The international standard series for securing Industrial Automation and Control Systems (IACS) — from corporate policy to fieldbus component. Applicable to every stakeholder in an OT environment.
Originally developed by ISA99 and adopted jointly by IEC and ISA, IEC 62443 is a multi-part standard series that defines a framework for securing Industrial Automation and Control Systems across their entire lifecycle. It addresses the people, processes, and technology required to establish and maintain a defensible OT security posture.
Covers IACS used in critical infrastructure — energy, water, manufacturing, oil & gas, transportation, pharmaceuticals, and building automation.
Six series of documents addressing general concepts, operational policies, system design, component requirements, and evaluation methodology.
Defines four Security Levels (SL 1–4) matched to threat severity, allowing proportionate security investment relative to actual risk.
Distinct requirements for asset owners, system integrators, and product manufacturers — each role has a dedicated body of normative guidance.
Underpins globally recognised certification schemes (ISASecure, TÜV, BSI) for both products and management systems.
In Australia, supports compliance with the SOCI Act, AESCSF, and ACSC Essential Eight. Also referenced by the EU NIS2 Directive, NERC CIP, and other international frameworks as the preferred technical standard for OT cybersecurity.
IEC 62443 deliberately separates obligations by role. The same system is viewed through three lenses — each with its own set of normative requirements.
Organisations that own and operate IACS. Responsible for security risk assessments, security management systems, patch management, and supplier qualification. Primarily addressed by Series 2.
Companies that design, build, integrate, and commission IACS solutions on behalf of asset owners. Required to conduct risk assessments and meet system-level security requirements. Primarily addressed by Series 3.
Vendors supplying hardware, software, and firmware components used in IACS (PLCs, RTUs, HMIs, historians, network devices). Subject to secure product development lifecycle requirements in Series 4.
Need help implementing IEC 62443 in your organisation? Get in touch ↗