IEC 62443 EXPLAINED
IEC 62443 Explained: Roles, Zones and Security Levels
What IEC 62443 is and how it works: the four groups of parts, asset owner, service provider and product supplier, zones and conduits, the seven foundational requirements, security levels and two worked examples.

IEC 62443 is the international series of standards for securing industrial automation and control systems (IACS): the PLCs, DCS, SCADA, HMIs, safety systems and networks that run plants, utilities and machines. Explained simply, it does four things. It splits responsibility between three roles (the asset owner, the service provider and the product supplier); it tells you to divide a system into zones and connect them only through controlled conduits; it groups technical requirements under seven foundational requirements; and it rates protection with security levels from 1 to 4. Published jointly as ISA/IEC 62443, it is now the common language of operational technology (OT) security in specifications, audits and product certification.
Facts about the series and ISA's programme were checked on isa.org in October 2026. The standards are sold by ISA and IEC; this guide paraphrases them at concept level.
How the series is organised
The series is grouped by who uses each part, from general concepts down to individual components. ISA's 62443 series page lists the parts and their current editions.
| Group | Key parts (edition) | What they cover | Main user |
|---|---|---|---|
| General | 1-1 (2007) | Terms, concepts and models | Everyone |
| Policies and procedures | 2-1 (2024), 2-2 (TR, 2025), 2-3 (TR, 2015), 2-4 (2018) | Asset owner programme, protection scheme, patching, service providers | Asset owner, service provider |
| System | 3-2 (2020), 3-3 (2013) | Risk assessment for design; system requirements and security levels | Asset owner, integrator |
| Component | 4-1 (2018), 4-2 (2018) | Secure development lifecycle; component technical requirements | Product supplier |
Technical reports (TR) give guidance; standards state requirements that can be assessed. A quick way to find the right part is to ask: who must do this, and at which stage of the system's life?
The three roles
Security in the series is shared, because no single organisation can secure a control system alone.
- Asset owner: runs the plant and owns the risk. Its security programme is part 2-1, and it sets the target security levels from the risk assessment in 3-2.
- Service provider: integrates components into a working system and may maintain it. Its own capabilities, such as handling remote access and patches, are covered by 2-4; the system it delivers must meet 3-3.
- Product supplier: makes controllers, switches and software. It develops them securely under 4-1, with the capabilities defined in 4-2.
One company can hold more than one role. A large automation vendor is a product supplier for its controllers and a service provider when its project team integrates a plant. The role, not the company, decides which part applies.
Zones and conduits
A zone is a group of assets that share the same security requirements. A conduit is the set of communication channels between zones, and it must meet the requirements of the zones it joins. Zoning lets you put strong controls where the risk is high without forcing them onto every device, and it limits how far an attacker can move.
Good zoning follows a few rules: group assets by function and criticality, keep safety systems in their own zone, separate assets maintained by different parties, and treat every path as a conduit, including remote access, wireless links and the laptop or USB stick that carries files. A VLAN on its own is not a zone unless the traffic between it and other zones is controlled.

Worked example: counting conduits
Every connection you allow is a conduit that needs controls, an owner and monitoring, so good designs keep the number small.
Scenario. A packaging line is divided into six zones: enterprise, a demilitarised zone, supervisory, control, safety and a remote access zone. How many conduits would there be if every zone could talk to every other, and how much does a design with five conduits reduce that?
- Every pair of n zones: n x (n - 1) / 2
- For six zones: 6 x 5 / 2 = 15 possible conduits
- Designed conduits: 5
- Reduction: 15 - 5 = 10 paths, which is 10 / 15 = 66.7 percent
Two thirds fewer paths means two thirds fewer rule sets to write, review and monitor, and in this design the enterprise network never talks to the supervisory zone directly.
The seven foundational requirements
Part 3-3 lists system requirements, and part 4-2 component requirements, under the same seven headings, so a system need can be traced straight to the component that meets it.
| FR | Name | Plain-words objective |
|---|---|---|
| FR1 | Identification and authentication control | Know who or what is connecting: people, software and devices |
| FR2 | Use control | Enforce what each one may do: roles, least privilege, session limits |
| FR3 | System integrity | Stop unauthorised changes to software, data and messages |
| FR4 | Data confidentiality | Stop unauthorised reading, in storage and in transit |
| FR5 | Restricted data flow | Segment into zones and conduits; limit unnecessary flows |
| FR6 | Timely response to events | Log, monitor and support a fast response |
| FR7 | Resource availability | Stay available under attack or failure; back up and recover |
Security levels
A security level describes how strong protection is, by the kind of attacker it can resist. A common shorthand: SL 1 protects against mistakes, SL 2 against a casual attacker with ordinary tools, SL 3 against a skilled attacker who knows control systems, and SL 4 against a well-funded, highly motivated team with that knowledge.
Three versions of the level matter. The asset owner sets the target (SL-T) for each zone and conduit; the product supplier or integrator states the capability (SL-C) of what it offers; and the installed system has an achieved level (SL-A), checked after commissioning and during operation. Each is a vector of seven numbers, one per FR. Where capability falls short of the target, you add compensating countermeasures, often at the zone boundary.
Worked example: rating programme maturity
Part 2-1 is about the asset owner's programme, and maturity levels describe how well each requirement is carried out: level 1 when someone remembers, level 2 documented with evidence, level 3 a standard process applied everywhere, level 4 measured and improved.
Scenario. An assessor rates seven programme elements at 3, 2, 2, 1, 3, 2 and 1. The site's goal is level 2 in every element.
- Sum: 3 + 2 + 2 + 1 + 3 + 2 + 1 = 14
- Mean: 14 / 7 = 2.0
- Elements below goal: the two at level 1
- Share meeting the goal: 5 / 7 = 71 percent
The mean is exactly on target, yet two elements fall short. Report the gaps, not the average: an average hides the weak elements an attacker will find.
How the risk assessment ties it together
Part 3-2 sets out a design workflow in plain steps: define the system under consideration, carry out a high-level risk assessment, partition into zones and conduits, compare initial risk with tolerable risk, assess each zone and conduit in detail, document the security requirements, and get the asset owner's approval. The result is a target security level for every zone and conduit, which the integrator then designs to.

