Overview
IEC 62443 is a standards series for industrial automation and control systems. It is not a single product checklist. It separates cybersecurity by role, system boundary, lifecycle stage, risk level, and component capability.
IEC 62443 topic map
The series is built for IACS, not only for devices on a network. Public ISA and ISAGCA material describes IACS as a lifecycle concern involving technology, people, work processes, safety, reliability, integrity, and security. That is why IEC 62443 assigns different evidence to asset owners, product suppliers, integration service providers, maintenance service providers, and system designers.
Series structure
Start here when the question is which part applies to an asset owner programme, service provider, system design, secure development lifecycle, or component.
Zones and security levels
Use this page for the system under consideration, zones, conduits, risk assessment, SL-T, SL-C, and SL-A.
Secure development
IEC 62443-4-1 belongs to the product supplier lifecycle for hardware, software, and firmware used in IACS.
Component requirements
IEC 62443-4-2 expresses technical component capability requirements through the seven foundational requirements.
System requirements
IEC 62443-3-3 applies the foundational requirements at control system level, together with the zones and conduits from system design.
Certification and conformity
Certificates and harmonised standards need their own scope. A component, process, system, service capability, and legal product file are not the same assessment object.
Reading order
The safest reading order follows the question being asked. A legal file, a component certificate, and a deployed system review should not start from the same part.
- Use Series structure to identify the role and part: asset owner, service provider, system designer, product supplier, or component.
- Use Zones, conduits, and security levels once the system boundary, operational environment, and risk question are known.
- Use System requirements when the claim is about a deployed or designed control system, not only a supplier product.
- Use Secure product development when the claim is about the supplier lifecycle behind a product.
- Use Component requirements when the claim is about an embedded device, host device, network device, software application, or control-system component.
Use beside product laws
IEC 62443 can support product-law evidence, but it does not replace the law. A product-law file still needs the applicable legal requirement, the product or system scope, the standard edition, and the exact claim being made. Certification and conformity claims are handled on the dedicated page.