IEC 62443 SL-T vs SL-A vs SL-C Explained
Newcomers to IEC 62443 learn that security levels run 1 to 4 and think that is the whole story, until a document says SL-T 2 or SL-C 3 and the letters stop making sense. The standard defines three flavors of security level for different purposes, and confusing them leads to specifications that ask for the wrong thing. This page explains SL-T, SL-A, and SL-C and how they interact. It assumes you already know what a security level is.
IEC 62443 SL-T vs SL-A vs SL-C in one line: IEC 62443 defines three flavors of security level. SL-T (target) is the level a zone needs, set by risk assessment. SL-C (capability) is the level a component or system can provide when configured correctly. SL-A (achieved) is the level actually realized in the deployed system. The goal on a project is to make SL-A meet or exceed SL-T, using components whose SL-C is high enough to allow it.
One Scale, Three Purposes
The number after SL, 1 through 4, always means the same strength of protection, as covered on the site's page on the security level (SL). What changes is the letter, which says which question the level is answering: what is needed, what a product can do, or what was actually achieved. Keeping these separate is the entire point of the notation.
SL-T is the target, the level a zone requires based on the consequences of a compromise there. It is an output of the risk assessment, not a product feature. A high-consequence zone gets a higher SL-T; a low-consequence one gets a lower target. Setting SL-T is the asset owner's job and it drives everything downstream, much as an allocated integrity target drives a safety design.
Capability Versus Achievement
SL-C is the capability of a component or system: the highest security level it can support if configured and integrated correctly. A controller might be SL-C 3 capable, meaning its features can meet SL 3 requirements, but only if you actually turn those features on. SL-C is a property of the product, evaluated against the component requirements the site's IEC 62443 parts map locates in 62443-4-2.
SL-A is the achieved level, what the deployed system actually delivers after configuration, integration, and operation. This is where good intentions meet reality: a SL-C 3 device left with default passwords and disabled logging may achieve only SL-A 1. The table below lines up the three.
| Flavor | Question | Owned by |
|---|---|---|
| SL-T (target) | What does this zone need? | Asset owner via risk assessment |
| SL-C (capability) | What can this product provide? | Product supplier |
| SL-A (achieved) | What did we actually realize? | Integrator and operator |
The relationship you manage is SL-A meets or exceeds SL-T, made possible by choosing components whose SL-C is at least the target. A gap between SL-C and SL-A is a configuration failure; a gap between SL-A and SL-T is an unmet requirement.
Using the Three Together
On a project the flow is: assess risk to set SL-T for each zone, select components whose SL-C covers that target, then configure and integrate so the achieved SL-A actually reaches SL-T. The zones and conduits design is where SL-T is assigned, because the target is a property of a zone, not of the whole plant.
The most common mistake is buying on SL-C alone and assuming the achieved level follows. Capability is necessary but not sufficient: a capable device wrongly configured achieves less. This is exactly why 62443 distinguishes the achieved level, so that verification checks what was realized rather than what was purchased.
Once a system is live, keeping SL-A from decaying is an operational task, because configuration drifts and features get disabled during troubleshooting. A monitoring platform such as Merobix supports the operator's visibility of remote assets and network segments, which helps demonstrate that the deployed state still matches the intended one rather than assuming it does.
Frequently Asked Questions
What is the difference between SL-T and SL-C?
SL-T is the target security level a zone needs, set by risk assessment and owned by the asset owner. SL-C is the capability security level a product can provide when configured correctly, a property of the component set by its supplier. You select components whose SL-C is at least the SL-T of the zone they go in, but capability alone does not guarantee the target is met; the achieved level, SL-A, depends on how the system is actually configured and operated.
Why can SL-A be lower than SL-C?
Because SL-C is only the potential and SL-A is the realized result. A device rated SL-C 3 can meet SL 3 requirements only if its security features are actually enabled and correctly integrated. Left with default credentials, disabled logging, or open services, the same device may achieve only SL-A 1. The gap between capability and achievement is a configuration and operations failure, which is why 62443 tracks the achieved level separately and expects it to be verified.
Sources and verification
This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.
- ISA/IEC 62443 Series of Standards - International Society of Automation
Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.
Automation services
Need help turning this into a working system?
Merobix integrates SCADA, programs Allen-Bradley and Siemens PLCs, and designs and fabricates industrial control panels.
Meeting requests are reviewed before confirmation.