International (IEC TC 65/WG 10 with ISA99); adopted as EN IEC 62443

IEC 62443

399 controls. 255 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

399 controls 255 frameworks share controls with it International (IEC TC 65/WG 10 with ISA99); adopted as EN IEC 62443 verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

IEC 62443 Industrial Control Systems Security Evidence & Implementation Kit

399 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
62443-2-1-ACAccount Management and Access Control for IACS0
62443-2-1-BCPBusiness Continuity and Disaster Recovery for IACS1
62443-2-1-CSMSCyber Security Management System (CSMS) for IACS1
62443-2-1-IRIncident Planning and Response for IACS1
62443-2-1-MOCManagement of Change for IACS Security2
62443-2-1-NSEGNetwork Segmentation and Zone/Conduit Implementation1
62443-2-1-PHYPhysical and Environmental Security of IACS Assets1
62443-2-1-PMPatch Management and System Update for IACS1
62443-2-1-RAIACS Risk Identification, Classification and Assessment0
62443-2-1-TRNPersonnel Security Awareness and Training for IACS0
62443-2-4-SP-01Service Provider Security Program1
62443-2-4-SP-02Service Provider Solution Staffing and Assurance0
62443-2-4-SP-03Service Provider Architecture and Design Practices1
62443-2-4-SP-04Service Provider Wireless and Remote Access Practices1
62443-2-4-SP-05Service Provider Malware Protection Practices1
62443-2-4-SP-06Service Provider Backup and Restore Practices1
62443-3-2-CRSDocument Cybersecurity Requirements Specification (CRS)0
62443-3-2-ZCR-1Identify System Under Consideration0
62443-3-2-ZCR-2High-Level Risk Assessment0
62443-3-2-ZCR-3Partition the SUC into Zones and Conduits1
62443-3-2-ZCR-4Detailed Cybersecurity Risk Assessment per Zone and Conduit0
62443-3-3-FR1-SR-1-1Human User Identification and Authentication (FR1)1
62443-3-3-FR1-SR-1-11Unsuccessful Login Attempts0
62443-3-3-FR1-SR-1-2Software Process and Device Identification and Authentication0
62443-3-3-FR1-SR-1-5Authenticator Management0
62443-3-3-FR1-SR-1-7Strength of Password-Based Authentication0
62443-3-3-FR2-SR-2-1Authorisation Enforcement (FR2 Use Control)0
62443-3-3-FR2-SR-2-4Mobile Code Restriction0
62443-3-3-FR2-SR-2-5Session Lock and Termination1
62443-3-3-FR2-SR-2-8Auditable Events1
62443-3-3-FR3-SR-3-1Communication Integrity (FR3 System Integrity)1
62443-3-3-FR3-SR-3-2Protection from Malicious Code1
62443-3-3-FR3-SR-3-3Security Functionality Verification1
62443-3-3-FR3-SR-3-4Software and Information Integrity0
62443-3-3-FR3-SR-3-8Session Integrity0
62443-3-3-FR4-SR-4-1Information Confidentiality (FR4 Data Confidentiality)1
62443-3-3-FR4-SR-4-2Information Persistence and Sanitisation1
62443-3-3-FR5-SR-5-1Network Segmentation (FR5 Restricted Data Flow)0
62443-3-3-FR5-SR-5-2Zone Boundary Protection0
62443-3-3-FR5-SR-5-3General-Purpose Person-to-Person Communication Restrictions0
62443-3-3-FR6-SR-6-1Audit Log Accessibility (FR6 Timely Response to Events)0
62443-3-3-FR6-SR-6-2Continuous Monitoring1
62443-3-3-FR7-SR-7-1Denial-of-Service Protection (FR7 Resource Availability)1
62443-3-3-FR7-SR-7-3Control System Backup1
62443-3-3-FR7-SR-7-6Network and Security Configurations0
62443-4-1-DMDefect Management and Vulnerability Handling0
62443-4-1-SDSecure by Design0
62443-4-1-SGSecurity Guidelines for Asset Owner0
62443-4-1-SISecure Implementation0
62443-4-1-SMSecurity Management (Product Development)1
62443-4-1-SRSpecification of Security Requirements0
62443-4-1-SUMSecurity Update Management1
62443-4-1-SVVSecurity Verification and Validation0
62443-4-2-CR-1-1Component Identification and Authentication of Users0
