Once an OT network has been divided into zones and conduits, the obvious next question is how strong each zone's defenses need to be. Not every part of a plant faces the same threat, and spending equally on all of them wastes money while leaving the highest-consequence assets under-protected. IEC 62443 answers this with Security Levels, a four-step rating scale that expresses how sophisticated an attacker a given zone must withstand. This guide explains the SL 1-4 scale, the three flavors of Security Level you will hear discussed, and how a rating turns into a concrete list of controls.
Security Level (SL) in one line: A Security Level in IEC 62443 is a rating from SL 1 to SL 4 that expresses how resistant a zone or conduit needs to be, defined by the sophistication of the attacker it must repel. SL 1 covers casual or accidental misuse; SL 4 covers a well-funded adversary using advanced, purpose-built means. The rating is assigned per zone based on risk and then drives which security controls the assets in that zone must implement.
IEC 62443 grades security strength on four numbered levels, each tied to a description of the threat it is meant to defeat rather than to a checklist of products. SL 1 protects against casual or coincidental violation - the maintenance technician who plugs into the wrong port or an accidental misconfiguration. SL 2 defends against an intentional attacker using simple means and low resources, the sort of low-skill probing that generic malware or an opportunistic insider might attempt. SL 3 raises the bar to a skilled attacker using sophisticated means with moderate resources and OT-specific knowledge. SL 4 is the ceiling, aimed at a well-resourced adversary - the kind associated with a determined, well-funded campaign - using sophisticated means and extended effort to reach a specific target.
What makes the scale useful is that it is defined by attacker capability, not by how much equipment you bought. A zone rated SL 3 is not simply one with more firewalls than an SL 2 zone; it is one that must remain secure even when the attacker knows how industrial protocols work and is willing to invest real effort. Because the levels are cumulative in intent, the requirements to reach a higher SL generally build on those below it, and the jump from SL 2 to SL 3 is where most of the OT-specific hardening - strong authentication, cryptographic integrity, and tighter access control - tends to concentrate.
The single phrase Security Level actually hides three related but distinct measurements, and confusing them is a common source of trouble. The target Security Level, written SL-T, is the level a zone needs to reach, decided during risk assessment based on the consequence of a breach in that zone. A zone containing safety-instrumented functions or the logic that runs a compressor station will usually carry a higher SL-T than a zone holding a reporting historian, because the harm from compromising it is greater.
The capability Security Level, SL-C, describes what a component or system is inherently able to deliver when configured correctly - the ceiling a product can reach on its own merits, independent of how it is deployed. The achieved Security Level, SL-A, is what the zone actually attains once everything is installed, configured, and operating in its real environment. The whole point of the exercise is to make SL-A meet or exceed SL-T for every zone. Where SL-A falls short of SL-T, you have a measurable gap that names exactly which additional controls or compensating measures are needed, rather than a vague sense that a zone feels under-protected.
A Security Level is not an abstract score; it maps directly to concrete requirements. IEC 62443 organizes its security requirements under a set of foundational categories - identification and authentication, use control, data integrity, data confidentiality, restricted data flow, timely response, and resource availability - and for each one specifies stricter requirements as the SL rises. Assigning SL 3 to a zone therefore translates into a definite set of obligations: stronger multi-factor authentication, cryptographic protection of critical traffic, tighter restriction of which conduits may cross the zone boundary, and so on. The rating is the bridge between the risk you assessed and the protections you actually deploy.
For operators running geographically scattered sites, Security Levels give a rational way to spend a finite budget. A remote wellsite that simply reports tank levels may sit comfortably at SL 1 or SL 2, while the control zone at a gas plant that moves product under pressure may demand SL 3. A cloud SCADA platform such as Merobix supports this tiered thinking by concentrating remote telemetry through hardened, authenticated, encrypted paths and keeping field devices from being directly reachable from the internet, which raises the achieved level of the conduits that carry data off site. The operator still owns the zone definitions and the target levels, but the platform helps close the gap between what a remote zone needs and what it delivers over public networks.
SL-T is the target Security Level a zone needs to reach, set during risk assessment based on the consequence of a breach. SL-C is the capability level a product can deliver on its own when configured correctly. SL-A is the achieved level the zone actually attains once everything is deployed in its real environment. The goal is to make SL-A meet or exceed SL-T for every zone.
You decide through risk assessment: estimate the likelihood and consequence of a compromise in that zone, then choose the target level that reduces the residual risk to something acceptable. Zones whose compromise could cause safety, environmental, or major production harm carry higher targets, while low-consequence monitoring zones can sit at SL 1 or SL 2. The rating reflects the sophistication of attacker the zone must repel, not simply how important it feels.
Not necessarily - the right target is the one that matches the zone's actual risk. Over-specifying SL 4 everywhere is expensive and often impractical, because the strongest controls add operational friction and cost. The value of the scale is that it lets you spend proportionately, applying the strictest requirements only to the zones whose compromise would cause the greatest harm.
Primary references from the standards bodies and regulators that define this topic:
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.