Back to briefings
    Briefing

    IEC 62443 for governance people

    IEC 62443 as a system of roles and decisions: which part binds which role, the concepts a governance reader must own, and where the series gets misread.

    Governance5 Sept 20269 min read

    Directive (EU) 2022/2555IEC 62443-2-4:2023IEC 62443-3-2:2020IEC 62443-3-3:2013IEC 62443-4-1:2018IEC TS 62443-1-1:2009ISO/IEC 27001:2022NIST CSWP 29Regulation (EU) 2024/2847
    On this page

    What it is

    IEC 62443 is a series, not a single standard. Its parts sit in four layers: general, policies and procedures, system, and component. Three roles carry them. The asset owner operates the industrial automation and control system, the integrator builds the automation solution, the supplier develops the product 1. The system part names the same audience, adding service providers and compliance authorities 2.

    Vocabulary sits in IEC TS 62443-1-1:2009, Terminology, concepts and models, a Technical Specification 3. Risk assessment for system design sits in IEC 62443-3-2:2020, the development process in IEC 62443-4-1:2018 4.

    Who is in scope (decision test)

    Five questions. The written answer is the record.

    1. Does the organisation operate an IACS? The term covers personnel, hardware and software able to affect how safely, securely and reliably an industrial process runs 5.
    2. Which role, and therefore which parts? The asset owner works to -2-1, establishing an IACS security programme; the integrator and service provider to IEC 62443-2-4:2023 and -3-2; the product supplier to -4-1 and -4-2. The development part binds the developer and maintainer, not the user 6.
    3. Is there a regulatory driver reaching OT? Article 21(2) of the NIS 2 Directive sets ten all-hazards measures covering the systems' physical environment 7. The Cyber Resilience Act reaches products with a data connection 8. No Annex III category is industrial: items enter by function, as operating systems, switches or firewalls; Annex IV names smart meter gateways 9.
    4. Has a zone and conduit model been done? Assets are grouped into zones and conduits, the grouping determined by risk, with safety-related assets separated 10.
    5. Are target security levels set and owned? A target level is set per zone or conduit, and management accountable for the process approves the assessment 11.
    OutcomeWhat it meansNext step
    In scopeAn IACS exists and a role is heldFix the role, take its parts
    Out of scopeNo industrial process is affectedRecord the reason; re-run after acquisitions
    Needs specialist inputThe role or plant boundary is arguableHave engineering confirm

    The concepts a governance reader must own

    ConceptWhat the text saysSource
    ZoneAssets grouped because they share security requirements; clear border, sub-zones allowed12
    ConduitA logical group of communication channels between two or more zones13
    Security levelThe effectiveness countermeasures and device properties need, from the risk assessed for that zone14
    Target, achieved, capabilityThe target comes from risk assessment; the achieved level reflects what is in place; capability belongs to countermeasures, devices or systems15
    The seven foundational requirementsIdentification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, resource availability16
    The security-level vectorOne value per foundational requirement for a stated domain, not a single score17

    Levels run 0 to 4 against a rising attacker, from casual violation to sophisticated means with extended resources 18. A second scale runs four maturity levels, initial to improving, read per practice 19.

    The eight practices are security management, specification of security requirements, secure by design, and secure implementation. The rest are security verification and validation testing, management of security-related issues, security update management, and security guidelines 20.

    Obligations by part

    PartWho it bindsWhat it asks forArtefactGovernance decision behind it
    IEC TS 62443-1-1:2009Every roleTerminology, concepts and models, with reference levels from process to enterprise 21Glossary and reference modelWhich vocabulary contracts use
    IEC 62443-2-4:2023Service providersSecurity programme requirements for IACS service providers 22Capability statement in the contractWhether the contract names a programme
    IEC 62443-3-2:2020Asset owner and integratorIdentify the system, partition it, assess risk, set the target, document requirements 23Requirements specification, eight sections 24Who owns tolerable risk
    IEC 62443-3-3:2013Integrators and product suppliersSystem requirements tied to the foundational requirements, defining capability levels 16Checklist per zoneWhich target is bought against
    IEC 62443-4-1:2018Product developer and maintainerA secure development lifecycle from requirements definition to product end-of-life 25Process evidence, per practiceWhether selection tests process

    Dates (verified)

    Designation or dateWhat it isSource
    IEC TS 62443-1-1:2009Technical Specification, Edition 1.0, July 20093
    IEC 62443-3-3:2013Edition 1.0, published 2013-08-0726
    IEC 62443-4-1:2018Edition 1.0, published 2018-01-1527
    IEC 62443-3-2:2020Edition 1.0, June 202028
    IEC 62443-2-4:2023Edition 2.0, published 2023-12-15; the 2015 edition is withdrawn22
    2026-09-11Cyber Resilience Act reporting starts29
    2027-12-11General application of that Regulation29

    Where governance people get it wrong

    A security level read as a compliance score. The achieved level is a function of time, falling as countermeasures degrade and vulnerabilities appear. The target is assigned in the assess phase, then defended in the maintain phase 30.

