What is IEC 62443-4-2?

IEC 62443-4-2 is the international standard containing the technical security requirements for individual components of industrial automation and control systems, such as PLCs, HMIs, switches and software applications. The standard was published in 2019 and translates the system requirements of IEC 62443-3-3 to the level of a single product. For each requirement it indicates at which security level (SL 1 to 4) it applies, so a supplier can demonstrate which level a component achieves technically: the SL-C (capability).


🧠 What types of component does the standard distinguish?

Component type Requirement prefix Examples
Software application SAR SCADA software, historian, engineering tool
Embedded device EDR PLC, RTU, IED, smart field devices
Host device HDR Operator station, engineering station, server
Network device NDR Switch, router, industrial firewall

In addition to these type-specific requirements there are common component requirements (CR) that apply to every type.


🔧 What requirements does IEC 62443-4-2 set?

The requirements are grouped under the seven foundational requirements (FR) from IEC 62443-1-1:

FR Subject Example requirements
FR 1 Identification and authentication Unique users, strong passwords, MFA at higher SLs
FR 2 Use control Role-based authorisation (RBAC), session lock, audit logs
FR 3 System integrity Signed software, secure boot, protection against malware
FR 4 Data confidentiality Encryption of stored and transmitted data
FR 5 Restricted data flow Support for segmentation and zones
FR 6 Timely response to events Accessible logs, integration with monitoring
FR 7 Resource availability Resilience against denial of service, backup and recovery

Each requirement (CR) can have requirement enhancements (RE) that only become mandatory at a higher security level.


📊 What do the security levels mean for a component?

SL Protects against
SL 1 Casual or coincidental misuse
SL 2 Intentional attack with simple means and little knowledge
SL 3 Targeted attack with IACS-specific knowledge and moderate resources
SL 4 Targeted attack with extensive resources, such as by nation-state actors

An asset owner determines the required SL-T (target) per zone through a risk assessment in line with IEC 62443-3-2, and then selects components whose SL-C is sufficient.


🔄 How does 4-2 relate to 4-1 and certification?

IEC 62443-4-2 describes the product; IEC 62443-4-1 describes the development process. For product certification through ISASecure CSA (Component Security Assurance), a supplier must meet both. For IIoT devices there is the ICSA variant. A growing number of tenders in the energy and process industries explicitly require a 4-2 certificate at a specific SL.


🛠️ How do you use IEC 62443-4-2 in procurement?

For asset owners, 4-2 is mainly a tool for selecting components:

  1. Determine the SL-T per zone through a risk assessment in line with IEC 62443-3-2
  2. Request the SL-C — which security level does the component achieve per foundational requirement?
  3. Compare per FR — a component may achieve SL 2 for FR 1 but only SL 1 for FR 4
  4. Close gaps with compensating measures — for example an firewall in front of a component without encryption
  5. Ask for evidence — an ISASecure CSA certificate or a test report from an independent party
  6. Record it in the purchase contract, together with the support period for security updates
Term Meaning
SL-T (target) The level a zone needs, following from the risk assessment
SL-C (capability) The level a component or system can achieve technically
SL-A (achieved) The level achieved in practice, after configuration and measures

❓ Frequently asked questions

What is the difference between IEC 62443-3-3 and IEC 62443-4-2?

IEC 62443-3-3 sets security requirements for a complete system, such as a control system with servers, network and controllers. IEC 62443-4-2 translates those requirements to individual components, such as a single PLC, switch or software application. A system can reach the required level by combining components with additional measures.

Which components are covered by IEC 62443-4-2?

IEC 62443-4-2 distinguishes four types of component: software applications such as SCADA software, embedded devices such as PLCs and RTUs, host devices such as operator stations and servers, and network devices such as switches, routers and firewalls. General and type-specific requirements apply to each type.

What security level does a component need?

The required security level depends on the zone in which the component is placed. For most industrial installations SL 2 is a common starting point; for critical infrastructure and safety systems SL 3 is often required. The asset owner determines this through a risk assessment in line with IEC 62443-3-2.

How do you recognise an IEC 62443-4-2 certified product?

An IEC 62443-4-2 certified product has a certificate from an accredited body, for example through ISASecure CSA or the IECEE scheme. The certificate states the product model, the firmware version and the security level achieved. ISASecure publishes a public list of certified products.

What is a compensating countermeasure in IEC 62443?

A compensating countermeasure is a security measure outside the component itself that makes up for a missing function. A PLC without encryption can, for example, be placed in an isolated zone behind an industrial firewall. IEC 62443 explicitly allows this, so that older equipment can keep operating within a secure design.


📌 In summary

IEC 62443-4-2 defines which technical security functions an industrial component must have, organised into seven foundational requirements and four security levels. This lets asset owners choose components that match the security level their zones require.