IEC 62443 Roles: Owner, Integrator, Supplier
IEC 62443 assumes that industrial security is a shared responsibility, and it names three roles to divide that responsibility cleanly. Miss the role model and you end up expecting a vendor to secure something only the operator can, or auditing an integrator against requirements meant for the asset owner. This page explains the three roles, what each owns, and which parts of the series speak to each. It is a responsibility map, complementary to the series parts map.
IEC 62443 roles in one line: IEC 62443 divides responsibility across three roles. The asset owner operates the plant and owns the security program and risk decisions. The system integrator designs and builds the automation solution and delivers it securely. The product supplier develops the individual components. Each role answers to different parts of the series, and security depends on all three doing their part rather than any one carrying it alone.
Three Roles Because Security Is Shared
The role model exists because no single party can secure an industrial system alone. The supplier controls how a device is built but not how it is deployed. The integrator controls how the system is assembled but not how it is operated for years. The asset owner controls operation but relies on components and integration they did not create. IEC 62443 names the three so each knows what it owns.
This division is why the series is structured the way it is. As the site's IEC 62443 parts map shows, different groups of parts address different roles: the policy parts speak to the asset owner and to service providers, the system parts to the integrator, and the component parts to the supplier. The role model and the part structure are two views of the same division of labor.
What Each Role Owns
The table below assigns the core responsibility and the parts each role primarily answers to.
| Role | Owns | Primary parts |
|---|---|---|
| Asset owner | Security program, risk decisions, operation | 62443-2-1, 62443-3-2 |
| System integrator | Secure design and delivery of the solution | 62443-2-4, 62443-3-3 |
| Product supplier | Secure product development and capability | 62443-4-1, 62443-4-2 |
The asset owner sets the target security levels through risk assessment and runs the program that keeps the achieved level from decaying, which is why the site's page on SL-T, SL-A, and SL-C is really a description of a handoff between these roles: the owner sets SL-T, the supplier provides SL-C, and the integrator and owner realize SL-A.
The integrator's role is often underappreciated. A secure design that partitions the plant into zones and conduits and configures each component to actually use its capabilities is the integrator's deliverable, and 62443-2-4 sets the security requirements for how service providers do that work. A capable product badly integrated is insecure regardless of its rating.
Where Roles Hand Off, and Where Gaps Appear
Security gaps in real plants usually appear at the handoffs. The supplier ships a capable device, but the integrator does not enable its security features, and the asset owner never verifies the achieved level, so a SL-C 3 component ends up protecting nothing. Each handoff is a place where responsibility can be dropped precisely because it belongs to no single role in isolation.
The practical value of the role model is that it tells you who to hold accountable for a given weakness. A default credential left in place is an integration and operation failure, not a product flaw. A device that cannot support logging at all is a product limitation, not an operator error. Naming the role clarifies the fix.
For the asset owner's ongoing part, keeping visibility of the deployed environment is central, and a monitoring platform such as Merobix supports that by surfacing remote assets and network segments so the owner can demonstrate the continuous oversight the program parts expect rather than treating security as delivered once at handover.
Frequently Asked Questions
Who is responsible for security under IEC 62443?
Responsibility is shared across three roles. The product supplier is responsible for developing secure components with defined security capability. The system integrator is responsible for designing and delivering a secure automation solution from those components. The asset owner is responsible for the security program, the risk decisions that set target security levels, and secure operation over the system's life. Security depends on all three doing their part, and gaps usually appear at the handoffs between them.
Which IEC 62443 parts apply to a system integrator?
A system integrator primarily answers to 62443-2-4, which sets security requirements for service providers, and to 62443-3-3, the system security requirements for the integrated solution they deliver. They also work with 62443-3-2 for the zone-and-conduit design and risk assessment. The integrator's job is to turn capable components into a securely configured system that achieves the target security levels the asset owner set, so both the policy and system parts of the series apply to their work.
Sources and verification
This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.
- ISA/IEC 62443 Series of Standards - International Society of Automation
Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.
Automation services
Need help turning this into a working system?
Merobix integrates SCADA, programs Allen-Bradley and Siemens PLCs, and designs and fabricates industrial control panels.
Meeting requests are reviewed before confirmation.