IEC 62443 EXPLAINED

IEC 62443 Explained: Roles, Zones and Security Levels

What IEC 62443 is and how it works: the four groups of parts, asset owner, service provider and product supplier, zones and conduits, the seven foundational requirements, security levels and two worked examples.

By EDWartens engineering team 11 October 2026 9 min
IEC 62443 Explained: Roles, Zones and Security Levels

IEC 62443 is the international series of standards for securing industrial automation and control systems (IACS): the PLCs, DCS, SCADA, HMIs, safety systems and networks that run plants, utilities and machines. Explained simply, it does four things. It splits responsibility between three roles (the asset owner, the service provider and the product supplier); it tells you to divide a system into zones and connect them only through controlled conduits; it groups technical requirements under seven foundational requirements; and it rates protection with security levels from 1 to 4. Published jointly as ISA/IEC 62443, it is now the common language of operational technology (OT) security in specifications, audits and product certification.

Facts about the series and ISA's programme were checked on isa.org in October 2026. The standards are sold by ISA and IEC; this guide paraphrases them at concept level.

How the series is organised

The series is grouped by who uses each part, from general concepts down to individual components. ISA's 62443 series page lists the parts and their current editions.

GroupKey parts (edition)What they coverMain user
General1-1 (2007)Terms, concepts and modelsEveryone
Policies and procedures2-1 (2024), 2-2 (TR, 2025), 2-3 (TR, 2015), 2-4 (2018)Asset owner programme, protection scheme, patching, service providersAsset owner, service provider
System3-2 (2020), 3-3 (2013)Risk assessment for design; system requirements and security levelsAsset owner, integrator
Component4-1 (2018), 4-2 (2018)Secure development lifecycle; component technical requirementsProduct supplier

Technical reports (TR) give guidance; standards state requirements that can be assessed. A quick way to find the right part is to ask: who must do this, and at which stage of the system's life?

The three roles

Security in the series is shared, because no single organisation can secure a control system alone.

  • Asset owner: runs the plant and owns the risk. Its security programme is part 2-1, and it sets the target security levels from the risk assessment in 3-2.
  • Service provider: integrates components into a working system and may maintain it. Its own capabilities, such as handling remote access and patches, are covered by 2-4; the system it delivers must meet 3-3.
  • Product supplier: makes controllers, switches and software. It develops them securely under 4-1, with the capabilities defined in 4-2.

One company can hold more than one role. A large automation vendor is a product supplier for its controllers and a service provider when its project team integrates a plant. The role, not the company, decides which part applies.

Zones and conduits

A zone is a group of assets that share the same security requirements. A conduit is the set of communication channels between zones, and it must meet the requirements of the zones it joins. Zoning lets you put strong controls where the risk is high without forcing them onto every device, and it limits how far an attacker can move.

Good zoning follows a few rules: group assets by function and criticality, keep safety systems in their own zone, separate assets maintained by different parties, and treat every path as a conduit, including remote access, wireless links and the laptop or USB stick that carries files. A VLAN on its own is not a zone unless the traffic between it and other zones is controlled.

IEC 62443 in five building blocks
IEC 62443 in five building blocks

Worked example: counting conduits

Every connection you allow is a conduit that needs controls, an owner and monitoring, so good designs keep the number small.

Scenario. A packaging line is divided into six zones: enterprise, a demilitarised zone, supervisory, control, safety and a remote access zone. How many conduits would there be if every zone could talk to every other, and how much does a design with five conduits reduce that?

  1. Every pair of n zones: n x (n - 1) / 2
  2. For six zones: 6 x 5 / 2 = 15 possible conduits
  3. Designed conduits: 5
  4. Reduction: 15 - 5 = 10 paths, which is 10 / 15 = 66.7 percent

Two thirds fewer paths means two thirds fewer rule sets to write, review and monitor, and in this design the enterprise network never talks to the supervisory zone directly.

The seven foundational requirements

Part 3-3 lists system requirements, and part 4-2 component requirements, under the same seven headings, so a system need can be traced straight to the component that meets it.

FRNamePlain-words objective
FR1Identification and authentication controlKnow who or what is connecting: people, software and devices
FR2Use controlEnforce what each one may do: roles, least privilege, session limits
FR3System integrityStop unauthorised changes to software, data and messages
FR4Data confidentialityStop unauthorised reading, in storage and in transit
FR5Restricted data flowSegment into zones and conduits; limit unnecessary flows
FR6Timely response to eventsLog, monitor and support a fast response
FR7Resource availabilityStay available under attack or failure; back up and recover

Security levels

A security level describes how strong protection is, by the kind of attacker it can resist. A common shorthand: SL 1 protects against mistakes, SL 2 against a casual attacker with ordinary tools, SL 3 against a skilled attacker who knows control systems, and SL 4 against a well-funded, highly motivated team with that knowledge.

