Reading IEC 62443: a practical guide for project leads

By SCI Editorial ·

IEC 62443 is the security standard for industrial automation and control systems. For a project lead encountering it for the first time, it can read as a binder-sized obligation that nobody on the team is qualified to deliver. It's neither — but only if it's scoped correctly.

The standard at a glance

  • 62443-1-x: terminology and concepts.
  • 62443-2-x: policies and procedures for asset owners and service providers.
  • 62443-3-x: system-level technical requirements, including the Security Level (SL) framework.
  • 62443-4-x: component-level requirements for products and components.

Where project leads spend their time

On a building project, the bulk of relevant content sits in 62443-3-3 (System Security Requirements and Security Levels). Most project teams apply 62443-3-2 alongside it to define their zones and conduits.

The 70% rule

Roughly 70% of the standard's clauses don't apply at the zone SLs a building project typically targets. The work is identifying which 30% does — and that's exactly what a focused scoping pass produces. Done well, it lands as a 10-20 page conformance pack rather than a binder.