The IEC 62443 parts are the reason most people bounce off the standard on first contact. It is not one document — it is a series of them, numbered in a scheme that gives no clue which one you actually need, and buying the wrong one is an expensive way to find out.
This guide sorts the IEC 62443 parts by the only question that matters: what is your role? Get that right and the series collapses from twelve-plus documents down to two or three.
What this guide covers
- The IEC 62443 parts are organised by role, not by topic
- The IEC 62443 parts by number
- If you operate a plant: the IEC 62443 parts you need
- If you supply products: a different set of IEC 62443 parts
- If you integrate or maintain: one part, plus a methodology
- How the IEC 62443 parts connect in practice
- Which IEC 62443 parts do you have to buy?
- Four mistakes people make with the IEC 62443 parts
- Frequently asked questions
- Where to start

The IEC 62443 parts are organised by role, not by topic
This is the insight that unlocks everything. The series recognises three roles, and the IEC 62443 parts that apply to you depend entirely on which one you occupy.
| Role | Who you are | Your parts |
|---|---|---|
| Asset owner | You operate the plant | 2-1, plus 3-2 and 3-3 |
| Service provider | You integrate or maintain someone’s plant | 2-4 |
| Product supplier | You build the components or systems | 4-1 and 4-2 |
Most confusion about the IEC 62443 parts comes from reading a summary written for a different role than yours. A component manufacturer’s blog about 4-2 is not useful to a plant manager, and vice versa.
The IEC 62443 parts by number
The numbering follows groups: 1-x general concepts, 2-x policies and procedures, 3-x system level, 4-x component level.
| Part | What it covers | Edition |
|---|---|---|
| 2-1 | Security programme requirements for asset owners — 87 requirements in 8 elements | Ed. 2.0, 2024 |
| 2-2 | IACS security programme ratings — a scheme for rating a programme’s implementation | PAS, 2025 |
| 2-3 | Patch management in the IACS environment (technical report) | TR |
| 2-4 | Security programme requirements for service providers | Ed. 1.1 (2015 + A1:2017) |
| 3-2 | Security risk assessment for system design — zones, conduits, target levels | Ed. 1.0, 2020 |
| 3-3 | System security requirements and security levels — the 7 foundational requirements | Ed. 1.0, 2013 |
| 4-1 | Secure product development lifecycle requirements | Ed. 1.0, 2018 |
| 4-2 | Technical security requirements for IACS components | Ed. 1.0, 2019 |
| 6-1 | Security evaluation methodology for 2-4 (technical specification) | Ed. 1.0, 2024 |
A currency warning worth having
A claim circulates that IEC 62443-4-2:2026 published in June 2026 and replaced the 2019 edition. It did not. As at August 2026 the IEC webstore still shows Edition 1.0:2019 with a stability date of 2027. The six pillar standards are being revised toward second editions, but revision in progress is not publication — verify any edition claim at source before acting on it.
If you operate a plant: the IEC 62443 parts you need
Start with 2-1. It is the asset owner standard and it specifies the security programme — policies, procedures, roles, training, risk management, incident response — for an IACS in operation. Edition 2.0, published August 2024, reorganised its requirements into eight Security Programme Elements and added a maturity model scored per requirement.
Add 3-2 for design. This is the methodology for defining your system under consideration, partitioning it into zones and conduits, assessing risk and assigning target security levels. You need it because 2-1 states explicitly that it does not define that methodology.
Add 3-3 for technical requirements. The seven foundational requirements and their per-level enhancements. You use it to specify what a system must do, and to verify what your installed system achieves.
You do not need 4-1 or 4-2 for your own engineering. You reference them when buying, which is a different activity covered below.
If you supply products: a different set of IEC 62443 parts
4-1 covers your development process — security requirements definition, threat modelling, secure design and coding, security testing, third-party component management, release, and vulnerability handling through the support period.
4-2 covers what your product must technically do. Its requirements derive from the system requirements in 3-3 and are expressed per component type: software application, embedded device, host device and network device.
The two are complementary. 4-1 is how you built it; 4-2 is what it can do. Customers increasingly ask for both, and they are separate claims with separate evidence.
If you integrate or maintain: one part, plus a methodology
2-4 specifies the security programme requirements for service providers — what your organisation must have in place when you install, configure and maintain somebody else’s control system.
