OT review
A review of OT controls in the language of IEC 62443.
IEC 62443 runs to more than a dozen documents, and most of them do not apply to any given installation. The Mini-Gap looks at remote access, segmentation and the remaining controls, then describes their state in the language of the part of the standard that does apply here.
01 Fit
When this service fits
When an industrial customer, auditor or insurer asks about OT security in IEC 62443 terms, and you first need a structured view of the state. It suits industrial companies and manufacturers of devices used in industry. We treat IEC 62443 as a recognised language of evidence about the security of industrial systems.
02 Scope
What we review
- Remote access to OT systems.
- Segmentation and network exposure.
- Accounts and permissions.
- Logging and event visibility.
- Updates and vulnerability management.
- Backup and restore.
- Basic requirements from industrial customers.
- Mapping the current state to IEC 62443 practices.
- Recommendations that order the next steps.
What we map to
IEC 62443 is a family of standards whose parts answer different questions. The review draws on four:
- IEC 62443-2-1 covers the security programme on the asset owner's side: who is responsible for what, and how that is documented.
- IEC 62443-3-2 introduces the split of an installation into zones (groups of assets sharing requirements) and conduits (controlled connections between them). That is the language we use to describe segmentation.
- IEC 62443-3-3 defines system requirements and security levels from SL 0 to SL 4. It separates the target level (SL-T), the level a given technology can reach (SL-C) and the level actually achieved (SL-A). The gap between SL-T and SL-A is usually what has to be shown to a board or a customer.
- IEC 62443-4-2 covers technical requirements for individual components, which helps when the question is about one device rather than the whole installation.
The standard groups requirements into seven foundational requirements (FR). Here is what we review, set against them directly:
| Foundational requirement | What we review in that area |
|---|---|
| FR 1 – identification and authentication control | Accounts, permissions and how authentication works for remote access |
| FR 2 – use control | What someone can do once logged in, including privileged and service accounts |
| FR 3 – system integrity | Updates, vulnerability management, change control |
| FR 4 – data confidentiality | Outside the scope of this review. In OT environments it is rarely the first problem, and assessing it properly requires an analysis of process data flows |
| FR 5 – restricted data flow | Segmentation, network exposure, the crossings between OT and IT |
| FR 6 – timely response to events | Logging, event visibility, whether an incident can be reconstructed |
| FR 7 – resource availability | Backups and a restore that has actually been tested |
The result describes the state against these requirements, and any security level number serves as a reference point for the conversation. The names of the parts and of the foundational requirements come from the structure of the standard; its text is under copyright and is not reproduced here. Available from the publisher: ISA/IEC 62443.
03 Result
What decision the result supports
You receive a structured view of the stronger controls, the gaps and the areas that need deeper work.
04 Inputs
What to prepare
- A short description of the OT environment and its architecture, with a network diagram if one exists.
- How remote access to OT systems works, and the available security documentation.
- Any requirements from industrial customers, auditors or an insurer, if you have received them.
05 Terms
How scope and quotation are set
Scope and quotation depend on the number of sites and OT systems, the material available and the conversations required. We establish both after a short scoping call.
06 Limits
What falls outside the scope
This is not IEC 62443 certification or a full system assessment. IEC 62443 is usually not mandatory as a single imposed standard; we treat it as a recognised language of evidence and map the state to its practices, we do not certify. The operator remains responsible for securing the OT systems and for decisions about changes.
07 Process
Signal → review → evidence → decision
Who is asking, and about what, in your OT environment?
What is the real state of the controls?
What can be shown in the language of IEC 62443?
Where to begin and what to defer?
08 Questions
Questions before starting
- Is this IEC 62443 certification? No. It is a review that orders the state and maps it to the standard's practices.
- Is IEC 62443 mandatory? Usually not as a single imposed standard, but industrial customers, auditors and insurers increasingly ask about it.
- Do you cover the whole plant? We establish the scope after a short scoping call, depending on the number of sites and systems.
09 Contact
Discuss the OT review scope
An outline of the OT environment and the current situation is all we need to open the conversation.
Talk to usEditorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 21 July 2026.