IEC 62443 — Security for industrial automation and control systems (series; anchored on Part 3-3: System security requirements and security levels)
A formal standard with no current OJ citation — applied by contract or as good practice.
Issuing body: IEC · Version: IEC 62443-3-3:2013 (series) · Published: 2013-08-01
Link verified August 5, 2026
Scope
The IEC's multi-part framework for securing industrial automation and control systems: security levels SL1-SL4, the zones-and-conduits architecture model, product and system requirements, and secure development lifecycle requirements. This entry anchors on Part 3-3, the system security requirements catalogue.
IEC 62443 is the industrial-cybersecurity vocabulary that railway security engineering borrowed wholesale: TS 50701 (and its successor work in CENELEC) explicitly adapts the 62443 concepts — security levels, foundational requirements, zones and conduits, component versus system requirements — to the railway context of signalling, rolling stock and fixed installations. Part 3-3 is the series' workhorse: seven foundational requirements decomposed into concrete system requirements per security level, which is what a tender means when it demands 'SL2 per IEC 62443-3-3'. Other much-used parts include 3-2 (risk assessment and system partitioning), 4-1 (secure development lifecycle) and 4-2 (component requirements). Voluntary in EU law, but contractually near-universal in modern CCS and rolling-stock procurements, and the technical complement to the NIS2 obligations.
Related documents
- Part of the IEC 62443 series

