Skip to content

What IEC 62443 is and how it applies to industrial control systems

IEC 62443 is the international standard series (IEC/ISA) dedicated to the cybersecurity of industrial automation and control systems (IACS): PLCs, DCS, SCADA, HMIs and the networks connecting them. Unlike NIS2 or the CRA, it is not a legal obligation but a voluntary technical standard, increasingly required contractually by operators and integrators.

The model is based on zones and conduits: assets are grouped into zones with homogeneous security requirements, while conduits are the communication channels between zones, each with specific controls. Each zone is assigned a target Security Level (SL 0-4) based on its risk profile.

The standard is organised into parts addressing different roles: IEC 62443-2-x for operators' security programme requirements, IEC 62443-3-x for system requirements, IEC 62443-4-x for manufacturers' component requirements. The Foundational Requirements (FR1-FR7) define the fundamental technical capabilities required at each Security Level.

For an industrial plant, applying IEC 62443 means first making the real OT network visible - assets, protocols, communications - then designing zones and conduits on concrete data instead of assumptions, and demonstrating over time compliance with the technical requirements associated with the chosen Security Level.

02OT · ICS · INTERNATIONAL STANDARD

IEC 62443

IEC 62443 - Industrial Automation and Control Systems Security

Reference standard for cybersecurity of industrial automation and control systems (IACS). Defines zones, conduits, security levels (SL 1-4) and requirements for asset owners, system integrators and component suppliers. Applicable to manufacturing, energy, oil & gas, water, building automation.

Key requirements
  • 01Zone and conduit segmentation (62443-3-2)
  • 02Foundational Requirements (FR1-FR7): identification, use control, data integrity, confidentiality, restricted flow, timely response, resource availability
  • 03Risk assessment and Security Level Target definition
  • 04Documented patch and vulnerability management
  • 05Continuous monitoring of OT network integrity
How MON5 helps

MON5 is OT-native: it recognises industrial protocols (Modbus, S7, EtherNet/IP, OPC UA, IEC 61850, DNP3 and more), identifies real zones and conduits from observed traffic, and provides technical evidence on FR1-FR7. From PROTECT up, CVE/EPSS correlation and advanced anomaly detection support higher SL-T on critical assets.

  • Native OT / ICS protocol recognition
  • Zone and conduit map based on real traffic
  • Documentable technical evidence for FR1-FR7
  • Patch management informed by CVE + EPSS scoring
  • IEC 62443 reporting (advanced in the ADVANCED tier)
Key terms
IACS
Industrial Automation and Control System: the set of personnel, hardware, software and policies involved in the safe operation of an industrial process.
Zone
A logical or physical grouping of IACS assets sharing common security requirements and a homogeneous target Security Level.
Conduit
A communication channel connecting two or more zones, subject to specific security controls (e.g. firewalls, unidirectional gateways) to manage flows between zones with different Security Levels.
Security Level (SL)
A protection level, from 0 to 4, expressing resistance to an increasing type and intensity of attack, from simple accidental error (SL1) to sophisticated actors with extended resources (SL4).
Foundational Requirements (FR1-FR7)
The standard's seven categories of fundamental technical requirements (identification and access control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, resource availability).
SUC (System Under Consideration)
The specific control system that is the subject of the risk analysis and the definition of zones and conduits, typically a plant or a production line.
Frequently asked questions
What is IEC 62443 and who does it apply to?+

IEC 62443 is the international standard for industrial automation and control systems (IACS) security. It applies to asset owners and operators, system integrators and component manufacturers in OT environments.

How are zones and conduits defined under IEC 62443?+

Zones group OT assets with similar security requirements (target Security Level). Conduits are the communication channels between zones. MON5 automatically maps topology, zones and conduits from real network traffic.

What Security Level does IEC 62443 require for a manufacturing plant?+

It depends on the risk profile. Most manufacturing plants target SL2 (protection against intentional attacks with moderate resources). MON5 produces FR1-FR7 evidence to demonstrate the achieved Security Level.

Is IEC 62443 a legal requirement?+

No, it is a voluntary standard, but it is increasingly cited as a technical reference in supply contracts, tenders and, indirectly, in regulations such as NIS2 and the CRA that recommend its adoption as good practice.

What is the difference between IEC 62443-2-x, -3-x and -4-x?+

The -2-x parts address plant operators (organisational security programme), the -3-x parts address system designers (technical system requirements and Security Levels), and the -4-x parts address component manufacturers (secure development and technical product requirements).

How long does it take to get IEC 62443 certified?+

It varies widely depending on starting maturity and scope, from a few months for a single well-documented system to over a year for an entire plant with zones and conduits to be mapped from scratch.

Can IEC 62443 and ISO 27001 be adopted together?+

Yes, and it often makes sense to: ISO 27001 provides the management system (ISMS) at the organisational level, while IEC 62443 adds the specific technical requirements for industrial control environments that ISO 27001 addresses only generically.

How does MON5 help define zones and conduits under IEC 62443?+

MON5 passively observes real network traffic and automatically reconstructs topology, assets and communications, providing the objective basis on which to design zones and conduits instead of starting from documentation that is often outdated.

READY FOR THE AUDIT?

Let's figure out what you really need.

Show us the OT perimeter and the regulations you need to cover: we will tell you what MON5 documents directly, where complementary work is needed, and which tier to start from - no hard selling.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna