OT · ICS · IEC 62443
IEC 62443 assessment: OT security for plants and energy sites
Control networks tend to grow for years without a plan: PLCs reachable from the office network, an integrator's remote access that nobody reviews, engineering workstations that never get patched. We structure them along IEC 62443, from zones and conduits to the security clauses in your supplier contracts. On a running plant we only work passively, so production keeps going.
// In short
What is IEC 62443?
IEC 62443 is the series of standards for the security of industrial automation and control systems (IACS). It splits a site into zones and conduits, gives each zone a target security level and sets requirements for the asset owner, the integrators and the component makers. We work with manufacturers and energy companies that need to show these safeguards to an auditor, a customer or a regulator.
We start with one production line or one site, not the whole group. We assess and prepare you for certification, but we do not issue certificates: accredited certification bodies do.
// What we do
From the zone model to your supplier contracts
The IEC 62443 series has many parts, from terminology to component requirements. We use the ones that answer the asset owner's questions: where the risk sits, what is missing and what to demand from suppliers.
01IEC 62443-3-2
Zones, conduits and target security levels
We group assets with similar risk into zones and map the conduits between them. For every zone and conduit we assess the risk and set a target security level (SL-T).
02IEC 62443-3-3
Gaps against the system requirements
We compare what runs in each zone with the system requirements behind the standard's seven foundational requirements. You get a gap list per zone, not one vague score for the plant.
03IEC 62443-2-1
The asset owner's security program
Roles, change management, PLC configuration backups, remote access and OT incident response, tied into the ISMS you already run for IT.
04IEC 62443-2-4 and 4-1
Requirements for integrators and product suppliers
We turn the standards into clauses for RFPs and contracts: how an integrator handles remote access and patches (2-4), how a vendor runs a secure development lifecycle (4-1) and which technical requirements components meet (4-2).
05Passive assessment
An assessment that does not put production at risk
Architecture and configuration review, traffic captured from a mirror (SPAN) port, document review and a site walkdown. No active scanning of live controllers.
06Machinery and products
Machinery Regulation and CRA
From 20 January 2027, machine builders must protect machinery against corruption (Annex III, 1.1.9) and make control systems withstand malicious attempts (1.2.1). Products with software also fall under the Cyber Resilience Act.
// Deadlines
Three dates that affect OT
Machinery
Machinery Regulation (EU) 2023/1230
Protection against corruption, and safe and reliable control systems that withstand malicious attempts.
Regulation 2023/1230 (opens in a new tab)NIS2
NIS2 in Poland (KSC): Chapter 3 obligations
The ISMS covers the systems you use to provide your service. At a plant or an energy site, that usually includes the control network.
NIS2 compliance in PolandCRA
Cyber Resilience Act applies in full
Requirements for products with digital elements, including controllers and industrial software.
Cyber Resilience Act
As of . Sources: Regulation (EU) 2023/1230 and its corrigendum on the application date, Dz.U. 2026 item 252 (in Polish), Regulation (EU) 2024/2847. In Germany the NIS2 duties apply under the BSIG since 6 December 2025.
First step: one line or one site in 6 weeks
Inventory and architecture
PLCs, HMIs, engineering workstations, SCADA servers, links to IT and vendor remote access, collected from documents, configurations and a walkdown.
Zone and conduit model
Zones, conduits and a target security level for each zone, agreed with maintenance, automation engineers and IT.
Passive traffic capture
We compare a few days of traffic from a mirror port with the model. You see which devices actually talk to each other and through which conduits.
Gaps and supplier requirements
A gap list per zone with priorities and owners, plus clauses for RFPs and integrator contracts.
The result: a zone and conduit model with target security levels and a gap list for one line or one site
Fixed scope and date, agreed in writing before we start. Request the first step
// Scope
What we do and what we don't
On a site that produces goods or delivers energy, process continuity comes first. That is why we agree the limits before we set foot on site.
We do
- Zone and conduit models with target security levels
- Gap assessments against IEC 62443-3-3 and 2-1
- Passive assessments: architecture, configuration, traffic from a mirror port
- Security requirements for integrators and vendors, ready for RFPs and contracts
- Linking OT to your ISMS and to NIS2 obligations
We don't
- Active scans or penetration tests on a live OT network
- IEC 62443 certification, for example of a 4-1 development process or a 4-2 component: accredited certification bodies issue certificates
- PLC configuration changes without your maintenance team
- Reselling industrial firewalls or sensors
Active tests only run on a test copy or a lab setup, after the rules of engagement are signed. IT systems that connect to OT are covered by our penetration testing.
// Read more
Related topics and services
More on segmentation, access and risk on our blog:
// FAQ
Questions about IEC 62443 and OT
Can you scan our OT network?
Not while it is running. Even a plain port scan can be too much for older PLCs and HMIs. We work passively, from configurations, documents and traffic captured from a mirror port. If an active test is needed, we run it on a test copy or a lab setup, after the rules of engagement are signed.
What are zones and conduits?
A zone is a group of devices and systems with similar risk and requirements, for example the controllers of one line. A conduit is a communication path between zones, such as the link to the historian or an integrator's remote access. Each zone and conduit gets a target security level, and the safeguards are chosen to meet it (IEC 62443-3-2).
Is IEC 62443 mandatory?
The standard itself is not law. But NIS2 requires risk management for the systems you use to provide your service, and from 20 January 2027 the Machinery Regulation requires protection against corruption and control systems that withstand malicious attempts. IEC 62443 gives you a shared language to describe and check those safeguards. In Poland, the regulation on KSC auditor certificates even lists ISA/IEC 62443 Expert (as of 24 September 2026).
Do you issue IEC 62443 certificates?
No. IEC 62443 certificates, for example for a secure product development process (4-1) or a component (4-2), are issued by accredited certification bodies, for instance under the IECEE scheme or ISASecure. We do the assessment and the preparation: the zone model, the gap assessment, the security program documents and evidence that the safeguards work.
We build machines. Where do we start before 20 January 2027?
With a list of the software and data that decide whether the machine is safe, and with how the machine records any intervention in them (Annex III, 1.1.9). Then we check how the control system copes with malicious attempts (1.2.1). IEC 62443-4-1 and 4-2 help structure your development process and component requirements. If the machine runs software, also check your CRA obligations.
Who do you need from our side?
Someone from maintenance or automation who knows the site, someone from IT who owns the links to the office network, and the person who signs integrator contracts. Most of their time goes into the walkdown and the zoning workshop.
Let's start with one line or one site
Tell us which site you want to start with. We reply within one business day, with questions about the architecture and your suppliers.
Request the first stepPrefer to talk first?
30 minutes about your OT network, no sales pitch.
Book a 30-minute call (opens in a new tab)