---
title: "IEC 62443 Zone &amp; Conduit Model | Control"
description: "Implement the IEC 62443 zone and conduit model with physical enforcement. Create verifiably separate zones with physically governed conduits. Discover."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/solutions/control/frameworks/iec-62443#webpage",
      "url": "https://fire-vault.com/solutions/control/frameworks/iec-62443",
      "name": "IEC 62443 Zone & Conduit Model",
      "description": "Implement the IEC 62443 zone and conduit model with physical enforcement. Create verifiably separate zones with physically governed conduits. Discover.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-solutions.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/solutions/control/frameworks/iec-62443#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/solutions/control/frameworks/iec-62443#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Solutions",
          "item": "https://fire-vault.com/solutions"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Control",
          "item": "https://fire-vault.com/solutions/control"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Frameworks",
          "item": "https://fire-vault.com/solutions/control/frameworks"
        },
        {
          "@type": "ListItem",
          "position": 5,
          "name": "IEC 62443 Zone & Conduit Model",
          "item": "https://fire-vault.com/solutions/control/frameworks/iec-62443"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

IEC 62443 

# Physical Enforcement of Industrial Automation Security 

IEC 62443 defines zone and conduit requirements for industrial control system security. Control provides the physical enforcement layer that ensures zones are truly separated and conduits are genuinely controlled.

Schedule a Demo[Back to Control](/solutions/control)

![Rows of locked server cabinets inside a secure Firevault data hall](/__l5e/assets-v1/a4d3902c-28a5-42f4-bbfb-c12ddaacce1b/hero-square-drive.png)

Exposure

How it worksExplore moreQuestions

The exposure in numbers 

01 

Security Level achievable with physical enforcement

SL 4 Security Level achievable with physical enforcement 

02 

Zone boundary physical enforcement

100% Zone boundary physical enforcement 

03 

Control modules mapping to IEC 62443 requirements

9 Control modules mapping to IEC 62443 requirements 

04 

Automated compliance evidence generation

Full Automated compliance evidence generation 

The Compliance Gap 

## Software-only zone enforcement falls short.

01 

### Logical vs Physical Zones

IEC 62443 defines zones and conduits, but most implementations rely on firewalls and VLANs that can be bypassed through misconfiguration or compromise.

02 

### Purdue Model Erosion

The Purdue model's hierarchical separation erodes as organisations connect Level 3 systems to cloud services and remote access platforms.

03 

### Evidence Gaps

Demonstrating continuous zone enforcement to auditors is difficult when boundaries are defined in software configurations that change frequently.

IEC 62443

> IEC 62443 requires zones and conduits. If those zones are defined by firewall rules rather than physical separation, every firewall misconfiguration is a potential zone boundary failure.

The Scenario

### Scenario: Zone Boundary Failure During Audit

During an IEC 62443 certification audit, the assessor discovers that a firewall rule change made three months earlier had inadvertently created a path between Level 2 (control system) and Level 4 (enterprise) zones. The change was part of a routine maintenance update and had passed through the change management process without flagging the zone boundary violation. For three months, the control system zone was directly reachable from the enterprise network. With Control, zone boundaries are physical. No software change, configuration error, or routine maintenance can create a path between zones without explicit, multi-party authorised physical activation.

"We passed our IEC 62443 assessment in January. By April, a routine firewall change had created a path from our enterprise zone directly into the control system zone. Nobody noticed for three months. The zone boundary existed only as long as the firewall rules were correct."

IEC 62443 mapping 

## Where IEC 62443 system requirements meet Control modules.

IEC 62443-3-3 defines seven foundational requirements and the system requirements (SR) beneath them. Control supplies the physical enforcement that turns those requirements from configurable intent into a boundary that holds.

Reference: IEC 62443-3-3:2013 System security requirements and security levels, mapped against the foundational requirements FR 1 to FR 7.

SEC 01

FR 1 - Identification and Authentication Control

Know who is acting before granting reach.

-   SR 1.1 
    
    Human user identification
    
    Named identity required for any reach into a protected zone.
    
    ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock 
    
-   SR 1.13 
    
    Access via untrusted networks
    
    Remote vendor reach is a time-bound, scoped session, not a standing tunnel.
    
