OTRISK
Standards · ISA/IEC 62443

IEC 62443, explained like an engineer.

The IEC 62443 series is how industrial cybersecurity is specified: one family of standards covering the plant owner’s program, the service providers, the systems and the components, written for environments where availability and safety outrank everything.

FAMILY
ISA/IEC 62443
SCOPE
IACS · industrial automation & control
ROLES
asset owner · service provider · supplier
LEVELS
SL 0–4 · ML 1–4

What it is

A family, not a single document. Grown from ISA-99 into an international series, its parts are numbered by audience: the 2-x parts address programs and providers, 3-x the systems, 4-x the products. The trick to reading it: first find your role, then your parts.

Asset owners. IEC 62443-2-1 for the security program, 3-2 for the risk assessment, 3-3 for system requirements.
Service providers. IEC 62443-2-4: the requirement catalogue for integrators and maintenance partners.
Product suppliers. IEC 62443-4-1 for the secure development process, 4-2 for component capabilities.

The concepts that do the work

Zones & conduits
Risk lives in partitions
The system under consideration is partitioned into zones of shared risk, connected by conduits. Requirements attach to zones, not to the plant as one blob.
Security levels
Targets trim scope
SL 1–4 grade capability against increasingly capable attackers. You set a target (SL-T) per zone, and only the requirements your target demands apply.
Maturity levels
For processes
Where the subject is a program (2-1, 2-4, 4-1), ML 1–4 grade how institutionalised the process is.

What it demands

The entry point for an asset owner is the 3-2 risk assessment: scope the system, assess initial risk, partition zones and conduits, set targets, assess in detail, document, approve. Seven gated steps that end in the Initial Risk Assessment and the Cybersecurity Requirements Specification. From there, 3-3 turns targets into system requirements, and the program parts keep it alive.

See the workflow in the product →Field note: five zone-partitioning mistakes we keep seeing →

How it relates to the laws

None of the laws name your PLC. They demand appropriate, demonstrable security, and IEC 62443 is how OT answers: the risk assessment decides what "appropriate" means for your installation, the evidence makes it demonstrable.

LawDutyIEC 62443-3-2 assessmentSL-T per zoneEvidenced requirementsSigned artifacts
Trace your law in the map →

How OTRISK runs it

The tabs are the standard. Open a risk assessment and the workspace reads ZCR 1–7, exactly as IEC 62443-3-2 defines them.
One engine, the whole series. 2-1, 2-4, 3-3, 4-1, 4-2, plus ISO/IEC 27001 and NIST SP 800-82, run as the same owned, reviewed evidence workflow.
References, not reprints. OTRISK cites clause numbers; the standards’ text stays in your licensed copies.

Questions we hear

Can we get "IEC 62443 certified"?

Certification programs exist for products and processes, run by certification bodies. For an asset owner’s site, what you produce is a conformant assessment and its evidence, which is what auditors and customers actually ask for.

IEC 62443 versus ISO 27001?

27001 governs the management system; IEC 62443 speaks OT: zones, safety, security levels. Most industrial organisations end up with both, one evidence discipline underneath.

Do we need to buy the standards?

Yes. OTRISK references clauses; the licensed text stays in your copies. Budget for the parts your role needs.

Where do we start?

With one system and its network drawing. The 3-2 assessment scopes the rest. That’s the point of it.

SOURCES · FACTS VERIFIED 30 JUL 2026
ISA · ISA/IEC 62443 series overview

From standard to signed-off.

Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.

See the risk assessment workflow →