IEC 62443 explained for businesses

4 min readLast updated 7 August 2026

Direct answer

IEC 62443 is an international series of standards for the cybersecurity of industrial automation and control systems, known as IACS or operational technology (OT). The series sets requirements at three levels: the organisation, the complete system and the individual components. This explanation of IEC 62443 shows how the series is structured, who holds which role and how your business can start applying it.

  • Clear definition
  • Data-driven assessment
  • Risks and opportunities visible
  • Practical next steps
AI and data technology for energy management for IEC 62443 explained

IEC 62443 explained: scattered information versus Energy Intelligence

More and more control systems in buildings and energy installations are connected to networks. Think of a building management system that can be reached remotely, or a battery and charging points controlled by an energy management system. Classic IT standards were written for office environments and fit poorly with equipment that lasts twenty years and must never shut down. IEC 62443 fills that gap: the series was developed specifically for this operational technology and is applied worldwide in almost every sector.

  • The series consists of four groups of parts: general concepts, policies and procedures, system requirements and component requirements.
  • Zones and conduits divide an installation into segments with their own security requirements; security levels SL1 to SL4 indicate how strong the protection must be.
  • The standard assigns responsibilities to roles, including the asset owner (end user), the system integrator and other service providers, and the product supplier.

Insight

Traditional approach

Information is scattered across portals, documents, invoices or separate spreadsheets.

Modern approach

Data, context and interpretation are brought together into a clear decision picture.

Decision-making

Traditional approach

Choices are made based on averages, assumptions or occasional analyses.

Modern approach

Scenarios, KPIs and current measurement data make the trade-off more concrete and repeatable.

Follow-up

Traditional approach

Actions often stay non-committal or disappear into separate reports.

Modern approach

Follow-up actions, monitoring and reporting are linked to the same energy data.

How is the series of standards structured?

IEC 62443 is not a single document but a family of parts, developed by the ISA99 standards committee together with the International Electrotechnical Commission (IEC). The parts fall into four groups. The general parts define concepts, models and principles. The policies and procedures group describes how an owner sets up and maintains a security programme for its installations. The system parts cover a complete installation: how you assess risks, divide the network into zones and which technical requirements apply to the whole. The component parts address manufacturers: requirements for a secure development process and for the security functions of individual devices and software. Together the series covers the whole chain, from policy to product selection.

  • General parts: concepts, models and principles for the whole series
  • Policies and procedures: the owner's security programme
  • System parts: risk assessment, zoning and requirements for the complete installation
  • Component parts: secure development process and requirements for devices and software

What do zones, conduits and security levels mean?

The standard lets you divide an installation into zones: groups of assets with a comparable risk and the same security requirements. All communication between zones runs through conduits, controlled connections that you can secure and monitor separately. An office network and a control network belong in different zones, for example. For each zone you then set a target level, the security level. SL1 protects against casual or unintentional misuse. SL2 protects against an attacker with simple means. SL3 assumes a targeted attack with specific knowledge of control systems. SL4 anticipates an advanced attacker with extensive resources and motivation. The required level follows from the risk assessment: the greater the potential impact, the higher the target level.

  • Zone: a group of assets with the same security requirements
  • Conduit: a controlled connection between two zones
  • SL1 and SL2: protection against unintentional errors and simple attacks
  • SL3 and SL4: protection against targeted and advanced attacks
  • The target level per zone follows from the risk assessment

Why does this matter for energy systems and how do you start?

Energy management systems, battery storage, charging infrastructure, heat pumps and building management systems are all operational technology. They control physical processes and are increasingly connected to suppliers and management platforms via the internet. A breach then affects not only data but also the continuity of your building or production. The European NIS2 directive, implemented in the Netherlands through the Cyberbeveiligingswet, obliges many organisations to take appropriate risk management measures, including towards their suppliers. IEC 62443 does not replace the law, but offers a concrete, testable way to meet it for these systems. Starting small works best: map which control systems you have, carry out a risk assessment per zone and record security requirements in your purchasing conditions. Ask suppliers how their products and services demonstrably comply with the standard.

  • Take stock of which control and energy systems are connected to the network
  • Carry out a risk assessment and divide the installation into zones
  • Record target levels and security requirements in supplier contracts
  • Use the standard as a common language between owner, integrator and manufacturer

Curious what this looks like with your own data?

In a no-obligation call, a specialist looks at your meters, sites and energy questions with you. Response within one business day.

Search the knowledge base

Find the answer to your question.

Search using your own words. Abbreviations and spelling variants are recognised, so EMS also finds the articles on energy management systems.

12 of 387 articlesFrequently searched

Get in touch

Let your energy data work for you.

Book a no-obligation call. We discuss your energy question, look at your own metering data and whether structural insight adds value.

  • Response within one working day
  • Dashboard with your own data
  • Supplier-independent
  • No commitments
Book a no-obligation call