What is IEC 62443 ?
IEC 62443 is the international standard series for Industrial Automation and Control Systems (IACS) security. Published by the International Electrotechnical Commission (IEC), it covers the entire industrial security lifecycle: policies and procedures (2-x series for asset owners), system requirements (3-x series for integrators), and component requirements (4-x series for component manufacturers). The standard defines 7 foundational requirements (FR) applied across all elements: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, incident response, and resource availability. It provides 4 security levels (SL 1 to SL 4) to graduate protection based on threat context and business objectives. The zones and conduits approach enables segmentation of industrial architecture, isolation of critical perimeters, and application of controls proportionate to each zone. This modular structure serves industrial organizations of all sizes operating OT (operational technology) assets: energy, chemicals, manufacturing, water, transportation. Certification of components and systems by accredited bodies provides objective proof of compliance.
Key Points
- 7 foundational requirements: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, incident response, resource availability
- 4 security levels (SL 1 to SL 4) enabling a graduated approach based on threat level
- Zones and conduits approach for industrial architecture segmentation
- Requirements for asset owners (2-x series), integrators (3-x series), and component manufacturers (4-x series)
- Possible component and system certification by accredited bodies
Why Zaxyr
Zaxyr helps industrial organizations structure and validate their IEC 62443 compliance. The platform organizes analysis through zones and conduits, assesses maturity against the 7 foundational requirements, determines target security level per zone and asset, then produces automated mapping to NIST 800-82 and NERC CIP. This provides a unified view of OT security posture across multiple frameworks.