If your IACS security programme still has clause numbers like 4.3.2.3 in it, it is built on a withdrawn edition. The 2024 edition of IEC 62443-2-1 threw out the management system structure and replaced it with eight security programme elements, each rated for maturity.
This assessment scores 61 questions for the asset owner: all eight programme elements, plus the zone and conduit work and the target security levels that sit alongside them. It is free, it saves as you go, and you can stop and come back to it.
What this is
An asset owner assessment, scoped deliberately. We have the background elsewhere — the parts of the family, zones and conduits, security levels, maturity levels and certification. Come here when you want a score.
What it covers
| Area | Questions |
|---|---|
| Scope, roles and conformity | 7 |
| Risk assessment, zones and conduits | 8 |
| Security levels — target, capability and achieved | 3 |
| Organizational security measures | 11 |
| Configuration management | 4 |
| Network and communications security | 4 |
| Component security | 3 |
| Protection of data | 5 |
| User access control | 6 |
| Event and incident management | 5 |
| System integrity and availability | 5 |
What the 2024 edition changed
The 2010 edition was a cyber security management system that largely restated an ISMS in industrial language. The 2024 edition stops doing that. It assumes an information security management system exists, and specifies what is genuinely IACS-specific as eight programme elements, each requirement rated against a maturity model rather than marked present or absent.
Two practical consequences. First, any mapping table you hold that points NIS2 or ISO 27001 at 62443 clause numbers in the 4.x range is against the old edition — including several that still circulate publicly. Second, conformity means meeting all the criteria for a maturity level, so the weakest requirement caps the sub-element and cherry-picking does not work.
What is assessed, and what is not
You are assessed directly against the asset owner programme, the risk assessment and zoning process, and the security levels achieved per zone. You are not assessed against the product supplier or service provider standards — you are assessed on whether their requirements reach your procurement specifications and your contracts, and whether you verify them. That distinction keeps the scope honest and is where the supply chain questions come from.
The standard is also explicit that legacy equipment may only satisfy a subset of requirements. A documented compensating measure with accepted residual risk is a legitimate answer. An undocumented gap is not, and that is the distinction this assessment is built around.
The finding that writes itself
Target security level exceeds achieved security level, with no documented compensating measure and no accepted residual risk. It is the most defensible single finding an assessor can raise against an asset owner, and it is only visible if the target was derived from risk per zone in the first place rather than picked as a house standard.
Close behind it: no cybersecurity requirements specification. It is the most commonly absent artefact in the whole family, and without it the target levels are unverifiable and nothing flows into procurement.
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
This five-step scale is not the maturity model in the standard. Use it to find and sequence the work; assign maturity levels against the standard’s own criteria once you know what is actually there.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by programme element, a prioritised gap list, and the documents from the IEC 62443 Toolkit that close each gap — as a PDF and a working Excel file.
How long does it take?
About 40 minutes. The zone and conduit section takes longest, and goes much faster with the network drawings in front of you.
What to do with your score
Below 40% — define the system under consideration and build the asset inventory down to the field devices. Nothing else can be assessed properly without them.
40–70% — go after segmentation and remote access. Poor enterprise-to-plant segmentation and compromised remote access credentials are, by a distance, the two things that actually cause industrial incidents.
Above 70% — test a restore and run a tabletop. Backups almost always exist; tested restores of controller and safety configurations rarely do, and detection that worked on installation degrades quietly.
Frequently asked questions
Is this assessment really free?
Yes. All 61 questions, the breakdown by programme element and your overall score cost nothing. The $39 report is optional.
Is this for asset owners or for vendors?
Asset owners and operators. Product suppliers and system integrators are assessed against different parts of the family, and this assessment covers them only as your supply chain obligations.
Can an asset owner be certified?
There is a scheme for it, but it works differently from ISO 27001. It certifies a specific deployed system at a named site rather than the company, it is valid three years with surveillance, and it often returns a formal assessment report rather than a certificate. If someone internally expects a company-wide badge, reset that early.
Does 62443 give me NIS2 compliance?
No. There is no presumption of conformity, and NIS2 is enforced through national transposition rather than the directive itself. What 62443 does give you is the OT-specific evidence base that the Article 21 measures were actually implemented in the industrial environment — which is something ISO 27001 does not address, because it has nothing to say about zones, safety system separation or controller patching constraints.
Do I need to buy the standard?
To go below sub-element level, yes. This assessment is written at programme element and sub-element level plus the zone and conduit requirements, all of which are publicly documented. The individual requirement wording beneath that is not, and we have not invented it.
Can I use this for a client?
Yes. Run one assessment per client organisation, or per site if the sites differ materially.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.