    ![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock 
    

SEC 02

FR 2 - Use Control

Authorise the action, not just the user.

-   SR 2.1 
    
    Authorisation enforcement
    
    Privileged actions require explicit approval before the path opens.
    
    ![FV-Execute module icon](/assets/execute-icon-kJl5Gtmk.png)Execute ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock 
    
-   SR 2.8 
    
    Auditable events
    
    Every governed action is captured and sealed beyond casual edit.
    
    ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate ![FV-Archive module icon](/assets/archive-icon-B3rc85NY.png)Archive 
    

SEC 03

FR 3 - System Integrity

Prove the system is in the expected state.

-   SR 3.1 
    
    Communication integrity
    
    Conduit state is continuously attested with cryptographic evidence.
    
    ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate 
    
-   SR 3.4 
    
    Software and information integrity
    
    Golden images and operational data live in tamper-evident offline copies.
    
    ![FV-Archive module icon](/assets/archive-icon-B3rc85NY.png)Archive ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate 
    

SEC 04

FR 4 - Data Confidentiality

Restrict what data can be reached, not just by whom.

-   SR 4.1 
    
    Information confidentiality
    
    Sensitive data crosses boundaries only through governed Transfer events.
    
    ![FV-Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)Transfer ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock 
    

SEC 05

FR 5 - Restricted Data Flow

Zones and conduits as physical fact, not policy.

-   SR 5.1 
    
    Network segmentation
    
    Zone boundaries are physically severed by default. The path does not exist until it is opened.
    
    ![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak ![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate 
    
-   SR 5.2 
    
    Zone boundary protection
    
    Cross-zone reach is a named, time-bound conduit with explicit approval.
    
    ![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate ![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay ![FV-Execute module icon](/assets/execute-icon-kJl5Gtmk.png)Execute 
    

SEC 06

FR 6 - Timely Response to Events

See and respond before the blast widens.

-   SR 6.1 
    
    Audit log accessibility
    
    Audit and conduit state remain readable from a side channel even during an incident.
    
    ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate ![FV-Archive module icon](/assets/archive-icon-B3rc85NY.png)Archive 
    
-   SR 6.2 
    
    Continuous monitoring
    
    Continuous attestation surfaces boundary drift before it becomes an incident.
    
    ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate 
    

SEC 07

FR 7 - Resource Availability

Recover from intentional and unintentional events.

-   SR 7.3 
    
    Control system backup
    
    Recovery copies sit in an offline vault that is not reachable on the live network.
    
    ![FV-Archive module icon](/assets/archive-icon-B3rc85NY.png)Archive ![FV-Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)Transfer 
    
-   SR 7.4 
    
    Control system recovery and reconstitution
    
    Restoration is an authorised, evidenced action with quorum approval.
    
    ![FV-Execute module icon](/assets/execute-icon-kJl5Gtmk.png)Execute ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate 
    

Modules & symbols

![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock Named access 

![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay Time-bound path 

![FV-Execute module icon](/assets/execute-icon-kJl5Gtmk.png)Execute Approved action 

![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate Integrity check 

![FV-Archive module icon](/assets/archive-icon-B3rc85NY.png)Archive Disconnected copy 

![FV-Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)Transfer Controlled move 