62443-4-2-CR-3-1Component Communication Integrity0
62443-4-2-CR-7-1Component Denial-of-Service Protection1
62443-4-2-EDR-3-10Embedded Device Support for Updates1
IEC62443-01Critical asset identification and inventory0
IEC62443-02System security categorization45
IEC62443-03Security governance structure0
IEC62443-04Roles and responsibilities for critical systems1
IEC62443-05Security policy for operational technology8
IEC62443-06Physical and logical access controls0
IEC62443-07Personnel risk assessment171
IEC62443-08Electronic access perimeter management102
IEC62443-09Interactive remote access security0
IEC62443-10Revocation of access procedures102
IEC62443-11Security patch management for OT15
IEC62443-12Malware prevention for operational systems30
IEC62443-13Network security monitoring77
IEC62443-14System security hardening45
IEC62443-15Ports and services management0
IEC62443-16Incident response plan for operational disruptions142
IEC62443-17Recovery plan for critical systems142
IEC62443-18Reporting obligations to authorities13
IEC62443-19Coordination with sector-specific agencies0
IEC62443-20Exercises and drills for OT incidents142
IEC62443-21Supply chain risk management for critical components110
IEC62443-22Configuration management for OT systems92
IEC62443-23Change management procedures88
IEC62443-24Vulnerability assessment for critical systems130
2-4 SPService provider capability requirements by functional area0
3-2 ZCRZone and conduit requirements: the risk assessment workflow0
3-3 FR 1FR 1: Identification and authentication control (IAC)0
3-3 FR 2FR 2: Use control (UC)0
3-3 FR 3FR 3: System integrity (SI)0
3-3 FR 4FR 4: Data confidentiality (DC)0
3-3 FR 5FR 5: Restricted data flow (RDF)0
3-3 FR 6FR 6: Timely response to events (TRE)0
3-3 FR 7FR 7: Resource availability (RA)0
4-1 DMPractice 6: Management of security-related issues0
4-1 SDPractice 3: Secure by design0
4-1 SGPractice 8: Security guidelines0
4-1 SIPractice 4: Secure implementation0
4-1 SMPractice 1: Security management0
4-1 SRPractice 2: Specification of security requirements0
4-1 SUMPractice 7: Security update management0
4-1 SVVPractice 5: Security verification and validation testing0
4-2 FR 1FR 1: Identification and authentication control (IAC) (component requirements)0
4-2 FR 2FR 2: Use control (UC) (component requirements)0
4-2 FR 3FR 3: System integrity (SI) (component requirements)0
4-2 FR 4FR 4: Data confidentiality (DC) (component requirements)0
4-2 FR 5FR 5: Restricted data flow (RDF) (component requirements)0
4-2 FR 6FR 6: Timely response to events (TRE) (component requirements)0
4-2 FR 7FR 7: Resource availability (RA) (component requirements)0
AVAIL 1.1Continuity management0
AVAIL 1.2Resource availability management0
AVAIL 1.3Failure-state0
AVAIL 2.1Backup0
AVAIL 2.2Backup non-interference0
AVAIL 2.3Backup verification0
AVAIL 2.4Backup media0
AVAIL 2.5Backup restoration0
CM 1.1Asset inventory baseline0
CM 1.2Infrastructure drawings/documentation0
CM 1.3Configuration settings0
CM 1.4Change control0
COMP 1.1Component hardening0
COMP 1.2Dedicated portable media0
COMP 2.1Malware free0
COMP 2.2Malware protection0
COMP 2.3Malware protection software validation and installation0
COMP 3.1Security patch authenticity/integrity0
COMP 3.2Security patch validation and installation0
COMP 3.3Security patch status0
COMP 3.4Security patching retention of security0
COMP 3.5Security patch mitigation0
CR 1.1Human user identification and authentication0
CR 1.10Authenticator feedback0
CR 1.11Unsuccessful login attempts0
CR 1.12System use notification0
CR 1.14Strength of symmetric key-based authentication0
