Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

ISA/IEC 62443:

Cryptography and PKI for Industrial Automation and Control Systems

Updated: August 24, 2026
Region International (primary impact: North America, Europe, Asia-Pacific) 
Applicability Asset Owners: organizations that operate Industrial Automation and Control Systems (IACS) in their own facilities System Integrators: companies that design, build, or commission IACS on behalf of asset owners  Component Manufacturers: companies that make the PLCs, HMIs, sensors, industrial routers, and embedded controllers that go into IACS 
Relevant sections ISA/IEC 62443-3-3: System-level security requirements and Security Levels) ISA/IEC 62443-4-2: Component technical security requirements) ISA/IEC 62443-2-4: Key management and service provider security programs) 

Overview

ISA/IEC 62443 is an international standard series for cybersecurity in Industrial Automation and Control Systems (IACS), defining security requirements across the full OT lifecycle, from embedded components through system integration and ongoing operations.  

In practical terms, the standard requires manufacturers to implement authenticated device communications, cryptographically protected control-plane traffic, and formally managed key lifecycles, aligned to Security Levels SL 1 through SL 4 based on the consequence severity of a potential compromise. 

Why It Matters 

Any organization that operates IACS, integrates OT systems for others, or supplies connected industrial components is in scope, and supply chain requirements increasingly cascade compliance obligations to upstream vendors and component suppliers. 

ISA/IEC 62443 conformance is increasingly a commercial prerequisite rather than a box-checking exercise. EU and North American procurement frameworks for critical infrastructure and defense supply chains require demonstrated OT security conformance, and cyber insurers are beginning to treat ISASecure certification as a condition of coverage. This makes compliance a direct enabler of contract wins, supply chain access, and favorable insurance terms. 

How This Maps to Cryptography 

SA/IEC 62443 addresses cryptography across its component, system, and operational layers. The key control families with direct cryptographic implications are: 

SectionFunctionWhat it says Products 
ISA/IEC 62443-4-2, CR 3.4 Software and Information Integrity Firmware and Software Integrity Components must support integrity verification of firmware, software, and configuration files using cryptographic methods AgileSec Command 
ISA/IEC 62443-3-3, SR 1.1–1.3 — Identification, Authentication, Authenticator Management Device and System Authentication Authenticated communications between IACS components EJBCA 
ISA/IEC 62443-3-3, SR 4.3 — Use of Cryptography Use of Cryptography  Cryptographic mechanisms protect the confidentiality and integrity of information stored and transmitted within IACS, with only approved algorithms permitted and key management procedures documented and enforced. EJBCA 
ISA/IEC 62443-4-2, CR 1.1–1.3 — Component Authentication Component-Level Authentication Embedded components must support cryptographic authentication capabilities EJBCA 
ISA/IEC 62443-2-4, SP 03.07 — Cryptographic Key Management Key Management  Service providers operating IACS must document and implement formal key management procedures  EJBCA 
ISA/IEC 62443-3-3, SR 3.1–3.3 — Communication Integrity Communication Integrity Integrity protection for all communications at SL 2 and above, mapping to message authentication codes, signed firmware, and certificate-based session authentication across control plane protocols  EJBCA SignServer 

Audit Readiness 

ISA/IEC 62443 conformance assessments, whether conducted internally, by customers, or by accredited certification bodies, focus on evidence of implemented controls rather than policy documentation alone. Key areas that examiners and auditors probe: 

  • Zone and Conduit Documentation: Has the organization mapped all IACS components into security zones, documented the security level target and achieved for each zone, and defined conduits with appropriate cryptographic protection?  
  • Cryptographic Algorithm Inventory: Can the organization enumerate the cryptographic algorithms in use across all IACS components?  
  • Device Identity Lifecycle: How are device credentials (certificates, keys) provisioned, renewed, and revoked; and is it documented?  
  • Third-Party Component Assessment: Are components from vendors assessed for compliance with ISA/IEC 62443-4-2 security requirements, including cryptographic capabilities?  
  • Key Management Documentation: Are cryptographic key management procedures documented and operationalized?  
  • Patch and Cryptographic Agility: Does the organization have a process for updating cryptographic controls when algorithms are deprecated or vulnerabilities discovered?