ISA/IEC 62443, OT security that isn't tribal knowledge.
ISA/IEC 62443 secures industrial automation and control systems (IACS) — OT and ICS environments — through seven Foundational Requirements covering identification, use control, system integrity, confidentiality, segmentation, monitoring, and availability. grComply seeds the real FR structure with OT-specific evidence types (zone/conduit diagrams, IACS audit logs, malware-protection coverage), and supports private on-prem or air-gapped deployment for industrial networks that can't touch the cloud.
What is ISA/IEC 62443? ISA/IEC 62443 is a series of standards for securing industrial automation and control systems (IACS) — operational technology (OT) and industrial control system (ICS) environments — organised around seven Foundational Requirements and a zone-and-conduit model for network segmentation, with security levels (SL1–SL4) indicating the rigour required.
How grComply benefits your ISA/IEC 62443 programme
Foundational Requirements as the domain layer
FR1–FR7 (identification/authentication through resource availability) — the actual 62443-3-3 structure, not a generic IT-security list relabelled for OT.
Zone and conduit model as evidence, not tribal knowledge
Network segmentation (FR5-1) requires a documented zone/conduit diagram, making an OT network's actual segmentation auditable.
OT-specific evidence types
Malware-protection coverage and IACS audit-log samples are modelled distinctly from generic IT evidence, matching how OT environments are actually assessed.
Backup/restore testing needs an attestation, not an assumption
A recovery test has to be proven — the same discipline applied to DORA's backup requirements.
Private on-prem or air-gapped deployment for OT networks
Matches how industrial environments are actually run when cloud connectivity isn't acceptable or even possible.
Cross-maps to NIST CSF and CIS for converged IT/OT programmes
A segmentation control can credit both 62443 and a NIST CSF Protect subcategory in one place.
Seven Foundational Requirements, seeded with real FR structure
Seeded from ISA/IEC 62443-3-3's own Foundational Requirement numbering — FR1 through FR7 — the structure every system-level security requirement in the standard builds from.
FR 1 — Identification and authentication control
Human user identification and authentication, and software process/device identification and authentication — who and what is allowed onto the IACS network.
FR 2 — Use control
Authorization enforcement and wireless use control — what an authenticated user or device is actually permitted to do.
FR 3 — System integrity
Communication integrity and malicious code protection, evidenced with OT-specific malware-protection coverage data.
FR 4 — Data confidentiality
Information confidentiality — protecting sensitive OT data from unauthorised disclosure.
FR 5 — Restricted data flow
Network segmentation and zone boundary protection — the zone-and-conduit model documented as its own evidenced control.
FR 6 — Timely response to events
Audit log accessibility and continuous monitoring — IACS-specific log evidence, not generic IT SIEM data.
FR 7 — Resource availability
Denial-of-service protection and backup/restore/recovery, evidenced with a recovery-test attestation.
Evidence grComply already models for ISA/IEC 62443
Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.
| Control | Evidence type | Example |
|---|---|---|
| FR5-1 — Network segmentation | Architecture diagram | Zone and conduit diagram |
| FR1-1 — Identity and access | Procedure document | IACS identity and access procedure |
| FR3-2 — Malicious code protection | Vulnerability scan report | OT malware protection coverage |
| FR6-1 — Audit log accessibility | SIEM log sample | IACS audit log sample |
| FR7-2 — Backup and restore | Attestation | OT backup restore test attestation |
Why this matters: OT/ICS segmentation is too often documented as a diagram in someone's head — modelling the zone-and-conduit model as its own evidenced control (FR5-1) with a required diagram is what turns 'we've segmented the network' from an assertion into something an assessor can actually verify.
ISA/IEC 62443, in the live workspace
The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to ISA/IEC 62443.






ISA/IEC 62443 in grComply
What is ISA/IEC 62443?
ISA/IEC 62443 is a series of standards for securing industrial automation and control systems (IACS) — OT and ICS environments — organised around seven Foundational Requirements and a zone-and-conduit segmentation model.
Who needs ISA/IEC 62443?
Organisations operating industrial control systems, manufacturing, utilities, and critical infrastructure operators — anywhere OT/ICS environments need to be secured distinctly from conventional IT.
Does grComply support the full Foundational Requirement structure?
Yes — all seven FRs (identification/authentication through resource availability) are seeded with real requirement language as a structural library.
What is the zone-and-conduit model, and how does grComply evidence it?
It's 62443's approach to network segmentation — grComply models it as control FR5-1 with a required zone-and-conduit diagram as evidence, so segmentation claims are documented, not assumed.
Does grComply support air-gapped deployment for OT networks?
Yes — private on-prem, including fully air-gapped deployment, is available for industrial networks that cannot or should not connect to cloud infrastructure.
How is OT evidence different from IT evidence in grComply?
Dedicated evidence types — OT malware-protection coverage and IACS audit-log samples — are modelled distinctly from generic IT scan/SIEM evidence, reflecting how OT environments are actually assessed.
Can 62443 cross-map to NIST CSF or CIS Controls?
Yes — for organisations running a converged IT/OT security programme, a segmentation or access control can credit both 62443 and an equivalent NIST CSF or CIS control from one piece of evidence.
What are the 62443 security levels (SL1–SL4)?
They indicate the rigour of protection required against increasingly capable adversaries; grComply's per-tenant configuration can scope which Foundational Requirements and target security level apply to a given IACS zone. See the full catalog on the Compliance Frameworks page.
See ISA/IEC 62443 mapped into your control library
Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →
Talk to us about ISA/IEC 62443
Tell us where your ISA/IEC 62443 programme stands today, and we'll route it to the right product specialist.
- A product specialist replies personally — not a bot
- No obligation after the first conversation
- WhatsApp support also available 24/7
By submitting, you agree to be contacted about your enquiry. We respect your privacy.
Book a meeting directly
Pick a time that works for you — 30 minutes with a product specialist, no sales script.
Ready to bring ISA/IEC 62443 into one control library?
We respond within one working day — or reach us instantly on WhatsApp.