What It Is

ISA/IEC 62443 is not a single checklist. It is a family of standards that defines how to:

  • Design secure industrial systems: security engineered in from the start.
  • Operate them safely over time: systems that run for decades need controls that endure.
  • Control access and trust: who and what may touch the process, and under which conditions.
  • Reduce cyber risk without disrupting operations: protection that respects production.

Unlike IT-focused frameworks, 62443 is built for environments where downtime is unacceptable, systems run for decades, and safety and availability matter more than convenience.

Think of it this way: ISA/IEC 62443 is cybersecurity designed for machines that move, control, and produce - not just computers.

What Information Is Regulated

ISA/IEC 62443 focuses on Industrial Automation and Control Systems, including:

  • PLCs and RTUs: the controllers executing the physical process.
  • SCADA and HMI systems: how operators see and command operations.
  • Distributed Control Systems (DCS): plant-wide process control.
  • Industrial networks and interfaces: the connective tissue between all of it.
  • Engineering workstations: the machines that can reprogram everything else.
  • OT servers and historians: operational data stores and their integrity.
  • Remote access solutions: the pathway attackers try first.

It also includes the operational disciplines around those systems:

  • User and admin access: identity as an OT control, not just an IT one.
  • Change management processes: undocumented change is the classic OT failure mode.
  • Monitoring and logging: visibility into environments that rarely had any.
  • Incident response and recovery: restoring safely, in the right order.

If compromise could impact operations, safety, or production, it is in scope.

IT Requirements

Ignore part numbers. Focus on what must actually be in place.

Asset Identification & Zoning

  • Inventory of OT assets: every controller, workstation, and interface, named.
  • Defined security zones and conduits: the standard's core architecture - grouping assets by risk and controlling the channels between groups.
  • Clear trust boundaries between IT and OT: decided deliberately, not discovered forensically.

Identity & Access Control

  • Role-based access: permissions mapped to operational roles.
  • Least privilege: nobody holds more control than the job requires.
  • Controlled remote access: brokered, logged, and time-bounded.
  • Strong authentication for privileged users: the accounts that can change the process get the strongest protection.

System Hardening & Secure Configuration

  • Baseline configurations: a known-good state for every asset class.
  • Limited services and ports: attack surface reduced to what production needs.
  • Secure engineering workstations: the highest-consequence endpoints in the plant.

Network Segmentation

  • Separation of IT and OT: a corporate phishing click must not reach a controller.
  • Controlled data flows: traffic between zones is defined and enforced.
  • Firewalls and access rules: conduits with policies, not open pipes.

Monitoring & Logging

  • Visibility into OT activity: you cannot defend a process you cannot see.
  • Detection of abnormal behavior: deviations from known-good patterns, flagged.
  • Log retention and review: evidence kept, and looked at.

Incident Response & Recovery

  • OT-aware response plans: IT playbooks applied blindly can make industrial incidents worse.
  • Safe recovery procedures: restoration sequenced around safety and process integrity.
  • Testing without disrupting operations: exercised carefully, not improvised.

Governance & Lifecycle Management

  • Secure system design: security requirements in the specification, not the retrofit.
  • Change management: every modification controlled and recorded.
  • Patch and vulnerability handling: evaluated on OT terms, with documented decisions.
  • Vendor accountability: suppliers and integrators held to defined security expectations.

ISA/IEC 62443 is about building security into operations - not bolting it on later.

How It Fits Into Cyber Risk Management

62443 compliance is not about checking boxes. It is about five disciplines our Cyber Risk Management practice runs on:

  • Knowing your systems: a real OT asset inventory.
  • Controlling access: identity discipline that reaches the plant floor.
  • Segmenting intelligently: zones and conduits that match how you operate.
  • Monitoring continuously: detection tuned to industrial behavior.
  • Responding safely: plans that protect the process while containing the threat.

Start with control. Protect operations.

How We Help With ISA/IEC 62443 Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment evaluates your OT environment against 62443's core expectations - asset inventory, zone and conduit segmentation, access control, monitoring, and OT-aware response - without disrupting production.

How to Prepare

  1. Identify OT assets and connections

    You don't start with certification. You start with visibility and control. Know what systems exist, how they connect, and where IT and OT intersect. Most organizations find connections nobody remembered making.

  2. Define zones and trust boundaries

    Separate corporate IT, OT operations, remote access, and vendor connections into distinct zones. Decide what may cross each boundary, then enforce it through controlled conduits.

  3. Lock down access

    This is critical. Role-based permissions: access mapped to operational need. MFA where feasible: applied wherever OT constraints allow. Controlled remote sessions: brokered, monitored, and ended on schedule. Access logging: every session recorded.

  4. Harden and monitor systems

    Reduce attack surface to what production requires. Monitor behavior against known-good baselines. Detect anomalies before they become outages.

  5. Document and practice response

    OT incidents require calm, rehearsed response - not improvisation. Write the plan with operations at the table, then exercise it without touching production.

Official source

Official source: International Society of Automation (ISA)

Secondary source: International Electrotechnical Commission (IEC)

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25