By Dustin Guttadauro, Product Line Manager - Telecom & Fiber, Infinite Electronics
As manufacturers strengthen cybersecurity programs, IEC 62443 has become one of the most widely referenced standards for securing industrial automation and control systems (IACS). Yet many organizations find the standard difficult to navigate. With multiple parts, technical terminology, and different requirements for asset owners, system integrators, and product suppliers, it's not always clear where to begin—or which sections apply to a manufacturing facility.
For most manufacturers, implementing IEC 62443 is less about achieving immediate compliance and more about building a structured approach to reducing cyber risk. Concepts such as zones, conduits, and security levels provide a practical framework for protecting industrial networks while supporting safe, reliable operations. This guide explains the parts of IEC 62443 that matter most to manufacturers, outlines what Security Level 2 (SL2) requires, and highlights practical steps organizations can take as they begin their implementation journey.
Key Takeaways
• IEC 62443 is the international standard for Industrial Automation and Control System (IACS) security. For manufacturers, the three most relevant parts are 3-2 (risk assessment and zone definition), 3-3 (system-level technical requirements), and 4-2 (component-level requirements). The rest of the series is primarily for system integrators and product vendors.
• The zone-and-conduit model is the architectural core of IEC 62443: zones are groups of assets with similar security requirements; conduits are the controlled communication paths between zones. Every connection between zones must be a defined conduit with an assigned security level.
• Security Level 2 (SL2) is where most mid-size manufacturers should be targeting. SL2 assumes a motivated attacker using simple means — a realistic threat model for most industrial environments — and its requirements are achievable without specialized security hardware or extensive cryptographic infrastructure.
• The 12 SL2 requirements manufacturers most commonly fail are not exotic: shared credentials, no MFA on remote access, absent audit logging, and flat networks without defined zones account for most assessment findings.
• Physical media choices are conduit security controls under IEC 62443, not just infrastructure decisions. Fiber optic isolation at zone boundaries provides physical conduit separation; shielded cabling reduces EMI-induced conduit vulnerabilities that logical controls can't address.
What is IEC 62443 and why does it apply to manufacturers?What is IEC 62443, and why does it apply to manufacturers?
IEC 62443 is the international standard series developed by the International Society of Automation (ISA) as ISA-99 and published jointly as IEC 62443. It defines security requirements for industrial automation and Control Systems — the PLCs, SCADA servers, HMIs, and networks that control physical manufacturing and process equipment.
Unlike IT security frameworks (ISO 27001, SOC 2), IEC 62443 is built for OT environments specifically. It accounts for legacy devices that can't run security software, protocols without native encryption, availability requirements that limit when changes can be made, and safety systems that cannot be disrupted for patching. The standard also distinguishes between asset owners (plant operators), system integrators (contractors who build and deploy systems), and product suppliers (equipment manufacturers) — and defines different requirements for each.
Which parts of IEC 62443 actually apply to a manufacturing plant?
The IEC 62443 series has more than a dozen published and in-development parts, which creates a common first reaction: 'How much of this do I need to read?' For a manufacturing plant operator implementing the standard for the first time, the answer is three parts plus one more context.
|
Part |
Short title |
Who uses it |
What practitioners actually do with it |
|
2-1 |
Policies & procedures |
Asset owners (plant security leads) |
Write and document the IACS security management system — risk methodology, security policies, staff training requirements |
|
2-3 |
Patch management |
Asset owners |
Define patch assessment and deployment process for OT components; document compensating controls when patching isn't feasible |
|
2-4 |
Service provider requirements |
System integrators, MSSPs |
Scope of security responsibilities for contractors; used in procurement and MSS contracts |
|
3-2 |
Security risk assessment |
Asset owners + integrators |
Conduct threat and risk assessment; define zones, conduits, and target security levels |
|
3-3 |
System security requirements |
System integrators, auditors |
The most-cited technical part: 51 foundational requirements (FR) with SL1–SL4 capability requirements for each |
|
4-1 |
Secure development lifecycle |
Component manufacturers |
Security requirements for how OT products are designed and built — relevant for vendors, not typically for plant operators |
|
4-2 |
Technical security requirements |
Asset owners + auditors |
Component-level requirements — what an individual PLC, switch, or HMI must be capable of at each SL |
For a plant security lead starting from scratch: read 3-2 first (it defines how to do the risk assessment and zone design that everything else depends on), then use 3-3 to understand the system-level requirements you'll need to meet at your target security level and use 4-2 when procuring new OT components to specify what security capabilities the hardware must have. Part 2-1 becomes relevant when documenting your security management system for an audit.
