Description
About the IEC 62443 Toolkit
IEC 62443 is the standard regulators, ENISA guidance and accredited bodies keep pointing at for operational technology. NIS2 and the EU Cyber Resilience Act both lead there. What almost nobody sells is the documentation an asset owner actually has to produce.
The IEC 62443 Toolkit is written against IEC 62443-2-1:2024, Edition 2.0 — the current edition, published August 2024 — and it covers all 87 of its security programme requirements.
The standard tells you what a documentation toolkit is worth, and it is unusually specific
Clause 4.2 of IEC 62443-2-1:2024 sets four maturity levels, drawn from the CMMI for Services model. Maturity level 2 is documentation: written policies, written procedures, written training. And the standard then says something most readers miss — the 87 requirement statements deliberately do not restate a documentation duty, because ML 2 and above already carry it.
So the position is precise, and it is checkable:
| Where you are | What moves you |
|---|---|
| ML 1 — Initial | The activity happens, ad hoc and undocumented |
| ML 2 — Managed | Adopt these documents, complete them for your site, approve and issue them, train your people. The IEC 62443 Toolkit documentation is the substance of ML 2 |
| ML 3 — Defined / Practiced | Operate the documented process on the IACS and keep the records. No document can supply this, and we do not claim otherwise |
| ML 4 — Improving | Measure the process and improve it |
Every other toolkit on the market implies it gets you certified. The IEC 62443 Toolkit tells you exactly which level it delivers and which it does not, because that is what the standard says and an assessor will check.
Most 62443 material you will find describes the wrong edition
Edition 2.0 restructured the standard. It reorganised the requirements into eight Security Programme Elements, added the maturity model, and — importantly — removed the duplication with an information security management system that Edition 1 carried.
That last change matters commercially. If you already hold ISO/IEC 27001, Edition 2.0 means you do not rebuild your ISMS. You identify the operational-technology delta and build only that.
The toolkit’s first requirement, ORG 1.1, is exactly this: coordinate the programme with your ISMS where one exists, or incorporate the equivalent management processes where one does not. So the IEC 62443 Toolkit ships an ISMS Delta Register carrying all 87 requirements, each dispositioned Covered, Extend, Build or Not applicable — with a default that protects you. An unconfirmed claim that “the ISMS covers it” reverts to Build, because the failure this register exists to prevent is a requirement both sides believe the other owns.
Our mappings are to the current editions. The standard’s own are not
Annex A of IEC 62443-2-1:2024 cross-references two other frameworks, and both are superseded:
- It maps to ISO/IEC 27001:2013, using control numbers like A.11.2.2, A.12.1.3 and A.17.2.1
— none of which exist in the 2022 edition’s A.5 to A.8 structure.
- It maps to NIST CSF 1.1, citing DE.DP and ID.BE, both withdrawn in CSF 2.0, and PR.AC,
which CSF 2.0 renamed PR.AA.
Transcribe Annex A and you ship dead identifiers. The IEC 62443 Toolkit bridges both: mapping matrices to ISO/IEC 27001:2022 and to NIST CSF 2.0, plus NIS2 Article 21 and a cross-reference to 62443-3-3, 4-2 and 2-4. All 87 requirements, all four matrices.
Who the IEC 62443 Toolkit is for, and who it is not for
It is for asset owners — the organisation that operates the IACS — and for the service providers that integrate and maintain it. That is the population NIS2 creates and it is by far the larger one.
The IEC 62443 Toolkit is not a product supplier pack. If you build products and need IEC 62443-4-1 secure development or 62443-4-2 component requirements for your own engineering, the IEC 62443 Toolkit is not what you need. It touches 4-2 only from the buying side: what you demand of a supplier and how you verify the claim.
Written for a plant, not an office
Controls that are routine on a corporate network are hazardous on a live process. That is not a disclaimer in the IEC 62443 Toolkit — it is built into the documents:
- Screen lock on a control room console is a recorded departure with compensating measures,
not an omission. A locked console during an upset is a safety problem.
- Lockout after repeated login failures is not the default on operator stations. Alert
instead. Locking an operator out mid-incident is worse than the risk it addresses.
- Antimalware does not delete on a control system. Quarantine and alert. A product that
deletes a file a control application needs causes the outage it was installed to prevent.
- Active vulnerability scanning is prohibited on live systems without a named approval
chain including process safety, an abort condition and a verified backup.
- The decision to shut the process down belongs to the Operations Manager, never to the
security function. That is stated in the incident response plan.
