Skip to content
IACS RadarIndustrial Cyber Exposure & Intelligence
Back to knowledge base

IEC 62443

Difference between IEC 62443-2-1 and IEC 62443-2-4

Two parts that are often confused: the security programme of the asset owner versus the requirements for service providers and integrators.

advanced 5 min read·Last review: 18 May 2026·IACS Radar editorial team
Asset ownerSystem integratorService provider

IEC 62443-2-1 and IEC 62443-2-4 are regularly mixed up because both parts are called "2-x" and deal with organisational requirements. The difference lies in who the standard addresses and on what.

IEC 62443-2-1: the security programme of the asset owner

This part is aimed at the organisation that operates the IACS environment — for example a grid operator. It describes how to set up a Cybersecurity Management System (CSMS): risk assessment, policy, asset inventory, incident response and supplier management. In short: -2-1 is about how the asset owner keeps their own house in order.

IEC 62443-2-4: requirements for service providers

This part sets requirements for external parties that provide services to the asset owner: system integrators that build substations, and service providers that carry out maintenance. It describes, among other things, how remote maintenance is carried out, how change management works and which competencies the service provider's staff must have. In short: -2-4 is about what the asset owner may expect from an external party.

Why the distinction matters

In practice these two parts work together. A grid operator records in its CSMS (in line with -2-1) which risks are acceptable and which requirements it sets for suppliers. In a tender it then checks whether the system integrator or service provider can demonstrate that it meets -2-4 — for example via a standardised audit report or certification.

A common mistake is that an asset owner does have a CSMS, but does not translate it into concrete, contractually enforceable requirements for service providers. The consequence is that remote access or change management by external parties falls outside the view of the organisation's own risk assessment.

Practical example

A grid operator outsources the maintenance of protection relays in substations to a system integrator. The contract stipulates that remote sessions run exclusively via a jump host managed by the grid operator, with session recording and time-bound authorisation — a direct application of the requirements from IEC 62443-2-4, imposed from the CSMS that is set up in line with -2-1.

Related to IEC 62443