What do the IEC 62443 security levels mean in practice?What do the IEC 62443 security levels mean in practice?
IEC 62443 defines four security levels (SL1–SL4) that describe the capability of a zone or conduit to resist attacks from progressively more sophisticated threat actors. Security levels are assigned to zones and conduits, not to the whole plant — a safety system might be SL3 while a non-critical process monitoring zone is SL1.
|
SL |
Threat actor assumed |
Typical environment |
Example requirement gap from SL1 |
Who typically targets this SL |
|
SL1 |
Unintentional / casual |
Non-critical process monitoring; building automation |
Baseline — change default credentials, basic access control |
Most manufacturing facilities start here |
|
SL2 |
Intentional, simple means, low motivation |
General manufacturing; food & beverage; light industrial |
MFA on all remote access, software update integrity verification, and independent audit log |
IEC 62443 auditors most commonly assess against SL2 |
|
SL3 |
Sophisticated means, moderate motivation |
Pharmaceuticals; chemicals; automotive; defense supply chain |
Defense-in-depth for safety systems; cryptographic key management; intrusion detection |
Regulatory or major customer requirement |
|
SL4 |
Nation-state / APT level |
Critical infrastructure; nuclear; utilities |
Formal cryptographic proof of integrity; extensive third-party validation |
Government-mandated utility sector regulatory compliance |
SL2 is the practical target for most manufacturing environments. The threat actor model — intentional, simple means, low motivation — covers the realistic attacker profile for most manufacturing facilities: opportunistic ransomware operators, disgruntled employees with some technical knowledge, and external attackers using publicly available tools and documented vulnerabilities. It does not assume a sophisticated, targeted attacker with extensive knowledge of the specific plant environment.
SL3 and SL4 are appropriate for environments with regulatory requirements (pharmaceuticals under FDA 21 CFR Part 11, chemicals under CFATS, utilities under NERC CIP) or where the consequence of compromise is severe enough to justify the additional control investment. If your plant makes consumer goods, SL2 is the right target. If you make precursor chemicals or supply critical infrastructure, SL3 may be required.
One important distinction: the standard defines three types of security level — target (SL-T, what you're aiming for), capability (SL-C, what the system can support), and achieved (SL-A, what's actually in place). An assessment checks SL-A against SL-T. Many plants discover that their SL-A is below SL1 when they first assess — which isn't a judgement; it's a baseline.
How do zones and conduits work in practice?
The zone-and-conduit model is the architectural framework that IEC 62443 uses to organize security requirements. A zone is a group of assets — devices, systems, and networks — that share the same security requirements and have a defined trust relationship. A conduit is the communication path between zones, with its own security level that must be at least as high as the lower of the two zones it connects.
Defining zones in a real manufacturing plant starts with the asset inventory from Part 3-2. Group assets by function, consequence of compromise, and connectivity requirements — not by physical location. A PLC on the factory floor that communicates with a SCADA server upstairs is in the same zone as that SCADA server, even though they're physically separated, if they share the same security requirements and trust relationship.
What makes a conduit a conduit?What makes a conduit a conduit?
Any communication path between zones is a conduit — regardless of whether it's a physical cable, a wireless link, a VPN tunnel, or a serial connection through a protocol gateway. Each conduit must be documented, assigned a security level, and have specific controls applied to achieve that level.
