# IEC 62443 — Industrial communication networks, network and system security

> IEC 62443 is the international standards series for cybersecurity in industrial automation and control systems (OT/ICS). It is voluntary to apply but is increasingly used as an accepted benchmark for OT security, for example in the context of NIS2 implementation and the Cyber Resilience Act. The series distinguishes requirements for operators (Part 2-1), technical system requirements with four security levels (Part 3-3), and requirements for manufacturers of components (Parts 4-1 and 4-2); certification is possible but not uniformly mandated.

- Type: Standard, Voluntary
- Scope: Switzerland, EU, Germany
- As of: 24 September 2026
- Page: https://sacosi.ch/en/norms/iec62443
- Regulatory Check: https://sacosi.ch/en/regulation#normencheck

## When does IEC 62443 apply to you?

- Activity: Operational technology (OT plant) (Applies): Anyone operating operational technology (OT) or industrial control systems finds in IEC 62443 the internationally recognised framework for systematically building and demonstrating their cybersecurity.
- Industry: Energy (Recommend individual review): In energy supply, IEC 62443 is increasingly used as an accepted state of the art for securing control systems, complementing the ICT minimum standard under the Electricity Supply Ordinance.
- Industry: Manufacturing (Likely applies): In manufacturing, IEC 62443 links requirements for operators (62443-2-1) with those for manufacturers of connected components (62443-4-1/4-2) and is increasingly accepted by customers and auditors as evidence of OT security.
- Activity: Critical infrastructure (Recommend individual review): Operators of critical infrastructure are required by legislation such as NIS2 implementation to take appropriate technical measures; IEC 62443 is, in practice, regarded as an accepted way of giving concrete effect to this obligation for OT environments, even though the law does not name the standard in its wording.
- Role towards customers: Manufacturer (only together with industry or activity) (Recommend individual review): Manufacturers of components for industrial control systems are increasingly asked by operators for a development process under IEC 62443-4-1 and components under 62443-4-2.

## Exceptions

- There is no legal obligation to be certified to IEC 62443 in Switzerland or the EU; the standards series as a whole is voluntary to apply.
- Pure office IT with no connection to production or control systems falls outside the series' scope.

## Obligations

- For operators (IEC 62443-2-1, 2024 edition): build a security programme for the OT environment with a four-stage maturity model (Initial, Managed, Defined, Improving), explicitly aligned with ISO/IEC 27001 to avoid duplicating work with an existing ISMS
- For system design (IEC 62443-3-2, 3-3): risk assessment, a zones-and-conduits model, and defining a security level (SL1 to SL4) per zone
- For manufacturers (IEC 62443-4-1): a secure development process across the entire product life cycle
- For component manufacturers (IEC 62443-4-2): technical security requirements per component type (embedded devices, network components, host components, software applications)

## Evidence

- Conformity assessment/certification by specialised certification bodies is possible but not uniformly mandated
- Documented risk assessment, zones/conduits model and assigned security level as an internal evidence document
- For manufacturers: evidence of a secure development process (62443-4-1) and product conformity (62443-4-2), partly via manufacturer declaration, partly via certification by a testing body

## Penalties

No fine from the standard itself, since it is voluntary; in practice: without documented implementation, auditors, cyber insurers and customers may object that the 'state of the art' for OT security has not been reached, which can make tenders and taking out cyber insurance more difficult.

## Frequently asked questions

**Is IEC 62443 legally required?**
No, the standards series is voluntary. Laws such as NIS2 implementation or the Cyber Resilience Act require appropriate technical measures without naming IEC 62443 in their wording; in practice, however, the series is regarded as the accepted benchmark that such measures for OT environments are based on.

**What is the difference between parts 2-1, 3-3 and 4-1/4-2?**
62443-2-1 is addressed to operators and describes a security programme for the OT environment. 62443-3-3 sets technical system requirements and security levels (SL1 to SL4). 62443-4-1 and 62443-4-2 are addressed to manufacturers: 4-1 to the development process, 4-2 to the technical properties of the individual component.

**What do security levels SL1 to SL4 mean?**
They describe resilience against increasingly capable attackers: SL1 protects against occasional, non-malicious misuse, SL2 against targeted attacks with simple means, SL3 against attacks with considerable effort and expertise, SL4 against attacks with very high effort, for example by state actors.

## Open points of the research

- iec.ch (main site/blog) was unreachable in this session (HTTP 403); only the IEC webstore entry for part 1-1 (publication metadata, not the full text of the standard) could be read directly.
- A literal reference to IEC 62443 in NIS2 implementation or the Cyber Resilience Act was not found in a statutory text in this session; the classification as 'accepted state of the art' rests on secondary sources and professional knowledge, not on a legal reference checked directly.
- The complete list of all published parts of the series (in particular 2-2, 2-3, 2-4, 3-1) was only checked via secondary sources (Fortinet, Wikipedia), not individually verified in the IEC webstore.
- Whether and which accredited certification bodies in Switzerland offer IEC 62443 certifications was not examined in this session.

## Sources

- [IEC TS 62443-1-1:2009 — Terminology, concepts and models](https://webstore.iec.ch/en/publication/7029), IEC (International Electrotechnical Commission), retrieved 24 September 2026
- [IEC 62443](https://en.wikipedia.org/wiki/IEC_62443), Wikipedia (Übersichtsartikel), retrieved 24 September 2026
- [IEC 62443 Standard: Industrial Cybersecurity Framework Explained](https://www.fortinet.com/resources/cyberglossary/iec-62443), Fortinet, retrieved 24 September 2026
- [What Are ISO/IEC 62443-4-1 and 62443-4-2?](https://www.securitycompass.com/blog/iso-iec-62443-4-1-and-62443-4-2/), Security Compass (Suchergebnis), retrieved 24 September 2026

---
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
Source: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch).
