62443’s structural insight is role separation: the asset owner runs a security programme (2-1) grounded in a zone-and-conduit risk assessment (3-2); the integrator delivers systems meeting target security levels (3-3); the product supplier develops components under a certified lifecycle (4-1) with technical requirements per component type (4-2); service providers align to 2-4. Each role’s evidence is consumable by the next — the series is a supply chain of assurance before it is a list of controls.
The security-level system grades everything against attacker capability, SL1 (casual) to SL4 (state-grade), applied per zone and per requirement rather than per brochure. Certification lives in two ecosystems: ISASecure (SDLA process certification, component and system certifications) and the IECEE CB scheme, both increasingly demanded in tenders as shorthand for “we won’t have to audit you ourselves”.
Its European moment is now: NIS2 supervisors and ENISA point to 62443 as the operational meaning of “state of the art” in industrial environments, and CEN/CENELEC is aligning EN IEC 62443 with CRA essential requirements — targeted at the late-2026 standards window. When that harmonisation lands, 62443 evidence graduates from best practice to presumption of conformity, which changes the economics of every OT security programme built on it.