Certificates, regulation and where to go next
For people, ISA runs the ISA/IEC 62443 Cybersecurity Certificate Program: the Fundamentals Specialist first, then Risk Assessment, Design and Maintenance Specialist in any order, with the Expert certificate awarded automatically when all four are held. ISA's IC32 course page says the course registration includes the fundamentals exam fee. Those certificate names are ISA's.
Regulation increasingly builds on the series: product rules such as the one described in our post on Cyber Resilience Act reporting obligations point the same way. For a broader free reading list, the NIST SP 800-82 Revision 3 guide to OT security, published in September 2023, is a good companion, and our roundup of free IEC 62443 training lists other no-cost options.
Learn the fundamentals free
The free IEC 62443 Cybersecurity Fundamentals Exam Prep course explains everything above in fourteen study modules mapped to the topics ISA lists for its IC32 course, with lessons from ICSBit Labs, ISA, exida and others, original notes, worked problems and original practice questions. You do not need to buy the standards to follow it. Never use exam dumps; they break ISA's rules and teach nothing you can use on a plant.
It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page. It is not an ISA or IEC certificate, and EDWartens is not affiliated with ISA or IEC. Start the IEC 62443 fundamentals course before you book ISA's exam.
Take the free course
Questions
What is IEC 62443 in simple terms?
IEC 62443 is the international series of standards for securing industrial automation and control systems. It splits responsibility between asset owners, service providers and product suppliers, divides systems into zones and conduits, groups requirements under seven foundational requirements and rates protection with security levels 1 to 4.
What are the parts of IEC 62443?
The series has four groups: general (1-1 terms and models), policies and procedures (2-1 asset owner programme, 2-2 protection scheme, 2-3 patching, 2-4 service providers), system (3-2 risk assessment, 3-3 system requirements) and component (4-1 secure development, 4-2 component requirements).
What are zones and conduits in IEC 62443?
A zone is a group of assets with the same security requirements. A conduit is the set of communication channels between zones and must meet the requirements of the zones it connects. Zoning limits how far an attacker can move and puts strong controls where risk is high.
What are IEC 62443 security levels?
Security levels 1 to 4 rate protection by the attacker it resists, from mistakes at SL 1 to a well-funded, skilled team at SL 4. The asset owner sets a target (SL-T), suppliers state a capability (SL-C), and the installed system has an achieved level (SL-A), each as seven values, one per FR.
Is there an IEC 62443 certification for people?
Yes. ISA runs the ISA/IEC 62443 Cybersecurity Certificate Program: Fundamentals Specialist first, then Risk Assessment, Design and Maintenance Specialist in any order, with the Expert certificate awarded automatically when all four are held. ISA states the certificates do not need renewing.
Is there a free IEC 62443 course with a certificate?
Yes. IEC 62443 Cybersecurity Fundamentals Exam Prep on EDWartens is a free course with a verifiable certificate of completion, mapped to the topics ISA lists for its IC32 course. It is not an ISA or IEC certificate.
Sources
- ISA: ISA/IEC 62443 Series of Standards (read 11 October 2026)
- ISA: ISA/IEC 62443 Cybersecurity Certificate Program (read 11 October 2026)
- ISA: IC32 course description (read 11 October 2026)
- NIST: SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security, September 2023 (read 11 October 2026)
Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.

Iran-Linked PLC Attacks in 2026: CISA's Warning and a UK Power Plant Outage

Purdue Model for ICS Security: The Levels Explained

OT Cybersecurity Explained: IEC 62443, the Purdue Model and Where to Start

Building Automation Cybersecurity: Risks and Standards

Zeek for ICS: Logging Industrial Protocols With ICSNPP

Edge AI in Industrial Automation: When to Run Models on the Plant Floor


