Security for Industrial Automation and Control Systems — Part 2-1: Security Program Requirements for IACS Asset Owners
Specifies the security programme an asset owner must operate for an industrial automation and control system in service, covering governance, risk management, asset inventory, access control, patching, monitoring and incident response. Developed jointly by ISA and IEC and commonly cited as ISA/IEC 62443.
Always verify against the current published text before relying on it for a submission or inspection.
Scope & applicability
The operator of the control system, not its supplier — the manufacturing site running the PLCs, DCS, SCADA and historians. This is the part of the 62443 series a regulated manufacturer owns directly; Part 4-1 and 4-2 place obligations on the product supplier instead.
Key requirements
- A documented security programme with defined organisational roles and accountability
- Inventory of IACS assets, including the systems and connections that are easy to forget
- Risk assessment driving zone and conduit definition rather than a flat network
- Access control including remote and third-party access, granted per session rather than standing
- Patch, backup, restore and incident-response arrangements suited to systems that cannot simply be rebooted
Implementation tips
- Edition 2.0 (2024) restructured the requirements around a maturity model — check which edition a supplier or auditor is working to.
- The zone and conduit model is the practical bridge between this standard and GMP: it makes explicit which systems a GxP-critical control depends on.
- Vendor remote access is the control most often granted informally and never revoked; treat it as a named requirement rather than an IT convenience.
Revision notes
Edition 2.0 (2024-08) replaced the 2010 first edition, restructuring asset-owner requirements and aligning them with the wider 62443 series.
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
IEC 62443-2-1:2024: frequently asked questions
Quick answers to common questions about IEC 62443-2-1:2024.
What is IEC 62443-2-1:2024?
IEC 62443-2-1:2024 — Security for Industrial Automation and Control Systems — Part 2-1: Security Program Requirements for IACS Asset Owners — is a standard issued by the International Electrotechnical Commission. Specifies the security programme an asset owner must operate for an industrial automation and control system in service, covering governance, risk management, asset inventory, access control, patching, monitoring and incident response. Developed jointly by ISA and IEC and commonly cited as ISA/IEC 62443.
Who does IEC 62443-2-1:2024 apply to?
The operator of the control system, not its supplier — the manufacturing site running the PLCs, DCS, SCADA and historians. This is the part of the 62443 series a regulated manufacturer owns directly; Part 4-1 and 4-2 place obligations on the product supplier instead.
What are the key requirements of IEC 62443-2-1:2024?
IEC 62443-2-1:2024 requires, among other things: A documented security programme with defined organisational roles and accountability; Inventory of IACS assets, including the systems and connections that are easy to forget; Risk assessment driving zone and conduit definition rather than a flat network; Access control including remote and third-party access, granted per session rather than standing.
When was IEC 62443-2-1:2024 last updated?
The current version of IEC 62443-2-1:2024 dates from August 2024. Edition 2.0 (2024-08) replaced the 2010 first edition, restructuring asset-owner requirements and aligning them with the wider 62443 series.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.