IEC 62443 · Process certification
IEC 62443. Cybersecurity for industrial control systems
The IEC 62443 series of standards defines cybersecurity requirements for industrial automation and control systems across their entire lifecycle.
Overview
What is it about?
IEC 62443 is an internationally coordinated series of standards for the security of Industrial Automation and Control Systems (IACS). It addresses the specific requirements of operational technology (OT), where availability and process integrity often take priority over classic IT priorities and where plants are operated over decades.
The series does not treat security as an isolated measure but as a shared responsibility of operators, integrators and product manufacturers. Key concepts are the division of the plant into zones and conduits, the definition of Security Levels (SL 1 to SL 4) according to attacker strength, and a lifecycle-oriented approach with seven Foundational Requirements.
Purpose & benefit
Certification demonstrates that processes for securing industrial control systems are established in conformity with the standard. It supports compliance with regulatory requirements such as NIS 2 and the Cyber Resilience Act and builds trust between operators, integrators and manufacturers.
What's included
- Zone and conduit model for segmenting plants and defining transitions
- Determination and demonstration of Security Levels (SL-T, SL-C, SL-A) based on a risk assessment
- The seven Foundational Requirements, including access control, use control and system integrity
- Secure product development process per IEC 62443-4-1 (Secure Development Lifecycle)
- Technical security requirements for components per IEC 62443-4-2
- Security management for operators (IEC 62443-2-1) including patch and vulnerability management
For whom
Is this right for you?
The series addresses operators of industrial plants and critical infrastructure, system integrators, and manufacturers of automation components and controllers. It is especially relevant for sectors such as energy, water, manufacturing, chemicals and mechanical engineering.
Your benefits
What it does for you
- Structured, standard-conform evidence of OT security across the entire lifecycle
- Clear delineation of roles between operator, integrator and manufacturer in the supply chain
- Objective proof of trust towards customers, operators and supervisory authorities
Our role
How we work
- 1Planning and conducting certification audits to assess the conformity of your management system with the requirements of the standard
- 2Independent decision on certification based on the audit results
- 3Issuing and maintaining certificates
- 4Conducting surveillance and recertification audits in accordance with the applicable rules and defined time intervals
Impartiality
Consulting or support services for the introduction, implementation or improvement of management systems are not part of our activity as a certification body.
FAQ
Frequently asked questions
What do the Security Levels SL 1 to SL 4 mean?
The Security Levels describe resilience against attackers of differing strength. From accidental or inadvertent impairment (SL 1) to targeted attacks with high effort, specific means and strong motivation (SL 4).
How does IEC 62443 relate to ISO/IEC 27001?
ISO/IEC 27001 describes a general management system for information security, whereas IEC 62443 specifically addresses the technical and procedural requirements of the industrial OT environment. The two can be used in a complementary way.
Your request
What would IEC 62443 cost for you?
Simply request a non-binding quote, quickly and directly.

