Back to glossary

IEC 62443

1 min read

IEC 62443 is the international standards series for the security of industrial automation and control systems. It is the reference an industrial client cites in a tender the way ISO 27001 is cited in corporate IT, and it is written for three distinct audiences: the asset owner, the system integrator and the product supplier.

July 29, 2026
Compartir:

Its central architectural idea is zones and conduits. The plant is divided into zones of assets with a common security requirement, and every communication path between zones is a conduit that is identified and controlled. It is network segmentation expressed as a design obligation rather than a recommendation, and it is what makes the rest of the series applicable to an environment where individual devices cannot be patched or hardened.

The series expresses requirements at security levels, numbered from one to four, defined by the capability of the adversary a zone is expected to withstand rather than by a list of products. Different parts of the series address different audiences: system level requirements for an integrated control system, and component level requirements for the products that go into it, alongside parts covering the supplier’s own development process.

Two things are worth stating for a client who is choosing between references. This does not replace the corporate standard; an industrial group typically has both, applied to different estates. And a supplier claim of conformance needs to name the part and the level, since a component certified at one level says nothing about the system built from it. Where OT and ICS security testing is in scope, the client’s own zone model is what defines the boundaries we work within, which is how the industrial and IoT testing scoped around the zones and conduits the client has defined is set up.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.