Glossary · Safety standards
IEC 62443
Also known as: IEC 62443 series, ISA/IEC 62443
German: IEC 62443
IEC 62443 is a family of international standards for the cybersecurity of industrial automation and control systems (IACS). It addresses asset owners, system integrators and product suppliers, and covers security management, risk assessment with zones and conduits, system and component requirements, and secure development.
- Standards
- Cybersecurity
In one sentence
IEC 62443 is the standards family for cybersecurity of industrial automation and control systems, from zones and conduits to secure development.
Example
The integrator of a bottling plant divides it into security zones, defines conduits to the MES, sets a target security level for each zone and selects PLCs certified to the component requirements of IEC 62443.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
- Machinery Regulation and CRA: coupled through standards, not cross-referencesWhy can the Machinery Regulation and the Cyber Resilience Act not simply refer to each other?UKDeutsch
- EN 50742: safety-related security levels and IEC 62443 working togetherIs EN 50742 a sign that legislators misunderstand technicalities, and do its SRSLs contradict IEC 62443?UKDeutsch
How it applies
- Structure: General concepts, policies and procedures for asset owners and service providers, system-level requirements including security zones and conduits, and component-level requirements with a secure product development lifecycle.
- Security levels: Target, capability and achieved security levels express the strength of protection against increasingly capable attackers.
- Machine safety: Cybersecurity weaknesses can defeat safety functions. The series explicitly addresses the IACS context, but coordination with functional safety must be organized in the project; see safety-security interface.
- Technical documentation: Product suppliers must describe security capabilities, hardening and secure use; integrators must document the zone model and the handover to the operator.
IEC 62443 vs. the Cyber Resilience Act
The CRA is law and applies to products with digital elements placed on the EU market. IEC 62443 is a voluntary standards series. It is widely expected to support CRA compliance for industrial products, but applying it does not by itself demonstrate conformity with the CRA.