---
title: "ISA/IEC 62443 Guide: Zones, Conduits and Securi… | Firevault"
description: "A practical guide to ISA/IEC 62443 for asset owners: how the series is structured, how zones and conduits are defined, what Security Levels mean, and how the…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/iec-62443-guide#webpage",
      "url": "https://fire-vault.com/learn/guides/iec-62443-guide",
      "name": "ISA/IEC 62443 Guide: Zones, Conduits and Securi…",
      "description": "A practical guide to ISA/IEC 62443 for asset owners: how the series is structured, how zones and conduits are defined, what Security Levels mean, and how the…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/iec-62443-guide.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/iec-62443-guide#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/iec-62443-guide#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "ISA/IEC 62443 Guide: Zones, Conduits and Security Levels in Practice",
          "item": "https://fire-vault.com/learn/guides/iec-62443-guide"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "ISA/IEC 62443 Guide: Zones, Conduits and Security Levels in Practice",
      "description": "A practical guide to ISA/IEC 62443 for asset owners: how the series is structured, how zones and conduits are defined, what Security Levels mean, and how the standard relates to the Purdue Model.",
      "url": "https://fire-vault.com/learn/guides/iec-62443-guide",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/iec-62443-guide.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-08-28T07:21:07.084367+00:00",
      "dateModified": "2026-08-28T10:12:43.171224+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/iec-62443-guide"
      },
      "inLanguage": "en-GB",
      "articleSection": "Standards & Frameworks",
      "wordCount": 1266,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

How the series is structuredZones and conduitsSecurity Levels: what they actua…62443 and the Purdue ModelWhere 62443 programmes commonly …Foundational requirements worth …Where physical controls contributeFrequently asked questionsMore

[Guides](/learn/knowledge?filter=guides)/ Standards & Frameworks 

Standards & Frameworks · 28 August 2026 

# ISA/IEC 62443 Guide: Zones, Conduits and Security Levels in Practice

A practical guide to ISA/IEC 62443 for asset owners: how the series is structured, how zones and conduits are defined, what Security Levels mean, and how the standard relates to the Purdue Model.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

7 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fiec-62443-guide)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fiec-62443-guide&text=ISA%2FIEC%2062443%20Guide%3A%20Zones%2C%20Conduits%20and%20Security%20Levels%20in%20Practice%0A%0AA%20practical%20guide%20to%20ISA%2FIEC%2062443%20for%20asset%20owners%3A%20how%20the%20series%20is%20structured%2C%20how%20zones%20and%20conduits%20are%20defined%2C%20what%20Security%20Levels%20mean%2C%20and%20how%20the%20standard%20relates%20to%20the%20Purdue%20Model.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fiec-62443-guide)[](mailto:?subject=ISA%2FIEC%2062443%20Guide%3A%20Zones%2C%20Conduits%20and%20Security%20Levels%20in%20Practice&body=A%20practical%20guide%20to%20ISA%2FIEC%2062443%20for%20asset%20owners%3A%20how%20the%20series%20is%20structured%2C%20how%20zones%20and%20conduits%20are%20defined%2C%20what%20Security%20Levels%20mean%2C%20and%20how%20the%20standard%20relates%20to%20the%20Purdue%20Model.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fiec-62443-guide)

![ISA/IEC 62443 Guide: Zones, Conduits and Security Levels in Practice](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/iec-62443-guide.jpg)

Standards & Frameworks 

Why it matters

## What this means for organisations holding critical data

A practical guide to ISA/IEC 62443 for asset owners: how the series is structured, how zones and conduits are defined, what Security Levels mean, and how the standard relates to the Purdue Model.

**On this page**[How the series is structured](#section-0)[Zones and conduits](#section-1)[Security Levels: what they actua…](#section-2)[62443 and the Purdue Model](#section-3)[Where 62443 programmes commonly …](#section-4)[Foundational requirements worth …](#section-5)[Where physical controls contribute](#section-6)[Frequently asked questions](#section-7)

On this page

1.  [How the series is structured](#section-0)
2.  [Zones and conduits](#section-1)
3.  [Security Levels: what they actually mean](#section-2)
4.  [62443 and the Purdue Model](#section-3)
5.  [Where 62443 programmes commonly go wrong](#section-4)
6.  [Foundational requirements worth reading closely](#section-5)
7.  [Where physical controls contribute](#section-6)
8.  [Frequently asked questions](#section-7)

**Written by Mark Fermor.** ISA/[IEC 62443](/solutions/control/frameworks/iec-62443) is the international standard series for the security of industrial automation and control systems. This guide is written for asset owners who need to use it, rather than for certification bodies who audit against it.

## How the series is structured

62443 is not a single document. It is a series, organised into four groups, and knowing which group you are reading prevents most of the confusion around it.

