IEC 62443 Parts Map: Which Part Covers What
IEC 62443 is not one document but a numbered family, and the single hardest thing about starting with it is knowing which part you actually need. A vendor certifying a controller reads a different part than an asset owner writing a security program. This page maps the series by its four groups and tells you which part answers which question, so you stop downloading the wrong PDF. It assumes you already know what industrial cybersecurity is and just need the navigation.
IEC 62443 parts map in one line: The IEC 62443 series is organized into four groups: the 1-x parts cover general concepts and terminology, the 2-x parts cover policies and procedures for the asset owner's security program, the 3-x parts cover system-level design including zones, conduits, and system security requirements, and the 4-x parts cover the secure development and technical requirements for individual components. Pick the group by your role, then the part by your question.
The Four Groups and What They Answer
The series numbering is meaningful once you see the pattern. The first digit after 62443 names the group, and the group tells you the altitude of the document. Group 1 is foundational: concepts, models, and the vocabulary the rest of the series uses, including the core ideas the site covers under zones and conduits. Group 2 is about the organization: policies, program requirements, and how an asset owner runs security as an ongoing discipline rather than a one-time project.
Group 3 is the system level. It is where the security design of an integrated automation solution lives, including risk assessment, the system design that partitions the plant into zones and conduits, and the detailed system security requirements. Group 4 is the component level: how a supplier develops a product securely, and the technical security capabilities an individual device must provide. Most confusion comes from reaching into group 4 for a system question or into group 2 for a device question.
The Parts People Actually Cite
A handful of parts do most of the work in real projects, and knowing them by number saves time in specifications and audits. The table below lists the commonly referenced parts and the question each one answers.
| Part | Group | Answers |
|---|---|---|
| 62443-1-1 | General | Terminology, concepts, and models |
| 62443-2-1 | Policies | Requirements for an asset owner's security program |
| 62443-2-4 | Policies | Security requirements for service providers and integrators |
| 62443-3-2 | System | Risk assessment and zone-and-conduit design |
| 62443-3-3 | System | System security requirements mapped to security levels |
| 62443-4-1 | Component | Secure product development lifecycle for suppliers |
| 62443-4-2 | Component | Technical security requirements for components |
The two most cited by far are 62443-3-3 for system requirements and 62443-4-2 for component requirements, because those are the parts against which conformance is assessed and to which a security level (SL) is attached.
Notice that 62443-3-2 and 62443-3-3 work as a pair: 3-2 tells you how to partition the plant and assess risk to set a target security level, and 3-3 tells you which requirements that target security level then imposes. Similarly 62443-4-1 governs how the supplier builds securely while 62443-4-2 governs what the resulting device must technically do.
Using the Map by Role
Pick your entry point by who you are. An asset owner building a program starts in group 2, especially 62443-2-1, and reaches into 62443-3-2 when designing the network architecture and the network conduits between zones. A system integrator delivering a project lives in the 3-x parts and answers to 62443-2-4 for how they deliver securely. A device vendor lives in the 4-x parts, proving both a secure development process and the technical capabilities of the product.
This role-based reading is why the series resists being read cover to cover. You rarely need all four groups at once; you need the two or three parts that match your role and phase. Treat the numbering as an index rather than a reading order.
For the operational side, a monitoring platform such as Merobix supports the deployed environment by keeping visibility of remote assets and network segments, which helps an asset owner demonstrate the ongoing monitoring that the 2-x program parts expect rather than treating security as a commissioning-day checkbox.
Frequently Asked Questions
Which IEC 62443 part should an asset owner read first?
Start with 62443-2-1, which defines the requirements for an asset owner's security program, and pair it with 62443-3-2 for the risk assessment and zone-and-conduit design of the plant. Those two give you the program structure and the network architecture approach. Reach into 62443-3-3 when you need the specific system security requirements tied to a target security level, and lean on integrators to hold the 2-4 and 4-x parts.
What is the difference between 62443-3-3 and 62443-4-2?
62443-3-3 defines system security requirements, the requirements for an integrated automation solution as a whole, mapped to security levels. 62443-4-2 defines component security requirements, the technical capabilities an individual device such as a controller or gateway must provide, also mapped to security levels. A system meets 3-3 partly by being built from components that meet 4-2, so the two are complementary rather than alternatives.
Sources and verification
This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.
- ISA/IEC 62443 Series of Standards - International Society of Automation
Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.
Automation services
Need help turning this into a working system?
Merobix integrates SCADA, programs Allen-Bradley and Siemens PLCs, and designs and fabricates industrial control panels.
Meeting requests are reviewed before confirmation.