Frequently Asked Questions
These questions explain the IEC 62443 boundaries that affect product suppliers, system designers, service providers, asset owners, and legal compliance teams.
Series structure
No. It is a series. Different parts address security programmes, service providers, system risk assessment, system requirements, secure product development, and component requirements.
They make the system boundary visible. A zone groups assets with similar security needs. A conduit describes communication between zones. Without that model, system requirements and security levels can become too vague.
SL-T is a target security level from risk work. SL-C is capability designed into a system or component. SL-A is achieved security level after assessment. The terms need a defined system, zone, conduit, or component scope.
Roles and claims
IEC 62443-4-1 is usually the secure development lifecycle part for product suppliers. IEC 62443-4-2 is usually the technical capability part for IACS components.
System work usually uses IEC 62443-3-2 for risk assessment and IEC 62443-3-3 for system security requirements. Product evidence from 4-1 or 4-2 does not replace system design evidence.
No. Asset-owner programme evidence covers the operating organisation and site lifecycle. Product security evidence covers the supplier product, secure development process, and component capabilities.
Certification and legal use
Not by itself. A certificate proves only what its scheme and scope say it proves. Legal conformity still depends on the applicable law, product, requirement, edition, and recognised standard route.
Yes. It can support secure development, component, system, and service evidence. The product-law file must still explain which legal requirement is being supported and why the IEC 62443 evidence is relevant.