What is IEC 62443?
The international cybersecurity standard for industrial automation + control systems (IACS) — the OT-world analogue of ISO 27001.
Also known as
IEC 62443 — explained.
IEC 62443 (also known as IEC/ISA 62443) is the international cybersecurity standard for Industrial Automation and Control Systems (IACS) — the operational-technology (OT) world's analogue of ISO 27001. It applies across the whole stack from individual components (sensors, controllers) up to the full system (SCADA, distributed control systems, safety instrumented systems) and the operator's processes. The standard is structured in four parts: general (terminology, concepts), policies & procedures (for asset owners), system (for system integrators), and component (for product suppliers). Sectors that adopt it: energy (oil & gas, electricity grid), water utilities, manufacturing, transportation infrastructure, building management systems, smart-cities deployments. Certification is by accredited third-party labs and is increasingly a procurement gate for OT vendors. For a Zeour Smart Parking deployment at an oil & gas operator, IEC 62443 alignment is the typical compliance posture — segmenting the parking IACS from the operator's plant network, defining zones and conduits, implementing the secure-by-design controls of the standard.
Zeour solutions that operate on this layer.
Verticals where iec 62443 is operationally critical.
Adjacent definitions to read next.
ISO 27001
Compliance & DataThe international standard for Information Security Management Systems (ISMS) — a certifiable framework for managing information-security risk.
Sovereign Deployment
Sovereign DeploymentSoftware that runs entirely inside the operator's perimeter — their hardware, their network, their backups, their keys — with no third-party dependency for continued operation.
Air-Gapped Deployment
Sovereign DeploymentA system deployed on a network with no physical or logical connection to the public internet — the strictest form of sovereign deployment.
NIS2
Compliance & DataThe EU's expanded cybersecurity directive (replacing NIS1) — mandates risk-management, incident reporting, and supply-chain security for thousands of in-scope entities.
CCPA / CPRA
Compliance & DataCalifornia's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.
Cyber Essentials
Compliance & DataThe UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.
Data Subject Access Request (DSAR)
Compliance & DataThe data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.
Explicit Consent
Compliance & DataConsent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.
Talk to a Zeour engineer.
A 30-minute scoping call to walk your operational profile against where iec 62443 actually sits in your stack, then a fixed-fee Discovery price by the end of the call.