Skip to content
IACS RadarIndustrial Cyber Exposure & Intelligence
Back to knowledge base

IEC 62443

What is IEC 62443?

An introduction to the main international series of standards for cybersecurity of industrial control systems, and why it is relevant to the energy sector.

basic 6 min read·Last review: 2 June 2026·IACS Radar editorial team
Asset ownerSecurity officerOT engineer

IEC 62443 is a series of international standards that describes how organisations can set up, assess and demonstrate the cybersecurity of industrial automation and control systems (Industrial Automation and Control Systems, IACS). Where many IT security standards assume office automation, IEC 62443 is written specifically for environments in which systems control physical processes: electricity substations, production lines, water treatment and power plants.

Why a separate standard for OT?

In an office environment, confidentiality usually comes first. In a substation the order is often reversed: availability and integrity of the control weigh more heavily than confidentiality, because an outage can directly affect the energy supply. IEC 62443 takes this into account by linking requirements to risk instead of applying a uniform security bar to all systems.

Structure of the series of standards

IEC 62443 consists of several parts, divided into four groups:

  • General (1-x): basic concepts, terminology and models.
  • Policies and procedures (2-x): requirements for the security programme of asset owners and service providers.
  • System (3-x): requirements for risk assessment, architecture (zones and conduits) and system security.
  • Component (4-x): requirements for the development and technology of individual products.

This division means that different parts address different roles: an asset owner works mainly with 2-1, a system integrator with 2-4 and 3-x, and a product supplier with 4-1 and 4-2.

Core concepts

Two concepts recur in almost every part:

  1. Zones and conduits — dividing a system into logical groups (zones) with a comparable risk level, connected by controlled communication paths (conduits).
  2. Security Levels — a scale from 1 to 4 that indicates which type of attacker a zone or component must be able to withstand, from coincidental exposure to an attacker with extensive resources.

Why this is relevant to the energy sector

Substations and control centres combine older, long-lived equipment with more and more IP-based connections. IEC 62443 offers a structured way to assess these mixed environments, without requiring that all equipment be secured identically. For grid operators the standard is now a common reference in tenders, risk assessments and conversations with supervisors.

How this knowledge centre treats the standard

This knowledge centre offers its own summaries and practical examples per part, per role and per Foundational Requirement. It does not replace the official standard texts: for certification and formal compliance, always consult the publications of IEC, ISA or an accredited certification body.

Related to IEC 62443

External sources