A safety-and-availability callout runs through the IEC 62443 Toolkit templates, and an Operations veto that the escalation clock does not override.
Legacy equipment is handled, not wished away
The standard’s own scope recognises that an IACS can run for more than twenty years and will contain hardware and software no longer supported. It says in terms that compensating security measures can be part of the policies and procedures it requires.
The failure is not having legacy equipment — it is having it undocumented, so nobody knows which requirements it fails or what stands in their place. The IEC 62443 Toolkit carries a single Legacy and Unsupported Asset register holding that whole position, plus a patch mitigation record for everything you deliberately do not patch. That second record is the half an assessor asks for first, and the half most sites do not have.
The IEC 62443 Toolkit ships seven workbooks already filled in
The IEC 62443 Toolkit workbooks are not blank templates. Seven of the 35 IEC 62443 Toolkit workbooks ship pre-loaded with all 87 requirements — identifier, Security Programme Element, group, requirement name and the toolkit document that answers it:
| Workbook | What it does |
|---|---|
| Applicability Statement | Every requirement dispositioned, with the justification and alternative-mitigation evidence clause 5.3.1 demands for anything you exclude |
| Maturity Assessment Workbook | All 87 scored ML 1–4, aggregated per element, with movement against the previous assessment |
| Conformity Evidence Register | Evidence mapped per requirement, using the evidence types clause 5.2 identifies |
| Internal Audit Checklist | Audit questions per requirement, testing existence, application and effectiveness |
| ISO/IEC 27001:2022 mapping | Bridged from the standard’s 2013 cross-reference |
| NIST CSF 2.0 mapping | Bridged from the standard’s CSF 1.1 cross-reference |
| 62443 parts cross-reference | To 62443-3-3, 4-2 and 2-4 |
All seven are generated from one requirement set, so they cannot drift apart from each other or from the documents.
The whole IEC 62443-3-2 design chain, in order
The IEC 62443 Toolkit carries, in sections 02 to 05, the work everything else depends on and most toolkits skip: the asset inventory, the system under consideration and its boundary, the partitioning into zones and conduits with its rationale, the initial and detailed risk assessments, and the assignment of target security levels — expressed as a vector across the seven foundational requirements, not a single number, because a zone rarely needs uniform strength.
It ends in the Cybersecurity Requirements Specification: the document that carries the zone model, the target levels and the requirements into procurement and engineering. Without it the assessment work never leaves the security function.
The IEC 62443 Toolkit also separates the three things everyone calls “security level” — SL-T what the zone needs, SL-C what the equipment can do, SL-A what your installed system actually achieves — and gives you a gap workbook that shows which one is holding a zone down and what it would take to fix. Recording a supplier’s SL-C claim as though the plant had achieved it is the commonest error in this area, and it is the one the IEC 62443 Toolkit is built to stop.
IEC 62443 Toolkit structure
| # | Section | Documents |
|---|---|---|
| 01 | Programme and Governance | 7 |
| 02 | Asset Inventory and Characterisation | 6 |
| 03 | Zones Conduits and Segmentation | 7 |
| 04 | Cybersecurity Risk Assessment | 8 |
| 05 | Security Levels | 5 |
| 06 | SPE 1 Organizational Security Measures | 9 |
| 07 | SPE 2 Configuration Management | 5 |
| 08 | SPE 3 Network and Communications Security | 9 |
| 09 | SPE 4 Component Security | 8 |
| 10 | SPE 5 Protection of Data | 6 |
| 11 | SPE 6 User Access Control | 9 |
| 12 | SPE 7 Event and Incident Management | 8 |
| 13 | SPE 8 System Integrity and Availability | 7 |
| 14 | Service Providers and Supply Chain | 8 |
| 15 | Conformance Maturity and Evidence | 8 |
| 16 | Mapping and Currency | 7 |
The IEC 62443 Toolkit is 82 Word documents and 35 Excel workbooks. Sections 06 to 13 are one per Security Programme Element, so the pack is laid out the way an assessor assesses and the way maturity is scored.
One document holds everything that moves
The IEC 62443 series is mid-revision. Several parts carry stability dates of 2027 and the pillar standards are being revised toward second editions. So every dated fact in the IEC 62443 Toolkit sits in a single Standards Currency Supplement with a watch log, and a change is a one-document edit rather than a sweep through 117 files.
It also carries a correction worth having. A claim circulates that IEC 62443-4-2:2026 published on 1 June 2026 and replaced the 2019 edition, adding new test modules. It did not. As at 26 August 2026 the IEC webstore shows Edition 1.0:2019 as current, stability date 2027. Every edition in the IEC 62443 Toolkit was verified at source, not from secondary reporting.
