Skip to content

Regulations

IEC 62443 in practice: from gap assessment to your first remediation plan

IEC 62443 is the reference standard for industrial control system cybersecurity. How to use it concretely: structure, gap assessment and a first five-step remediation plan.

4 min read

What IEC 62443 is and what it is not

IEC 62443 is the international reference standard for the cybersecurity of industrial control systems (IACS, Industrial Automation and Control Systems). It is developed jointly by ISA (International Society of Automation) and IEC, and is recognised worldwide as the technical framework for OT security.

What it is not: IEC 62443 is not a checklist to fill in to obtain a certification. It is a structured framework covering processes, architectures, technical requirements and maturity criteria, designed to be applied in proportion to the organisation's specific reality.

The confusion stems from its complexity: the standard is made up of four series (General, Policies & Procedures, System, Component), each divided into parts, for a total of more than ten documents. It is not a linear body of rules that you read from start to finish; it is a reference library.

The structure: series, parts and security levels

The four series cover different perspectives:

  • Series 1 (General): terminology, concepts, metrics. The conceptual foundation.
  • Series 2 (Policies & Procedures): oriented towards control system operators. It deals with security programmes, patch management and requirements for suppliers.
  • Series 3 (System): the part most used in practice. It defines security requirements at system level, the zones and conduits model, and the Security Levels (SL) from SL 1 to SL 4.
  • Series 4 (Component): oriented towards component manufacturers. Requirements for secure product development.

The Security Levels are the heart of the model: they define the level of protection required against attackers with different capabilities, from accidental attacks (SL 1) to motivated attackers with sophisticated resources (SL 4). The choice of target SL for each zone is the outcome of the risk analysis.

The gap assessment: how it is carried out

An IEC 62443 gap assessment serves to understand the distance between the organisation's current state and the standard's requirements for the target security level. It is the starting point of any structured programme.

Step 1, Scope and inventory: define what falls within the scope of the assessment. Not necessarily the entire OT environment: you often start from a specific site, a critical production line, or a high-risk system. Then catalogue all the assets within the scope.

Step 2, Defining the target Security Level: for each zone in the environment, define the target SL based on the risk analysis. A control system for a critical infrastructure has different targets from those of a secondary production line.

Step 3, Gathering evidence: assess the current state against the requirements of the standard's "Foundational Requirements" (FR 1-7: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, resource availability). Collection takes place through interviews, configuration inspection, documentation analysis and on-site observation.

Step 4, Gap analysis: for each requirement, determine the level currently reached (SL-A, Security Level Achieved) and compare it with the target (SL-T). The gap between the two is the measure of the work to be done.

Step 5, Reporting and prioritisation: document the gaps with their impact on risk and the feasibility of remediation. Not all gaps have the same urgency; prioritisation must balance risk reduction, implementation cost and operational impact.

Zones, conduits and the security model

The zones and conduits model is IEC 62443's most practical and applicable contribution to OT architectures.

A zone is a logical grouping of assets with similar security requirements and the same level of trust. All assets within a zone can communicate freely with one another; communications between zones must pass through controlled conduits.

A conduit is the authorised communication channel between zones. It is not necessarily a physical device (firewall, DMZ): it can also be a process (physically controlled access, data transfer on isolated media). But in practice, conduits are implemented with firewalls, DMZs and data diode systems where required.

Partitioning into zones follows a simple logic: if an attacker compromises an asset in one zone, the damage should be contained to that zone. Conduits are the boundary controls that prevent propagation.

Where to start: priorities and quick wins

For most organisations approaching IEC 62443 for the first time, the feeling is one of facing a system too elaborate to know where to begin. Some practical pointers:

Do not try to cover everything at once: choose a limited scope (a site, a critical system) and run a thorough assessment on it. The results will give a concrete view of the distance from the standard and a realistic work plan.

Quick wins do exist: some measures have a high impact on risk with low implementation cost. Managing default credentials, basic segmentation between IT and OT, network traffic visibility: these are not advanced IEC 62443 requirements, but their absence is an immediate gap in almost every assessment.

IEC 62443 should not be read alone: part 2-1 (Security Management System) and 3-3 (System Security Requirements) are the documents most used in practice. Start there, preferably with the support of someone experienced in carrying out IEC 62443 assessments in real industrial environments.

The standard is a tool, not a goal. The goal is to reduce cyber risk in the OT environment. IEC 62443 is the most rigorous framework available for doing so in a structured way.

The MON5 angle

An IEC 62443 gap assessment without an inventory has no foundation, as step 1 described above reminds us. This is why MON5 starts from the DISCOVER phase: passive or hybrid asset discovery and network topology, without stopping production, to give the comparison with the standard a factual basis.

The ANALYZE phase then maps zones and conduits according to IEC 62443 and correlates CVE vulnerabilities with EPSS scores and real-world exposure, turning gaps into a prioritised remediation plan. The path is modular: you start from the assessment and activate capabilities in phases. Book an OT assessment to measure the distance from your target Security Level.

Related articles

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

Learn more about the regulation: IEC 62443

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna