OT review

A review of OT controls in the language of IEC 62443.

IEC 62443 runs to more than a dozen documents, and most of them do not apply to any given installation. The Mini-Gap looks at remote access, segmentation and the remaining controls, then describes their state in the language of the part of the standard that does apply here.

01 Fit

When this service fits

When an industrial customer, auditor or insurer asks about OT security in IEC 62443 terms, and you first need a structured view of the state. It suits industrial companies and manufacturers of devices used in industry. We treat IEC 62443 as a recognised language of evidence about the security of industrial systems.

02 Scope

What we review

  • Remote access to OT systems.
  • Segmentation and network exposure.
  • Accounts and permissions.
  • Logging and event visibility.
  • Updates and vulnerability management.
  • Backup and restore.
  • Basic requirements from industrial customers.
  • Mapping the current state to IEC 62443 practices.
  • Recommendations that order the next steps.

What we map to

IEC 62443 is a family of standards whose parts answer different questions. The review draws on four:

  • IEC 62443-2-1 covers the security programme on the asset owner's side: who is responsible for what, and how that is documented.
  • IEC 62443-3-2 introduces the split of an installation into zones (groups of assets sharing requirements) and conduits (controlled connections between them). That is the language we use to describe segmentation.
  • IEC 62443-3-3 defines system requirements and security levels from SL 0 to SL 4. It separates the target level (SL-T), the level a given technology can reach (SL-C) and the level actually achieved (SL-A). The gap between SL-T and SL-A is usually what has to be shown to a board or a customer.
  • IEC 62443-4-2 covers technical requirements for individual components, which helps when the question is about one device rather than the whole installation.

The standard groups requirements into seven foundational requirements (FR). Here is what we review, set against them directly:

Foundational requirementWhat we review in that area
FR 1 – identification and authentication controlAccounts, permissions and how authentication works for remote access
FR 2 – use controlWhat someone can do once logged in, including privileged and service accounts
FR 3 – system integrityUpdates, vulnerability management, change control
FR 4 – data confidentialityOutside the scope of this review. In OT environments it is rarely the first problem, and assessing it properly requires an analysis of process data flows
FR 5 – restricted data flowSegmentation, network exposure, the crossings between OT and IT
FR 6 – timely response to eventsLogging, event visibility, whether an incident can be reconstructed
FR 7 – resource availabilityBackups and a restore that has actually been tested

The result describes the state against these requirements, and any security level number serves as a reference point for the conversation. The names of the parts and of the foundational requirements come from the structure of the standard; its text is under copyright and is not reproduced here. Available from the publisher: ISA/IEC 62443.

03 Result

What decision the result supports

You receive a structured view of the stronger controls, the gaps and the areas that need deeper work.

04 Inputs

What to prepare

  • A short description of the OT environment and its architecture, with a network diagram if one exists.
  • How remote access to OT systems works, and the available security documentation.
  • Any requirements from industrial customers, auditors or an insurer, if you have received them.

05 Terms

How scope and quotation are set

Scope and quotation depend on the number of sites and OT systems, the material available and the conversations required. We establish both after a short scoping call.

06 Limits

What falls outside the scope

This is not IEC 62443 certification or a full system assessment. IEC 62443 is usually not mandatory as a single imposed standard; we treat it as a recognised language of evidence and map the state to its practices, we do not certify. The operator remains responsible for securing the OT systems and for decisions about changes.

07 Process

Signal → review → evidence → decision

Signal

Who is asking, and about what, in your OT environment?

Review

What is the real state of the controls?

Evidence

What can be shown in the language of IEC 62443?

Decision

Where to begin and what to defer?

08 Questions

Questions before starting

  • Is this IEC 62443 certification? No. It is a review that orders the state and maps it to the standard's practices.
  • Is IEC 62443 mandatory? Usually not as a single imposed standard, but industrial customers, auditors and insurers increasingly ask about it.
  • Do you cover the whole plant? We establish the scope after a short scoping call, depending on the number of sites and systems.

09 Contact

Discuss the OT review scope

An outline of the OT environment and the current situation is all we need to open the conversation.

Talk to us

Editorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 21 July 2026.