Editions the IEC 62443 Toolkit is written against
| Part | Edition |
|---|---|
| IEC 62443-2-1 Security program requirements for IACS asset owners | Ed. 2.0, 2024-08 |
| IEC 62443-2-4 Security program requirements for IACS service providers | Ed. 1.1 (2015 + AMD1:2017) |
| IEC 62443-3-2 Security risk assessment for system design | Ed. 1.0, 2020 |
| IEC 62443-3-3 System security requirements and security levels | Ed. 1.0, 2013 |
| IEC 62443-4-1 Secure product development lifecycle requirements | Ed. 1.0, 2018 |
| IEC 62443-4-2 Technical security requirements for IACS components | Ed. 1.0, 2019 + cor. 2022 |
| IEC TS 62443-6-1 Security evaluation methodology for IEC 62443-2-4 | Ed. 1.0, 2024-03 |
Every document names the requirements it answers
Each of the 82 Word documents opens with a Requirements addressed table listing the requirement identifiers it satisfies and what it provides for each. You can hand any single document to an assessor and they can see immediately what it is for.
All 87 IEC 62443 Toolkit requirements are covered, and the build fails if any one of them is left without a document — which is a check we run, not a claim we make.
List of Documentation Toolkit:
01 — Programme and Governance (7 documents)
- IACS Cybersecurity Policy.docx
- IACS Security Programme Charter and Objectives.docx
- Toolkit Index and Deployment Guide.docx
- Security Roles Responsibilities and Authorities.docx
- OT and IT Governance Interface Procedure.docx
- IACS Security Programme Management Review Procedure.docx
- IACS Security Programme Metrics and Reporting.xlsx
02 — Asset Inventory and Characterisation (6 documents)
- IACS Asset Inventory Baseline Procedure.docx
- IACS Asset Inventory Register.xlsx
- System under Consideration Boundary Statement.docx
- Infrastructure Drawings and Documentation Control Procedure.docx
- Essential Function and Criticality Register.xlsx
- Reference Architecture and Zone Model Guide.docx
03 — Zones Conduits and Segmentation (7 documents)
- Zone and Conduit Partitioning Procedure.docx
- Zone and Conduit Register.xlsx
- Zone and Conduit Design Rationale Report.docx
- Network Segmentation Standard.docx
- IACS Demilitarised Zone Design Pattern Guide.docx
- Safety System Segregation Standard.docx
- Network Architecture and Data Flow Diagram Set.docx
04 — Cybersecurity Risk Assessment (8 documents)
- IACS Cybersecurity Risk Management Procedure.docx
- Initial Cybersecurity Risk Assessment Report.docx
- Detailed Cybersecurity Risk Assessment Procedure.docx
- Detailed Cybersecurity Risk Assessment Report.docx
- Threat Vulnerability and Consequence Register.xlsx
- Risk Scoring and Tolerable Risk Criteria Guide.docx
- Risk Treatment Plan.xlsx
- Cybersecurity Requirements Specification.docx
05 — Security Levels (5 documents)
- Security Level Determination Procedure.docx
- Target Security Level Register.xlsx
- Target Security Level Rationale Report.docx
- Capability and Achieved Security Level Verification Procedure.docx
- Security Level Gap Analysis Workbook.xlsx
06 — SPE 1 Organizational Security Measures (9 documents)
- Security Programme and ISMS Coordination Procedure.docx
- ISMS Delta Register.xlsx
- Personnel Screening and Background Check Policy.docx
- IACS Security Awareness Training Programme.docx
- Security Responsibilities Training Plan and Competence Matrix.xlsx
- Training Record Register.xlsx
- IACS Supply Chain Security Policy.docx
- Security Assessment and Anomaly Discovery Procedure.docx
- IACS Physical Access Control Standard.docx
07 — SPE 2 Configuration Management (5 documents)
- IACS Configuration Management Procedure.docx
- Configuration Settings Standard.docx
- Configuration Baseline Register.xlsx
- IACS Change Control Procedure.docx
- Change Request and Approval Record.xlsx
08 — SPE 3 Network and Communications Security (9 documents)
- IACS Network Security Standard.docx
- Network Autonomy and Disconnection Procedure.docx
- Network Accessible Services Register.xlsx
- User Messaging Control Standard.docx
- Network Time Distribution Standard.docx
- IACS Wireless Security Standard.docx
- Wireless Asset and Address Register.xlsx
- Secure Remote Access Policy and Procedure.docx
- Remote Access Authorisation Register.xlsx
09 — SPE 4 Component Security (8 documents)
- IACS Component Hardening Standard.docx
- Hardening Baseline Checklists.xlsx
- Portable Media Control Procedure.docx
- IACS Malware Protection Standard.docx
- Malware-Free Verification and Acceptance Record.docx
- IACS Security Patch Management Procedure.docx
- Patch Status and Validation Register.xlsx
- Patch Mitigation and Compensating Measure Record.docx
10 — SPE 5 Protection of Data (6 documents)
- IACS Data Classification Policy.docx
- Data Inventory and Classification Register.xlsx
- Data Confidentiality and Integrity Standard.docx
- Safety System Configuration Mode Control Procedure.docx
- IACS Data Retention and Disposal Policy.docx
- Cryptographic Controls and Key Management Standard.docx
11 — SPE 6 User Access Control (9 documents)
- IACS Identity and Access Management Policy.docx
- User Identity and Access Rights Register.xlsx
- IACS Joiners Movers and Leavers Procedure.docx
- IACS Authentication Standard.docx
- Software Service Account Standard.docx
- Password and Credential Management Standard.docx
- Session Management and Login Control Standard.docx
- Authorization and Privilege Elevation Procedure.docx
- Access Review and Recertification Record.xlsx
12 — SPE 7 Event and Incident Management (8 documents)
- IACS Event Detection and Monitoring Standard.docx
- Event Reporting Procedure and Interfaces.docx
- IACS Logging Standard.docx
- Event Analysis Procedure.docx
- IACS Incident Response Plan.docx
- Incident Classification and Severity Matrix.docx
- Incident Register and Report Form.xlsx
- IACS Vulnerability Handling Procedure.docx
13 — SPE 8 System Integrity and Availability (7 documents)
- IACS Continuity Management Plan.docx
- Resource Availability Management Standard.docx
- Failure-State and Fail-Safe Design Standard.docx
- IACS Backup Restore and Archive Procedure.docx
- Backup Register and Verification Log.xlsx
- Backup Media Handling Standard.docx
- Restoration Test Plan and Record.docx
14 — Service Providers and Supply Chain (8 documents)
- Service Provider Security Requirements Specification.docx
- Service Provider Evaluation Procedure.docx
- Service Provider Assessment Workbook.xlsx
- Product Supplier Security Questionnaire.xlsx
- IACS Procurement Security Clauses and Contract Schedule.docx
- Secure Development and Support Assurance Procedure.docx
- Integration and Commissioning Security Handover Checklist.docx
- Supply Chain Security Register.xlsx
15 — Conformance Maturity and Evidence (8 documents)
- Security Programme Element Applicability Statement.xlsx
- Maturity Level Assessment Procedure.docx
- Security Programme Maturity Assessment Workbook.xlsx
- Conformity Evidence Register.xlsx
- Security Profile Definition and Adoption Guide.docx
- IACS Internal Audit Procedure and Programme.docx
- IACS Internal Audit Checklist.xlsx
- Nonconformity and Corrective Action Register.xlsx
16 — Mapping and Currency (7 documents)
- Mapping to ISO IEC 27001 2022.xlsx
- Mapping to NIST Cybersecurity Framework 2.0.xlsx
- Mapping to NIS2 Article 21.xlsx
- Requirement Cross-Reference to Other IEC 62443 Parts.xlsx
- IACS Security Programme Implementation Roadmap.docx
- Legacy and Unsupported Asset Compensating Measures Procedure.docx
- Standards Currency Supplement.docx
Frequently Asked Questions (FAQ)
What is the IEC 62443 Toolkit?
The IEC 62443 Toolkit is a set of 117 editable Microsoft Word and Excel templates for industrial automation and control system security — 82 documents and 35 workbooks across sixteen sections, covering all 87 security programme requirements of IEC 62443-2-1:2024 Edition 2.0, together with the zone and conduit design work required by IEC 62443-3-2, security level determination, service provider assurance to IEC 62443-2-4, and mapping to ISO/IEC 27001:2022, NIST CSF 2.0 and NIS2.
Which edition of IEC 62443-2-1 does the IEC 62443 Toolkit follow?
Edition 2.0, published August 2024 — the current edition. This matters more than usual here. Edition 2.0 restructured the standard into eight Security Programme Elements, introduced the maturity model, and removed the duplication with an ISMS that Edition 1 carried. A great deal of the 62443 material available online still describes Edition 1 and cannot be mapped requirement-for-requirement onto the current text.
