IEC 62443
Industrial Automation and Control Systems Security
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
62443-2-1 Security Program Requirements
| Code | Title |
|---|---|
| 62443-2-1-AC | Account Management and Access Control for IACS |
| 62443-2-1-BCP | Business Continuity and Disaster Recovery for IACS |
| 62443-2-1-CSMS | Cyber Security Management System (CSMS) for IACS |
| 62443-2-1-IR | Incident Planning and Response for IACS |
| 62443-2-1-MOC | Management of Change for IACS Security |
| 62443-2-1-NSEG | Network Segmentation and Zone/Conduit Implementation |
| 62443-2-1-PHY | Physical and Environmental Security of IACS Assets |
| 62443-2-1-PM | Patch Management and System Update for IACS |
| 62443-2-1-RA | IACS Risk Identification, Classification and Assessment |
| 62443-2-1-TRN | Personnel Security Awareness and Training for IACS |
62443-2-4 Service Provider Requirements
| Code | Title |
|---|---|
| 62443-2-4-SP-01 | Service Provider Security Program |
| 62443-2-4-SP-02 | Service Provider Solution Staffing and Assurance |
| 62443-2-4-SP-03 | Service Provider Architecture and Design Practices |
| 62443-2-4-SP-04 | Service Provider Wireless and Remote Access Practices |
| 62443-2-4-SP-05 | Service Provider Malware Protection Practices |
| 62443-2-4-SP-06 | Service Provider Backup and Restore Practices |
62443-3-2 Risk Assessment and System Design
| Code | Title |
|---|---|
| 62443-3-2-CRS | Document Cybersecurity Requirements Specification (CRS) |
| 62443-3-2-ZCR-1 | Identify System Under Consideration |
| 62443-3-2-ZCR-2 | High-Level Risk Assessment |
| 62443-3-2-ZCR-3 | Partition the SUC into Zones and Conduits |
| 62443-3-2-ZCR-4 | Detailed Cybersecurity Risk Assessment per Zone and Conduit |
62443-3-3 System Security Requirements
| Code | Title |
|---|---|
| 62443-3-3-FR1-SR-1-1 | Human User Identification and Authentication (FR1) |
| 62443-3-3-FR1-SR-1-11 | Unsuccessful Login Attempts |
| 62443-3-3-FR1-SR-1-2 | Software Process and Device Identification and Authentication |
| 62443-3-3-FR1-SR-1-5 | Authenticator Management |
| 62443-3-3-FR1-SR-1-7 | Strength of Password-Based Authentication |
| 62443-3-3-FR2-SR-2-1 | Authorisation Enforcement (FR2 Use Control) |
| 62443-3-3-FR2-SR-2-4 | Mobile Code Restriction |
| 62443-3-3-FR2-SR-2-5 | Session Lock and Termination |
| 62443-3-3-FR2-SR-2-8 | Auditable Events |
| 62443-3-3-FR3-SR-3-1 | Communication Integrity (FR3 System Integrity) |
| 62443-3-3-FR3-SR-3-2 | Protection from Malicious Code |
| 62443-3-3-FR3-SR-3-3 | Security Functionality Verification |
| 62443-3-3-FR3-SR-3-4 | Software and Information Integrity |
| 62443-3-3-FR3-SR-3-8 | Session Integrity |
| 62443-3-3-FR4-SR-4-1 | Information Confidentiality (FR4 Data Confidentiality) |
| 62443-3-3-FR4-SR-4-2 | Information Persistence and Sanitisation |
| 62443-3-3-FR5-SR-5-1 | Network Segmentation (FR5 Restricted Data Flow) |
| 62443-3-3-FR5-SR-5-2 | Zone Boundary Protection |
| 62443-3-3-FR5-SR-5-3 | General-Purpose Person-to-Person Communication Restrictions |
| 62443-3-3-FR6-SR-6-1 | Audit Log Accessibility (FR6 Timely Response to Events) |
| 62443-3-3-FR6-SR-6-2 | Continuous Monitoring |
| 62443-3-3-FR7-SR-7-1 | Denial-of-Service Protection (FR7 Resource Availability) |
| 62443-3-3-FR7-SR-7-3 | Control System Backup |
| 62443-3-3-FR7-SR-7-6 | Network and Security Configurations |
62443-4-1 Secure Product Development Lifecycle
| Code | Title |
|---|---|
| 62443-4-1-DM | Defect Management and Vulnerability Handling |
| 62443-4-1-SD | Secure by Design |
| 62443-4-1-SG | Security Guidelines for Asset Owner |
| 62443-4-1-SI | Secure Implementation |
| 62443-4-1-SM | Security Management (Product Development) |
| 62443-4-1-SR | Specification of Security Requirements |
