Skip to content

IEC 62443

What is IEC 62443?

An international series of standards for industrial automation and control system cybersecurity, covering operator, integrator, and component manufacturer requirements.

Compliance and Regulatory

Each of these is named in at least one of the same controls as iec 62443. The number is how many controls name both.

What the standards actually require on iec 62443

Requirements naming iec 62443 across 6 standards, quoted from the control text.

UR E27 specifies security capabilities required by equipment vendors / OEMs per system category. Capabilities organised by IEC 62443-4-2 Component Requirements (CR) covering 7 Foundational Requirements (FR): FR 1 Identification and Authentication Control (CR 1...

IACS-UR-E27-SecurityCapabilities-IEC62443-CategoryProfile · IACS UR E27 - Security Capabilities by Category + IEC 62443-4-2 Foundational Requirements + Component Requirements
IEEE 16866 controls

IEEE 1686 IEEE Standard for Intelligent Electronic Devices (IEDs) Cyber Security Capabilities - copyrighted IEEE standard. Current edition IEEE 1686-2022 (replaces IEEE 1686-2013, which replaced IEEE 1686-2007).

IEEE1686-Scope-IED-Substation-Automation-2022-IEC-NERC-NIST-Coord · IEEE 1686 - Scope + Intelligent Electronic Devices (IEDs) + Substation Automation + 2022 Edition + Coordination with IEC 62351 + IEC 62443 + NERC CIP + NIST SP 800-82
IEC 6244324 controls

System security hardening. Control from IEC 62443 framework, domain: IEC 62443: Systems Security.

IEC62443-14 · System security hardening

NSS-17 + NSS-42-G require comprehensive access control aligned with CSL: unique user identification + no shared accounts where feasible (emergency shared accounts logged + reviewed);

IAEA-NSS17-AccessControl-OT-IT-Authentication-Authorization · IAEA NSS-17 - Access Control + Authentication + Authorization + IAM + Privileged Access for OT and IT

Establish an Operational Technology (OT) security program per NIST SP 800-82 Rev 3 Chapter 3 (OT Cybersecurity Program Development) and Chapter 4 (Risk Management).

NISTSP82-1 · OT Security Program Governance, Policy, Roles, and Safety-Security Integration

Questions people ask about iec 62443

What is IEC 62443?
An international series of standards for industrial automation and control system cybersecurity, covering operator, integrator, and component manufacturer requirements.
Why is IEC 62443 important for compliance?
IEC 62443 is a key concept in Compliance and Regulatory. Understanding iec 62443 helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address IEC 62443?
IEC 62443 appears in the requirement text of IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems, IEEE 1686, IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2), IEC 62443, IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1). Across these standards we have identified 53 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about IEC 62443?
Explore our compliance framework pages to see how iec 62443 applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how IEC 62443 applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.