Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Security Frameworks

ANSI/ISA-62443

Also known as: ISA/IEC 62443, IEC 62443, ISA-62443
Simply put

ANSI/ISA-62443 is a series of voluntary cybersecurity standards designed to protect industrial automation and control systems—the technology that runs factories, utilities, and other operational environments—from cyber threats. It sets out best practices for building secure products and for managing security across an industrial operation. Because it is a standard rather than a law, it is not legally binding in itself, though organizations may adopt it or be required to follow it under a contract.

Formal definition

ANSI/ISA-62443 is a multi-part series of standards addressing cybersecurity for operational technology (OT) in industrial automation and control systems (IACS). Developed within the ISA standards process and aligned with the IEC 62443 series (hence the common designation ISA/IEC 62443), it spans distinct parts covering, among other topics, secure product development lifecycle requirements (e.g., ANSI/ISA-62443-4-1) and security program frameworks encompassing risk management, technical controls, legacy support, and supplier coordination (e.g., ANSI/ISA-62443-2-1). The series also provides a means to assess security performance, including through security levels. It is a voluntary, best-practice standard—not a regulation—and carries legal force only where incorporated by contract, sector rule, or applicable law; obligations depend on the specific part adopted and the operational context. This entry does not cover the detailed requirements of individual parts, applicable certification schemes, or jurisdiction-specific mandates. Individual parts are periodically revised (part numbers carry edition years such as -2018 or -2024), so readers should verify scope and requirements against the current official published text.

Why it matters

Industrial automation and control systems (IACS) run the physical processes behind factories, utilities, and other operational environments. Unlike conventional IT systems, a security failure in operational technology (OT) can disrupt physical operations, and cyber threats to these environments have been escalating. ANSI/ISA-62443 matters because it offers a structured, widely referenced body of best practice for defending this class of system, addressing both how secure products are built and how security is managed across an operation.

The series is significant precisely because it spans the full lifecycle and supply chain of industrial systems rather than a single control point. It covers secure product development requirements for suppliers as well as security program frameworks for operators, including risk management, technical controls, legacy support, and supplier coordination. This breadth allows different parties in an industrial ecosystem—product vendors, integrators, and asset owners—to align around a common vocabulary and set of expectations.

It is important to keep the standard's legal character in view. ANSI/ISA-62443 is a voluntary, best-practice standard, not a regulation, and it carries no legal force in itself. It becomes binding only where it is incorporated by contract, referenced in a sector rule, or made applicable by law in a given jurisdiction. Organizations often adopt it to demonstrate diligence or to satisfy customer and procurement requirements, but the specific obligations depend entirely on which part is adopted and the operational context. Readers should not treat conformance with the standard as equivalent to compliance with any particular regulatory regime.

Who it's relevant to

Industrial product vendors and developers
Suppliers who design and build components, devices, or software for industrial automation and control systems may look to the parts of the series that specify process requirements for secure product development. Adopting these requirements can help demonstrate a disciplined development lifecycle to customers, though whether conformance is mandatory depends on contractual or procurement terms rather than the standard itself.
Asset owners and operators of OT environments
Organizations running factories, utilities, and similar operational environments may use the security program framework parts to structure risk management, technical controls, legacy support, and supplier coordination across their industrial systems. The framework helps operators establish a consistent security program, but the specific obligations depend on which part is adopted and the operational context.
System integrators and supply chain coordinators
Parties who assemble, deploy, or maintain industrial control systems sit between vendors and operators, and the series' attention to supplier coordination and legacy support is directly relevant to their role. The standard can provide a shared reference for allocating security responsibilities across the supply chain.
Security and compliance professionals in industrial sectors
Auditors, assessors, and compliance staff supporting industrial operations may reference the series to evaluate security performance, including through its security levels. They should keep in mind that conformance with a voluntary standard is distinct from compliance with any binding regulation, and that application to specific circumstances requires professional judgment and verification against the current published text.

Inside ANSI/ISA-62443

Series structure
ANSI/ISA-62443 is a series of standards rather than a single document, organized into groups addressing general concepts and terminology, policies and procedures, system-level requirements, and component-level requirements. The scope and applicability of each part differ, so citing the specific part matters.
Focus on industrial automation and control systems (IACS)
The series addresses security for industrial automation and control systems, including the operational technology environments found in manufacturing, energy, and critical infrastructure sectors, as distinct from general enterprise IT security frameworks.
Security levels (SL) concept
The series describes a tiered approach to security capability, generally used to express the strength of security required or achieved against defined threat characteristics. The precise definitions and how levels are applied are set out in the relevant parts and should be verified against the current text.
Roles and responsibilities across stakeholders
The standards distinguish among asset owners, system integrators, and product suppliers, allocating different security responsibilities to each. This role separation is central to how the series is intended to be applied across a supply chain.
Voluntary and consensus-based nature
As an ANSI/ISA standard developed through a consensus process, ANSI/ISA-62443 is a voluntary standard. It is not law in itself, though it may become contractually binding or be referenced by regulators or sector authorities in particular jurisdictions.
Relationship to IEC 62443
The ISA-developed material is closely related to the internationally published IEC 62443 series. Practitioners should confirm which numbering, edition, and publishing body applies to their obligations, as the two are aligned but maintained through different processes.