    Zones drawn on the org chart. Grouping runs on risk, criticality, operational function, location, required access, or responsible organisation 31. A departmental boundary is one candidate among six, rarely the one the network agrees to.

    -4-1 treated as the supplier's problem. Article 21(3) of the NIS 2 Directive requires account of each direct supplier's vulnerabilities and secure development procedures 32. That makes -4-1 a buyer's instrument.

    The service-provider part left out of the contract. Integration and maintenance is where remote access, spares and configuration changes arrive.

    An ISMS scope stopping at the plant gate. Where the certified scope excludes the plant, the board's register is not the one carrying process risk.

    Mapping to ISO/IEC 27001 and NIST CSF 2.0

    IEC 62443ISO/IEC 27001:2022 or 27002:2022NIST CSF 2.0Gap
    -3-2 clause 4.3.1, ZCR 2.1 initial risk assessment 33Clause 6.1.2 Information security risk assessment 34Risk Assessment (ID.RA)Consequence stated in safety terms
    -3-2 clause 4.4.2Control 8.22 Segregation of networks 35Technology Infrastructure Resilience (PR.IR)No partition as a risk artefact
    -3-2 clauses 4.6.7, 4.8.2Clause 5.3 Organizational roles, responsibilities and authorities 36Roles, Responsibilities, and Authorities (GV.RR)Accountability tied to the process
    -3-3 foundational requirementsControl 8.20 Networks security 37Identity Management, Authentication, and Access Control (PR.AA)Graded by level, not binary
    -4-1 practicesControl 8.25 Secure development life cycle 38Platform Security (PR.PS)Maturity assessed per practice
    -2-4 programmeControl 5.21 Managing information security in the ICT supply chain 39Cybersecurity Supply Chain Risk Management (GV.SC)Capability sits with the integrator

    Category names are CSF 2.0 Core 40.

    Next 90 days

    WeekActionOwnerOutput
    1-2Answer the five scope questions; list each system under consideration, with its perimeterGovernance leadScope note; system inventory
    2-4Run or refresh the initial risk assessment per systemRisk ownerWorst-case risk per system
    4-6Draw zones and conduits, separating safety-related assetsPlant engineeringZone and conduit drawings
    6-8Set a target level per zone and conduit, as a vectorRisk ownerTarget register
    8-10Put the assessment to management accountable for the processGovernance leadSigned approval
    10-12Open the requirements specification; add the service-provider and development parts to supplier questionsGovernance leadDraft specification; new questionnaire

    References

    1. IEC. IEC TS 62443-1-1:2009 — Industrial communication networks - Network and system security - Part 1-1: Terminology, concepts and models. https://webstore.iec.ch/en/publication/7029 3
    2. IEC. IEC 62443-3-2:2020 — Security for industrial automation and control systems - Part 3-2: Security risk assessment for system design. https://webstore.iec.ch/en/publication/30727 28
    3. IEC. *IEC 62443-3-3:2013 — Industrial communication networks - Network and system security
    4. IEC. IEC 62443-4-1:2018 — Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements. https://webstore.iec.ch/en/publication/33615 27
    5. IEC. IEC 62443-2-4:2023 — Security for industrial automation and control systems - Part 2-4: Security program requirements for IACS service providers. https://webstore.iec.ch/en/publication/67631 22
    6. European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). https://publications.europa.eu/resource/celex/32022L2555 7
    7. European Parliament and Council. Regulation (EU) 2024/2847 (Cyber Resilience Act). https://publications.europa.eu/resource/celex/32024R2847 9
    8. ISO/IEC. ISO/IEC 27001:2022, contents. ISO Online Browsing Platform. https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 41
    9. ISO/IEC. ISO/IEC 27002:2022 — Information security, cybersecurity and privacy protection — Information security controls. https://www.iso.org/standard/75652.html 37
    10. NIST. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://doi.org/10.6028/NIST.CSWP.29 40

