AS IEC 62443 is now Australia's national OT cyber standard. Here is what that actually means.
Standards Australia has adopted the IEC 62443 series as the national reference for protecting operational technology and industrial control environments. For SOCI Act responsible entities, mining operations, utilities, water, energy and critical manufacturing, this is the standard your CIRMP will increasingly be measured against.
This page summarises the structure of the standard, the parts most Australian operators should start with, and how 62443 maps to the CIRMP obligations under the Security of Critical Infrastructure Act 2018.
Adopted by Standards Australia
AS IEC 62443 series
OT and ICS scope
Plant, SCADA, PLCs, RTUs, historians
SOCI CIRMP aligned
Cyber and information security hazard
Before this adoption, Australian operators referenced an international standard. After it, they reference an Australian one.
The substantive engineering content of IEC 62443 has not changed. What has changed is the contractual and regulatory weight it now carries inside Australia. AS IEC 62443 can be referenced directly in procurement specifications, integrator agreements, SOCI CIRMP attestations and APRA-regulated supply chain reviews without the friction of citing a foreign standards body.
For operators of energy networks, water and wastewater plants, mining sites, telecommunications infrastructure and food processing facilities, this is the standard your auditors, insurers and regulators will increasingly expect to see referenced in your control system risk documentation.
Four parts. Different audiences.
AS IEC 62443 is a series, not a single document. Each part targets a different role in the industrial automation ecosystem. Asset owners (you) live mostly in parts 2 and 3. Product vendors live in part 4. Integrators sit across 2 and 4.
Concepts, terminology and models
Foundational language. Defines the zones and conduits model, security levels (SL-1 to SL-4), and the asset owner / system integrator / product supplier roles every later part of the standard references.
Policies and procedures for asset owners
Where most Australian operators start. Cyber security management system requirements (62443-2-1), patch management (62443-2-3), and security programme requirements for service providers (62443-2-4).
System-level requirements
Risk assessment for system design (62443-3-2) and the seven foundational system security requirements (62443-3-3). This is the part procurement teams cite in tender responses.
Component-level requirements
Secure development lifecycle requirements for product suppliers (62443-4-1) and component-level technical requirements (62443-4-2). The reference vendors increasingly cite to claim certified products.
How 62443 maps to your CIRMP obligations.
Responsible entities under the Security of Critical Infrastructure Act 2018 must adopt and maintain a Critical Infrastructure Risk Management Program. The cyber and information security hazard is one of four hazard categories. AS IEC 62443 is the cleanest way to evidence the technical control side of that hazard for OT environments.
Cyber and information security hazard
AS IEC 62443-2-1 cyber security management system
Both require a documented, risk-based programme covering identification, protection, detection, response and recovery for operational assets.
Material risk register and tolerance levels
AS IEC 62443-3-2 zones, conduits, target security levels
The SOCI CIRMP risk register becomes far more credible when underpinned by zone-conduit segmentation and quantified target security levels per zone.
Annual board attestation
AS IEC 62443-2-1 management review and continuous improvement
62443-2-1 already requires a documented management review cycle. Boards can attest against the same review with one shared evidence pack.
Critical worker and supply chain provisions
AS IEC 62443-2-4 security programme requirements for service providers
62443-2-4 sets contractual expectations for the integrators and managed service providers operating inside your environment. Directly maps to SOCI supply chain expectations.
A six-step pathway most Australian operators follow.
You do not implement 62443 in one project. You implement the management system first, then the zone-conduit model, then the technical control gap, then the integrator and supplier alignment. The pathway below is the order we use on Australian mine sites, water utilities and critical manufacturing.
Asset and zone inventory
Document every PLC, RTU, HMI, historian, jump host, engineering workstation and SCADA server. Group them into zones with shared trust boundaries (process control, supervisory, DMZ, enterprise). This is the foundation for everything downstream.
Risk assessment (62443-3-2)
For each zone, run the IEC risk assessment process: identify threats, score impact and likelihood, set a target security level (SL-T). Capture the residual risk decisions and route them to the operational risk register.
Foundational requirements (62443-3-3)
Walk each zone against the seven foundational requirements: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability. Gap analysis becomes the remediation plan.
