The IEC 62443 series is how industrial cybersecurity is specified: one family of standards covering the plant owner’s program, the service providers, the systems and the components, written for environments where availability and safety outrank everything.
A family, not a single document. Grown from ISA-99 into an international series, its parts are numbered by audience: the 2-x parts address programs and providers, 3-x the systems, 4-x the products. The trick to reading it: first find your role, then your parts.
The entry point for an asset owner is the 3-2 risk assessment: scope the system, assess initial risk, partition zones and conduits, set targets, assess in detail, document, approve. Seven gated steps that end in the Initial Risk Assessment and the Cybersecurity Requirements Specification. From there, 3-3 turns targets into system requirements, and the program parts keep it alive.
See the workflow in the product →Field note: five zone-partitioning mistakes we keep seeing →None of the laws name your PLC. They demand appropriate, demonstrable security, and IEC 62443 is how OT answers: the risk assessment decides what "appropriate" means for your installation, the evidence makes it demonstrable.
Certification programs exist for products and processes, run by certification bodies. For an asset owner’s site, what you produce is a conformant assessment and its evidence, which is what auditors and customers actually ask for.
27001 governs the management system; IEC 62443 speaks OT: zones, safety, security levels. Most industrial organisations end up with both, one evidence discipline underneath.
Yes. OTRISK references clauses; the licensed text stays in your copies. Budget for the parts your role needs.
With one system and its network drawing. The 3-2 assessment scopes the rest. That’s the point of it.
Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.