Skip to main content
OT Consulting

Service 01

IEC 62443 audit

OT cybersecurity maturity and compliance assessment against the IEC 62443 series, with findings prioritized by real plant-floor risk.

Problem
Most industrial plants operate with partial visibility of their own exposure: uninventoried assets, undocumented zones and conduits, and security controls inherited from IT that don't fit the availability and determinism requirements of the process. Without a reference framework, every finding is debated as opinion, not as a verifiable gap.
Scope
Maturity audit against the system requirements of IEC 62443-3-3 (System security requirements and security levels) and, when the organization has or is building a formal security program, against the program requirements of IEC 62443-2-1 (Establishing an IACS security program). Includes asset inventory, review of zone and conduit segmentation, and a comparison of target security levels (SL-T) against the achieved ones (SL-A).
Deliverables
  • Findings report with the achieved security level (SL-A) per zone, contrasted against the target (SL-T)
  • Non-conformity matrix against IEC 62443-3-3, prioritized by real process risk, not theoretical severity
  • Remediation plan with a recommended sequence, designed for plants that can't afford downtime
Fit
It's the starting point when there is no documented OT cybersecurity baseline, or when management or a client needs the real status justified against a recognized industry standard. If network segmentation is already known to be insufficient and what's missing is the design itself, the architecture and segmentation service is the more direct starting point.

Why an audit against IEC 62443

IEC 62443 is the de facto reference for cybersecurity in industrial automation and control systems (IACS). Unlike a generic IT framework, it recognizes that a PLC or a SCADA can’t just be “restarted to apply the patch,” nor tolerate the same availability profile as an office server.

The audit doesn’t evaluate against an abstract checklist: it relies on the system requirements of IEC 62443-3-3 (the seven foundational requirements — access control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability) to establish the security level (SL) each zone has today, against the one it should have.

How it’s carried out

  1. Asset inventory and zone/conduit modeling. Without knowing what assets exist and how they communicate, any assigned security level is a guess.
  2. Assessment against IEC 62443-3-3, requirement by requirement, with field evidence — not interview alone.
  3. If an organizational security program exists (or is being built), it is also assessed against IEC 62443-2-1: policies, roles, patch management, incident response.
  4. Prioritization by real process risk: a vulnerability in a system that can stop the plant or compromise physical safety weighs more than one with high technical severity on an isolated system.

What this service does not cover

It does not include active penetration testing or vulnerability exploitation on production systems: the risk of interrupting a running industrial process is not accepted in this catalog. The audit is assessment and evidence, not intrusion.