IT security frameworks assume you can patch on Tuesday and reboot at will. Operational technology, the systems that move water, power, production lines, and increasingly buildings, breaks both assumptions, and IEC 62443 is the standard family written for that reality.
The ideas that matter
62443 is a series, with parts aimed at asset owners, integrators, and product suppliers, but three concepts carry most of its practical weight.
Zones and conduits. Segment the system into zones of equipment with similar criticality and trust, and control the conduits between them. It is network segmentation elevated to a design discipline: the corporate network, the SCADA servers, the PLC layer, and the safety systems do not share one flat network, and everything crossing between zones is deliberate, inventoried, and controlled.
Security levels. Zones are assigned target security levels, SL1 through SL4, scaled against the capability of the attacker to be resisted, from casual misuse up to sophisticated, resourced adversaries. This gives OT projects something IT frameworks lack: a vocabulary for “how much security does this zone need,” decided by consequence, not budget momentum.
Shared responsibility across the supply chain. Separate parts address the product supplier (secure development, component requirements), the integrator (secure integration and service), and the asset owner (program and operations). A certified-secure PLC installed with default passwords by an unvetted integrator illustrates why all three roles have parts.
Why this belongs on a security site
Building and physical security systems are OT. Access controllers, PACS servers, camera networks, elevator controls, and building automation share the OT profile: long lifecycles, patching constraints, vendor remote access, and physical consequences of compromise. The 62443 lens applies almost verbatim: put the PACS and video networks in their own zones, treat the integrator’s remote access as a controlled conduit, demand secure development evidence from product vendors, and match rigour to consequence. Canadian critical infrastructure operators, under growing regulatory attention on cyber, increasingly write 62443 language into specifications that security integrators must answer.
What trips people up
Trying to eat the series whole: it is thousands of pages, and real programs start with segmentation and the integrator/owner split of duties. Assuming IT tooling transfers: scanners and agents that are routine on office networks can disrupt fragile OT gear, and 62443-minded assessment respects that. And certification confusion: products and development processes can be certified against specific parts, so “62443 certified” claims need the same which-part scrutiny as any compliance claim.
How it fits
62443 is the OT counterpart to the IT-centric catalogues: organize the program with the NIST CSF, run baseline hygiene from the CIS Controls, and apply 62443’s zones, levels, and role requirements where systems touch the physical world.
Related guides
References
Last updated 2026-07-24.