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak Physical sever 

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate Zone boundary 

Direct map Module satisfies clause 

Featured In

[![TechRadar Pro logo](/press/techradar-pro-logo.svg) ](https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough "Read about Firevault on TechRadar Pro") [![Yahoo Finance logo](/assets/yahoo-finance-logo-white-aNkUpCH7.png) ](https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html "Read about Firevault on Yahoo Finance") [![Channel Insider logo](/assets/channel-insider-logo-white-CFFo4iu7.png) ](https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/ "Read about Firevault on Channel Insider") [![Security Buyer logo](/assets/security-buyer-logo-white-o6oIaBWz.png) ](https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/ "Read about Firevault on Security Buyer") [![SecurityBrief logo](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAT8AAAA1CAYAAAA3Sux5AAAL+0lEQVR4nO2dT4gdSRnAf++Ri5ODEcTJvoB0PIjgxdkFlejsTkBExFlhzWhEWPDkYWfXxZfoRSK73vKPJQrePHjamLhg5iAswrzNkFVyyBz04kqYJ2tmM6CQS2bxss9Dvcrr6emu+qq7ql/3e/WDZv50dVW9ftVff1Xfn+qMRiMiEY/cBpZTf78M/HpKfYlECukIhd8Z4IalzBbwIjCs2KdIO1kHfmU436mrI5FIih5wKvX3fWAb7MKvrFq4BTxb8tpI++gBDwTlogCM1IFEWVvr5vxzBSX0qsyHl8fX71SoI9IeXvVUz8hyLHlqJ1LMEmrpIn3fH6I0+6ZzGdVfm+ADOJ4Vfn1g02NnEqoJ0Ug7+Jyw3ELFdr5f8frQPMQuwCXHLdSzUzc94B4H12wBFlFLGpdr75Gc2yj5JSYt/NYJ9+GiAJxtficstx+0F9Nn0VM9q6hZ04jqLwwX3rScdxIuNZI1sonQwq+HebHaB1EAzi43BWWeDt6L2eQxShOsA2cB0gDWKdlvLfzu+euLkbhmM7t0gI2Cc+cYW9gipVgF7tTQzl4NbfimrNL2UAs/ibq+gRKWnczRRQ1uCW+59jDSKp5HjYkT40OPlyvT7NSMcIrwU2CbUWMrcPuhyMqtLnCzi+yGrqEGdt7UdYQa3BI3hkTS00jr2R0fcanDL48D138TOEq+BrhG89zXzljO76HkUnYcjgCOAL8UNCJZ0wH1ZmjjukEkEpot4CwHZ1kfB54BnkNNbZvAPnAcpRQdG/9vd2q9MfOK5fwl08kjwJf99YVrzLbwy9Nu50W7yX5235971u/jXSYacZoBk2WBW9iF4Mr4mtDs03zr/Gct539jOpnn5FyF+57rW8fNN6rnse2LOW18lHPoczYVPI12Yyg6XFwKbPclfU8WLGV3OCjkzlD82Ueoe6S549CPvPMSzlvaWBHeE+l31RPUJV2H+0hQ5nlBmWeE7c0DNluFUXh3gT/764s3a5EeWC6WnFVUiFVV3yj9wJ93vO4GcsGVWM67tm3ihdTvn7KUTYCnxr9LPOXT/TxVWEqhHZRDLtr/RFhOEgEgrc+3dnTdcv5/HtpIUC+KPmq81+FL2Bu3tUJD1v67wC8E5aRv5t1xnScMh4nXHNoy8Rjl+OiKNDTGhA6xaSsuhoqmWv+GnuqZhlPvPyzn/57526SVpp+BpdT/d1CRXJdR4/0xSnPvWOqT3o8eh2cCD8ZtbXJ45rMiqLPMbMF4X1ymvdIPP2KytpF3mK674NAfG8uocCMJWtvzSXaq1xZc7oPP78snPjVnE0V+jVX4keX8wKEuvf5+Gbsv71+YaP1FPGc5v4R65h5gnwmk2eTwMkpIloEF1zU/rdX4fiNKhZQri4K6V6iu7RUhyXTSZgbT7kABEu8EWyiXhKse6kjTwV+InOYKsuf1rxXbuYUSsFX6r9d0a0ELP9t0NIsWglpVrsIt/H/haRYxhwdtBmwb2j0FnmW+ZzkviUYaOLRnUzR62I0iZZ416Trofco/h7fx66ozoob0Z/oL2aWcF/4p8i1/UnrIb9qQw9Ela8Jri9qoSzDt1NTOvPN26nfXF3oW2zTR1bjXR72Es8dtJlNFEyGm2Glsa41FPCSMe5vEOl6J9NvoHHZLkwmtsro86NJp4QngZM7/b6KEoKTfWUHnEmd8lcOCtwOcFl6f0O5EnpdQ4+M0Ki09yEMas+yTfy8l9+eS4doOB9PlSxxzXxP3+jBlEjWs5hzL2DWuDWRuMFUoY7XuI9cWhygD2QZyQ1kZo6WUD49k/nEW+DfV1vQSlKDx9YVJHgppvxMmlkBpMocuxRriANW/O9gXeF+ifXtZHOXwQzGgPZ/jOubp7QXyvR0SQd11RT2Yxl9ZrjLp/2XKW8clKfBOUHyv+pY6llHGyJvjej7InLdph3nXPDX+3yhvHeIcfrSUVdSXVvThJALW5e0q0UT0+p708+XFBebxFUGZnwvbbAodmu/hb+NsyeuuWc77NnQUYQzPcmTIREPuo5a5dEx+3qzKhkRrPor5JXFlXMaENkZqFywXV5e8a564cpkWYV3W1EwUSXfJW2PbsS1bf5Pxz5cEdfke4CGNOr5p8xTdlbzlD9s6dF3+f+dR2k3VfH5blBNwJmxuTmvIXp772DXPIOMxO+3NotfUQBZ3WEQfFYfnOg0OZZD4uqCM6wDvYhbooResI/lsYB63P6D5uQb1LKqsEPCdjUXivypNhgLwQ8xeF0GWjGzCL40WXAnlrJerTObv02QB+GKAekP4P06Dl+1FWsVVzMKvz8ElkxVLfVWiWoqulVpLywjAEN/nC/Yi7AAfE9ZnmxV9lSkLP80Q9QUsAK/j9sDfGF+blGjXF8do1xS0brLhU21n4Fj+m5bztvXAIi4BPzWcXwL+hH1sXrTUk+W3DmWlSGZOicf2vuSxridUyeqyz8Q44mr2/0SFdqsSBZ+Z96bdgQAMHcraQuPKzlxsO9xto/Lo2TRL19C9EEarYwHqNJGEqFSb0U2HZLF1G7k6vkB5h0of7OEv8D3SDj5vOe+Sjiw0kvW5NsaMNw6J5udi5JB41f+M6bpQPALen2L7EqTaadwQSoZtvElju6VO7aGxJfEMzaMpt++FMmt+JiSOn19DlkYLwrlc/B77IvMSblbANzE71A7x725Q1657s8AadiFnW78e+OmKlSHmqd4n6+lGIW9jVoqu49ew+a7Hup7gW/hJ+O8U2swi2QbwHm7C1xYonzjUJWHFc32zju1h7NEcV6WkxrbK8BbmRMMrlHcwr40uMtO9z+nVO+OfEi1I4gidRidDNR0g1+h8ptpy9da3rUOFzkYzb9hSXIWOrXXhP1Nu3zbDW8R91rZQcCSunZPSBb4hKCedXkkCkXX2mKGgbB+5hrOAW3JNSRabRew+jXqfBxtvpH4fCsqbpmjzmibrxYrXm15ATdl4S/LdvmMvEhxbMhGXrCwXUdmk844dAhmkusiNDyOUJrSOeuB13v8llEV4hPsAkkwlNsftJgXnk/F5yZ6m6QVraVaShEmMsn6b6f0IdHpuCem3pcRJFCba6kMOpv6eVxY5vN+Ey/4Tb5Rsd1jyOgkJ6gWvnyEJTRgDkmmtpJ/r2N13gq75SffbXUTN9V02FkqTnWIXbYSe166PnHiDzN9PI9dq+5SP4MhawV3DqaJv4oS8l5x0ilU2E4uP6AIdolaVJkXgDLFPS0eo5/7HKBe3Y6jNrNYF14JyTQuSQUcLv2ep522S58PUpYbEheQ/INvIvsAqrNHcTZ/nEVusbx5lEv2GoknpxD6D7NldprxnwvGS11lJ+/mF9mEq8gEcYU9rE6pt8O9+kqXIylgmGeas4yOLkI0mGS5caVq2nRHVM2abCCoX0sJvQLgP0sWs/ewTbuCbkilqOoRZ1zENVq11hqq/jUw76UUedQhkCSGFTBV2CTMOTxM4GCIb4aE/yNBT/UPkCUF1+ixfG5/r1PPSKedJ/Gm/J5ENiJOUv9ezJvg0PsdAES7a/rQFsk442vSlkw5+lgc2xnUNPNRlpCi8TfrwmiibIfY41dTd15lkq3VlQLUkrlrgDh2uOYnqsxTXTNuuvorZtN+++JdD2eOEdSoeei7nmz0mY6nsXim6Hp/l/2k5r8dmmbRfG6jn3mVZYliinSd0RiORnaOH2gLvO+QbB/ZQ2UCu4f9N2Qe+zWFr9B7wISpO94/AH/A/WBPgW6gU9HkW1yHwN1S4j4+F6DPAKxz8rPreXiD/bWhzQM9alk3lq1jWOsAXHPohZR34Lvnf/11UqGSZuiUD31UB6GDf+NvEB7gbHk1tlqnPlDTBdWysoJ6fdP7MR+Of76H2Cn63RL2aSp9dKvwikVkjhPCLtIgq+fwikbYiiUSqkrE50gKi5heZNxJkDvOnqS+LS2QKRM0vMk/0kUcKDQL2I9IAppHSKhIJTQ+Vtux9VO7GT+OW/j2043ukAUThF5lFXkVNbxPck20MidsczAVx2huJHCRqfXNCFH6RyISmhpBFAhCnvZGIQu9kGJkTouYXmXeuI48/j8wQUfhFZpG7gjI6drbxG+1EwhCdnCPzQDpetenZUSI18X+Dj/KN9NJspQAAAABJRU5ErkJggg==) ](https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks "Read about Firevault on SecurityBrief") 

Capabilities

## What you get with every deployment

01 

### Physical Zone Enforcement

Zone boundaries are physical, not logical. No software change can create an unauthorised path between zones regardless of privilege level.

02 

### Conduit Control

Every conduit between zones requires multi-party authorisation, operates within defined time windows, and generates full audit evidence.

03 

### Continuous Evidence

Automated logging generates continuous IEC 62443 compliance evidence, eliminating the gap between point-in-time assessments.

04 

### Purdue Model Alignment

Control modules map directly to Purdue model levels, providing clear, auditable alignment between your architecture and the standard.

05 

### Audit-Ready Logs

Tamper-proof logs record every zone boundary state change, conduit activation, and access authorisation for assessor review.

06 

### Evidence Preservation

Tamper-evident compliance records are held independently of production systems so audit evidence persists through compromise.

Demo to Live

## Adoption Guide

Step 1 

#### Zone and Conduit Assessment

Map your current IEC 62443 zone architecture and identify where logical boundaries should be replaced with physical enforcement.

Step 2 

#### Physical Zone Design

Design physically enforced zone boundaries with Control modules at each conduit, aligned to your target Security Level.

Step 3 

#### Compliance Validation

Deploy in a representative zone boundary with full evidence generation to validate compliance claims before your next assessment.

Step 4 

#### Full Zone Enforcement

Physical enforcement across all zone boundaries with continuous compliance evidence and tamper-proof audit archives.

Step 1 

#### Zone and Conduit Assessment

Map your current IEC 62443 zone architecture and identify where logical boundaries should be replaced with physical enforcement.

Step 2 

#### Physical Zone Design

Design physically enforced zone boundaries with Control modules at each conduit, aligned to your target Security Level.

Step 3 

#### Compliance Validation

Deploy in a representative zone boundary with full evidence generation to validate compliance claims before your next assessment.

Step 4 

#### Full Zone Enforcement

Physical enforcement across all zone boundaries with continuous compliance evidence and tamper-proof audit archives.

[Organise a Demo](/contact)

## Explore More

[

### Control for OT Environments

Physical network governance for SCADA, ICS and industrial control.

Learn more about Control for OT Environments ](/control-for-ot-environments)[

### Control for Oil and Gas

Upstream, midstream, and refinery control path protection.

Learn more about Control for Oil and Gas ](/control-for-oil-and-gas)[

### NIST CSF Framework

Identify, protect, detect, respond, recover alignment.

Learn more about NIST CSF Framework ](/solutions/control/frameworks/nist-csf)

Questions

## Frequently Asked

Which IEC 62443 parts does Control address? 

How does Control support Security Level 4? 

Can Control be deployed alongside existing firewalls? 

How does the evidence generation work?