IEC 62443 (ISA/IEC 62443)
IEC 62443 (ISA/IEC 62443) is a series of international standards that defines cybersecurity requirements for industrial automation and control systems, covering asset owners, system integrators and product suppliers across the system life cycle.
IEC 62443, also published as ISA/IEC 62443, is a series of international standards for the cybersecurity of industrial automation and control systems (IACS). It is developed by the ISA99 committee together with IEC Technical Committee 65 and is organised into four groups: general concepts and terminology, policies and procedures, system-level requirements and component-level requirements. Its core concepts include zones and conduits, security levels, seven foundational requirements and defence in depth.
The series assigns responsibilities to the principal roles in an industrial system's life: asset owners who operate it, product suppliers who build components, and service providers such as system integrators and maintenance contractors. It is widely used in manufacturing, energy, oil and gas, water and building automation as the reference for OT security programmes, procurement specifications and product certification. Key parts include IEC 62443-2-1 for asset-owner security programmes, 62443-3-2 for risk assessment, 62443-3-3 for system requirements, 62443-4-1 for secure product development and 62443-4-2 for component requirements.
IEC 62443 is risk-based rather than tied to particular products, so applying it starts with an inventory, a risk assessment and a zone and conduit model. Products and development processes can be certified, for example through ISASecure or IECEE schemes, and conformance is often written into supplier contracts. It complements ISO/IEC 27001, which addresses information security management at organisation level, and works alongside functional safety standards such as IEC 61508 and IEC 61511.
Key points
- Developed by the ISA99 committee and the IEC as the ISA/IEC 62443 series
- Organised into general, policies and procedures, system and component parts
- Core concepts: zones and conduits, security levels and seven foundational requirements
- Addresses asset owners, product suppliers and service providers such as integrators
- Products and development processes can be certified, for example via ISASecure
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- Zones and ConduitsOT & Industrial Cybersecurity
- IEC 62443 Security Levels (SL)OT & Industrial Cybersecurity
- IEC 62443-3-3 System Security RequirementsOT & Industrial Cybersecurity
- IEC 62443-4-1 Secure Product Development LifecycleOT & Industrial Cybersecurity
- Purdue ModelOT & Industrial Cybersecurity
- ISO/IEC 27001Cybersecurity & Compliance
Terms that refer to IEC 62443 (ISA/IEC 62443)
- CNC ControllerCNC & Precision Machining
- Cyber Resilience Act (CRA)Cybersecurity & Compliance
- Cyber-Physical System (CPS)Industry 4.0 & Manufacturing Operations
- Defence in DepthOT & Industrial Cybersecurity
- Device Provisioning (Onboarding)Industrial IoT & Edge
- DNC (Distributed or Direct Numerical Control)CNC & Precision Machining
- Edge ComputingIndustrial IoT & Edge
- EtherNet/IPPLC & Industrial Control