Conduit controls fall into three categories:
- Logical controls: firewalls, deep packet inspection, access control lists, VPN encryption, protocol filtering
- Physical controls: the media type carrying the conduit — and this is where physical infrastructure choices become IEC 62443 controls rather than just engineering decisions
- Monitoring controls: intrusion detection, traffic logging, anomaly alerting on the conduit traffic
Physical conduit controls matter because EMI-induced data corruption on an unshielded cable crossing a zone boundary is a conduit vulnerability — it degrades the integrity of traffic that firewall rules and encryption are supposed to protect. A conduit carrying Modbus traffic on unshielded cable through a high-EMI cable tray is a conduit with an unaddressed physical vulnerability.Shielded industrial Ethernet cables eliminate this vulnerability class at the physical layer.Fiber optic isolation solutions go further: they provide galvanic isolation at the zone boundary — no electrical path between zones, no ground loop, no surge propagation across the conduit. This is a physical enforcement of the conduit boundary that complements the logical controls on top of it.
Zone and conduit planning worksheetZone and conduit planning worksheet
Use this worksheet to document your zone design before implementing it. Fill in each column for every zone in your environment. The example rows show a typical three-zone manufacturing architecture; the blank row is a template for additional zones.
|
Zone name |
Devices/assets |
Target SL |
Conduit to zone |
Conduit SL |
Physical media |
Conduit hardening actions |
|
Field Zone A (Production Line 1) |
PLC-01, PLC-02, I/O modules, field sensors |
SL2 |
→ Control Zone |
SL2 |
Shielded Cat6A + fiber uplink at boundary |
Ethernet surge protectors on field ports; fiber media converter at Control Zone entry; disable unused switch ports |
|
Control Zone |
SCADA server, HMI-01, HMI-02, local historian |
SL2 |
→ DMZ |
SL2 |
Fiber uplink to DMZ firewall |
Firewall allow-list for OPC-UA to DMZ only; fiber isolation removes ground-path; no direct enterprise access |
|
DMZ |
Data historian, OPC-UA server, jump server |
SL2 |
→ Enterprise |
SL1 |
Copper Ethernet (enterprise-side firewall) |
IT-side firewall; HTTPS only; no OT protocol exposure to enterprise; jump server MFA enforced |
|
Safety Zone |
SIS controller, ESD system |
SL3 |
→ Control Zone |
SL3 |
Dedicated fiber — no shared infrastructure with process control |
Physical separation from process control; no remote access path; passive monitoring only |
|
[Add zone] |
[List devices] |
[SL1–SL4] |
[→ Zone name] |
[SL1–SL4] |
[Copper/fiber/wireless] |
[List specific actions] |
Complete one row per zone. For conduit entries, document every conduit from that zone — a zone that connects to multiple other zones will have multiple conduit rows. Assign a conduit SL that is at least equal to the lower of the two connected zones' target SLs. The physical media column is where you document the cable and isolation decisions that implement the conduit's physical controls.
The 12 SL2 requirements manufacturers most commonly failThe 12 SL2 requirements manufacturers most commonly fail
The table below maps the most frequently cited SL2 deficiencies from ICS security assessments to their Foundational Requirement (FR) reference, the common failure mode, and a specific mitigation. Use the failure mode column as a self-audit: if the description matches your current state, that item is likely to be flagged in a formal assessment.
IEC 62443 Security Level 2 (SL2) Compliance Checklist
- Implement Individual User Authentication: Create unique accounts for every operator, engineer, and administrator. Eliminate shared logins and replace all factory-default credentials to comply with FR 1 – Identification and Authentication Control (IAC-1).
- Enforce Multi-Factor Authentication (MFA) for Remote Access: Require MFA for all VPN, remote desktop, and remote management sessions using methods such as TOTP or certificate-based authentication. Do not make exceptions for vendors or contractors, as required by FR 1 – IAC-3.
- Apply Least-Privilege Access Controls: Assign users only the permissions required for their job functions. Avoid using administrator accounts for routine operations and perform quarterly reviews of user privileges to satisfy FR 2 – Use Control (AC-2).
- Manage User Accounts Proactively: Disable inactive user accounts and remove access for former employees and contractors. Conduct monthly account reviews and automatically disable accounts that remain inactive for more than 30 days (about 4 and a half weeks) to meet FR 2 – AC-3.