    Sources

    1. 1IEC 62443-4-1:2018 Figure 1 and Figure 2, licensed copy · verified 2026-09-05
    2. 2IEC 62443-3-3:2013 clause 0.2, licensed copy · verified 2026-09-05
    3. 3IEC TS 62443-1-1:2009 front matter, licensed copy · verified 2026-09-05
    4. 4IEC 62443-3-2:2020 clause 1 and IEC 62443-4-1:2018 clause 1, licensed copies · verified 2026-09-05
    5. 5IEC TS 62443-1-1:2009 clause 3.2.57, licensed copy · verified 2026-09-05
    6. 6IEC 62443-4-1:2018 Figure 1, Figure 2 and clause 1, licensed copy · verified 2026-09-05
    7. 7EU Publications Office CELEX 32022L2555 Art. 21(2) · verified 2026-09-05
    8. 8EU Publications Office CELEX 32024R2847 Art. 2(1) · verified 2026-09-05
    9. 9EU Publications Office CELEX 32024R2847 Annex III and Annex IV · verified 2026-09-05
    10. 10IEC 62443-3-2:2020 clause 4.4.2 and clause 4.4.4, licensed copy · verified 2026-09-05
    11. 11IEC 62443-3-2:2020 clause 4.6.7 and clause 4.8.2, licensed copy · verified 2026-09-05
    12. 12IEC TS 62443-1-1:2009 clause 3.2.117, licensed copy · verified 2026-09-05
    13. 13IEC 62443-3-2:2020 clause 3.1.3, licensed copy · verified 2026-09-05
    14. 14IEC TS 62443-1-1:2009 clause 3.2.108, licensed copy · verified 2026-09-05
    15. 15IEC TS 62443-1-1:2009 clause 5.11.2, licensed copy · verified 2026-09-05
    16. 16IEC 62443-3-3:2013 clause 1, licensed copy · verified 2026-09-05
    17. 17IEC 62443-3-3:2013 Annex A clause A.3.3, licensed copy · verified 2026-09-05
    18. 18IEC 62443-3-2:2020 Annex A, licensed copy · verified 2026-09-05
    19. 19IEC 62443-4-1:2018 clause 4.2 Table 1, licensed copy · verified 2026-09-05
    20. 20IEC 62443-4-1:2018 clauses 5 to 12, licensed copy · verified 2026-09-05
    21. 21IEC TS 62443-1-1:2009 clause 6.2.2, licensed copy · verified 2026-09-05
    22. 22IEC 62443-2-4:2023 product page, webstore.iec.ch · verified 2026-09-03
    23. 23IEC 62443-3-2:2020 clause 1, licensed copy · verified 2026-09-05
    24. 24IEC 62443-3-2:2020 clause 4.7.2, licensed copy · verified 2026-09-05
    25. 25IEC 62443-4-1:2018 clause 1, licensed copy · verified 2026-09-05
    26. 26IEC 62443-3-3:2013 product page, webstore.iec.ch · verified 2026-09-03
    27. 27IEC 62443-4-1:2018 product page, webstore.iec.ch · verified 2026-09-03
    28. 28IEC 62443-3-2:2020 front matter, licensed copy · verified 2026-09-05
    29. 29EU Publications Office CELEX 32024R2847 Art. 71(2) · verified 2026-09-04
    30. 30IEC TS 62443-1-1:2009 clauses 5.11.2.3 and 5.12.1, licensed copy · verified 2026-09-05
    31. 31IEC 62443-3-2:2020 clause 3.1.25, licensed copy · verified 2026-09-05
    32. 32EU Publications Office CELEX 32022L2555 Art. 21(3) · verified 2026-09-05
    33. 33IEC 62443-3-2:2020 clause 4.3.1, licensed copy · verified 2026-09-05
    34. 34ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03
    35. 35ISO/IEC 27002:2022 control 8.22, licensed copy · verified 2026-09-05
    36. 36ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
    37. 37ISO/IEC 27002:2022 control 8.20, licensed copy · verified 2026-09-05
    38. 38ISO/IEC 27002:2022 control 8.25, licensed copy · verified 2026-09-05
    39. 39ISO/IEC 27002:2022 control 5.21, licensed copy · verified 2026-09-05
    40. 40NIST CSWP 29 Appendix A, nvlpubs.nist.gov · verified 2026-09-05
    41. 41ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03