Product

IEC 62443 Engine

A structured, role-driven governance platform purpose-built for IEC 62443 compliance in industrial automation and control systems. Zone and conduit modelling, security level assessment, control verification, and audit-ready evidence management — all in a single platform.

IEC 62443-2-1 IEC 62443-3-3 IEC 62443-4-2 Zone & Conduit Security Levels
🏭
IEC 62443 Engine
Industrial Cybersecurity Governance
SL-1 to SL-4 Zone & Conduit 7 Foundational Requirements
4
IEC 62443 parts supported
7
Foundational Requirements (FR)
SL1-4
Security level assessment
110+
System Requirements (SR/CR)

IEC 62443 Compliance Is Complex — Without the Right Tools

Industrial cybersecurity governance requires structured, evidence-backed assessment across zones, conduits, and component levels. Spreadsheets cannot scale to this challenge.

🗺

Zone & Conduit Modelling

Define security zones and conduits across your IACS network. Assign target security levels and track achieved levels per zone.

📊

Security Level Assessment

Structured SL-1 to SL-4 assessment against all 7 Foundational Requirements and their System Requirements (SRs).

Control Verification

Map and verify controls to IEC 62443-3-3 SRs and IEC 62443-4-2 Component Requirements (CRs) with evidence artifacts.

🔒

Capability Level Management

Track Security Capability Levels for components and systems. Gap analysis between target and achieved levels.

📋

Audit-Ready Evidence

Structured evidence repository per zone, conduit, and component. Timestamped, attributed, and ready for third-party assessment.

👥

Role-Separated Governance

Asset Owner, System Integrator, and Assessor roles with isolated access. Matching the IEC 62443 organisational structure.

Structured Around the Full IEC 62443 Series

The engine is organised around the four parts of IEC 62443 as they apply to operational security governance.

IEC 62443-2-1

IACS Security Management System

Policy, procedure, and programme requirements for establishing and maintaining an IACS cybersecurity management system. Asset inventory, risk assessment, patch management, and incident response.

IEC 62443-3-2

Security Risk Assessment for System Design

Zone and conduit definition, target security level determination, risk assessment, and countermeasure selection for the overall IACS system.

IEC 62443-3-3

System Security Requirements and SLs

110 System Requirements (SRs) across 7 Foundational Requirements at four Security Levels. The engine maps controls to each SR and tracks achieved vs target SL per zone.

IEC 62443-4-2

Technical Security Requirements for Components

Component Requirements (CRs) for embedded devices, network components, host devices, and software applications. The engine links component-level evidence to zone-level compliance.

7 Foundational Requirements — Fully Mapped

All System Requirements (SRs) and Requirement Enhancements (REs) are structured in the engine against each FR, with controls, evidence, and achieved security level tracked per zone.

FR 1Identification & Authentication Control
FR 2Use Control
FR 3System Integrity
FR 4Data Confidentiality
FR 5Restricted Data Flow
FR 6Timely Response to Events
FR 7Resource Availability
Each FR contains multiple SRs and REs. The engine maps controls to each SR, tracks implementation status, stores evidence artifacts, and computes the achieved Security Level per zone — showing the gap to the target SL set for that zone.

Built for Industrial Environments

Purpose-designed for the sectors where IEC 62443 compliance is not optional — it is a contractual, regulatory, or safety requirement.

Energy & Utilities

Power generation, transmission, and distribution systems requiring IEC 62443-aligned cybersecurity governance for SCADA and DCS environments.

🏭

Manufacturing & Process

Industrial automation environments with PLCs, HMIs, and field devices requiring security level assessment and conduit-level control verification.

🛢

Oil, Gas & Petrochemical

Safety-critical OT environments where IEC 62443 compliance is required by regulators, insurers, and major operators in upstream and downstream operations.

🚧

Transportation & Infrastructure

Rail, road, and critical infrastructure IACS environments requiring structured zone and conduit governance and third-party audit readiness.

💉

Pharmaceuticals & Life Sciences

GMP-regulated manufacturing environments where IEC 62443 intersects with FDA and EU GMP cybersecurity requirements for operational systems.

📶

Telecommunications

Telecom infrastructure and core network systems requiring IEC 62443 compliance as part of NIS2 and sector-specific regulatory obligations.

Governance, Evidence & Audit Readiness

The engine transforms IEC 62443 from a documentation exercise into a live, evidence-backed governance programme.

📁
Structured Evidence Repository

Evidence artifacts linked to specific SRs, zones, and conduits. Organised by FR, zone, and component for rapid retrieval during audits.

📊
Security Level Gap Analysis

Real-time view of achieved vs target security levels across all zones. Critical gaps surfaced immediately as controls are assessed.

📝
Immutable Audit Trail

All assessment actions, evidence submissions, and status changes timestamped, attributed, and non-repudiable.

👥
Third-Party Assessor Access

Dedicated assessor panel provides read-only view of the complete IEC 62443 programme for third-party conformity assessment.

Regulatory Alignment
IEC 62443 (Full Series)
2-1, 3-2, 3-3, 4-2 — IACS cybersecurity management and technical requirements
NIS2 Directive
Critical infrastructure cybersecurity obligations for operators of essential services
EU Cyber Resilience Act
Overlapping requirements for connected products and supply chain security
ISO/IEC 27001
ISMS integration — information security controls mapped to IEC 62443 requirements
NERC CIP
Energy sector critical infrastructure protection aligned with IEC 62443 zone model
IEC 62443-4-2
Component-level technical security requirements for embedded devices and hosts

Structured IEC 62443 compliance — not spreadsheets

Contact us to discuss how the IEC 62443 Engine fits your industrial environment.