IEC / ISA 62443

Industrial Cybersecurity
Standards Framework

The international standard series for securing Industrial Automation and Control Systems (IACS) — from corporate policy to fieldbus component. Applicable to every stakeholder in an OT environment.

OT / ICS Security Risk-Based Framework Asset Owner Guidance System Integrator Requirements Component Certification SOCI Act & AESCSF Alignment

What is IEC 62443?

Originally developed by ISA99 and adopted jointly by IEC and ISA, IEC 62443 is a multi-part standard series that defines a framework for securing Industrial Automation and Control Systems across their entire lifecycle. It addresses the people, processes, and technology required to establish and maintain a defensible OT security posture.

🏭

Scope

Covers IACS used in critical infrastructure — energy, water, manufacturing, oil & gas, transportation, pharmaceuticals, and building automation.

📐

Structure

Six series of documents addressing general concepts, operational policies, system design, component requirements, and evaluation methodology.

🎯

Risk-Based

Defines four Security Levels (SL 1–4) matched to threat severity, allowing proportionate security investment relative to actual risk.

🤝

Multi-Stakeholder

Distinct requirements for asset owners, system integrators, and product manufacturers — each role has a dedicated body of normative guidance.

🏅

Certification

Underpins globally recognised certification schemes (ISASecure, TÜV, BSI) for both products and management systems.

⚖️

Regulatory Alignment

In Australia, supports compliance with the SOCI Act, AESCSF, and ACSC Essential Eight. Also referenced by the EU NIS2 Directive, NERC CIP, and other international frameworks as the preferred technical standard for OT cybersecurity.

Three Primary Audiences

IEC 62443 deliberately separates obligations by role. The same system is viewed through three lenses — each with its own set of normative requirements.

Asset Owners

Organisations that own and operate IACS. Responsible for security risk assessments, security management systems, patch management, and supplier qualification. Primarily addressed by Series 2.

System Integrators

Companies that design, build, integrate, and commission IACS solutions on behalf of asset owners. Required to conduct risk assessments and meet system-level security requirements. Primarily addressed by Series 3.

Product Manufacturers

Vendors supplying hardware, software, and firmware components used in IACS (PLCs, RTUs, HMIs, historians, network devices). Subject to secure product development lifecycle requirements in Series 4.

Need help implementing IEC 62443 in your organisation? Get in touch ↗