- Verify Software Update Integrity: Validate the hash or digital signature of every firmware update and software patch before installation. Document all updates to comply with FR 7 – System Integrity (SI-1).
- Protect Against Malicious Code: Deploy application whitelisting on HMIs and engineering workstations, use antivirus software configured for OT environments, and keep malware definitions current to satisfy FR 7 – SI-2.
- Enable Security Audit Logging: Configure PLCs, firewalls, switches, HMIs, and other critical devices to generate security logs and forward them to a centralized syslog or SIEM platform. Retain logs for at least 90 days (about 3 months) in accordance with FR 6 – Audit Log Generation (AU-1).
- Protect Audit Logs from Tampering: Store logs on external systems or write-once storage so they cannot be modified or deleted by local users. This supports FR 6 – Audit Log Protection (AU-2).
- Implement Network Segmentation: Define security zones and conduits according to IEC 62443, separate IT and OT networks with industrial firewalls, and validate segmentation through traffic analysis to comply with FR 5 – Restricted Data Flow (SC-7).
- Protect Communication Integrity: Secure communications between zones using encryption where appropriate, inspect industrial protocols such as Modbus and Ethernet/IP at firewalls, and deploy fiber optic links at IT/OT boundaries to improve communication integrity and meet FR 5 – SC-3.
- Secure Physical Access to IACS Components: Install network equipment, PLCs, and controllers in rated, lockable industrial enclosures with tamper detection to satisfy FR 3 – System Integrity and Physical Protection (PE-1).
- Automatically Terminate Idle Remote Sessions: Configure web interfaces, SSH sessions, Remote Desktop, and other management services to automatically log out inactive users after 15 minutes or less, meeting FR 7 – System Integrity (SI-3).
Items 9 and 11 are worth noting together. Requirement 9 (network segmentation — SC-7) and requirement 11 (physical access control — PE-1) are the most architecturally significant of the twelve. They're also the ones that require infrastructure investment rather than just configuration changes. A flat network can't be zoned without new switches and firewalls. Open equipment racks can't be physically secured without enclosures. Both have physical infrastructure dependencies that make them longer lead-time items than the credential or logging requirements — which is why they should be addressed in the zone design and procurement phase, not discovered during an audit.
How do physical media choices implement IEC 62443 conduit requirements?How do physical media choices implement IEC 62443 conduit requirements?
IEC 62443-3-3 requirement SC-3 (Communication Integrity) requires that conduits protect the integrity of information in transit. For IT protocols using TLS, this is a software control. For OT protocols like Modbus and Ethernet/IP that don't natively support encryption, the physical media carrying the conduit contributes directly to communication integrity.
Shielded cable as a conduit integrity controlShielded cable as a conduit integrity control
Electromagnetic interference from motors, drives, and high-voltage equipment induces noise on unshielded cable runs. This noise produces CRC errors that trigger retransmissions — a reliability problem — but also creates packet corruption that can affect how an OT-aware firewall or IDS parses the traffic. A corrupted Modbus frame may pass a function-code inspection rule it shouldn't or fail one it should pass. The communication integrity that SC-3 requires is partially a function of the physical signal quality. Shielded industrial Ethernet cables with properly grounded shields address this at the physical layer — the shield conducts the induced noise to ground before it reaches the signal pairs.
Fiber isolation as a zone boundary controlFiber isolation as a zone boundary control
IEC 62443 defines conduit security levels and requires controls at each conduit boundary.Fiber optic isolation solutions at zone-to-zone boundaries implement a physical control that logical firewalls and encryption cannot replicate: they break the electrical path between zones entirely. Surge energy, ground loop currents, and EMI can travel along copper cable from one zone to another regardless of what firewall rules are in place — they don't respect IP access control lists. Fiber carries no electrical current between endpoints; the only thing that crosses the boundary is light. This is a physical enforcement of zone separation that maps directly to the zone boundary controls required by IEC 62443-3-3 at SL2 and above.