| 62443-4-1-SUM | Security Update Management |
| 62443-4-1-SVV | Security Verification and Validation |
62443-4-2 Component Security Requirements
| Code | Title |
|---|---|
| 62443-4-2-CR-1-1 | Component Identification and Authentication of Users |
| 62443-4-2-CR-3-1 | Component Communication Integrity |
| 62443-4-2-CR-7-1 | Component Denial-of-Service Protection |
| 62443-4-2-EDR-3-10 | Embedded Device Support for Updates |
IEC 62443: Access Management
Controlling access to critical infrastructure systems (IEC 62443)
| Code | Title |
|---|---|
| IEC62443-06 | Physical and logical access controls |
| IEC62443-07 | Personnel risk assessment |
| IEC62443-08 | Electronic access perimeter management |
| IEC62443-09 | Interactive remote access security |
| IEC62443-10 | Revocation of access procedures |
IEC 62443: Asset Identification & Governance
Identifying and governing critical assets (IEC 62443)
| Code | Title |
|---|---|
| IEC62443-01 | Critical asset identification and inventory |
| IEC62443-02 | System security categorization |
| IEC62443-03 | Security governance structure |
| IEC62443-04 | Roles and responsibilities for critical systems |
| IEC62443-05 | Security policy for operational technology |
IEC 62443: Incident Response & Recovery
Responding to incidents in critical infrastructure (IEC 62443)
| Code | Title |
|---|---|
| IEC62443-16 | Incident response plan for operational disruptions |
| IEC62443-17 | Recovery plan for critical systems |
| IEC62443-18 | Reporting obligations to authorities |
| IEC62443-19 | Coordination with sector-specific agencies |
| IEC62443-20 | Exercises and drills for OT incidents |
IEC 62443: Supply Chain & Configuration
Managing supply chain and system configurations (IEC 62443)
| Code | Title |
|---|---|
| IEC62443-21 | Supply chain risk management for critical components |
| IEC62443-22 | Configuration management for OT systems |
| IEC62443-23 | Change management procedures |
| IEC62443-24 | Vulnerability assessment for critical systems |
IEC 62443: Systems Security
Securing operational technology systems (IEC 62443)
| Code | Title |
|---|---|
| IEC62443-11 | Security patch management for OT |
| IEC62443-12 | Malware prevention for operational systems |
| IEC62443-13 | Network security monitoring |
| IEC62443-14 | System security hardening |
| IEC62443-15 | Ports and services management |
Your Compliance Coverage
If you comply with IEC 62443, you already cover:
NIS2 Directive
21%
17 controls mapped
Compare →DO-326A / ED-202A
21%
17 controls mapped
Compare →C2M2
21%
17 controls mapped
Compare →+ 566 more: API 1164 (21%), BIMCO Cyber Security (21%)
See all 569 mapped frameworks ↓Maps to 569 other frameworks
Frequently Asked Questions
What is IEC 62443?
IEC 62443 is a compliance framework from International with 11 domains and 81 controls. Industrial Automation and Control Systems Security It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does IEC 62443 have?
IEC 62443 has 81 controls organised across 11 domains. The largest domains are 62443-3-3 System Security Requirements (24 controls), 62443-2-1 Security Program Requirements (10 controls), 62443-4-1 Secure Product Development Lifecycle (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does IEC 62443 map to?
IEC 62443 maps to 569 other compliance frameworks. The top mapping partners are NIS2 Directive (21% coverage), DO-326A / ED-202A (21% coverage), C2M2 (21% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with IEC 62443 compliance?
Start your IEC 62443 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IEC 62443 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 81 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required