IEC 62443: Industrial and OT Security

The standard family for securing operational technology: zones, conduits, security levels, and what it means for building and security systems.

StandardIEC 62443 series
Applies toAsset owners, system integrators, and product suppliers in industrial automation and, increasingly, building and physical security systems.
When it appliesVoluntary but contractually required in industrial procurement; referenced in critical infrastructure regulation and OT-heavy specifications.

IT security frameworks assume you can patch on Tuesday and reboot at will. Operational technology, the systems that move water, power, production lines, and increasingly buildings, breaks both assumptions, and IEC 62443 is the standard family written for that reality.

The ideas that matter

62443 is a series, with parts aimed at asset owners, integrators, and product suppliers, but three concepts carry most of its practical weight.

Zones and conduits. Segment the system into zones of equipment with similar criticality and trust, and control the conduits between them. It is network segmentation elevated to a design discipline: the corporate network, the SCADA servers, the PLC layer, and the safety systems do not share one flat network, and everything crossing between zones is deliberate, inventoried, and controlled.

Security levels. Zones are assigned target security levels, SL1 through SL4, scaled against the capability of the attacker to be resisted, from casual misuse up to sophisticated, resourced adversaries. This gives OT projects something IT frameworks lack: a vocabulary for “how much security does this zone need,” decided by consequence, not budget momentum.

Shared responsibility across the supply chain. Separate parts address the product supplier (secure development, component requirements), the integrator (secure integration and service), and the asset owner (program and operations). A certified-secure PLC installed with default passwords by an unvetted integrator illustrates why all three roles have parts.

Why this belongs on a security site

Building and physical security systems are OT. Access controllers, PACS servers, camera networks, elevator controls, and building automation share the OT profile: long lifecycles, patching constraints, vendor remote access, and physical consequences of compromise. The 62443 lens applies almost verbatim: put the PACS and video networks in their own zones, treat the integrator’s remote access as a controlled conduit, demand secure development evidence from product vendors, and match rigour to consequence. Canadian critical infrastructure operators, under growing regulatory attention on cyber, increasingly write 62443 language into specifications that security integrators must answer.

What trips people up

Trying to eat the series whole: it is thousands of pages, and real programs start with segmentation and the integrator/owner split of duties. Assuming IT tooling transfers: scanners and agents that are routine on office networks can disrupt fragile OT gear, and 62443-minded assessment respects that. And certification confusion: products and development processes can be certified against specific parts, so “62443 certified” claims need the same which-part scrutiny as any compliance claim.

How it fits

62443 is the OT counterpart to the IT-centric catalogues: organize the program with the NIST CSF, run baseline hygiene from the CIS Controls, and apply 62443’s zones, levels, and role requirements where systems touch the physical world.

Related guides

This is a plain-language guide, not the standard. It paraphrases and interprets; it does not reproduce the text. Requirements change between editions and provinces modify the codes that reference them. For design, installation, or compliance decisions, work from the current official text and your authority having jurisdiction.

References

  1. IEC 62443 series, industrial communication networks and system securityInternational Electrotechnical Commission · retrieved 2026-07-24
  2. ISA/IEC 62443 series of standardsInternational Society of Automation · retrieved 2026-07-24

Last updated 2026-07-24.