IECExecution MethodologyStandard
IEC 62443-3-3:2013

Industrial Communication Networks — Network and System Security — Part 3-3: System Security Requirements and Security Levels

Defines system security requirements against the seven foundational requirements of the 62443 series and assigns security levels, so that the protection a control system needs can be stated as a target rather than argued case by case.

LAST REVISED
August 2013
PRODUCT AREAS
SterileSolid DoseBiotechApiDevices
SOURCE & PROVENANCE
ISSUING BODY
International Electrotechnical Commission
JURISDICTION
International
DOCUMENT ID
IEC 62443-3-3:2013
Official site — International Electrotechnical Commission

Always verify against the current published text before relying on it for a submission or inspection.

Scope & applicability

The control system as an integrated whole, at the design stage. It is the part that turns a risk assessment into testable system requirements, which is why it is the natural counterpart to a GMP user-requirement specification for an automated system.

Key requirements

  • Seven foundational requirements: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely response to events, resource availability
  • Security levels 1 to 4 expressing the capability required against the threat assumed
  • Requirements stated so they can be verified during system acceptance rather than asserted
  • Zone-level target security levels derived from risk assessment

Implementation tips

  • Target security level per zone is the decision that matters; it is set by risk assessment under Part 3-2, not by this part.
  • Map the seven foundational requirements onto the automation user-requirement specification so security is tested at FAT and SAT rather than retrofitted.
  • This part dates from 2013 and predates much current OT practice — use it for the requirement structure, and read it alongside the 2024 asset-owner edition.

Revision notes

Edition 1.0 (2013-08) remains the current edition of this part; later work in the series has extended rather than replaced it.

CHECKING ACCESS

Checking your Professional access…

Where this control fails

live FDA enforcement
See all FDA enforcement →

Live FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

IEC 62443-3-3:2013: frequently asked questions

Quick answers to common questions about IEC 62443-3-3:2013.

What is IEC 62443-3-3:2013?

IEC 62443-3-3:2013 — Industrial Communication Networks — Network and System Security — Part 3-3: System Security Requirements and Security Levels — is a standard issued by the International Electrotechnical Commission. Defines system security requirements against the seven foundational requirements of the 62443 series and assigns security levels, so that the protection a control system needs can be stated as a target rather than argued case by case.

Who does IEC 62443-3-3:2013 apply to?

The control system as an integrated whole, at the design stage. It is the part that turns a risk assessment into testable system requirements, which is why it is the natural counterpart to a GMP user-requirement specification for an automated system.

What are the key requirements of IEC 62443-3-3:2013?

IEC 62443-3-3:2013 requires, among other things: Seven foundational requirements: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely response to events, resource availability; Security levels 1 to 4 expressing the capability required against the threat assumed; Requirements stated so they can be verified during system acceptance rather than asserted; Zone-level target security levels derived from risk assessment.

When was IEC 62443-3-3:2013 last updated?

The current version of IEC 62443-3-3:2013 dates from August 2013. Edition 1.0 (2013-08) remains the current edition of this part; later work in the series has extended rather than replaced it.