Common questions

Answers to the questions practitioners most commonly ask about ANSI/ISA-62443.

Is ANSI/ISA-62443 a law that industrial operators are legally required to follow?
Not in itself. ANSI/ISA-62443 is a series of voluntary consensus standards for the security of industrial automation and control systems (IACS), developed through the ISA99 committee and adopted as an ANSI standard, with a closely related set of standards under IEC 62443. As a standard, it carries no independent legal force. It can become binding, however, where a regulator references it, where a contract requires conformance, or where a sector-specific authority incorporates it into mandatory requirements. Whether any such obligation applies depends on the jurisdiction and sector, so readers should verify against the applicable regulatory instrument rather than assume the standard is mandatory.
Does ANSI/ISA-62443 apply only to a single role, such as the asset owner running the plant?
No. The series is structured to address multiple roles across the IACS lifecycle, distinguishing among parties such as asset owners (operators), system integrators, and product suppliers, with different parts of the standard oriented toward different responsibilities. Treating it as a single obligation on one actor misreads its structure. Because responsibilities are allocated across roles, organizations should identify which parts of the series correspond to their function before determining what conformance would involve. Confirm role-specific applicability against the current text of the relevant parts.
How does an organization decide which parts of the ANSI/ISA-62443 series are relevant to it?
Selection generally begins with identifying the organization's role in the IACS lifecycle and the systems within scope, then mapping those to the corresponding parts of the series, which are organized into groupings addressing general concepts, policies and procedures, system-level requirements, and component-level requirements. The relevant parts differ for an asset owner defining a security program versus a product supplier developing components. Because the series is periodically revised and individual parts may be updated or superseded, verify the current structure and version of each part against the authoritative source before scoping.
What is the difference between conforming to ANSI/ISA-62443 and being certified against it?
Conformance describes meeting the requirements of a given part of the standard, while certification refers to a formal attestation, typically issued by an accredited third party under a defined certification scheme, that a product, system, or process meets specified requirements. Conformance can exist without certification, and the availability and details of certification depend on the scheme in question. Certification schemes and their versions change over time, so readers should confirm the scope, current version, and accreditation basis of any scheme directly with the certifying body.
How do the security levels defined in ANSI/ISA-62443 factor into implementation?
The series uses a concept of security levels to express the strength of protection needed against different classes of threat, which supports a risk-based approach to defining and verifying requirements rather than a single uniform baseline. In practice, an organization would generally assess the risk associated with a given zone or system and target a corresponding level, recognizing that requirements scale with the level selected. Because the precise definitions and their application are set out in the standard's text and may be refined across revisions, verify the applicable definitions against the current version before relying on them.
Can ANSI/ISA-62443 be used alongside other security frameworks and standards?
In many cases organizations use it together with broader information security standards and frameworks, since ANSI/ISA-62443 focuses specifically on industrial automation and control systems while other instruments address enterprise information security more generally. Mapping across them can help avoid duplicated effort, but the standards are distinct in scope and are not interchangeable, and any mapping should be validated rather than assumed. How they combine in a particular environment is fact-specific and depends on the systems, sector, and any applicable regulatory requirements, so professional judgment is required for a given deployment.

Common misconceptions

ANSI/ISA-62443 is a legal requirement that all industrial operators must follow.
It is a voluntary consensus standard, not a regulation. It carries legal force only where a jurisdiction, sector regulator, or contract incorporates it by reference. Whether it applies to a given organization depends on the specific legal or contractual context, which should be verified against authoritative sources.
The series is just another general IT cybersecurity framework interchangeable with enterprise-focused standards.
ANSI/ISA-62443 is specifically scoped to industrial automation and control systems and operational technology environments, which have different priorities and constraints than general enterprise IT. It is not intended as a drop-in substitute for enterprise IT security frameworks, nor they for it.
Achieving a security level under the standard is a one-time certification that guarantees a system is secure.
Security levels express capability or requirement against defined threat characteristics rather than a permanent guarantee of security. The standard is periodically revised, and application depends on the specific system, its role allocation, and risk context. Any related conformity or certification schemes and their versions change over time and should be checked against current sources.

Best practices

Identify and cite the specific part of the ANSI/ISA-62443 series relevant to your objective, since the series covers distinct topics ranging from terminology to system-level and component-level requirements.
Clarify your organization's role as asset owner, system integrator, or product supplier, because the series allocates different security responsibilities to each stakeholder.
Confirm which edition and publishing body applies to your situation, distinguishing the ANSI/ISA-62443 material from the related IEC 62443 series and verifying against the current authoritative text.
Treat the standard as voluntary unless a regulator, sector authority, or contract in your jurisdiction has made it binding, and confirm that status before assuming an obligation exists.
Apply the security levels concept in the context of your defined threat characteristics and system risk rather than treating a level as a permanent or absolute assurance of security.
Engage qualified professional judgment to map the standard to your specific operational technology environment, as application to particular circumstances is fact-dependent and interpretations may evolve.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.