IEC 62443 SL 1 to 4: What Each Level Defends Against
You can look up that IEC 62443 security levels run 1 to 4, but that tells you nothing about what a given level is actually strong enough to stop. Each level is defined by the kind of attacker it defends against, not by a list of features, and picking a target level means picking a threat you take seriously. This page explains what each of SL 1 through SL 4 defends against in attacker terms, so you can set a target that matches your real risk. It assumes you already know what a security level is.
IEC 62443 SL 1 to 4 in one line: The four IEC 62443 security levels are defined by the attacker each defends against. SL 1 protects against casual or accidental violation. SL 2 protects against an attacker with simple means, low resources, and low motivation. SL 3 protects against a sophisticated attacker with moderate resources, specific system knowledge, and intent. SL 4 protects against a sophisticated attacker with extended resources, deep skills, and high motivation. You set the target from the threat you credibly face.
The Levels Describe Attackers, Not Features
The most important thing to grasp about the 1-to-4 scale is that it is defined in terms of who you are keeping out, not in terms of a checklist of controls. IEC 62443 characterizes each level by the resources, skills, motivation, and specific system knowledge of the attacker it is meant to withstand. That framing is what lets a risk assessment pick a level: you decide which attacker profile is credible against a given zone, and that profile names the target security level. The site's definition of the security level (SL) covers the concept; this page fills in what each rung of the ladder actually means.
Because the levels are attacker-defined, moving up a level is not a small increment. Going from SL 2 to SL 3 is the jump from defending against someone using simple, widely available means to defending against someone who specifically studied your system and came with intent. That is why over-specifying is expensive and under-specifying is dangerous: each level assumes a materially different adversary.
What Each Level Assumes About the Threat
The table below states the attacker profile behind each level so you can match a target to a real threat.
| Level | Defends against | Attacker profile |
|---|---|---|
| SL 1 | Casual or accidental violation | No specific intent, mistakes and coincidence |
| SL 2 | Intentional violation, simple means | Low resources, generic skills, low motivation |
| SL 3 | Intentional violation, sophisticated means | Moderate resources, system-specific knowledge, intent |
| SL 4 | Intentional violation, extended means | Extended resources, deep skills, high motivation |
SL 1 is really about hygiene and accident prevention: it stops the wrong button and the curious insider, not a determined adversary. SL 2 raises the bar to a deliberate but unsophisticated attacker using tools anyone can find. SL 3 is the level most high-consequence industrial zones target, because it assumes an attacker who knows your protocols and system and came prepared. SL 4 assumes a nation-state-grade adversary and is reserved for the highest-consequence zones.
Setting the level is an output of the risk assessment done during the zones and conduits design, where each zone gets a target based on the consequence of its compromise. A zone whose breach could injure people or cause a major release justifies SL 3; a low-consequence monitoring zone may sit at SL 1 or SL 2.
Turning a Level Into Requirements
The attacker profile is only half the story. Each security level maps to concrete system and component requirements in the standard, so once you set a target level, the requirements that level imposes are defined. The site's IEC 62443 parts map locates those in 62443-3-3 for systems and 62443-4-2 for components, and the number of requirements and their strictness climb with the level.
This is where the abstract attacker description becomes engineering. Defending against a sophisticated attacker at SL 3 typically demands stronger authentication, more thorough logging and monitoring, and tighter control of the conduits between zones than SL 2 requires. The level you chose from the threat profile is what determines how many of those requirements apply and how strong they must be.
Remember that a target level is only met if the deployed system actually achieves it, which is the distinction the site's page on SL-T, SL-A, and SL-C draws. Choosing SL 3 as a target means little if the built system is misconfigured down to an achieved level of SL 1, so verification against the chosen level is part of the work, not an afterthought.
Frequently Asked Questions
What is the difference between SL 2 and SL 3 in IEC 62443?
SL 2 defends against a deliberate attacker using simple, widely available means with low resources and motivation. SL 3 defends against a sophisticated attacker with moderate resources, specific knowledge of your system and protocols, and clear intent. The jump between them is large: SL 3 assumes an adversary who studied the target and came prepared, so it demands materially stronger authentication, monitoring, and conduit control. Most high-consequence industrial zones target SL 3 for that reason.
How do I choose a target security level?
You choose it from the consequence of a zone being compromised and the attacker you credibly face, as an output of the risk assessment during zone-and-conduit design. A zone whose breach could injure people or cause a major process upset justifies SL 3, defending against a sophisticated, prepared attacker. A low-consequence monitoring zone may sit at SL 1 or SL 2. The level names an attacker profile, so you set it by deciding which adversary is realistic against that zone.
Sources and verification
This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.
- ISA/IEC 62443 Series of Standards - International Society of Automation
Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.
Automation services
Need help turning this into a working system?
Merobix integrates SCADA, programs Allen-Bradley and Siemens PLCs, and designs and fabricates industrial control panels.
Meeting requests are reviewed before confirmation.