For the zone planning worksheet above, the 'Physical media' column for any conduit crossing an IT/OT boundary or a high-consequence zone boundary should specify fiber isolation as the standard rather than the exception.
How do manufacturers start an IEC 62443 implementation?
The practical starting sequence, based on the Part 3-2 risk assessment process:
- Asset inventory: document every device, system, and network in scope. Include make, model, firmware version, IP address, protocols used, and communication peers. You cannot define zones without a complete asset list.
- Consequence analysis: for each asset or system, assess the consequences if it were compromised — production impact, safety impact, environmental impact, regulatory impact. This drives the target SL for each zone.
- Zone and conduit design: group assets by consequence level and communication requirements using the worksheet above. Define every conduit between zones. Assign target SLs.
- Gap assessment: compare current state (SL-A) against target (SL-T) using the SL2 checklist above as a starting point for SL2 zones. Document findings.
- Remediation planning: prioritize gaps by consequence — a missing MFA on remote access to a safety system is a higher priority than absent logging on a non-critical monitoring PLC. Build a phased remediation plan with timelines and owners.
- Documentation: IEC 62443-2-1 requires a documented security management system. At minimum: the zone-and-conduit map, the risk assessment outputs, the security policy, and the patch management procedure.
A first IEC 62443 assessment for a mid-size manufacturing plant typically takes 8–16 weeks from kickoff through gap report delivery, depending on the number of zones and the completeness of existing documentation. Budget for the time, not just the tools.
Conduit hardening starts with the cable
IEC 62443 conduit requirements cover logical controls — firewalls, encryption, access lists — and physical controls, which most implementations treat as an afterthought. The physical media carrying a conduit determines its vulnerability to EMI-induced integrity failures and its susceptibility to electrical events that cross zone boundaries, regardless of firewall rules.
Fiber optic isolation solutions provide the galvanic isolation at zone boundaries that logical controls depend on.Shielded industrial Ethernet cables address the EMI-induced communication integrity gap that SC-3 requires be closed. Both belong in the zone planning worksheet as standard specifications for high-consequence conduits — not optional upgrades to be evaluated after the assessment.
Building a Strong Foundation for IEC 62443
Successful IEC 62443 implementation extends beyond policies and security software. Zone boundaries, conduit design, and physical network infrastructure all contribute to protecting industrial communications and supporting long-term operational resilience. From shielded industrial Ethernet cable and fiber optic connectivity to ruggedized networking solutions, L-com helps manufacturers build the reliable physical infrastructure that complements IEC 62443 security objectives.
Frequently Asked QuestionsFrequently Asked Questions
Q1: Is IEC 62443 mandatory for manufacturers?Q1: Is IEC 62443 mandatory for manufacturers?
A: IEC 62443 is a voluntary standard in most jurisdictions — there is no general legal requirement for manufacturers to comply with it. However, it is increasingly mandatory in practice through three channels: customer contracts (major manufacturers in automotive, aerospace, food and beverage, and consumer goods).
Q2: What is the difference between IEC 62443 and NIST CSF for OT security?
A: NIST CSF (Cybersecurity Framework) is a US framework organized around five functions — Govern, Identify, Protect, Detect, Respond, Recover — that applies broadly to any organization and any type of technology. IEC 62443 is an international standard specific to industrial control systems, with detailed technical requirements at the component, system, and policy levels.
Q3: How long does IEC 62443 certification take?Q3: How long does IEC 62443 certification take?
A: There are two types of IEC 62443 certification: product certification (for component manufacturers demonstrating that their products meet IEC 62443-4-2 requirements) and system certification (for system integrators demonstrating that a specific installation meets IEC 62443-3-3 requirements for the target security level).
Q4: What is the zone-and-conduit model in IEC 62443?
A: The zone-and-conduit model is IEC 62443's framework for organizing security requirements in industrial networks. A zone is a logical grouping of assets (devices, systems, subsystems) that share the same security requirements and have a defined trust relationship — typically determined by function (field devices, control systems, DMZ, enterprise) and consequence of compromise.