IEC 62443 in the plant, not in a binder
Zones and conduits derived from the communication that actually runs. With a target security level per zone and an order of work that fits maintenance windows.
A zone concept is a statement about the plant
A zone model can be drawn at a desk, but it only holds once it matches the connections that are actually open. The test of it is two questions. Which paths run today between the office network and the control level? Are they all in the concept?
The standard is awkwardly concrete on this point. A zone model to 62443-3-2 is a statement about the architecture: which parts of the plant share a security level, where the boundary runs, and what may cross it. That cannot be written without knowing the plant.
Underneath there is usually a Purdue model, the division into levels from the field up to the office network. It orders the plant, but it does not replace a zone model. Purdue describes levels, 62443 asks for zones with a security level and named crossings. Two parts of a plant on the same Purdue level can belong to different zones.
So we start with the communication that really runs, and not with the network plan that ought to hold.
What we do not do
- No audit. We prepare for an assessment, we do not carry it out. Anyone offering both ends up auditing their own advice.
- No certification. That is issued by an accredited body, and we are not one.
- No legal advice. Whether your company is affected and which deadlines apply is for your legal department. We say what stands behind it technically.
Zones and transitions as they really run
Between office IT and the control level, many plants have a connection that grew there: a remote maintenance path nobody switched off, a historian with two network cards, an access granted to an integrator three years ago. On paper, level 3.5 is a line; in the plant it is a list of exceptions.
We record the actual communication, passively and during operation, and set it against the intended state. Out of that comes the zone and conduit model to 62443-3-2, with a target security level per zone and a list of the transitions that actually exist.
What regularly stands out is not the missing firewall but the path that goes around it.
Security levels, and why there are three
IEC 62443 knows the protection level in three forms, and telling them apart decides whether a zone model holds.
| Abbreviation | What it denotes | Who sets it |
|---|---|---|
| SL-T | The target protection level of a zone, derived from the risk | The operator, in the zone model |
| SL-C | The level a component can achieve on its own | The manufacturer, in the data sheet |
| SL-A | The level actually reached in the installed plant | Shows up in testing |
What matters is the gap between SL-T and SL-A. That gap is the actual work. Where a component does not reach the required level, either a measure in the network closes it or it is documented and accepted as residual risk. Both are permissible, only staying silent about it is not.
Which part of 62443 applies to whom
The series is extensive. For an operator four parts decide it.
62443-2-1: the programme
What the operator has to build organisationally. Responsibilities, change and patch procedures, dealing with suppliers. The part that most resembles an ISMS and overlaps with NIS2.
62443-3-2: the zones
Risk analysis and the division of the plant into zones and conduits, each with a target security level. This is the part that means architecture and not only documentation.
62443-2-4: the service providers
What an integrator or service provider has to bring along. An operator needs this part because it is what tenders and offer comparisons are written against. 62443-4-2 comes in as soon as individual components are procured.
62443-3-3: the requirements
What a system has to be capable of in order to reach a security level. This is where it shows whether a controller from 2009 can carry the target at all, or whether the compensation has to lie in the zone around it.
Which requirement is evidenced by what
Compliance rarely fails on willingness and often on the mapping. This table records what is required, what it means in a plant, what evidences it and who delivers it.
| Requirement | In the plant that means | Evidenced by | Delivered by |
|---|---|---|---|
| NIS2 applicability check | Establishing whether sector, size and turnover cover the entity | The documented classification, kept by the company | Legal, we supply the technical side through our NIS2 consulting |
| Registration with the BSI | The entity registers and names a point of contact | Registration confirmation, named person | Company |
| Risk management under § 30 BSIG | A risk analysis that includes the plant and not only the office IT | Risk register with ratings and measures | Assessment |
| Network segmentation | The plant is divided into zones, the crossings are named and controlled | Zone and conduit model to IEC 62443-3-2 | Compliance advice, on the basis of the assessment |
| An appropriate protection level | A target protection level per zone, derived from the risk | SL-T per zone, with reasoning | Compliance advice |
| Attack detection under § 31 BSIG | Reading at the crossings, rules on top, a documented response | Sensors, use cases, playbooks, evaluations from operation | OT SOC |
| Duty to evidence | Showing the BSI every three years that the measures work | The documentation of the points above, brought together | Company, we supply the parts |
| Duty to report | A significant incident is reported within the statutory deadlines | Reporting routes, responsibilities, a practised procedure | Crisis exercise |
| Staff training | Whoever operates the plant knows the attack paths against it | Certificates of attendance, contents, interval | OT Security Training |
The paragraph references are to the BSIG as amended by the NIS2 implementation act, in force since 6 December 2025, alongside the KRITIS umbrella act with its duties on physical protection. Deadlines and thresholds depend on the individual case and belong in a legal review rather than on a service page.
From the survey to the zone model
Four steps, with no intervention in the process.
Passive capture
Capture at the handover points, evaluation of the protocols that actually run: IEC 60870-5-104, IEC 61850 with MMS and GOOSE, Modbus, DNP3, OPC UA. No active scan in the production network.
Plant and communication picture
Which devices speak to which, in which direction, how often. Only from that does it become visible which boundaries already exist and which are merely asserted.
Zones and conduits
Division by protection requirement and function, a target security level per zone, and for every transition the question of what it has to carry and what it permits today.
Measures in order
Separated into immediate, next maintenance window, and capital planning. A plant cannot be rebuilt in a quarter, but it can be made safer in a sensible order.
From plants, not from reading standards
Our zone models come out of the same work as our penetration tests and our OT monitoring: substations, control rooms, power plant environments and interlocking landscapes. What we find there in the way of transitions flows back into the question of which zone boundary holds in practice.
Our own research comes on top. Our lab holds real controllers, and in the demonstrators YekTrain, YekCar and YekCity we try attacks and detection on rigs that cost nobody their operation.
Common questions about OT compliance
For operators the usual route is an evidenced programme to 62443-2-1 and a reasoned zone model to 3-2. We prepare both, but we do not audit what we have advised on.
NIS2 says you have to manage risks. 62443 says what that looks like in an automation environment. For operators of critical infrastructure, 62443 is the most workable way to evidence the state of the art.
No. The survey runs passively over mirror ports and captures. Active tests we do only on spare or lab rigs, or in agreed windows with abort criteria fixed beforehand.
That is the normal case and no reason to stop. If a device cannot carry a security level itself, the zone has to carry it. That is exactly what the model is for: it allows old technology to keep running and still lets you explain why that is defensible.
Certifications and memberships.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.