Skip to main content

IEC 62443 in the plant, not in a binder

Zones and conduits derived from the communication that actually runs. With a target security level per zone and an order of work that fits maintenance windows.

Zone and conduit model to IEC 62443-3-2 Five levels whose transitions are assessed one by one: verified, incomplete, or not present at all. L4 OFFICE IT L3.5 DMZ L3 OPERATIONS L2 SCADA · HMI L1/0 PLC · FIELD IEC 62443 · ZONES AND CONDUITS
Trusted by
The starting position

A zone concept is a statement about the plant

A zone model can be drawn at a desk, but it only holds once it matches the connections that are actually open. The test of it is two questions. Which paths run today between the office network and the control level? Are they all in the concept?

The standard is awkwardly concrete on this point. A zone model to 62443-3-2 is a statement about the architecture: which parts of the plant share a security level, where the boundary runs, and what may cross it. That cannot be written without knowing the plant.

Underneath there is usually a Purdue model, the division into levels from the field up to the office network. It orders the plant, but it does not replace a zone model. Purdue describes levels, 62443 asks for zones with a security level and named crossings. Two parts of a plant on the same Purdue level can belong to different zones.

So we start with the communication that really runs, and not with the network plan that ought to hold.

Boundaries

What we do not do

  • No audit. We prepare for an assessment, we do not carry it out. Anyone offering both ends up auditing their own advice.
  • No certification. That is issued by an accredited body, and we are not one.
  • No legal advice. Whether your company is affected and which deadlines apply is for your legal department. We say what stands behind it technically.
The core

Zones and transitions as they really run

Zone and conduit model to IEC 62443-3-2 Five levels whose transitions are assessed one by one: verified, incomplete, or not present at all. L4 OFFICE IT L3.5 DMZ L3 OPERATIONS L2 SCADA · HMI L1/0 PLC · FIELD IEC 62443 · ZONES AND CONDUITS

Between office IT and the control level, many plants have a connection that grew there: a remote maintenance path nobody switched off, a historian with two network cards, an access granted to an integrator three years ago. On paper, level 3.5 is a line; in the plant it is a list of exceptions.

We record the actual communication, passively and during operation, and set it against the intended state. Out of that comes the zone and conduit model to 62443-3-2, with a target security level per zone and a list of the transitions that actually exist.

What regularly stands out is not the missing firewall but the path that goes around it.

Protection level

Security levels, and why there are three

IEC 62443 knows the protection level in three forms, and telling them apart decides whether a zone model holds.

AbbreviationWhat it denotesWho sets it
SL-TThe target protection level of a zone, derived from the riskThe operator, in the zone model
SL-CThe level a component can achieve on its ownThe manufacturer, in the data sheet
SL-AThe level actually reached in the installed plantShows up in testing

What matters is the gap between SL-T and SL-A. That gap is the actual work. Where a component does not reach the required level, either a measure in the network closes it or it is documented and accepted as residual risk. Both are permissible, only staying silent about it is not.

The four parts that count

Which part of 62443 applies to whom

The series is extensive. For an operator four parts decide it.

62443-2-1: the programme

What the operator has to build organisationally. Responsibilities, change and patch procedures, dealing with suppliers. The part that most resembles an ISMS and overlaps with NIS2.

62443-3-2: the zones

Risk analysis and the division of the plant into zones and conduits, each with a target security level. This is the part that means architecture and not only documentation.

62443-2-4: the service providers

What an integrator or service provider has to bring along. An operator needs this part because it is what tenders and offer comparisons are written against. 62443-4-2 comes in as soon as individual components are procured.

62443-3-3: the requirements

What a system has to be capable of in order to reach a security level. This is where it shows whether a controller from 2009 can carry the target at all, or whether the compensation has to lie in the zone around it.

The mapping

Which requirement is evidenced by what

Compliance rarely fails on willingness and often on the mapping. This table records what is required, what it means in a plant, what evidences it and who delivers it.

RequirementIn the plant that meansEvidenced byDelivered by
NIS2 applicability checkEstablishing whether sector, size and turnover cover the entityThe documented classification, kept by the companyLegal, we supply the technical side through our NIS2 consulting
Registration with the BSIThe entity registers and names a point of contactRegistration confirmation, named personCompany
Risk management under § 30 BSIGA risk analysis that includes the plant and not only the office ITRisk register with ratings and measuresAssessment
Network segmentationThe plant is divided into zones, the crossings are named and controlledZone and conduit model to IEC 62443-3-2Compliance advice, on the basis of the assessment
An appropriate protection levelA target protection level per zone, derived from the riskSL-T per zone, with reasoningCompliance advice
Attack detection under § 31 BSIGReading at the crossings, rules on top, a documented responseSensors, use cases, playbooks, evaluations from operationOT SOC
Duty to evidenceShowing the BSI every three years that the measures workThe documentation of the points above, brought togetherCompany, we supply the parts
Duty to reportA significant incident is reported within the statutory deadlinesReporting routes, responsibilities, a practised procedureCrisis exercise
Staff trainingWhoever operates the plant knows the attack paths against itCertificates of attendance, contents, intervalOT Security Training

The paragraph references are to the BSIG as amended by the NIS2 implementation act, in force since 6 December 2025, alongside the KRITIS umbrella act with its duties on physical protection. Deadlines and thresholds depend on the individual case and belong in a legal review rather than on a service page.

Approach

From the survey to the zone model

Four steps, with no intervention in the process.

1

Passive capture

Capture at the handover points, evaluation of the protocols that actually run: IEC 60870-5-104, IEC 61850 with MMS and GOOSE, Modbus, DNP3, OPC UA. No active scan in the production network.

2

Plant and communication picture

Which devices speak to which, in which direction, how often. Only from that does it become visible which boundaries already exist and which are merely asserted.

3

Zones and conduits

Division by protection requirement and function, a target security level per zone, and for every transition the question of what it has to carry and what it permits today.

4

Measures in order

Separated into immediate, next maintenance window, and capital planning. A plant cannot be rebuilt in a quarter, but it can be made safer in a sensible order.

Where this comes from

From plants, not from reading standards

Our zone models come out of the same work as our penetration tests and our OT monitoring: substations, control rooms, power plant environments and interlocking landscapes. What we find there in the way of transitions flows back into the question of which zone boundary holds in practice.

Our own research comes on top. Our lab holds real controllers, and in the demonstrators YekTrain, YekCar and YekCity we try attacks and detection on rigs that cost nobody their operation.

Common questions

Common questions about OT compliance

For operators the usual route is an evidenced programme to 62443-2-1 and a reasoned zone model to 3-2. We prepare both, but we do not audit what we have advised on.

NIS2 says you have to manage risks. 62443 says what that looks like in an automation environment. For operators of critical infrastructure, 62443 is the most workable way to evidence the state of the art.

No. The survey runs passively over mirror ports and captures. Active tests we do only on spare or lab rigs, or in agreed windows with abort criteria fixed beforehand.

That is the normal case and no reason to stop. If a device cannot carry a security level itself, the zone has to carry it. That is exactly what the model is for: it allows old technology to keep running and still lets you explain why that is defensible.

Credentials

Certifications and memberships.

Certifications held in the team
Memberships
Next step

Talk to us.

A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Location
Dortmund
Ruhrallee 9 · 44139