Do I need to buy the standard as well?
Yes, and you should. IEC 62443 is a licensed standard sold by the IEC and by national standards bodies; unlike an EU regulation it is not published free of charge. The IEC 62443 Toolkit cites requirement identifiers — ORG 1.1, NET 2.3, USER 1.19 and so on — and states in our own words what each asks for, so you can work with it alongside your licensed copy. It does not reproduce the standard’s text, and no toolkit that respects IEC copyright can.
Will this make us certified to IEC 62443?
No IEC 62443 Toolkit can. Certification requires an accredited body to assess your operating programme, not your document library. What the IEC 62443 Toolkit download gives you is specific: it is the documented policies, procedures and training that maturity level 2 consists of, and it gives you the applicability statement, evidence register, maturity workbook and audit checklist an assessment will ask for. Reaching ML 3 requires you to operate the processes on your IACS and keep the records — the pack tells you exactly that, in the Maturity Level Assessment Procedure.
Is this for product suppliers building to IEC 62443-4-1 or 4-2?
No. This is an asset owner and service provider toolkit. If you manufacture components or systems and need secure development lifecycle documentation for your own engineering, the IEC 62443 Toolkit is not the right pack — it addresses 62443-4-2 only from the procurement side: what you require of a supplier, how you verify a capability claim and what you check at handover.
We already hold ISO/IEC 27001. How much of this do we need?
Less than you might think, and the IEC 62443 Toolkit is built around that question. Edition 2.0 deliberately removed ISMS duplication, and requirement ORG 1.1 requires the programme to be coordinated with an existing ISMS. The ISMS Delta Register carries all 87 requirements and asks you to disposition each one as Covered, Extend, Build or Not applicable, with an ISO/IEC 27001:2022 mapping matrix alongside. Most organisations find a substantial covered set, a larger extend set — controls that exist for IT and must be stretched to the plant — and a genuine OT-only remainder.
Does it cover zones and conduits, and security levels?
Yes, in full. Sections 03 and 05 carry the partitioning procedure, the zone and conduit register with trusted or untrusted designation, the design rationale report, target security level determination as a per-foundational-requirement vector, and a gap workbook comparing target, capability and achieved levels. IEC 62443-2-1 states expressly that it does not define these methodologies — they come from 62443-3-2 — which is why they are in the pack as their own sections rather than assumed.
Will these documents work on a live plant?
The IEC 62443 Toolkit templates are written for one. Screen lock, account lockout, patching, antimalware, monitoring and scanning all carry the operational departures a control environment actually needs, recorded as deliberate decisions with compensating measures rather than left as gaps. There is a safety and availability veto held by Operations and process safety that the pack does not let security override, and no IEC 62443 Toolkit control is applied to a live system without confirming it cannot trip the process, delay an operator or affect a safety function.
We have equipment we cannot patch or harden. Is that a problem?
It is the normal condition, and the standard says so — it scopes itself to systems that can run more than twenty years and contain unsupported hardware and software, and it accepts compensating measures as part of the required policies and procedures. The IEC 62443 Toolkit carries a Legacy and Unsupported Asset register and a Patch Mitigation record so that position is documented, compensated, reviewed and evidenced rather than invisible.
Does it help with NIS2?
Yes. A mapping matrix shows which parts of the programme evidence each measure in NIS2 Article 21(2), with columns for the OT owner and the corporate owner, because most of those measures are shared. It is presented as evidence mapping, not as a claim that conformance with one delivers compliance with the other.
What formats are the documents in?
Microsoft Word (.docx) and Microsoft Excel (.xlsx) — 82 and 35 respectively. Every IEC 62443 Toolkit file is fully editable, unlocked and unprotected, ready to be rebranded and populated with your own information. The workbooks carry drop-down validation, frozen headers, autofilters and worked example rows flagged for deletion.
How long does it take to deploy?
The IEC 62443 Toolkit Index and Deployment Guide sets out an eight-phase order, starting with a single decision — whether an ISMS already covers your IACS — because that determines how much of the pack you build yourself. The guide is explicit that you should not start at the Security Programme Element sections and work forwards: without the asset inventory, the zone model and the risk assessment there is no basis for deciding which requirements apply, and the applicability statement becomes guesswork.
ISO 42001 Toolkit - Comprehensive AI Governance Templates 




































Reviews
There are no reviews yet