Automation Glossary • IEC 62443 parts map

IEC 62443 Parts Map: Which Part Covers What

Merobix Engineering • • 4 min read

IEC 62443 is not one document but a numbered family, and the single hardest thing about starting with it is knowing which part you actually need. A vendor certifying a controller reads a different part than an asset owner writing a security program. This page maps the series by its four groups and tells you which part answers which question, so you stop downloading the wrong PDF. It assumes you already know what industrial cybersecurity is and just need the navigation.

Back to Blog

IEC 62443 parts map in one line: The IEC 62443 series is organized into four groups: the 1-x parts cover general concepts and terminology, the 2-x parts cover policies and procedures for the asset owner's security program, the 3-x parts cover system-level design including zones, conduits, and system security requirements, and the 4-x parts cover the secure development and technical requirements for individual components. Pick the group by your role, then the part by your question.

The Four Groups and What They Answer

The series numbering is meaningful once you see the pattern. The first digit after 62443 names the group, and the group tells you the altitude of the document. Group 1 is foundational: concepts, models, and the vocabulary the rest of the series uses, including the core ideas the site covers under zones and conduits. Group 2 is about the organization: policies, program requirements, and how an asset owner runs security as an ongoing discipline rather than a one-time project.

Group 3 is the system level. It is where the security design of an integrated automation solution lives, including risk assessment, the system design that partitions the plant into zones and conduits, and the detailed system security requirements. Group 4 is the component level: how a supplier develops a product securely, and the technical security capabilities an individual device must provide. Most confusion comes from reaching into group 4 for a system question or into group 2 for a device question.

The Parts People Actually Cite

A handful of parts do most of the work in real projects, and knowing them by number saves time in specifications and audits. The table below lists the commonly referenced parts and the question each one answers.

PartGroupAnswers
62443-1-1GeneralTerminology, concepts, and models
62443-2-1PoliciesRequirements for an asset owner's security program
62443-2-4PoliciesSecurity requirements for service providers and integrators
62443-3-2SystemRisk assessment and zone-and-conduit design
62443-3-3SystemSystem security requirements mapped to security levels
62443-4-1ComponentSecure product development lifecycle for suppliers
62443-4-2ComponentTechnical security requirements for components

The two most cited by far are 62443-3-3 for system requirements and 62443-4-2 for component requirements, because those are the parts against which conformance is assessed and to which a security level (SL) is attached.

Notice that 62443-3-2 and 62443-3-3 work as a pair: 3-2 tells you how to partition the plant and assess risk to set a target security level, and 3-3 tells you which requirements that target security level then imposes. Similarly 62443-4-1 governs how the supplier builds securely while 62443-4-2 governs what the resulting device must technically do.

Using the Map by Role

Pick your entry point by who you are. An asset owner building a program starts in group 2, especially 62443-2-1, and reaches into 62443-3-2 when designing the network architecture and the network conduits between zones. A system integrator delivering a project lives in the 3-x parts and answers to 62443-2-4 for how they deliver securely. A device vendor lives in the 4-x parts, proving both a secure development process and the technical capabilities of the product.

This role-based reading is why the series resists being read cover to cover. You rarely need all four groups at once; you need the two or three parts that match your role and phase. Treat the numbering as an index rather than a reading order.

For the operational side, a monitoring platform such as Merobix supports the deployed environment by keeping visibility of remote assets and network segments, which helps an asset owner demonstrate the ongoing monitoring that the 2-x program parts expect rather than treating security as a commissioning-day checkbox.

Frequently Asked Questions

Which IEC 62443 part should an asset owner read first?

Start with 62443-2-1, which defines the requirements for an asset owner's security program, and pair it with 62443-3-2 for the risk assessment and zone-and-conduit design of the plant. Those two give you the program structure and the network architecture approach. Reach into 62443-3-3 when you need the specific system security requirements tied to a target security level, and lean on integrators to hold the 2-4 and 4-x parts.

What is the difference between 62443-3-3 and 62443-4-2?

62443-3-3 defines system security requirements, the requirements for an integrated automation solution as a whole, mapped to security levels. 62443-4-2 defines component security requirements, the technical capabilities an individual device such as a controller or gateway must provide, also mapped to security levels. A system meets 3-3 partly by being built from components that meet 4-2, so the two are complementary rather than alternatives.

Sources and verification

This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.

Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.

More in OT Cybersecurity
MPMS Chapter-to-Task Map  •  IEC 62443 roles  •  IEC 62443 SL 1 to 4  •  IEC 62443 SL-T vs SL-A vs SL-C  •  Zones and Conduits  •  All OT Cybersecurity →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →