IEC 62443

Physical Enforcement of Industrial Automation Security

IEC 62443 defines zone and conduit requirements for industrial control system security. Control provides the physical enforcement layer that ensures zones are truly separated and conduits are genuinely controlled.

Back to Control
Rows of locked server cabinets inside a secure Firevault data hall
The exposure in numbers
01
Security Level achievable with physical enforcement
SL 4Security Level achievable with physical enforcement
02
Zone boundary physical enforcement
100%Zone boundary physical enforcement
03
Control modules mapping to IEC 62443 requirements
9Control modules mapping to IEC 62443 requirements
04
Automated compliance evidence generation
FullAutomated compliance evidence generation
The Compliance Gap

Software-only zone enforcement falls short.

01

Logical vs Physical Zones

IEC 62443 defines zones and conduits, but most implementations rely on firewalls and VLANs that can be bypassed through misconfiguration or compromise.

02

Purdue Model Erosion

The Purdue model's hierarchical separation erodes as organisations connect Level 3 systems to cloud services and remote access platforms.

03

Evidence Gaps

Demonstrating continuous zone enforcement to auditors is difficult when boundaries are defined in software configurations that change frequently.

IEC 62443

IEC 62443 requires zones and conduits. If those zones are defined by firewall rules rather than physical separation, every firewall misconfiguration is a potential zone boundary failure.

The Scenario

Scenario: Zone Boundary Failure During Audit

During an IEC 62443 certification audit, the assessor discovers that a firewall rule change made three months earlier had inadvertently created a path between Level 2 (control system) and Level 4 (enterprise) zones. The change was part of a routine maintenance update and had passed through the change management process without flagging the zone boundary violation. For three months, the control system zone was directly reachable from the enterprise network. With Control, zone boundaries are physical. No software change, configuration error, or routine maintenance can create a path between zones without explicit, multi-party authorised physical activation.

"We passed our IEC 62443 assessment in January. By April, a routine firewall change had created a path from our enterprise zone directly into the control system zone. Nobody noticed for three months. The zone boundary existed only as long as the firewall rules were correct."

IEC 62443 mapping

Where IEC 62443 system requirements meet Control modules.

IEC 62443-3-3 defines seven foundational requirements and the system requirements (SR) beneath them. Control supplies the physical enforcement that turns those requirements from configurable intent into a boundary that holds.

Reference: IEC 62443-3-3:2013 System security requirements and security levels, mapped against the foundational requirements FR 1 to FR 7.

SEC 01

FR 1 - Identification and Authentication Control

Know who is acting before granting reach.

  • SR 1.1

    Human user identification

    Named identity required for any reach into a protected zone.

    FV-Lock module iconLock
  • SR 1.13

    Access via untrusted networks

    Remote vendor reach is a time-bound, scoped session, not a standing tunnel.

    FV-Relay module iconRelayFV-Lock module iconLock
SEC 02

FR 2 - Use Control

Authorise the action, not just the user.

  • SR 2.1

    Authorisation enforcement

    Privileged actions require explicit approval before the path opens.

    FV-Execute module iconExecuteFV-Lock module iconLock
  • SR 2.8

    Auditable events

    Every governed action is captured and sealed beyond casual edit.

    FV-Validate module iconValidateFV-Archive module iconArchive
SEC 03

FR 3 - System Integrity

Prove the system is in the expected state.

  • SR 3.1

    Communication integrity

    Conduit state is continuously attested with cryptographic evidence.

    FV-Validate module iconValidate
  • SR 3.4

    Software and information integrity

    Golden images and operational data live in tamper-evident offline copies.

    FV-Archive module iconArchiveFV-Validate module iconValidate
SEC 04

FR 4 - Data Confidentiality

Restrict what data can be reached, not just by whom.

  • SR 4.1

    Information confidentiality

    Sensitive data crosses boundaries only through governed Transfer events.

    FV-Transfer module iconTransferFV-Lock module iconLock
SEC 05

FR 5 - Restricted Data Flow

Zones and conduits as physical fact, not policy.

  • SR 5.1

    Network segmentation

    Zone boundaries are physically severed by default. The path does not exist until it is opened.

    FV-Firebreak module iconFirebreakFV-Isolate module iconIsolate
  • SR 5.2

    Zone boundary protection

    Cross-zone reach is a named, time-bound conduit with explicit approval.

    FV-Isolate module iconIsolateFV-Relay module iconRelayFV-Execute module iconExecute
SEC 06

FR 6 - Timely Response to Events

See and respond before the blast widens.

  • SR 6.1

    Audit log accessibility

    Audit and conduit state remain readable from a side channel even during an incident.

    FV-Validate module iconValidateFV-Archive module iconArchive
  • SR 6.2

    Continuous monitoring

    Continuous attestation surfaces boundary drift before it becomes an incident.

    FV-Validate module iconValidate
SEC 07

FR 7 - Resource Availability

Recover from intentional and unintentional events.

  • SR 7.3

    Control system backup

    Recovery copies sit in an offline vault that is not reachable on the live network.

    FV-Archive module iconArchiveFV-Transfer module iconTransfer
  • SR 7.4

    Control system recovery and reconstitution

    Restoration is an authorised, evidenced action with quorum approval.

    FV-Execute module iconExecuteFV-Validate module iconValidate

Modules & symbols

FV-Lock module iconLockNamed access
FV-Relay module iconRelayTime-bound path
FV-Execute module iconExecuteApproved action
FV-Validate module iconValidateIntegrity check
FV-Archive module iconArchiveDisconnected copy
FV-Transfer module iconTransferControlled move
FV-Firebreak module iconFirebreakPhysical sever
FV-Isolate module iconIsolateZone boundary
Direct mapModule satisfies clause

Featured In

TechRadar Pro logoYahoo Finance logoChannel Insider logoSecurity Buyer logoSecurityBrief logo

Capabilities

What you get with every deployment

01

Physical Zone Enforcement

Zone boundaries are physical, not logical. No software change can create an unauthorised path between zones regardless of privilege level.

02

Conduit Control

Every conduit between zones requires multi-party authorisation, operates within defined time windows, and generates full audit evidence.

03

Continuous Evidence

Automated logging generates continuous IEC 62443 compliance evidence, eliminating the gap between point-in-time assessments.

04

Purdue Model Alignment

Control modules map directly to Purdue model levels, providing clear, auditable alignment between your architecture and the standard.

05

Audit-Ready Logs

Tamper-proof logs record every zone boundary state change, conduit activation, and access authorisation for assessor review.

06

Evidence Preservation

Tamper-evident compliance records are held independently of production systems so audit evidence persists through compromise.

Demo to Live

Adoption Guide

Step 1

Zone and Conduit Assessment

Map your current IEC 62443 zone architecture and identify where logical boundaries should be replaced with physical enforcement.

Step 2

Physical Zone Design

Design physically enforced zone boundaries with Control modules at each conduit, aligned to your target Security Level.

Step 3

Compliance Validation

Deploy in a representative zone boundary with full evidence generation to validate compliance claims before your next assessment.

Step 4

Full Zone Enforcement

Physical enforcement across all zone boundaries with continuous compliance evidence and tamper-proof audit archives.

Step 1

Zone and Conduit Assessment

Map your current IEC 62443 zone architecture and identify where logical boundaries should be replaced with physical enforcement.

Step 2

Physical Zone Design

Design physically enforced zone boundaries with Control modules at each conduit, aligned to your target Security Level.

Step 3

Compliance Validation

Deploy in a representative zone boundary with full evidence generation to validate compliance claims before your next assessment.

Step 4

Full Zone Enforcement

Physical enforcement across all zone boundaries with continuous compliance evidence and tamper-proof audit archives.

Questions

Frequently Asked