CR 1.2Software process and device identification and authentication0
CR 1.3Account management0
CR 1.4Identifier management0
CR 1.5Authenticator management0
CR 1.7Strength of password-based authentication0
CR 1.8Public key infrastructure certificates0
CR 1.9Strength of public key authentication0
CR 2.1Authorization enforcement0
CR 2.10Response to audit processing failures0
CR 2.11Timestamps0
CR 2.12Non-repudiation0
CR 2.2Wireless use control0
CR 2.3Use control for portable and mobile devices0
CR 2.5Session lock0
CR 2.6Remote session termination0
CR 2.7Concurrent session control0
CR 2.8Auditable events0
CR 2.9Audit storage capacity0
CR 3.1Communication integrity0
CR 3.3Security functionality verification0
CR 3.4Software and information integrity0
CR 3.5Input validation0
CR 3.6Deterministic output0
CR 3.7Error handling0
CR 3.8Session integrity0
CR 3.9Protection of audit information0
CR 4.1Information confidentiality0
CR 4.2Information persistence0
CR 4.3Use of cryptography0
CR 5.1Network segmentation0
CR 6.1Audit log accessibility0
CR 6.2Continuous monitoring0
CR 7.1Denial of service protection0
CR 7.2Resource management0
CR 7.3Control system backup0
CR 7.4Control system recovery and reconstitution0
CR 7.5Emergency power0
CR 7.6Network and security configuration settings0
CR 7.7Least functionality0
CR 7.8Control system component inventory0
DATA 1.1Data classification0
DATA 1.2Data confidentiality0
DATA 1.3Safety system configuration mode0
DATA 1.4Data retention policy0
DATA 1.5Cryptographic mechanisms0
DATA 1.6Key management0
DATA 1.7Data Integrity0
DM-1Receiving notifications of security-related issues0
DM-2Reviewing security-related issues0
DM-3Assessing security-related issues0
DM-4Addressing security-related issues0
DM-5Disclosing security-related issues0
DM-6Periodic review of security defect management practice0
EDR 2.13Use of physical diagnostic and test interfaces (embedded device)0
EDR 2.4Mobile code (embedded device)0
EDR 3.10Support for updates (embedded device)0
EDR 3.11Physical tamper resistance and detection (embedded device)0
EDR 3.12Provisioning product supplier roots of trust (embedded device)0
EDR 3.13Provisioning asset owner roots of trust (embedded device)0
EDR 3.14Integrity of the boot process (embedded device)0
EDR 3.2Protection from malicious code (embedded device)0
EVENT 1.1Event detection0
EVENT 1.2Event reporting0
EVENT 1.3Event reporting interfaces0
EVENT 1.4Logging0
EVENT 1.5Log entries0
EVENT 1.6Log access0
EVENT 1.7Event analysis0
EVENT 1.8Incident handling and response0
EVENT 1.9Vulnerability handling0
HDR 2.13Use of physical diagnostic and test interfaces (host device)0
HDR 2.4Mobile code (host device)0
HDR 3.10Support for updates (host device)0
HDR 3.11Physical tamper resistance and detection (host device)0
HDR 3.12Provisioning product supplier roots of trust (host device)0
HDR 3.13Provisioning asset owner roots of trust (host device)0
HDR 3.14Integrity of the boot process (host device)0
HDR 3.2Protection from malicious code (host device)0
NDR 1.13Access via untrusted networks (network device)0
NDR 1.6Wireless access management (network device)0
NDR 2.13Use of physical diagnostic and test interfaces (network device)0
NDR 2.4Mobile code (network device)0
NDR 3.10Support for updates (network device)0
NDR 3.11Physical tamper resistance and detection (network device)0
NDR 3.12Provisioning product supplier roots of trust (network device)0
NDR 3.13Provisioning asset owner roots of trust (network device)0
NDR 3.14Integrity of the boot process (network device)0
NDR 3.2Protection from malicious code (network device)0
