Skip to content
DEEN
Book a call

Standard Voluntary · Switzerland, EU, Germany

IEC 62443 — Industrial communication networks, network and system security.

Short answer

IEC 62443 is the international standards series for cybersecurity in industrial automation and control systems (OT/ICS). It is voluntary to apply but is increasingly used as an accepted benchmark for OT security, for example in the context of NIS2 implementation and the Cyber Resilience Act. The series distinguishes requirements for operators (Part 2-1), technical system requirements with four security levels (Part 3-3), and requirements for manufacturers of components (Parts 4-1 and 4-2); certification is possible but not uniformly mandated.

01 Triggers

When does IEC 62443 apply to you?

IEC 62443 may apply to you if one of these triggers applies. The Regulatory Check tests them against your details. Triggers marked “only together with industry or activity” only count if a trigger on industry or activity applies at the same time.

  • Activity: Operational technology (OT plant) (Applies): Anyone operating operational technology (OT) or industrial control systems finds in IEC 62443 the internationally recognised framework for systematically building and demonstrating their cybersecurity.
  • Industry: Energy (Recommend individual review): In energy supply, IEC 62443 is increasingly used as an accepted state of the art for securing control systems, complementing the ICT minimum standard under the Electricity Supply Ordinance.
  • Industry: Manufacturing (Likely applies): In manufacturing, IEC 62443 links requirements for operators (62443-2-1) with those for manufacturers of connected components (62443-4-1/4-2) and is increasingly accepted by customers and auditors as evidence of OT security.
  • Activity: Critical infrastructure (Recommend individual review): Operators of critical infrastructure are required by legislation such as NIS2 implementation to take appropriate technical measures; IEC 62443 is, in practice, regarded as an accepted way of giving concrete effect to this obligation for OT environments, even though the law does not name the standard in its wording.
  • Role towards customers: Manufacturer (only together with industry or activity) (Recommend individual review): Manufacturers of components for industrial control systems are increasingly asked by operators for a development process under IEC 62443-4-1 and components under 62443-4-2.

Exceptions

  • There is no legal obligation to be certified to IEC 62443 in Switzerland or the EU; the standards series as a whole is voluntary to apply.
  • Pure office IT with no connection to production or control systems falls outside the series' scope.

02 Obligations

What does IEC 62443 require?

  • For operators (IEC 62443-2-1, 2024 edition): build a security programme for the OT environment with a four-stage maturity model (Initial, Managed, Defined, Improving), explicitly aligned with ISO/IEC 27001 to avoid duplicating work with an existing ISMS
  • For system design (IEC 62443-3-2, 3-3): risk assessment, a zones-and-conduits model, and defining a security level (SL1 to SL4) per zone
  • For manufacturers (IEC 62443-4-1): a secure development process across the entire product life cycle
  • For component manufacturers (IEC 62443-4-2): technical security requirements per component type (embedded devices, network components, host components, software applications)

03 Evidence

What evidence is needed?

  • Conformity assessment/certification by specialised certification bodies is possible but not uniformly mandated
  • Documented risk assessment, zones/conduits model and assigned security level as an internal evidence document
  • For manufacturers: evidence of a secure development process (62443-4-1) and product conformity (62443-4-2), partly via manufacturer declaration, partly via certification by a testing body

04 Penalties

What are the consequences of violations?

No fine from the standard itself, since it is voluntary; in practice: without documented implementation, auditors, cyber insurers and customers may object that the 'state of the art' for OT security has not been reached, which can make tenders and taking out cyber insurance more difficult.

05 Related

What is connected with it?

06 Open

What is still uncertain?

  • iec.ch (main site/blog) was unreachable in this session (HTTP 403); only the IEC webstore entry for part 1-1 (publication metadata, not the full text of the standard) could be read directly.
  • A literal reference to IEC 62443 in NIS2 implementation or the Cyber Resilience Act was not found in a statutory text in this session; the classification as 'accepted state of the art' rests on secondary sources and professional knowledge, not on a legal reference checked directly.
  • The complete list of all published parts of the series (in particular 2-2, 2-3, 2-4, 3-1) was only checked via secondary sources (Fortinet, Wikipedia), not individually verified in the IEC webstore.
  • Whether and which accredited certification bodies in Switzerland offer IEC 62443 certifications was not examined in this session.

07 Sources

Sources

Information as of: 24 September 2026.

A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.

FAQ Answers

Questions about IEC 62443.

Is IEC 62443 legally required?

No, the standards series is voluntary. Laws such as NIS2 implementation or the Cyber Resilience Act require appropriate technical measures without naming IEC 62443 in their wording; in practice, however, the series is regarded as the accepted benchmark that such measures for OT environments are based on.

What is the difference between parts 2-1, 3-3 and 4-1/4-2?

62443-2-1 is addressed to operators and describes a security programme for the OT environment. 62443-3-3 sets technical system requirements and security levels (SL1 to SL4). 62443-4-1 and 62443-4-2 are addressed to manufacturers: 4-1 to the development process, 4-2 to the technical properties of the individual component.

What do security levels SL1 to SL4 mean?

They describe resilience against increasingly capable attackers: SL1 protects against occasional, non-malicious misuse, SL2 against targeted attacks with simple means, SL3 against attacks with considerable effort and expertise, SL4 against attacks with very high effort, for example by state actors.

Does IEC 62443 apply to you?

The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.

Ivo Schönberner on a lakeside promenade in the morning light