 62443-3-3:2013 | Edition 1.0, published 2013-08-07 | 26 |
| IEC 62443-4-1:2018 | Edition 1.0, published 2018-01-15 | 27 |
| IEC 62443-3-2:2020 | Edition 1.0, June 2020 | 28 |
| IEC 62443-2-4:2023 | Edition 2.0, published 2023-12-15; the 2015 edition is withdrawn | 22 |
| 2026-09-11 | Cyber Resilience Act reporting starts | 29 |
| 2027-12-11 | General application of that Regulation | 29 |
Where governance people get it wrong
A security level read as a compliance score. The achieved level is a function of time, falling as countermeasures degrade and vulnerabilities appear. The target is assigned in the assess phase, then defended in the maintain phase 30.
Zones drawn on the org chart. Grouping runs on risk, criticality, operational function, location, required access, or responsible organisation 31. A departmental boundary is one candidate among six, rarely the one the network agrees to.
-4-1 treated as the supplier's problem. Article 21(3) of the NIS 2 Directive requires account of each direct supplier's vulnerabilities and secure development procedures 32. That makes -4-1 a buyer's instrument.
The service-provider part left out of the contract. Integration and maintenance is where remote access, spares and configuration changes arrive.
An ISMS scope stopping at the plant gate. Where the certified scope excludes the plant, the board's register is not the one carrying process risk.
Mapping to ISO/IEC 27001 and NIST CSF 2.0
| IEC 62443 | ISO/IEC 27001:2022 or 27002:2022 | NIST CSF 2.0 | Gap |
|---|---|---|---|
| -3-2 clause 4.3.1, ZCR 2.1 initial risk assessment 33 | Clause 6.1.2 Information security risk assessment 34 | Risk Assessment (ID.RA) | Consequence stated in safety terms |
| -3-2 clause 4.4.2 | Control 8.22 Segregation of networks 35 | Technology Infrastructure Resilience (PR.IR) | No partition as a risk artefact |
| -3-2 clauses 4.6.7, 4.8.2 | Clause 5.3 Organizational roles, responsibilities and authorities 36 | Roles, Responsibilities, and Authorities (GV.RR) | Accountability tied to the process |
| -3-3 foundational requirements | Control 8.20 Networks security 37 | Identity Management, Authentication, and Access Control (PR.AA) | Graded by level, not binary |
| -4-1 practices | Control 8.25 Secure development life cycle 38 | Platform Security (PR.PS) | Maturity assessed per practice |
| -2-4 programme | Control 5.21 Managing information security in the ICT supply chain 39 | Cybersecurity Supply Chain Risk Management (GV.SC) | Capability sits with the integrator |
Category names are CSF 2.0 Core 40.
Next 90 days
| Week | Action | Owner | Output |
|---|---|---|---|
| 1-2 | Answer the five scope questions; list each system under consideration, with its perimeter | Governance lead | Scope note; system inventory |
| 2-4 | Run or refresh the initial risk assessment per system | Risk owner | Worst-case risk per system |
| 4-6 | Draw zones and conduits, separating safety-related assets | Plant engineering | Zone and conduit drawings |
| 6-8 | Set a target level per zone and conduit, as a vector | Risk owner | Target register |
| 8-10 | Put the assessment to management accountable for the process | Governance lead | Signed approval |
| 10-12 | Open the requirements specification; add the service-provider and development parts to supplier questions | Governance lead | Draft specification; new questionnaire |
References
- IEC. IEC TS 62443-1-1:2009 — Industrial communication networks - Network and system security - Part 1-1: Terminology, concepts and models. https://webstore.iec.ch/en/publication/7029 3
- IEC. IEC 62443-3-2:2020 — Security for industrial automation and control systems - Part 3-2: Security risk assessment for system design. https://webstore.iec.ch/en/publication/30727 28
- IEC. *IEC 62443-3-3:2013 — Industrial communication networks - Network and system security
- Part 3-3: System security requirements and security levels*. https://webstore.iec.ch/en/publication/7033 26