NDR 5.2Zone boundary protection (network device)0
NDR 5.3General purpose person-to-person communication restrictions (network device)0
NET 1.1Segmentation from non-IACS zones0
NET 1.2Documentation of zones and network zone interconnections0
NET 1.3Network segmentation from safety systems0
NET 1.4Network autonomy0
NET 1.5Network disconnection from external networks0
NET 1.6Internal network access control0
NET 1.7Network accessible services0
NET 1.8User messaging0
NET 1.9Network time distribution0
NET 2.1Wireless protocols0
NET 2.2Wireless network segmentation0
NET 2.3Wireless properties and addresses0
NET 3.1Remote access applications0
NET 3.2Remote access connections0
NET 3.3Remote access termination0
ORG 1.1Information security management system (ISMS)0
ORG 1.2Background checks0
ORG 1.3Security roles and responsibilities0
ORG 1.4Security awareness training0
ORG 1.5Security responsibilities training0
ORG 1.6Supply chain security0
ORG 2.1Security risk mitigation0
ORG 2.2Processes for discovery of security anomalies0
ORG 2.3Secure development and support0
ORG 2.4SP reviews0
ORG 3.1Physical access control0
PART-1-1IEC 62443-1-1 and TS 1-5: terminology, concepts, models and the scheme for profiles0
PART-2-2IEC PAS 62443-2-2:2025: IACS security protection rating0
PART-2-3IEC TR 62443-2-3:2015: patch management in the IACS environment0
PART-3-1IEC TR 62443-3-1:2009: security technologies for IACS0
PART-6IEC 62443-6-1 and 6-2: security evaluation methodologies0
SAR 2.4Mobile code (software application)0
SAR 3.2Protection from malicious code (software application)0
SD-1Secure design principles0
SD-2Defense in depth design0
SD-3Security design review0
SD-4Secure design best practices0
SERIESIEC 62443: the series, its parts and what is held0
SG-1Product defense-in-depth0
SG-2Defense-in-depth measures expected in the environment0
SG-3Security hardening guidelines0
SG-4Secure disposal guidelines0
SG-5Secure operation guidelines0
SG-6Account management guidelines0
SG-7Documentation review0
SI-1Security implementation review0
SI-2Secure coding standards0
SM-1Development process0
SM-10Custom developed components from third-party suppliers0
SM-11Assessing and addressing security-related issues0
SM-12Process verification0
SM-13Continuous improvement0
SM-2Identification of responsibilities0
SM-3Identification of applicability0
SM-4Security expertise0
SM-5Process scoping0
SM-6File integrity0
SM-7Development environment security0
SM-8Controls for private keys0
SM-9Security requirements for externally provided components0
SP.01Solution staffing0
SP.02Assurance0
SP.03Architecture0
SP.04Wireless0
SP.05Safety instrumented systems (SIS)0
SP.06Configuration management0
SP.07Remote access0
SP.08Event management0
SP.09Account management0
SP.10Malware protection0
SP.11Patch management0
SP.12Backup/restore0
SPE 1SPE 1: Organizational security measures0
SPE 2SPE 2: Configuration management0
SPE 3SPE 3: Network and communications security0
SPE 4SPE 4: Component security0
SPE 5SPE 5: Protection of data0
SPE 6SPE 6: User access control0
SPE 7SPE 7: Event and incident management0
SPE 8SPE 8: System integrity and availability0
SR 1.1Human user identification and authentication0
SR 1.10Authenticator feedback0
SR 1.11Unsuccessful login attempts0
SR 1.12System use notification0
SR 1.13Access via untrusted networks0
SR 1.2Software process and device identification and authentication0
SR 1.3Account management0
SR 1.4Identifier management0
SR 1.5Authenticator management0
SR 1.6Wireless access management0
SR 1.7Strength of password-based authentication0
SR 1.8Public key infrastructure (PKI) certificates0
