The IEC 62443 programme for industrial automation and control systems.
IEC 62443 is a family, not a single certificate — and which parts apply depends on whether you own the asset, integrate the system or build the product. We work across all three roles, from an initial risk assessment through to certification readiness.
- 2-1 / 3-2 / 3-3
- Asset owner & system
- 4-1 / 4-2
- Product supplier
- SL-T / SL-A
- Security level driven
Standards in scope
IEC 62443-2-1
Security programme for IACS asset owners
IEC 62443-3-2
Security risk assessment for system design
IEC 62443-3-3
System security requirements and security levels
IEC 62443-4-1 / 4-2
Secure product development and component requirements
The parts of the series that actually apply to you.
We start by fixing your role in the standard — asset owner, system integrator or product supplier — because that determines which parts you are accountable for and what evidence an assessor will ask to see.
Security programme for IACS asset owners
The cybersecurity management system for the organisation that operates the control system: policies, organisational responsibilities, risk management and the operational processes that keep security running.
How we support you
- CSMS design aligned to your operating model
- Cybersecurity policy, standards and procedure set
- Roles, responsibilities and governance structure
- Patch, backup, change and access management processes
- Maturity assessment and improvement roadmap
- Incident response process suited to OT constraints
Security risk assessment for system design
The methodology for partitioning a system into zones and conduits, assessing risk for each, and deriving target security levels that drive the rest of the design.
How we support you
- System under consideration definition and asset inventory
- Zone and conduit partitioning model
- Initial and detailed cyber risk assessment
- Target security level (SL-T) allocation per zone
- Countermeasure selection and residual risk statement
- Cybersecurity requirements specification (CRS)
System security requirements and security levels
The seven foundational requirements and the system-level controls that deliver security levels 1 to 4 — the yardstick your architecture and vendors are measured against.
How we support you
- Assessment of achieved security level (SL-A) against SL-T
- Foundational requirement gap analysis
- Segmentation, industrial DMZ and remote access design
- Control selection mapped to FR 1–7
- Vendor and integrator requirement packs
- Verification and validation evidence
Secure product development and component requirements
For product suppliers: the secure development lifecycle (SDL) your organisation must follow, and the technical security capabilities your components must provide.
How we support you
- Secure development lifecycle process definition
- Practice-by-practice gap assessment (SM, SR, SD, SI, SVV, DM, SU, SG)
- Threat modelling and security requirement derivation
- Component security capability assessment against 4-2
- Security update and vulnerability handling processes
- Certification readiness for ISASecure / IECEE schemes
Where we typically get involved.
The same seven services run across every practice, so you can compare scope without re-learning the menu.
Risk assessment
Structured risk assessment to identify what can actually go wrong, how likely it is, and what it would cost you.
Advisory & consulting
Strategy, governance and architecture guidance shaped around your operating model rather than a template.
VA-PT & security testing
Vulnerability assessment and penetration testing, scoped so that testing never threatens availability.
Compliance & audit readiness
Gap analysis, evidence assembly and internal audit so the first challenge to your evidence is not the assessor's.
Implementation support
Turning designs into deployed controls — segmentation, hardening, access control and monitoring.
Security operations
Continuous monitoring, detection and incident response support suited to the environment's constraints.
Training & capability
Building internal capability so the programme keeps running after the engagement ends.
Typical engagements.
Risk assessment (3-2)
Structured zone and conduit risk assessment across ICS, SCADA, DCS and PLC environments, producing defensible target security levels.
Maturity & gap assessment
Where your programme stands against IEC 62443-2-1 and NIST CSF, with gaps ranked by risk reduction per rupee rather than by clause number.
Secure architecture design
Segmentation, industrial DMZ, conduit design and remote access architecture that reduces lateral movement without breaking operational continuity.
Implementation support
Turning the design into deployed controls — hardening, access control, monitoring integration and the operational processes around them.
Certification readiness
Evidence packs, internal audit and dry-run assessment for IEC 62443 certification against ISASecure and IECEE schemes.
Team capability
IEC 62443 training for engineering, operations and leadership so the programme survives after the consultants leave.
Systems we work across
- SCADA and distributed control systems (DCS)
- PLC, RTU and safety instrumented systems
- Substation automation and protection relays
- Plant historians, engineering workstations and HMIs
- Industrial networks, firewalls and remote access
- OT monitoring platforms (Dragos, Claroty, Nozomi)
- Vendor and contractor access pathways
- Greenfield projects and brownfield migrations
What you receive
- Asset inventory and system under consideration definition
- Zone and conduit diagram with risk register
- Cybersecurity requirements specification (CRS)
- SL-T versus SL-A gap analysis
- Policy, procedure and CSMS documentation set
- Prioritised remediation roadmap and certification plan
Starting or stalling on an IEC 62443 programme?
Tell us your role in the standard, the environment in scope and whether there is a certification or audit date in play — we'll tell you the shortest credible path.