# What is IEC 62443?

> IEC 62443 is a series of international standards and technical reports for cybersecurity of industrial automation and control systems (IACS).

- Canonical URL: https://yellowcube.eu/glossary/iec-62443/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Developed through ISA99 and IEC TC 65/WG 10, it addresses terminology, security programs, service providers, system risk and requirements, secure product development, and components. Different parts apply to asset owners, integrators, service providers, product suppliers, and lifecycle stages.

Applying IEC 62443 begins by identifying the system and roles, selecting applicable parts, and using risk assessment to define requirements. IEC 62443-3-2 addresses partitioning the system under consideration into zones and conduits, assessing risk, and documenting target security levels. IEC 62443-3-3 defines system security requirements associated with foundational requirements and capability security levels.

### Key points

- **Select the relevant document:** “IEC 62443 compliant” is incomplete without the applicable part, edition, role, system or product scope, requirements, and assessment basis.
- **Use zones and conduits:** Group assets with compatible security needs, define controlled communication paths, assess risk for each, and document the target security level and requirements.
- **Distinguish security levels:** Target, capability, and achieved security levels answer different questions; they are not a generic one-to-four maturity score for an organization.
- **Treat security as a lifecycle:** Asset-owner programs, supplier development practices, service delivery, system integration, maintenance, patching, incident handling, and decommissioning involve different responsibilities.
- **Important limitation:** IEC 62443 is not a single product certificate or a shortcut to secure operation. A component certificate does not establish that an integrated system, site program, configuration, or operating process conforms. Cybersecurity measures must also be engineered so they do not undermine functional safety or required availability.

### Related terms

[Operational technology (OT) security](<https://yellowcube.eu/glossary/operational-technology-security/>) · [Industrial control system (ICS)](<https://yellowcube.eu/glossary/industrial-control-system/>) · [Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Safety instrumented system (SIS)](<https://yellowcube.eu/glossary/safety-instrumented-system/>)

### Sources

[ISA: ISA/IEC 62443 Series of Standards](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards) · [IEC 62443-3-2:2020](https://webstore.iec.ch/en/publication/30727) · [IEC 62443-3-3:2013](https://webstore.iec.ch/en/publication/7033)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