Conduits and segmentation
Implement enforced segmentation between zones using industrial firewalls, data diodes where unidirectional flow is acceptable, and audited jump hosts. No flat OT networks. No shared IT/OT VLANs.
Supplier and integrator alignment
Update procurement and managed services contracts to reference 62443-2-4 for service providers and 62443-4-1 for product suppliers. Make supplier evidence part of the CIRMP register.
Continuous improvement
62443-2-1 is a management system standard. Set a review cadence (quarterly operational, annual board) and feed incident learnings, audit findings and threat intelligence back into the zone risk assessments.
The engineering work behind a credible 62443 programme.
We do not write the policies and walk away. The pieces below are the engineering and operational work we run alongside your control system integrators, plant managers and risk teams.
Zone and conduit design
We document your current OT topology, define zone boundaries, and design the conduits that connect them. Output is the architecture artefact that supports both CIRMP and 62443-3-2 evidence.
62443-3-3 control mapping
Workshop-based gap assessment against the seven foundational requirements per zone. We produce a remediation plan with owners, target security levels and operational sequencing.
OT segmentation and monitoring
We engineer the segmentation (industrial firewalls, jump hosts, asset-aware monitoring) and integrate it into the same operations centre we run for your IT side. One pane of glass for incidents.
Evidence pack for boards and auditors
A combined CIRMP / 62443 evidence pack. Zone diagrams, risk register, control test results, integrator attestations, and a management review record. Ready for board attestation and APRA, ASD or DRBP enquiry.
This page is general guidance for operators and is not legal advice. AS IEC 62443 implementation should be scoped against your specific operational environment, regulatory obligations and contractual commitments.
The questions operators ask us about 62443.
Is AS IEC 62443 mandatory in Australia?
Not in itself. AS IEC 62443 is a voluntary national standard adopted by Standards Australia. It becomes effectively mandatory when it sits inside a contract (procurement specifications, integrator agreements) or when a regulator references it as the expected baseline for cyber and information security hazards. For SOCI Act responsible entities running a CIRMP, 62443 is the cleanest engineering-grade evidence of operational technology security controls.
How does AS IEC 62443 differ from Essential Eight?
Essential Eight is an IT mitigation framework for Microsoft-led corporate environments. AS IEC 62443 is an OT security framework for industrial automation and control systems. They are complementary, not competing. Run Essential Eight on the corporate environment, 62443 on the plant, and explicitly engineer the conduits between them with audited jump hosts and unidirectional gateways where appropriate.
Which part of 62443 should we start with?
Most Australian operators start with 62443-2-1 (the management system) and 62443-3-2 (the risk assessment process). Together they establish the governance and the zoning model that every later technical requirement is scoped against. Component-level work (62443-4-x) is usually a supplier conversation rather than your own first move.
Do we need to be certified to 62443?
Certification is available for products (62443-4-x), system integrators (62443-2-4) and asset owners (62443-2-1) through schemes like IECEE CB and ISASecure. Most Australian operators do not pursue formal certification at the asset owner level. Instead they document conformance through their CIRMP, integrator contracts, and the management review cycle. Certification matters most for vendors selling into critical infrastructure tenders.
How does 62443 relate to ISO 27001?
ISO 27001 is an information security management system for the whole organisation. AS IEC 62443-2-1 is a more specific management system targeted at industrial control environments. If you already operate an ISO 27001 ISMS, treat 62443-2-1 as the OT extension and integrate the document set rather than running parallel systems.
What does Real Bytes deliver against 62443?
Zone and conduit design, 62443-3-3 foundational requirement gap assessments, OT segmentation engineering, asset-aware monitoring tied into our operations centre, and the evidence pack that supports CIRMP attestation. We deliver this jointly with your control system integrator where one is engaged, and we work to the operational change windows of the plant, not the IT helpdesk calendar.
Related in this cluster
Other operational and regulatory pages for Australian businesses.
From standard to operating posture
Run AS IEC 62443 with engineers who already operate OT in Australia.
Real Bytes runs zone and conduit design, 62443-3-3 gap assessments, OT segmentation engineering and the management review cadence that keeps the programme alive. We work jointly with your control system integrator and to the change windows of the plant.
This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.

Remote Support