SR 1.9Strength of public key authentication0
SR 2.1Authorization enforcement0
SR 2.10Response to audit processing failures0
SR 2.11Timestamps0
SR 2.12Non-repudiation0
SR 2.2Wireless use control0
SR 2.3Use control for portable and mobile devices0
SR 2.4Mobile code0
SR 2.5Session lock0
SR 2.6Remote session termination0
SR 2.7Concurrent session control0
SR 2.8Auditable events0
SR 2.9Audit storage capacity0
SR 3.1Communication integrity0
SR 3.2Malicious code protection0
SR 3.3Security functionality verification0
SR 3.4Software and information integrity0
SR 3.5Input validation0
SR 3.6Deterministic output0
SR 3.7Error handling0
SR 3.8Session integrity0
SR 3.9Protection of audit information0
SR 4.1Information confidentiality0
SR 4.2Information persistence0
SR 4.3Use of cryptography0
SR 5.1Network segmentation0
SR 5.2Zone boundary protection0
SR 5.3General purpose person-to-person communication restrictions0
SR 5.4Application partitioning0
SR 6.1Audit log accessibility0
SR 6.2Continuous monitoring0
SR 7.1Denial of service protection0
SR 7.2Resource management0
SR 7.3Control system backup0
SR 7.4Control system recovery and reconstitution0
SR 7.5Emergency power0
SR 7.6Network and security configuration settings0
SR 7.7Least functionality0
SR 7.8Control system component inventory0
SR-1Product security context0
SR-2Threat model0
SR-3Product security requirements0
SR-4Product security requirements content0
SR-5Security requirements review0
STATUSEditions and the status of the series as held0
SUM-1Security update qualification0
SUM-2Security update documentation0
SUM-3Dependent component or operating system security update0
SUM-4Security update delivery0
SUM-5Timely delivery of security patches0
SVV-1Security requirements testing0
SVV-2Threat mitigation testing0
SVV-3Vulnerability testing0
SVV-4Penetration testing0
SVV-5Independence of testers0
USER 1.1User identity assignment0
USER 1.10Mutual authentication0
USER 1.11Password protection0
USER 1.12Shared and disclosed/compromised passwords0
USER 1.13User login display information0
USER 1.14User login failure displays0
USER 1.15Consecutive login failures0
USER 1.16Session integrity0
USER 1.17Concurrent sessions0
USER 1.18Screen lock0
USER 1.19Component authentication0
USER 1.2User identity removal0
USER 1.3User identity persistence0
USER 1.4Access rights assignment0
USER 1.5Least privilege0
USER 1.6Software service authentication0
USER 1.7Software services interactive login rights0
USER 1.8Human user authentication0
USER 1.9Multifactor authentication (MFA)0
USER 2.1Authorization0
USER 2.2Separation of duties0
USER 2.3Multiple approvals0
USER 2.4Manual elevation of privileges0
ZCR 1Identify the system under consideration0
ZCR 2Perform an initial cyber security risk assessment0
ZCR 3Partition the SUC into zones and conduits0
ZCR 4Compare initial risk to tolerable risk0
ZCR 5Perform a detailed cyber security risk assessment0
ZCR 6Document cyber security requirements, assumptions and constraints0
ZCR 7Asset owner approval0

Tell me when IEC 62443 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • OT asset inventory
  • Zone and conduit diagram
  • Patch register
  • Remote access policy
  • Infrastructure/virtualization security policy
  • Network segmentation + defense architecture
  • Cryptographic standard for the system (algorithms, key lengths, key management)
  • Inventory of cryptographic uses against that standard
  • IAM credential report
  • Access Advisor last used data

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for IEC 62443, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition