What Is IEC 62443?

IEC 62443 (also known as ISA/IEC 62443) is the international standard for industrial automation and control systems (IACS) cybersecurity. Developed jointly by the International Society of Automation (ISA) and the International Electrotechnical Commission (IEC), it provides a comprehensive framework for securing operational technology environments.

Unlike IT-focused standards like ISO 27001, IEC 62443 was purpose-built for environments where availability and safety are paramount — where a cybersecurity failure can halt production lines, damage equipment, or endanger workers.

For manufacturing facilities, IEC 62443 is increasingly becoming a contractual requirement from OEMs, a regulatory expectation, and a prerequisite for cyber insurance.

Why Manufacturing Needs IEC 62443

Manufacturing Is the #1 Target

Manufacturing has been the most-attacked industry by ransomware for 3 consecutive years (IBM X-Force, 2024–2026). The average production downtime from a cyber incident is 72 hours, costing $280,000–$400,000 per hour depending on facility type.

Manufacturing environments face unique cybersecurity challenges:

  • Legacy equipment — PLCs and HMIs running 15–20 year old firmware that can't be patched
  • IT/OT convergence — Industry 4.0 and IIoT connecting previously air-gapped systems to corporate networks and cloud
  • Vendor access sprawl — dozens of equipment vendors with persistent remote access to production systems
  • Safety-critical systems — robotic cells, presses, and CNC machines that can injure workers if safety controls are compromised
  • IP concentration — production recipes, tooling parameters, and process knowledge stored in control systems

IEC 62443 addresses all of these with a risk-based, zone-oriented approach that maps directly to how manufacturing plants are physically organized.

IEC 62443 Structure — The 4 Layers

IEC 62443 is organized into four document layers, each targeting a different stakeholder:

LayerDocumentsTarget AudienceFocus
1 — General62443-1-xEveryoneConcepts, terminology, metrics
2 — Policies & Procedures62443-2-xAsset Owners (you)Security management system, patch management, risk assessment
3 — System62443-3-xSystem IntegratorsSecurity levels, zones & conduits, system design
4 — Component62443-4-xProduct SuppliersSecure development lifecycle, component security requirements

As a manufacturing plant operator, your primary focus is Layer 2 (your security management system) and Layer 3 (how your systems are architected and segmented). Layers 1 and 4 apply to your equipment vendors and integrators.

The 7 Foundational Requirements (FR1–FR7)

IEC 62443-3-3 defines 7 Foundational Requirements that every industrial control system must address. These are the backbone of your compliance program:

FR1: Identification and Authentication Control

Every user, device, and software component must be identified and authenticated before accessing the IACS.

Manufacturing examples: Individual user accounts on HMIs, device certificates for PLCs, MFA for remote access

FR2: Use Control (Authorization)

Enforce least-privilege access. Users and processes should only have permissions required for their role.

Manufacturing examples: Role-based access on MES, operator vs. engineer permissions on HMIs, restricted PLC programming access

FR3: System Integrity

Ensure the IACS operates correctly and has not been tampered with.

Manufacturing examples: Application allowlisting on HMIs, PLC logic integrity monitoring, firmware version tracking

FR4: Data Confidentiality

Protect sensitive data (recipes, configurations, production data) from unauthorized disclosure.

Manufacturing examples: Encrypted OPC UA communications, protected recipe/formula storage, secure backup encryption

FR5: Restricted Data Flow

Segment the network to control data flow between zones and to external networks.

Manufacturing examples: Firewalls between IT and OT, DMZ for data historians, data diodes for critical zones

FR6: Timely Response to Events

Detect, report, and respond to security events in a timely manner.

Manufacturing examples: OT-specific SIEM, anomaly detection on control traffic, incident response procedures for production

FR7: Resource Availability

Ensure the IACS remains available and resilient against denial-of-service conditions.

Manufacturing examples: Redundant controllers, tested backup/recovery, network resilience, manual fallback procedures

Security Levels Explained (SL 0–4)

IEC 62443 uses a Security Level (SL) scale from 0 to 4 to express the strength of security controls. Each zone in your facility gets a Target Security Level based on its risk profile:

LevelProtection AgainstTypical Manufacturing Application
SL 0No specific requirementsNon-critical monitoring displays
SL 1Casual or coincidental violationGeneral production monitoring, environmental sensors
SL 2Intentional violation using simple meansStandard production lines, MES, quality systems
SL 3Intentional violation using sophisticated meansSafety systems, high-value IP (recipes), critical infrastructure
SL 4State-sponsored attackDefense manufacturing, critical national infrastructure

Most manufacturing facilities should target SL 2 for general production zones and SL 3 for safety systems, IP-critical processes, and high-value production.

Key Concept: SL-T vs SL-A vs SL-C

SL-T (Target) = the security level you need based on risk assessment. SL-C (Capability) = what your components can achieve. SL-A (Achieved) = what you've actually implemented. Your compliance gap = SL-T minus SL-A.

Get Your IEC 62443 Maturity Score

Our Manufacturing OT Security Assessment scores your facility across all 7 foundational requirements and provides a target Security Level recommendation per zone.

IEC 62443 Compliance Checklist for Manufacturing

Use this checklist to evaluate your facility's IEC 62443 alignment. Each item maps to a Foundational Requirement and target Security Level.

FR1 — Identification & Authentication

FR2 — Use Control (Authorization)

FR3 — System Integrity

FR4 — Data Confidentiality

FR5 — Restricted Data Flow

FR6 — Timely Response to Events

FR7 — Resource Availability

Zones and Conduits — Segmenting the Plant Floor

The zone and conduit model is the architectural heart of IEC 62443. It requires you to divide your facility into logical zones (groups of assets with the same security requirements) connected by conduits (communication paths between zones).

Typical Manufacturing Zone Architecture

Purdue Model for Manufacturing:

Level 5: Enterprise Network (Cloud, SaaS, Corporate)

Level 4: Business Network (ERP, Email, Business Apps)

─── Industrial DMZ (Data Historian, Patch Server, Remote Access) ───

Level 3: Site Operations (MES, Plant Historian, Scheduling)

Level 2: Area Supervisory (SCADA, HMI, Engineering WS)

Level 1: Basic Control (PLCs, DCS, RTUs, Safety PLCs)

Level 0: Physical Process (Sensors, Actuators, Robots, CNC)

The golden rule: No direct communication should cross more than one level boundary without passing through a conduit with appropriate security controls. Level 4 traffic should never reach Level 1/0 directly.

Zone Segmentation Tips for Manufacturing

  • Segment by production line — each line or cell should be its own zone, so a compromise in Line A doesn't propagate to Line B
  • Isolate safety systems — safety PLCs (IEC 61508/62061) should be in a dedicated zone with the highest Security Level
  • Separate quality systems — QMS and inspection data often has regulatory requirements (FDA, ISO 9001) that justify a dedicated zone
  • IIoT edge zone — sensors and edge gateways connecting to cloud should have their own zone with outbound-only data flow

Top 5 Compliance Gaps in Manufacturing

Based on our assessments of 50+ manufacturing facilities, these are the most common IEC 62443 gaps:

#1

Flat OT Networks

FR5
67% of facilities

No segmentation between production lines, safety systems, and IT. A single compromise reaches everything.

#2

Shared Credentials on HMIs

FR1
72% of facilities

Operators share a single login ("operator1/password") across all HMIs on a shift. No individual accountability.

#3

Persistent Vendor Access

FR2
58% of facilities

Equipment vendors have always-on VPN connections with no session monitoring or time limits.

#4

No PLC Change Detection

FR3
81% of facilities

PLC logic changes go undetected. No baselines, no alerts, no version control.

#5

No OT Incident Response Plan

FR6
63% of facilities

IR plan exists for IT but doesn't cover production systems, manual fallback, or safety system compromise.

90-Day Implementation Roadmap

A practical timeline for manufacturing facilities starting their IEC 62443 journey:

Days 1–30

Discovery & Risk Assessment

  • Inventory all OT assets (PLCs, HMIs, switches, safety systems)
  • Map network topology and identify zone boundaries
  • Conduct risk assessment per IEC 62443-3-2
  • Assign Target Security Level (SL-T) per zone
  • Document current Security Level Achieved (SL-A)
  • Identify and prioritize compliance gaps
Days 31–60

Quick Wins & Critical Controls

  • Eliminate shared credentials — deploy individual HMI accounts
  • Change all default passwords on production equipment
  • Implement network segmentation between IT DMZ and OT
  • Deploy application allowlisting on engineering workstations
  • Establish PLC logic backup and change detection baselines
  • Restrict vendor access to on-demand with MFA
Days 61–90

Monitoring & Maturation

  • Deploy OT network monitoring with protocol-aware detection
  • Develop OT-specific incident response playbooks
  • Test backup and recovery procedures for critical production lines
  • Train plant operations team on security awareness and manual fallback
  • Document policies for IEC 62443-2-1 security management system
  • Plan cell-level micro-segmentation for next quarter

IEC 62443 vs Other OT Frameworks

How IEC 62443 compares to other frameworks commonly referenced in manufacturing:

AspectIEC 62443NERC CIPNIST SP 800-82
ScopeAll industrial sectorsElectric utilities onlyAll OT (guidance)
Mandatory?Contractual / insurance (increasingly)Yes (FERC enforced)No (voluntary guidance)
Certifiable?Yes (ISASecure certifications)Audit-based complianceNo
Architecture ModelZones & conduits + security levelsBES Cyber System categoriesPurdue Model guidance
Best For Manufacturing✓ Primary standardN/A (utility-specific)Complementary guidance

Recommendation: For manufacturing, use IEC 62443 as your primary compliance framework and supplement with NIST SP 800-82 for additional implementation guidance. If you have energy generation or utility operations on-site, add NERC CIP for those specific assets.

How Does Your Plant Score?

Our Manufacturing OT Security Assessment evaluates all 5 manufacturing-specific security domains, quantifies your risk exposure in dollars, and maps your facility to IEC 62443 maturity levels.