6-1, published March 2024, is the evaluation methodology for 2-4. It exists so that assessments of a service provider are repeatable, reproducible and comparable, based on a common understanding of acceptable evaluation criteria and conformance evidence. If you are being assessed, or doing the assessing, this is the part that makes the result mean something.
How the IEC 62443 parts connect in practice
The parts are not independent. A real programme threads through several of them:
- You define your system and partition it into zones and conduits using 3-2.
- You assign target security levels per zone, also under 3-2.
- You express what the system must do using the requirements in 3-3, and what components must do using 4-2.
- You put those into a specification and buy against it, asking suppliers for 4-1 development evidence and 4-2 capability claims.
- You require your integrator to meet 2-4, assessed using 6-1.
- You run the whole thing as a programme under 2-1, scored for maturity.
Read that list again and the numbering scheme starts making sense: 2-x is organisational, 3-x is system, 4-x is component, and 6-x tells you how to assess.
Which IEC 62443 parts do you have to buy?
All of them are licensed publications sold by the IEC and national standards bodies. Unlike an EU regulation, none is free.
For an asset owner starting out, 2-1 and 3-2 are the two that earn their cost immediately. Add 3-3 when you begin specifying or verifying technical requirements. Most operators never need to buy 4-1 or 4-2 — you ask suppliers to evidence conformance rather than assessing against the text yourself.
Four mistakes people make with the IEC 62443 parts
Buying 4-2 as an operator. It is the most frequently purchased part by people who do not need it. If you run a plant, 4-2 tells you what to ask suppliers for — it does not tell you what to do on Monday morning.
Treating 3-3 as a checklist to implement directly. Its requirements are expressed per security level, and the level comes from your risk assessment under 3-2. Working through 3-3 without having assigned target levels first means implementing enhancements you may not need and skipping ones you do.
Reading Edition 1 material about 2-1. A great deal of published commentary still describes the pre-2024 structure, which mirrored an ISMS clause by clause. Edition 2.0 restructured into eight Security Programme Elements and removed that duplication, so an Edition 1 mapping cannot be applied requirement-for-requirement to the current text.
Assuming a supplier certificate covers your purchase. Certificates against these IEC 62443 parts carry a scope — a named development organisation, a product family, a firmware range. Read the scope statement and confirm it covers the model and version you are actually buying.
Frequently asked questions
Which of the IEC 62443 parts can we be certified against?
It depends on the role. Asset owners are assessed against 2-1, service providers against 2-4, product development against 4-1 and components against 4-2. Certification bodies accredited under ISO/IEC 17065 offer assessment against these. There is no single “IEC 62443 certified” status that covers everything.
Is 62443-3-3 out of date, being from 2013?
It remains current and is correctly cited — its stability date is 2027 and a second edition is in development. Just be aware when reading it alongside 2-1 Edition 2.0 that the two reflect different periods of thinking, and expect a revision at some point.
Do we need 4-2 certificates for every component?
No, and in practice it is not feasible — a moderately sized system would need dozens of certificates. The usual approach is to assess the system as a whole against 3-3, and require 4-2 evidence selectively for components in your highest-target-level zones or performing safety-related functions.
Where does NIS2 fit across the IEC 62443 parts?
NIS2 does not name the standard, but the mapping is straightforward: 2-1 evidences the governance and risk management measures of Article 21, 3-3 evidences the technical measures, and requiring 4-1 and 4-2 of your suppliers evidences the supply chain measures.
Where to start
If you operate a plant, the practical order is: read 2-1 to understand what a programme contains, use 3-2 to draw your zones and conduits, then assign IEC 62443 security levels and specify against 3-3.
If you already hold an information security certification, our comparison of IEC 62443 vs ISO 27001 covers how much of the asset owner programme your ISMS already satisfies. For the regulatory driver behind most of this work, see NIS2 requirements. The asset owner standard itself is IEC 62443-2-1:2024.
Our IEC 62443 Toolkit is built for the asset owner role specifically — 117 editable documents covering all 87 requirements of 2-1, the 3-2 design chain, and the procurement side of 4-1, 4-2 and 2-4. It is deliberately not a product supplier pack, because those are genuinely different IEC 62443 parts serving a different job.