Trust & Compliance / IEC 62443
IEC 62443
Protect OT data across every zone and conduit.
IEC 62443 is the international series of standards for securing industrial automation and control systems (IACS). XQ supports its system requirements at the data layer: every telemetry record, file and command is encrypted at creation, only verified users and devices can open it, and every access is logged — so data stays protected as it crosses zones, conduits and the IT/OT boundary.
Built for Asset owners in energy, utilities, water and manufacturing · OT integrators and service providers (IEC 62443-2-4) · Suppliers building IACS components (IEC 62443-4-2)
At a glance
StandardISA/IEC 62443 series for IACS security
Key parts3-3 (systems), 4-2 (components), 2-4 (service providers)
Security levelsSL 1 to SL 4, set per zone and conduit
XQ coversIdentification, use control, integrity, confidentiality, monitoring
Works with SCADA and historians · Edge gateways · AWS · Azure · On-premises · SIEM tools
Segment at the data layer
Each data object carries its own access policy, so protection holds even where network segmentation is hard to maintain.
Connect OT to the cloud safely
Move plant data to cloud analytics and support secure remote access without exposing it in transit or at rest.
Show the evidence
Audit logs record who accessed which data, when and where — ready for assessments and incident response.
What IEC 62443 requires
IEC 62443 splits responsibility between asset owners, service providers and product suppliers. It divides a system into zones (groups of assets with the same security needs) and conduits (the communication paths between them), and assigns each a target security level from SL 1 (casual violation) to SL 4 (sophisticated, well-resourced attack).
- Seven foundational requirements: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability.
- IEC 62443-3-3 sets the system requirements (SRs) an IACS must meet for each security level.
- IEC 62443-4-2 sets the matching component requirements (CRs) for devices, host and embedded software.
- IEC 62443-2-4 sets security program requirements for integration and maintenance service providers.
How XQ maps to IEC 62443-3-3
| System requirement | How XQ helps |
|---|---|
| SR 1.1 / SR 1.2 — Human user, and software process and device, identification and authentication | XQ verifies identity through your identity provider, multi-factor authentication or device certificates before it releases any key — including for IoT and edge endpoints. |
| SR 2.1 — Authorization enforcement | Role- and policy-based decryption enforces least privilege on every data object, and access can be revoked in real time. |
| SR 2.8 / SR 6.1 — Auditable events and audit log accessibility | Every encryption, decryption and access attempt is logged with user, data and time, and can be exported to your SIEM. |
| SR 3.1 — Communication integrity | Data is encrypted end to end, so tampering or interception in transit is prevented or detectable. |
| SR 4.1 / SR 4.3 — Information confidentiality and use of cryptography | Data is encrypted at creation, in transit and at rest with unique per-object keys managed outside the device, and keys can rotate with each transmission. |
| SR 5.1 / SR 5.2 — Network segmentation and zone boundary protection | XQ complements network segmentation: data that crosses a conduit stays encrypted and policy-bound, so a breach of one zone does not expose data from another. |
| SR 6.2 — Continuous monitoring | Real-time tracking of data flows and access patterns flags unusual access or modification for faster response. |
Want to see what XQ would protect in your OT environment?
Suppliers and service providers
Component suppliers can add object-level encryption and key management to their products with XQ’s APIs and SDKs, supporting the confidentiality and integrity requirements of IEC 62443-4-2. Integrators and service providers working under IEC 62443-2-4 can enforce data-access policy automatically and keep control of the keys even when data is shared with third parties.
Data segmentation beyond the Purdue model
Traditional OT security relies on network layers and firewalls between them. XQ protects the data itself, so it stays governed as it moves from sensors to historians, the enterprise network and the cloud — and a compromised device can be cut off from keys without anyone touching the plant floor.
Related resources and articles
FAQ
IEC 62443, answered directly.
What is IEC 62443?
IEC 62443 is a series of international standards for the cybersecurity of industrial automation and control systems. It sets requirements for asset owners, service providers and product suppliers, and uses zones, conduits and security levels to match protection to risk.
How does XQ help meet IEC 62443-3-3?
XQ supports the identification, authorization, integrity, confidentiality, audit and monitoring system requirements at the data layer: data is encrypted with unique keys, only verified users and devices can decrypt it, and every access is logged.
Does XQ replace network segmentation?
No. XQ complements zones and conduits by protecting the data itself, so it stays encrypted and policy-bound when it crosses a zone boundary or leaves the plant for the cloud.
Can suppliers build XQ into IACS components?
Yes. XQ’s APIs and SDKs let component suppliers add object-level encryption and key management to devices and software, supporting IEC 62443-4-2 confidentiality and integrity requirements.
Can XQ cut off a compromised OT device?
Yes. Every key is released by policy, so a compromised device can be denied keys in real time and can no longer read protected data — without anyone touching the plant floor.
Secure OT data without slowing operations.
Get an operational assessment of your IT/OT data flows and where XQ fits in your IEC 62443 program.