Series Structure
IEC 62443 is organised around shared responsibility. The first decision is not which checklist to fill in. It is which role, lifecycle stage, system boundary, and assessment object the claim is about.
Role split
The main roles are asset owner, integration service provider, maintenance service provider, and product supplier. ISAGCA explains that a role is not necessarily the same thing as an organisation. One organisation can hold several roles, and one role can be split across several organisations.
Asset owner
Accountable for the IACS and usually the operator of the IACS and equipment under control.
Integration service provider
Designs, installs, configures, tests, commissions, and hands over an Automation Solution.
Maintenance service provider
Provides support and maintenance activities for an Automation Solution after or around handover.
Product supplier
Develops and supports hardware or software products, including control systems, embedded devices, host devices, network devices, and software applications.
Main parts
The part number usually reveals the level of the claim. Part 2 is mainly programme and service process, Part 3 is system analysis and system requirements, Part 4 is product development and component capability, and Part 6 material supports evaluation methodology.
IEC 62443-2-1:2024 addresses the asset owner security programme for an IACS in operation. IEC states that asset owner includes the operator in this context. The subject is policy and procedure around IACS security, not a set of native technical features that every legacy system must already contain.
This part is often relevant when the reader asks how an operating site governs roles, risk methods, patch constraints, compensating measures, supplier responsibilities, and long-lived systems.
IEC 62443-2-4:2023 addresses security-related processes that IACS service providers can offer to an asset owner during integration and maintenance of an Automation Solution. IEC describes these capabilities as policy, procedure, practice, and personnel related.
This part is the natural home for system integrator and maintenance provider capability claims. It is not a product technical certificate and it is not the asset owner's operating programme.
IEC 62443-3-2:2020 establishes requirements for defining the system under consideration, partitioning it into zones and conduits, assessing risk for each zone and conduit, establishing SL-T, and documenting security requirements.
IEC 62443-3-3:2013 provides detailed control system requirements tied to the seven foundational requirements. It is used with the zones and conduits of the system under consideration when developing target security levels for a specific asset.
IEC 62443-4-1:2018 applies to the developer and maintainer of products used in IACS. IEC describes its lifecycle as covering security requirements definition, secure design, secure implementation, verification and validation, defect management, patch management, and product end-of-life.
IEC 62443-4-2:2019 applies to IACS components. It defines component requirements and component security capability levels through the seven foundational requirements from IEC TS 62443-1-1.
IEC TS 62443-6-1:2024 is an evaluation methodology for IEC 62443-2-4. IEC says it supports repeatable and reproducible evaluation results in first-party, second-party, or third-party conformity assessment activity. It does not replace the 2-4 requirements.
Source status
The page uses public IEC, ISA, and ISAGCA descriptions. Full requirements remain in the standards themselves. Do not infer clause compliance from a public overview, a product name, a certificate logo, or a generic statement that the organisation follows IEC 62443.
- Edition matters: IEC 62443-2-1 is listed by IEC as 2024; IEC 62443-2-4 is listed by IEC as 2023, while some existing certification material still refers to 2015 and AMD1:2017.
- Assessment scope matters: process capability, product capability, system capability, service-provider capability, and application of capabilities are different claims.
- Legal effect matters: an IEC or ISA publication is not the same thing as an OJ-cited harmonised standard for CRA presumption of conformity.