IEC 62443-3-3

IEC 62443-3-3 defines system security requirements for industrial automation and control systems. XIRIQ covers its requirement set as a gap assessment.

Requirements covered

The assessment presents 51 system requirements, grouped under the standard's seven foundational requirements (identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, resource availability). Requirement wording is paraphrased for assessment support; verify against the standard itself before formal use.

SL-T scoping

On Setup you choose a target security level, SL-T 1 to 3, for the system under assessment. The requirement list is scoped to it: requirements that only apply at higher security levels drop out of scope at lower SL-T, so you are never asked to assess controls the standard does not expect of your target level. Changing SL-T rescopes the list; answers you have already given are kept.

Example
The SL-T choice on Setup for IEC 62443 assessments, with SL-T 2 selected.

Status vocabulary

62443 items are judged implemented, partially implemented or not implemented, with not-relevant available for requirements that genuinely do not apply (a reason is required). This differs deliberately from CAF vocabulary: 62443 assesses whether a control exists, while the CAF judges whether an outcome is achieved.

Can't find what you need? Browse the Resources articles or use the feedback button inside the app.