Industrial Communication Networks — Network and System Security — Part 3-3: System Security Requirements and Security Levels
Defines system security requirements against the seven foundational requirements of the 62443 series and assigns security levels, so that the protection a control system needs can be stated as a target rather than argued case by case.
Always verify against the current published text before relying on it for a submission or inspection.
Scope & applicability
The control system as an integrated whole, at the design stage. It is the part that turns a risk assessment into testable system requirements, which is why it is the natural counterpart to a GMP user-requirement specification for an automated system.
Key requirements
- Seven foundational requirements: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely response to events, resource availability
- Security levels 1 to 4 expressing the capability required against the threat assumed
- Requirements stated so they can be verified during system acceptance rather than asserted
- Zone-level target security levels derived from risk assessment
Implementation tips
- Target security level per zone is the decision that matters; it is set by risk assessment under Part 3-2, not by this part.
- Map the seven foundational requirements onto the automation user-requirement specification so security is tested at FAT and SAT rather than retrofitted.
- This part dates from 2013 and predates much current OT practice — use it for the requirement structure, and read it alongside the 2024 asset-owner edition.
Revision notes
Edition 1.0 (2013-08) remains the current edition of this part; later work in the series has extended rather than replaced it.
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
IEC 62443-3-3:2013: frequently asked questions
Quick answers to common questions about IEC 62443-3-3:2013.
What is IEC 62443-3-3:2013?
IEC 62443-3-3:2013 — Industrial Communication Networks — Network and System Security — Part 3-3: System Security Requirements and Security Levels — is a standard issued by the International Electrotechnical Commission. Defines system security requirements against the seven foundational requirements of the 62443 series and assigns security levels, so that the protection a control system needs can be stated as a target rather than argued case by case.
Who does IEC 62443-3-3:2013 apply to?
The control system as an integrated whole, at the design stage. It is the part that turns a risk assessment into testable system requirements, which is why it is the natural counterpart to a GMP user-requirement specification for an automated system.
What are the key requirements of IEC 62443-3-3:2013?
IEC 62443-3-3:2013 requires, among other things: Seven foundational requirements: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely response to events, resource availability; Security levels 1 to 4 expressing the capability required against the threat assumed; Requirements stated so they can be verified during system acceptance rather than asserted; Zone-level target security levels derived from risk assessment.
When was IEC 62443-3-3:2013 last updated?
The current version of IEC 62443-3-3:2013 dates from August 2013. Edition 1.0 (2013-08) remains the current edition of this part; later work in the series has extended rather than replaced it.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.