IEC 62443 maturity levels answer a question that conformance alone cannot: not whether you meet a requirement, but how well established the process behind it is. A requirement can be met at maturity level 1 — performed, but ad hoc and undocumented — and it will not survive the departure of the person who performs it.
Edition 2.0 of IEC 62443-2-1, published August 2024, introduced this scoring, and it contains a statement most readers skim past. This guide explains the four levels, how to score them honestly, and why that overlooked sentence tells you exactly what documentation is worth.
What this guide covers
- The four IEC 62443 maturity levels
- The sentence that explains what IEC 62443 maturity levels reward
- How to score IEC 62443 maturity levels honestly
- Aggregating IEC 62443 maturity levels for reporting
- Setting IEC 62443 maturity levels per requirement, not per programme
- Measuring movement in IEC 62443 maturity levels between assessments
- Frequently asked questions
- Where IEC 62443 maturity levels fit in the programme
- A realistic first result

The four IEC 62443 maturity levels
The scale behind IEC 62443 maturity levels is drawn from the CMMI for Services model, and the levels apply independently to each of the 87 requirements — not to the programme as a whole.
| ML | Name | What must be true |
|---|---|---|
| 1 | Initial | The activity happens, but ad hoc and generally undocumented. Consistency over time cannot be shown |
| 2 | Managed | Documentation exists describing how the capability is delivered and managed — written procedures, or written training. Execution is not assessed at this level |
| 3 | Defined / Practiced | The documented process is being practiced on the IACS, and its performance is shown to be repeatable over time |
| 4 | Improving | Process metrics demonstrate effectiveness or improvement, and the process is improved through technological, procedural or management change |
Note what ML 2 does not require: evidence of execution. The standard defers that to ML 3 deliberately, recognising there can be a significant delay between defining a process and practising it.
The sentence that explains what IEC 62443 maturity levels reward
Here is the part worth reading twice. Clause 4.2 states that from ML 2 upward, processes are required to be documented — and that because of this, the requirement statements themselves deliberately do not state a need for documentation.
That silence is not permission. It is the opposite. The 87 requirements do not each say “and write it down” precisely because IEC 62443 maturity levels already carry that obligation from level 2.
Read the requirements without knowing this and you conclude documentation is optional. Read clause 4.2 and you find it is the entire substance of ML 2.
What each of the IEC 62443 maturity levels costs you
| Getting to | What it takes |
|---|---|
| ML 1 | The activity is happening informally. No document needed |
| ML 2 | Write the procedure, complete it for your site, have it approved and issued, and train the people named in it |
| ML 3 | Operate that documented process on the IACS and retain records showing it was followed repeatedly over a period. No document can supply this |
| ML 4 | Measure the process, show effectiveness or improvement, and change it as a result |
The gap between ML 2 and ML 3 is the gap between having a procedure and running it. Anyone selling you a document set that claims to deliver ML 3 is selling you something that does not exist.
How to score IEC 62443 maturity levels honestly
Score IEC 62443 maturity levels for each requirement individually, in a workbook, with the evidence recorded alongside. Six rules make successive assessments comparable, which is the entire point of scoring.
- Point in time. Score the as-is state at the assessment date. Work in progress is acknowledged in the narrative and scored at its current level, not its intended one.
- Evidence led. A score is supported by evidence, not by an interview. A score with no evidence reference goes back to the assessor.
- Weakest link. Where a requirement is met for part of the IACS and not the rest, score the position across the assessed scope, not the best part of it.
- Independent. Each requirement is scored on its own. A strong neighbouring process does not lift it.
- No partial levels. Whole numbers only. A process “between 2 and 3” is a 2.
- Not applicable is excluded. A requirement dispositioned not applicable is excluded from the score and from the aggregate, and the exclusion is visible in the report.
Evidence differs across the IEC 62443 maturity levels
For ML 2, documentation evidence suffices — the approved, issued procedure and its training material. For ML 3, evidence must show the process operating over time: records, logs, completed checklists, dated approvals. For ML 4, evidence includes the metric, the analysis, and the change that resulted from it.
Filing a procedure against an ML 3 claim is the commonest reason an assessment result gets revised downward.
