Skip to main content
CERT-In Empanelled Since 2008

IEC 62443 Compliance

IEC 62443 compliance for industrial control systems: OT security assessments, gap analysis and certification preparation.

IEC 62443
OT Security Standard
148+
Industrial Engagements
OT-Aware
Methodology
Since 2008
CERT-In Empanelled

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

How the series is built

Four groups of documents, and you are probably only in one of them

IEC 62443 is a series, not a standard, and the part that applies depends on whether you operate the plant, integrate the system or build the product.

01 62443-1-x

General

What it covers
Concepts, terminology and models for the series, including the vocabulary the rest of it depends on, such as zones, conduits and security levels.
02 62443-2-x

Policies and procedures

What it covers
The asset owner’s side: establishing and operating a security programme for an industrial automation and control system, and requirements for service providers supporting it.
Who it is for
Asset owners and operators: the plant, the utility, the manufacturer. If you run the environment, this is where your obligations concentrate.
03 62443-3-x

System

What it covers
Security risk assessment and system design, including partitioning the system into zones and conduits, and the system security requirements and security levels that follow from it.
Who it is for
System integrators, and asset owners at the point where a system is being designed or modernised. The zone and conduit model is produced here and everything downstream references it.
04 62443-4-x

Component

What it covers
Secure product development lifecycle requirements, and technical security requirements for the components themselves.
Who it is for
Product suppliers and automation vendors. An asset owner meets this part indirectly, as a procurement question about what the vendor can evidence.

The model everything rests on

Zones and conduits, and why the boundary drawing is the engagement

Not by geography

A zone is a grouping by shared security requirement

Assets grouped because they need the same protection. Drawing zones honestly is the point at which an OT estate becomes assessable.

And is where control lives

A conduit carries communication between zones

Because a conduit is where traffic crosses a boundary, it is where segmentation is enforced and where an assessment can actually verify something.

Target, capability, achieved

Security Levels run 1 to 4

The scale describes the sophistication of the adversary a zone is expected to withstand. The useful distinction is between the level you target, the level your components are capable of, and the level currently achieved. The gap between those three is the roadmap.

Where we look first

OT and IT boundaries are the usual finding

The business network and the control network are rarely as separated as the diagram says. Engineering workstations, historians, remote-access paths for vendors and flat legacy segments are the recurring routes across.

How OT assessment differs

What we will and will not do to a live plant

AreaHow it is approached
Live control systems Passive analysis, configuration and architecture review, and traffic observation. Active scanning is not run against production control systems without an explicit, scoped agreement, because a probe that is harmless on IT can halt a PLC.
The IT/OT boundary Tested actively from the IT side, which is where the realistic attack path runs and where testing carries no process risk.
Engineering workstations and remote access Assessed directly. Vendor remote-access paths are the most common route into a control network and the least often inventoried.
Windows during maintenance Where deeper testing is warranted, it is scheduled into a planned outage. Availability is the primary safety property in this environment, and an assessment that ignores that is not competent in it.

Live control systems

How it is approached
Passive analysis, configuration and architecture review, and traffic observation. Active scanning is not run against production control systems without an explicit, scoped agreement, because a probe that is harmless on IT can halt a PLC.

The IT/OT boundary

How it is approached
Tested actively from the IT side, which is where the realistic attack path runs and where testing carries no process risk.

Engineering workstations and remote access

How it is approached
Assessed directly. Vendor remote-access paths are the most common route into a control network and the least often inventoried.

Windows during maintenance

How it is approached
Where deeper testing is warranted, it is scheduled into a planned outage. Availability is the primary safety property in this environment, and an assessment that ignores that is not competent in it.

What you receive

A zone model you can build against

The deliverable that matters on an IEC 62443 engagement is the zone and conduit model: a documented partitioning of the environment with a target security level attached to each zone, the conduits between them, and an honest statement of what is achieved today against what is targeted. Everything else reads from it. The gap analysis is expressed against it, the remediation roadmap is sequenced by it, and the procurement conversation with your automation vendors becomes specific because you can state a required capability level. Alongside it we provide the technical assessment (architecture and configuration review, IT/OT boundary testing, remote-access and engineering-workstation assessment) and the evidence pack and residual-risk statement that a certification body will expect if you take the environment forward to certification. We prepare that submission; an accredited certification body issues the certificate, and keeping those two roles separate is what makes the preparation worth anything.

"We swap auditors every two years as policy. Security Brigade is the only firm we've kept continuously since 2016. The difference is Lemon — every engagement follows the same methodology, every finding gets three-layer review, and our RBI auditors have never questioned a report. That kind of consistency across 300+ annual assessments is rare."
CISO, Top-3 Indian Bank
Chief Information Security Officer

Read more client stories →

FAQ

IEC 62443, answered

Scope, safety and sequencing. Talk to our team about your control environment.

Contact us
Which part of IEC 62443 applies to us?+
It depends on your role. If you operate the environment (a plant, a utility, a manufacturing site) your obligations concentrate in the 2-x parts covering the security programme for an industrial automation and control system, and in the 3-x parts when a system is being designed or modernised. If you integrate systems, the 3-x parts are your centre of gravity. If you build products, the 4-x parts covering secure development and component requirements are yours. Most asset owners meet the 4-x parts only indirectly, as a procurement question about what a vendor can evidence.
What are zones and conduits?+
A zone is a grouping of assets that share a security requirement, and a conduit is the communication path between zones. The important thing is that zones are drawn by required protection and not by geography or by how the plant grew, which is why the exercise is genuinely difficult and why it is the part of an engagement that produces the most value. Conduits matter because a boundary is where a control can be enforced and where an assessment can verify one.
What does a Security Level mean?+
It describes the capability of the adversary a zone is expected to withstand, on a scale of 1 to 4. Three readings are useful and are often confused: the level you are targeting for a zone, the level your installed components are capable of supporting, and the level actually achieved today. The distance between those three is the remediation roadmap, and stating it plainly is what lets you hold a procurement conversation in specifics.
Will testing disrupt our plant?+
Not if it is scoped by someone who understands the environment. We do not run active scanning against live control systems without an explicit, scoped agreement, because a probe that is harmless on an IT network can halt a PLC. Live systems are approached through passive analysis, configuration and architecture review; the IT/OT boundary is tested actively from the IT side where the realistic attack path runs; and anything deeper is scheduled into a planned maintenance window.
Can Security Brigade certify us to IEC 62443?+
No consultancy can. Certification is issued by an accredited certification body, and independence from the preparation work is what gives it value. We do the assessment, build the zone and conduit model, close the gaps with you and prepare the evidence pack and residual-risk statement the certification body will expect.

Secure your application before attackers do.

Get a free scoping call with our security architects. We'll assess your risk profile and recommend the right approach.

Typically responds within 1 business day · No commitment required

Request a Scoping Call