- IEC. IEC 62443-4-1:2018 — Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements. https://webstore.iec.ch/en/publication/33615 27
- IEC. IEC 62443-2-4:2023 — Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers. https://webstore.iec.ch/en/publication/67631 22
- European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). https://publications.europa.eu/resource/celex/32022L2555 7
- European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). https://publications.europa.eu/resource/celex/32024R2847 9
- ISO/IEC. ISO/IEC 27001:2022, contents. ISO Online Browsing Platform. https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 41
- ISO/IEC. ISO/IEC 27002:2022 — Information security, cybersecurity and privacy protection — Information security controls. https://www.iso.org/standard/75652.html 37
- NIST. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://doi.org/10.6028/NIST.CSWP.29 40
Sources
- 1IEC 62443-4-1:2018 Figure 1 and Figure 2, licensed copy · verified 2026-09-05
- 2IEC 62443-3-3:2013 clause 0.2, licensed copy · verified 2026-09-05
- 3IEC TS 62443-1-1:2009 front matter, licensed copy · verified 2026-09-05
- 4IEC 62443-3-2:2020 clause 1 and IEC 62443-4-1:2018 clause 1, licensed copies · verified 2026-09-05
- 5IEC TS 62443-1-1:2009 clause 3.2.57, licensed copy · verified 2026-09-05
- 6IEC 62443-4-1:2018 Figure 1, Figure 2 and clause 1, licensed copy · verified 2026-09-05
- 7EU Publications Office CELEX 32022L2555 Art. 21(2) · verified 2026-09-05
- 8EU Publications Office CELEX 32024R2847 Art. 2(1) · verified 2026-09-05
- 9EU Publications Office CELEX 32024R2847 Annex III and Annex IV · verified 2026-09-05
- 10IEC 62443-3-2:2020 clause 4.4.2 and clause 4.4.4, licensed copy · verified 2026-09-05
- 11IEC 62443-3-2:2020 clause 4.6.7 and clause 4.8.2, licensed copy · verified 2026-09-05
- 12IEC TS 62443-1-1:2009 clause 3.2.117, licensed copy · verified 2026-09-05
- 13IEC 62443-3-2:2020 clause 3.1.3, licensed copy · verified 2026-09-05
- 14IEC TS 62443-1-1:2009 clause 3.2.108, licensed copy · verified 2026-09-05
- 15IEC TS 62443-1-1:2009 clause 5.11.2, licensed copy · verified 2026-09-05
- 16IEC 62443-3-3:2013 clause 1, licensed copy · verified 2026-09-05
- 17IEC 62443-3-3:2013 Annex A clause A.3.3, licensed copy · verified 2026-09-05
- 18IEC 62443-3-2:2020 Annex A, licensed copy · verified 2026-09-05
- 19IEC 62443-4-1:2018 clause 4.2 Table 1, licensed copy · verified 2026-09-05
- 20IEC 62443-4-1:2018 clauses 5 to 12, licensed copy · verified 2026-09-05
- 21IEC TS 62443-1-1:2009 clause 6.2.2, licensed copy · verified 2026-09-05
- 22IEC 62443-2-4:2023 product page, webstore.iec.ch · verified 2026-09-03
- 23IEC 62443-3-2:2020 clause 1, licensed copy · verified 2026-09-05
- 24IEC 62443-3-2:2020 clause 4.7.2, licensed copy · verified 2026-09-05
- 25IEC 62443-4-1:2018 clause 1, licensed copy · verified 2026-09-05
- 26IEC 62443-3-3:2013 product page, webstore.iec.ch · verified 2026-09-03
- 27IEC 62443-4-1:2018 product page, webstore.iec.ch · verified 2026-09-03
- 28IEC 62443-3-2:2020 front matter, licensed copy · verified 2026-09-05
- 29EU Publications Office CELEX 32024R2847 Art. 71(2) · verified 2026-09-04
- 30IEC TS 62443-1-1:2009 clauses 5.11.2.3 and 5.12.1, licensed copy · verified 2026-09-05
- 31IEC 62443-3-2:2020 clause 3.1.25, licensed copy · verified 2026-09-05
- 32EU Publications Office CELEX 32022L2555 Art. 21(3) · verified 2026-09-05
- 33IEC 62443-3-2:2020 clause 4.3.1, licensed copy · verified 2026-09-05
- 34ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03
- 35ISO/IEC 27002:2022 control 8.22, licensed copy · verified 2026-09-05
- 36ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
- 37ISO/IEC 27002:2022 control 8.20, licensed copy · verified 2026-09-05
- 38ISO/IEC 27002:2022 control 8.25, licensed copy · verified 2026-09-05
- 39ISO/IEC 27002:2022 control 5.21, licensed copy · verified 2026-09-05
- 40NIST CSWP 29 Appendix A, nvlpubs.nist.gov · verified 2026-09-05
- 41ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03