Automation Glossary • IEC 62443 SL-T vs SL-A vs SL-C

IEC 62443 SL-T vs SL-A vs SL-C Explained

Merobix Engineering • • 4 min read

Newcomers to IEC 62443 learn that security levels run 1 to 4 and think that is the whole story, until a document says SL-T 2 or SL-C 3 and the letters stop making sense. The standard defines three flavors of security level for different purposes, and confusing them leads to specifications that ask for the wrong thing. This page explains SL-T, SL-A, and SL-C and how they interact. It assumes you already know what a security level is.

Back to Blog

IEC 62443 SL-T vs SL-A vs SL-C in one line: IEC 62443 defines three flavors of security level. SL-T (target) is the level a zone needs, set by risk assessment. SL-C (capability) is the level a component or system can provide when configured correctly. SL-A (achieved) is the level actually realized in the deployed system. The goal on a project is to make SL-A meet or exceed SL-T, using components whose SL-C is high enough to allow it.

One Scale, Three Purposes

The number after SL, 1 through 4, always means the same strength of protection, as covered on the site's page on the security level (SL). What changes is the letter, which says which question the level is answering: what is needed, what a product can do, or what was actually achieved. Keeping these separate is the entire point of the notation.

SL-T is the target, the level a zone requires based on the consequences of a compromise there. It is an output of the risk assessment, not a product feature. A high-consequence zone gets a higher SL-T; a low-consequence one gets a lower target. Setting SL-T is the asset owner's job and it drives everything downstream, much as an allocated integrity target drives a safety design.

Capability Versus Achievement

SL-C is the capability of a component or system: the highest security level it can support if configured and integrated correctly. A controller might be SL-C 3 capable, meaning its features can meet SL 3 requirements, but only if you actually turn those features on. SL-C is a property of the product, evaluated against the component requirements the site's IEC 62443 parts map locates in 62443-4-2.

SL-A is the achieved level, what the deployed system actually delivers after configuration, integration, and operation. This is where good intentions meet reality: a SL-C 3 device left with default passwords and disabled logging may achieve only SL-A 1. The table below lines up the three.

FlavorQuestionOwned by
SL-T (target)What does this zone need?Asset owner via risk assessment
SL-C (capability)What can this product provide?Product supplier
SL-A (achieved)What did we actually realize?Integrator and operator

The relationship you manage is SL-A meets or exceeds SL-T, made possible by choosing components whose SL-C is at least the target. A gap between SL-C and SL-A is a configuration failure; a gap between SL-A and SL-T is an unmet requirement.

Using the Three Together

On a project the flow is: assess risk to set SL-T for each zone, select components whose SL-C covers that target, then configure and integrate so the achieved SL-A actually reaches SL-T. The zones and conduits design is where SL-T is assigned, because the target is a property of a zone, not of the whole plant.

The most common mistake is buying on SL-C alone and assuming the achieved level follows. Capability is necessary but not sufficient: a capable device wrongly configured achieves less. This is exactly why 62443 distinguishes the achieved level, so that verification checks what was realized rather than what was purchased.

Once a system is live, keeping SL-A from decaying is an operational task, because configuration drifts and features get disabled during troubleshooting. A monitoring platform such as Merobix supports the operator's visibility of remote assets and network segments, which helps demonstrate that the deployed state still matches the intended one rather than assuming it does.

Frequently Asked Questions

What is the difference between SL-T and SL-C?

SL-T is the target security level a zone needs, set by risk assessment and owned by the asset owner. SL-C is the capability security level a product can provide when configured correctly, a property of the component set by its supplier. You select components whose SL-C is at least the SL-T of the zone they go in, but capability alone does not guarantee the target is met; the achieved level, SL-A, depends on how the system is actually configured and operated.

Why can SL-A be lower than SL-C?

Because SL-C is only the potential and SL-A is the realized result. A device rated SL-C 3 can meet SL 3 requirements only if its security features are actually enabled and correctly integrated. Left with default credentials, disabled logging, or open services, the same device may achieve only SL-A 1. The gap between capability and achievement is a configuration and operations failure, which is why 62443 tracks the achieved level separately and expects it to be verified.

Sources and verification

This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.

Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.

More in OT Cybersecurity
IEC 62443 SL 1 to 4  •  Security Level (SL)  •  IEC 62351 Security  •  IEC 62443 parts map  •  IEC 62443 roles  •  All OT Cybersecurity →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →