ISA/IEC 62443:
Cryptography and PKI for Industrial Automation and Control Systems
| Region | International (primary impact: North America, Europe, Asia-Pacific) |
| Applicability | Asset Owners: organizations that operate Industrial Automation and Control Systems (IACS) in their own facilities System Integrators: companies that design, build, or commission IACS on behalf of asset owners Component Manufacturers: companies that make the PLCs, HMIs, sensors, industrial routers, and embedded controllers that go into IACS |
| Relevant sections | ISA/IEC 62443-3-3: System-level security requirements and Security Levels) ISA/IEC 62443-4-2: Component technical security requirements) ISA/IEC 62443-2-4: Key management and service provider security programs) |
Overview
ISA/IEC 62443 is an international standard series for cybersecurity in Industrial Automation and Control Systems (IACS), defining security requirements across the full OT lifecycle, from embedded components through system integration and ongoing operations.
In practical terms, the standard requires manufacturers to implement authenticated device communications, cryptographically protected control-plane traffic, and formally managed key lifecycles, aligned to Security Levels SL 1 through SL 4 based on the consequence severity of a potential compromise.
Why It Matters
Any organization that operates IACS, integrates OT systems for others, or supplies connected industrial components is in scope, and supply chain requirements increasingly cascade compliance obligations to upstream vendors and component suppliers.
ISA/IEC 62443 conformance is increasingly a commercial prerequisite rather than a box-checking exercise. EU and North American procurement frameworks for critical infrastructure and defense supply chains require demonstrated OT security conformance, and cyber insurers are beginning to treat ISASecure certification as a condition of coverage. This makes compliance a direct enabler of contract wins, supply chain access, and favorable insurance terms.
How This Maps to Cryptography
SA/IEC 62443 addresses cryptography across its component, system, and operational layers. The key control families with direct cryptographic implications are:
| Section | Function | What it says | Products |
|---|---|---|---|
| ISA/IEC 62443-4-2, CR 3.4 Software and Information Integrity | Firmware and Software Integrity | Components must support integrity verification of firmware, software, and configuration files using cryptographic methods | AgileSec Command |
| ISA/IEC 62443-3-3, SR 1.1–1.3 — Identification, Authentication, Authenticator Management | Device and System Authentication | Authenticated communications between IACS components | EJBCA |
| ISA/IEC 62443-3-3, SR 4.3 — Use of Cryptography | Use of Cryptography | Cryptographic mechanisms protect the confidentiality and integrity of information stored and transmitted within IACS, with only approved algorithms permitted and key management procedures documented and enforced. | EJBCA |
| ISA/IEC 62443-4-2, CR 1.1–1.3 — Component Authentication | Component-Level Authentication | Embedded components must support cryptographic authentication capabilities | EJBCA |
| ISA/IEC 62443-2-4, SP 03.07 — Cryptographic Key Management | Key Management | Service providers operating IACS must document and implement formal key management procedures | EJBCA |
| ISA/IEC 62443-3-3, SR 3.1–3.3 — Communication Integrity | Communication Integrity | Integrity protection for all communications at SL 2 and above, mapping to message authentication codes, signed firmware, and certificate-based session authentication across control plane protocols | EJBCA SignServer |
Audit Readiness
ISA/IEC 62443 conformance assessments, whether conducted internally, by customers, or by accredited certification bodies, focus on evidence of implemented controls rather than policy documentation alone. Key areas that examiners and auditors probe:
- Zone and Conduit Documentation: Has the organization mapped all IACS components into security zones, documented the security level target and achieved for each zone, and defined conduits with appropriate cryptographic protection?
- Cryptographic Algorithm Inventory: Can the organization enumerate the cryptographic algorithms in use across all IACS components?
- Device Identity Lifecycle: How are device credentials (certificates, keys) provisioned, renewed, and revoked; and is it documented?
- Third-Party Component Assessment: Are components from vendors assessed for compliance with ISA/IEC 62443-4-2 security requirements, including cryptographic capabilities?
- Key Management Documentation: Are cryptographic key management procedures documented and operationalized?
- Patch and Cryptographic Agility: Does the organization have a process for updating cryptographic controls when algorithms are deprecated or vulnerabilities discovered?
TAKE THIS TO MANAGEMENT
Our factories run on connected systems that control real physical processes and ISA/IEC 62443 sets the security bar for all of it. That means making sure devices can prove who they are, that commands can’t be tampered with in transit, and that we actually know where all our cryptographic credentials are across thousands of endpoints.
If we can’t show that our OT environment has proper certificate management and authenticated communications, we’re exposed, not just to regulators and customers who are increasingly asking for it, but to insurers who are starting to make it a condition of coverage. We also need to start thinking about quantum: our OT systems will be running for 15-25 years, and the cryptographic choices we make today have to hold up for the entire life of those assets.