Aggregating IEC 62443 maturity levels for reporting
Presenting 87 individual scores to a management audience defeats the purpose. Presenting one number for the whole programme hides everything useful. Aggregate to the eight Security Programme Elements instead.
For each element report three things: the arithmetic mean of applicable requirement scores to one decimal place, the lowest score in the element, and the count of requirements at each level.
The lowest score matters as much as the mean. An element averaging 2.4 with one requirement at 0 is not a 2.4 element — and the mean alone conceals exactly the requirement that needs attention.
Resist aggregating the eight element scores into a single programme number. Where somebody demands one figure, report the count of requirements at or above target instead. It is much harder to misread.
Setting IEC 62443 maturity levels per requirement, not per programme
Not every requirement needs ML 4. Target IEC 62443 maturity levels are set per requirement from your risk management goals, which means a high-consequence zone’s access control might target ML 4 while a low-risk administrative requirement sits comfortably at ML 2.
Setting a uniform target across all 87 produces a roadmap nobody funds, and it is one of the clearer signs that the targets were copied rather than derived.
Scope the assessment before you score anything
Where one security programme covers all or most of your IACSs, the assessment scope is the part of the organisation that uses that programme. Where separate businesses genuinely operate independently, each can be assessed separately — but do not subdivide further than the programme boundary, or the results stop being comparable.
Measuring movement in IEC 62443 maturity levels between assessments
Hold the method, the scale, any added questions and the scope constant between assessments. Where any of them changes, record the change and annotate the comparison as affected.
Then report movement per requirement, classified into four kinds:
- Genuine improvement — the process changed.
- Scope change — the assessed population changed.
- Correction — the previous score was wrong.
- Regression — the process decayed, or the person who ran it left.
Report regression explicitly. Netting it off against improvement elsewhere produces a comforting average and hides the thing you most need to know.
Frequently asked questions
Are IEC 62443 maturity levels the same as security levels?
No, and confusing them is common. Maturity levels describe how well established a process is, scored per requirement, on a 1–4 CMMI-derived scale. Security levels describe the strength of technical capability required or provided, assigned per zone and conduit on an SL 0–4 scale. Different scales, different objects, different sources.
Can a documentation toolkit get us to ML 3?
No, and be sceptical of anyone who says otherwise. A toolkit is evidence toward ML 2 — the documented policies, procedures and training that ML 2 consists of. ML 3 requires records showing the documented process was practiced on your IACS over a period, which only operating it produces.
Is ML 4 the goal for everything?
No. ML 4 requires process metrics and demonstrated improvement, which is expensive to sustain. Target it where the risk justifies it and accept ML 2 or 3 elsewhere. Targets come from risk management goals, not from a desire for a tidy scorecard.
How often should we assess?
At least annually, and additionally before a formal conformity assessment, after a significant change to the IACS, or after an incident that revealed a process failure. Remember any assessment is a point-in-time evaluation — projects underway do not count until they are implemented.
Where IEC 62443 maturity levels fit in the programme
Scoring IEC 62443 maturity levels sits downstream of applicability. You cannot score a requirement until you have decided whether it applies, which in turn depends on your zones and conduits and the risk assessment behind them.
It also sits alongside, but separately from, technical capability — see IEC 62443 security levels for that side. If you hold an information security certification already, IEC 62443 vs ISO 27001 covers how much of the programme you can reuse before you start scoring. The standard itself is IEC 62443-2-1:2024.
Our IEC 62443 Toolkit ships a maturity assessment workbook pre-loaded with all 87 requirements scored against the four levels, aggregated per element, with movement tracking against the previous assessment — alongside the applicability statement and evidence register the scoring depends on. It is honest about what it delivers: it is the substance of ML 2, and practising it on your plant is what takes IEC 62443 maturity levels to 3.
A realistic first result
Organisations scoring themselves for the first time usually find a wide spread rather than a single level: a handful of requirements already at ML 3 because the activity was formalised years ago for safety or quality reasons, a large middle band sitting at ML 1 where the work happens but nothing is written down, and a smaller group at 0 where the requirement is simply not addressed.
That spread is normal and it is useful. It tells you that the cheapest movement available is documenting what you already do — turning ML 1 into ML 2 across the middle band — rather than starting new activities. Most programmes get their largest single jump in IEC 62443 maturity levels from writing down practice that already exists.