Three versions of the level matter. The asset owner sets the target (SL-T) for each zone and conduit; the product supplier or integrator states the capability (SL-C) of what it offers; and the installed system has an achieved level (SL-A), checked after commissioning and during operation. Each is a vector of seven numbers, one per FR. Where capability falls short of the target, you add compensating countermeasures, often at the zone boundary.

“3. IEC 62443 Standards Explained | Structure, Evolution & Key Parts” by ICSBit Labs, 10 min. Played from the creator's own YouTube channel; the video belongs to them.

Worked example: rating programme maturity

Part 2-1 is about the asset owner's programme, and maturity levels describe how well each requirement is carried out: level 1 when someone remembers, level 2 documented with evidence, level 3 a standard process applied everywhere, level 4 measured and improved.

Scenario. An assessor rates seven programme elements at 3, 2, 2, 1, 3, 2 and 1. The site's goal is level 2 in every element.

  1. Sum: 3 + 2 + 2 + 1 + 3 + 2 + 1 = 14
  2. Mean: 14 / 7 = 2.0
  3. Elements below goal: the two at level 1
  4. Share meeting the goal: 5 / 7 = 71 percent

The mean is exactly on target, yet two elements fall short. Report the gaps, not the average: an average hides the weak elements an attacker will find.

How the risk assessment ties it together

Part 3-2 sets out a design workflow in plain steps: define the system under consideration, carry out a high-level risk assessment, partition into zones and conduits, compare initial risk with tolerable risk, assess each zone and conduit in detail, document the security requirements, and get the asset owner's approval. The result is a target security level for every zone and conduit, which the integrator then designs to.

The 3-2 design workflow, paraphrased
The 3-2 design workflow, paraphrased

Certificates, regulation and where to go next

For people, ISA runs the ISA/IEC 62443 Cybersecurity Certificate Program: the Fundamentals Specialist first, then Risk Assessment, Design and Maintenance Specialist in any order, with the Expert certificate awarded automatically when all four are held. ISA's IC32 course page says the course registration includes the fundamentals exam fee. Those certificate names are ISA's.

Regulation increasingly builds on the series: product rules such as the one described in our post on Cyber Resilience Act reporting obligations point the same way. For a broader free reading list, the NIST SP 800-82 Revision 3 guide to OT security, published in September 2023, is a good companion, and our roundup of free IEC 62443 training lists other no-cost options.

Learn the fundamentals free

The free IEC 62443 Cybersecurity Fundamentals Exam Prep course explains everything above in fourteen study modules mapped to the topics ISA lists for its IC32 course, with lessons from ICSBit Labs, ISA, exida and others, original notes, worked problems and original practice questions. You do not need to buy the standards to follow it. Never use exam dumps; they break ISA's rules and teach nothing you can use on a plant.

It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page. It is not an ISA or IEC certificate, and EDWartens is not affiliated with ISA or IEC. Start the IEC 62443 fundamentals course before you book ISA's exam.

Take the free course

Questions

What is IEC 62443 in simple terms?

IEC 62443 is the international series of standards for securing industrial automation and control systems. It splits responsibility between asset owners, service providers and product suppliers, divides systems into zones and conduits, groups requirements under seven foundational requirements and rates protection with security levels 1 to 4.

What are the parts of IEC 62443?

The series has four groups: general (1-1 terms and models), policies and procedures (2-1 asset owner programme, 2-2 protection scheme, 2-3 patching, 2-4 service providers), system (3-2 risk assessment, 3-3 system requirements) and component (4-1 secure development, 4-2 component requirements).

What are zones and conduits in IEC 62443?

A zone is a group of assets with the same security requirements. A conduit is the set of communication channels between zones and must meet the requirements of the zones it connects. Zoning limits how far an attacker can move and puts strong controls where risk is high.

What are IEC 62443 security levels?

Security levels 1 to 4 rate protection by the attacker it resists, from mistakes at SL 1 to a well-funded, skilled team at SL 4. The asset owner sets a target (SL-T), suppliers state a capability (SL-C), and the installed system has an achieved level (SL-A), each as seven values, one per FR.

Is there an IEC 62443 certification for people?

Yes. ISA runs the ISA/IEC 62443 Cybersecurity Certificate Program: Fundamentals Specialist first, then Risk Assessment, Design and Maintenance Specialist in any order, with the Expert certificate awarded automatically when all four are held. ISA states the certificates do not need renewing.

Is there a free IEC 62443 course with a certificate?

Yes. IEC 62443 Cybersecurity Fundamentals Exam Prep on EDWartens is a free course with a verifiable certificate of completion, mapped to the topics ISA lists for its IC32 course. It is not an ISA or IEC certificate.

Sources

Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.