Standard & Scheme · General Purpose

IEC 62443 — the operating system of OT security

One series covers the plant operator, the system integrator, the product supplier and the service provider — which is why NIS2 supervisors read it as the state of the art and why Europe is aligning it with the CRA right now. Used well, it is three regulations' worth of evidence from one programme.

At a glance

Owner

IEC (with ISA heritage)

European alignment via CEN/CENELEC as EN IEC 62443

Structure

Four tiers of parts

General (1-x), policies (2-x), system (3-x), component (4-x)

Key parts

4-1, 4-2, 3-3, 2-4, 3-2

Secure development, component & system requirements, service providers, risk assessment

Levels

Security Levels 1–4

Graded by attacker capability, from casual to state-grade

Certifications

ISASecure, IECEE CB

SDLA for processes; component and system certifications for products

Regulatory hooks

NIS2, CRA, Machinery Reg.

EN IEC 62443 CRA-alignment work targets the late-2026 window

What it is

One vocabulary for everyone who touches the plant

62443’s structural insight is role separation: the asset owner runs a security programme (2-1) grounded in a zone-and-conduit risk assessment (3-2); the integrator delivers systems meeting target security levels (3-3); the product supplier develops components under a certified lifecycle (4-1) with technical requirements per component type (4-2); service providers align to 2-4. Each role’s evidence is consumable by the next — the series is a supply chain of assurance before it is a list of controls.

The security-level system grades everything against attacker capability, SL1 (casual) to SL4 (state-grade), applied per zone and per requirement rather than per brochure. Certification lives in two ecosystems: ISASecure (SDLA process certification, component and system certifications) and the IECEE CB scheme, both increasingly demanded in tenders as shorthand for “we won’t have to audit you ourselves”.

Its European moment is now: NIS2 supervisors and ENISA point to 62443 as the operational meaning of “state of the art” in industrial environments, and CEN/CENELEC is aligning EN IEC 62443 with CRA essential requirements — targeted at the late-2026 standards window. When that harmonisation lands, 62443 evidence graduates from best practice to presumption of conformity, which changes the economics of every OT security programme built on it.

When it's the right tool

Almost always in OT — the question is which parts, how deep

Product suppliers: 4-1 first

A certified secure development lifecycle is the highest-leverage move — it feeds every component certification, every CRA process requirement, every customer audit.

Operators: 3-2 before controls

Zones, conduits and honestly derived target levels turn NIS2’s “appropriate measures” into a defensible engineering position — including for legacy that cannot be patched.

Integrators & service providers: 2-4 as sales asset

One certification answers the questionnaire flood — and NIS2 entities are contractually pushing supply-chain duties downward every quarter.

Don't cherry-pick controls

Isolated 62443 controls without the risk assessment and maturity model behind them impress no auditor and no regulator. The system is the value.

Where it matters

62443 in your industry

The home domain

The full 62443 backbone: CRA mapping, honest SL targets, NIS2 supervision and the Machinery Regulation’s safety–security merge.

Industrial IoT crossover

Connected industrial devices face RED and CRA alongside 62443-4-2 — one evidence architecture should serve both.

Critical connectivity

Private 5G in plants and telco equipment in OT environments sit exactly on the 62443 / NESAS boundary.

The certification market

ISASecure and IECEE capacity, CRA notified-body scopes for OT categories — the operators’ side of the 62443 economy.

Expert notes

What we tell clients before they commit

The CRA delta is real — close it now

62443-4-1 and 4-2 cover most CRA process and product requirements, but not all: SBOM expectations, EU reporting flows, support-period declarations and some Annex I items have no 62443 home. Until the aligned EN IEC 62443 texts are cited in the OJEU, the standard supports conformity without presuming it. The delta is documentable today; vendors who wait for the harmonised text are betting market access on a committee schedule.

Our position: run the explicit 62443-to-Annex-I mapping, close the gaps in your SDL this year, and treat the future harmonisation as an upgrade — not a prerequisite.

SL-T must fall out of a 3-2 risk assessment, SL-C claims must survive an assessor applying them per requirement, and component SLs mean little outside an architecture that supports them. The recurring industry failure is certified components composed into an uncertifiable system because nobody owned the zone-level rationale. SL3 tender demands deserve scrutiny — sometimes they are risk-based, often they are copy-paste.

Our position: we write SL rationales that an assessor can test, and we will tell you when the right answer to an SL3 requirement is a documented challenge rather than eighteen months of engineering.

OT assurance with the plant floor in view

Gap assessments, SDL certification, SL rationales, ISASecure and CRA routes — thirty minutes to sequence it.

Contact us

Request this document

We’ll send you access by email.