IEC 62443

« Back to Glossary Index

Theme: A shared requirements language for distributed lifecycle accountability

Quick definition

IEC 62443 is a series of international standards for cybersecurity in industrial automation and control systems, or IACS. Its parts address concepts, security programmes, system risk and requirements, secure product development and component requirements. Work is distributed among stakeholders; IEC 62443 is not one certification.

Stakeholders and parts

IEC 62443-2-1:2024 covers security programmes for asset owners and operators. IEC 62443-2-4:2023 covers security processes offered by IACS service providers during integration and maintenance. IEC 62443-4-1:2018 applies to product developers and maintainers, not the product integrator or user.

In context: system architecture and risk

Other parts address the system under consideration, zones and conduits, risk at boundaries, and technical system or component requirements. A selected security level is not a general maturity score. Requirements need a defined scope, threat context, consequence and verification method.

A concrete procurement example

For example, a manufacturer modernises a production line. The owner needs a security programme and accepted risk; the integrator needs governed installation and maintenance processes; the product supplier needs secure development and patch management. The contract maps the correct IEC part to each delivery and requires integrated system testing.

Opportunities

The series can provide shared language for accountability, risk, architecture, product requirements and verification across a long IACS lifecycle. It can sharpen procurement and help legacy systems use documented compensating measures when native technical capabilities are unavailable.

Important limitations

A product certificate does not establish that an entire facility, organisation or operating process meets every relevant part. Referring to IEC 62443 without part, edition, scope and verification is insufficient. The series does not prove regulatory compliance or replace applicable law and local risk assessment.

HubMind’s view

Use IEC 62443 as a stakeholder-specific requirements and evidence framework. Start with the system boundary, consequences and responsibilities. Then select relevant parts and editions, allocate requirements among owner, service providers and product suppliers, and define the evidence expected for each requirement.

A practical next step

Take one current security requirement and add the system boundary, responsible stakeholder, IEC part and edition, acceptance criterion and evidence. Check that no certification label substitutes for facility testing, operating processes or assessment against current legal obligations.

Related concepts

Cybersecurity (OT), Network Segmentation, NIS2, OT.

Sources and further reading

Scope and freshness

The IEC 62443 series viewed through current IEC 62443-2-1:2024 Edition 2, IEC 62443-2-4:2023 Edition 2 and IEC 62443-4-1:2018 Edition 1. Other parts contain further system and component requirements. Reviewed 31 August 2026.

« Back to Glossary Index
Contact us