IEC 62443-2-1 and IEC 62443-2-4 are regularly mixed up because both parts are called "2-x" and deal with organisational requirements. The difference lies in who the standard addresses and on what.
IEC 62443-2-1: the security programme of the asset owner
This part is aimed at the organisation that operates the IACS environment — for example a grid operator. It describes how to set up a Cybersecurity Management System (CSMS): risk assessment, policy, asset inventory, incident response and supplier management. In short: -2-1 is about how the asset owner keeps their own house in order.
IEC 62443-2-4: requirements for service providers
This part sets requirements for external parties that provide services to the asset owner: system integrators that build substations, and service providers that carry out maintenance. It describes, among other things, how remote maintenance is carried out, how change management works and which competencies the service provider's staff must have. In short: -2-4 is about what the asset owner may expect from an external party.
Why the distinction matters
In practice these two parts work together. A grid operator records in its CSMS (in line with -2-1) which risks are acceptable and which requirements it sets for suppliers. In a tender it then checks whether the system integrator or service provider can demonstrate that it meets -2-4 — for example via a standardised audit report or certification.
A common mistake is that an asset owner does have a CSMS, but does not translate it into concrete, contractually enforceable requirements for service providers. The consequence is that remote access or change management by external parties falls outside the view of the organisation's own risk assessment.
Practical example
A grid operator outsources the maintenance of protection relays in substations to a system integrator. The contract stipulates that remote sessions run exclusively via a jump host managed by the grid operator, with session recording and time-bound authorisation — a direct application of the requirements from IEC 62443-2-4, imposed from the CSMS that is set up in line with -2-1.