Consulting · IEC 62443

The IEC 62443 programme for industrial automation and control systems.

IEC 62443 is a family, not a single certificate — and which parts apply depends on whether you own the asset, integrate the system or build the product. We work across all three roles, from an initial risk assessment through to certification readiness.

2-1 / 3-2 / 3-3
Asset owner & system
4-1 / 4-2
Product supplier
SL-T / SL-A
Security level driven

Standards in scope

  • IEC 62443-2-1

    Security programme for IACS asset owners

  • IEC 62443-3-2

    Security risk assessment for system design

  • IEC 62443-3-3

    System security requirements and security levels

  • IEC 62443-4-1 / 4-2

    Secure product development and component requirements

Standards

The parts of the series that actually apply to you.

We start by fixing your role in the standard — asset owner, system integrator or product supplier — because that determines which parts you are accountable for and what evidence an assessor will ask to see.

IEC 62443-2-1

Security programme for IACS asset owners

The cybersecurity management system for the organisation that operates the control system: policies, organisational responsibilities, risk management and the operational processes that keep security running.

How we support you

  • CSMS design aligned to your operating model
  • Cybersecurity policy, standards and procedure set
  • Roles, responsibilities and governance structure
  • Patch, backup, change and access management processes
  • Maturity assessment and improvement roadmap
  • Incident response process suited to OT constraints
IEC 62443-3-2

Security risk assessment for system design

The methodology for partitioning a system into zones and conduits, assessing risk for each, and deriving target security levels that drive the rest of the design.

How we support you

  • System under consideration definition and asset inventory
  • Zone and conduit partitioning model
  • Initial and detailed cyber risk assessment
  • Target security level (SL-T) allocation per zone
  • Countermeasure selection and residual risk statement
  • Cybersecurity requirements specification (CRS)
IEC 62443-3-3

System security requirements and security levels

The seven foundational requirements and the system-level controls that deliver security levels 1 to 4 — the yardstick your architecture and vendors are measured against.

How we support you

  • Assessment of achieved security level (SL-A) against SL-T
  • Foundational requirement gap analysis
  • Segmentation, industrial DMZ and remote access design
  • Control selection mapped to FR 1–7
  • Vendor and integrator requirement packs
  • Verification and validation evidence
IEC 62443-4-1 / 4-2

Secure product development and component requirements

For product suppliers: the secure development lifecycle (SDL) your organisation must follow, and the technical security capabilities your components must provide.

How we support you

  • Secure development lifecycle process definition
  • Practice-by-practice gap assessment (SM, SR, SD, SI, SVV, DM, SU, SG)
  • Threat modelling and security requirement derivation
  • Component security capability assessment against 4-2
  • Security update and vulnerability handling processes
  • Certification readiness for ISASecure / IECEE schemes
Services

Where we typically get involved.

The same seven services run across every practice, so you can compare scope without re-learning the menu.

Risk assessment

Structured risk assessment to identify what can actually go wrong, how likely it is, and what it would cost you.

Advisory & consulting

Strategy, governance and architecture guidance shaped around your operating model rather than a template.

VA-PT & security testing

Vulnerability assessment and penetration testing, scoped so that testing never threatens availability.

Compliance & audit readiness

Gap analysis, evidence assembly and internal audit so the first challenge to your evidence is not the assessor's.

Implementation support

Turning designs into deployed controls — segmentation, hardening, access control and monitoring.

Security operations

Continuous monitoring, detection and incident response support suited to the environment's constraints.

Training & capability

Building internal capability so the programme keeps running after the engagement ends.

Where we get involved

Typical engagements.

Risk assessment (3-2)

Structured zone and conduit risk assessment across ICS, SCADA, DCS and PLC environments, producing defensible target security levels.

Maturity & gap assessment

Where your programme stands against IEC 62443-2-1 and NIST CSF, with gaps ranked by risk reduction per rupee rather than by clause number.

Secure architecture design

Segmentation, industrial DMZ, conduit design and remote access architecture that reduces lateral movement without breaking operational continuity.

Implementation support

Turning the design into deployed controls — hardening, access control, monitoring integration and the operational processes around them.

Certification readiness

Evidence packs, internal audit and dry-run assessment for IEC 62443 certification against ISASecure and IECEE schemes.

Team capability

IEC 62443 training for engineering, operations and leadership so the programme survives after the consultants leave.

Environments

Systems we work across

  • SCADA and distributed control systems (DCS)
  • PLC, RTU and safety instrumented systems
  • Substation automation and protection relays
  • Plant historians, engineering workstations and HMIs
  • Industrial networks, firewalls and remote access
  • OT monitoring platforms (Dragos, Claroty, Nozomi)
  • Vendor and contractor access pathways
  • Greenfield projects and brownfield migrations
Work products

What you receive

  • Asset inventory and system under consideration definition
  • Zone and conduit diagram with risk register
  • Cybersecurity requirements specification (CRS)
  • SL-T versus SL-A gap analysis
  • Policy, procedure and CSMS documentation set
  • Prioritised remediation roadmap and certification plan
Consulting enquiries

Starting or stalling on an IEC 62443 programme?

Tell us your role in the standard, the environment in scope and whether there is a certification or audit date in play — we'll tell you the shortest credible path.

Raise an enquiry otfuriouswarrior@svratechcyber.com