IEC 62443
IEC 62443 — Security for Industrial Automation and Control Systems
IEC 62443 — Sicherheit industrieller Automatisierungs- und Steuerungssysteme
IEC 62443 is the authoritative series of standards for the cybersecurity of industrial automation and control systems (IACS). Unlike pure IT standards, it explicitly addresses the particularities of operational technology and distributes responsibility across all parties — operators, integrators and manufacturers. In the OT world it is what ISO 27001 is in classic IT.
History & facts. The series grew out of the work of the ISA (originally as ISA-99) and was developed together with the IEC into the international standard IEC 62443. Central concepts are the division of a plant into zones and conduits to separate trust areas, and graduated Security Levels (SL 1-4) that describe the desired protection level against differently capable attackers. The series addresses various roles across the lifecycle in a differentiated way.
Outlook & recommendation. With the NIS2 extension to industry and energy suppliers and the CRA for products, IEC 62443 is increasingly moving from a best-practice framework to a de-facto expectation. For operators, starting with zoning and passive monitoring is pragmatic — many OT systems tolerate no active intervention. Monitoring and securing such environments is part of NEOSEC's core business.