-   **General (62443-1-x).** Concepts, terminology and models. The vocabulary the rest of the series depends on.
-   **Policies and procedures (62443-2-x).** Requirements for the asset owner's security programme, and for service providers. 62443-2-1 covers the security management system; 62443-2-4 covers requirements for IACS service providers, which is the part to cite in supplier contracts.
-   **System (62443-3-x).** 62443-3-2 covers security risk assessment and system design, and is where zones, conduits and target Security Levels are established. 62443-3-3 defines system security requirements and Security Levels.
-   **Component (62443-4-x).** 62443-4-1 covers the secure product development lifecycle; 62443-4-2 covers technical security requirements for components. These are supplier-facing, and useful for procurement questions.

A crucial structural point: the series divides responsibility between asset owners, system integrators and product suppliers. A vendor claiming their product "is 62443 compliant" is usually referring to 62443-4-1 or 4-2. That is a real and useful claim, but it does not make your installation compliant, because your obligations sit in the 2-x and 3-x documents.

## Zones and conduits

The central design idea in 62443 is that you group assets into **zones** that share security requirements, and you define every permitted communication path between zones as a **conduit** with its own requirements.

Two properties make this more rigorous than drawing boxes on a network diagram:

-   **Zones are defined by security requirement, not by geography or subnet.** Two devices in the same cabinet may belong in different zones if they carry different consequence. Conversely, a zone may span sites.
-   **Every conduit is explicit and justified.** If a path is not defined as a conduit, it should not exist. That reverses the usual default, in which paths accumulate for legitimate operational reasons and are never revisited.

62443-3-2 sets out the workflow: identify the system under consideration, perform an initial risk assessment, partition into zones and conduits, perform a detailed risk assessment for each, assign a target Security Level, document the requirements, and then design.

## Security Levels: what they actually mean

Security Levels in 62443 are defined by the capability of the adversary a zone or conduit is expected to withstand, not by how much technology has been deployed.

-   **SL 0.** No specific requirements.
-   **SL 1.** Protection against casual or coincidental violation.
-   **SL 2.** Protection against intentional violation using simple means, with low resources, generic skills and low motivation.
-   **SL 3.** Protection against intentional violation using sophisticated means, with moderate resources, IACS-specific skills and moderate motivation.
-   **SL 4.** Protection against intentional violation using sophisticated means, with extended resources, IACS-specific skills and high motivation.

The standard also distinguishes **SL-T** (the target level, set by risk assessment), **SL-C** (the capability a component or system can provide), and **SL-A** (the level actually achieved as installed and operated). The gap between SL-C and SL-A is where most real-world risk lives: capable equipment, configured or operated in a way that does not deliver the target.

Setting SL-T at 3 for a zone is a significant commitment. It implies an adversary with industrial control system expertise and moderate resources, which raises questions about remote access, supply chain, firmware provenance and recovery that SL 2 arrangements typically do not answer.

## 62443 and the Purdue Model

These two are complementary and frequently conflated. The Purdue Enterprise Reference Architecture is a functional reference model that describes where systems sit in layers, from field devices up to enterprise IT. It is not a security standard and it prescribes nothing.

62443 supplies the security constructs Purdue lacks. Purdue tells you a historian sits at Level 3 and an enterprise reporting service at Level 4. Zones and conduits tell you which security domains exist, what may cross between them, in which direction, using which protocol, under whose authority, and to what Security Level. In practice, a Purdue-style level diagram is a useful starting sketch, and zone and conduit definitions are the design artefact you actually operate against.

NIST SP 800-82 Revision 3 is worth reading alongside both. It is guidance rather than a certifiable standard, and it presents a Purdue-style architecture with a demilitarised zone as one example while referencing 62443 zones and conduits.

## Where 62443 programmes commonly go wrong

1.  **Zoning by network topology.** Reusing existing VLANs as zones bakes in the architecture you were trying to assess.
2.  **Undocumented conduits.** Engineering laptops, vendor connections, wireless links, cellular modems on skid equipment and cloud telemetry from smart devices are the paths that never appear on the diagram.
3.  **Assigning target Security Levels uniformly.** SL 3 everywhere is not conservative, it is unaffordable and therefore unimplemented.
4.  **Confusing capability with achievement.** Buying SL-C 3 components does not deliver SL-A 3.
5.  **Ignoring 62443-2-4 in procurement.** Integrators and maintainers hold privileged access, and their obligations must be contractual.
6.  **Treating recovery as out of scope.** If a zone is compromised, the question of where the known-good configurations, project files and firmware images live becomes the whole recovery timeline.

## Foundational requirements worth reading closely

62443-3-3 organises system requirements under seven foundational requirements: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability. For asset owners with an ageing estate, restricted data flow and resource availability tend to drive the most architectural change, because they are the requirements least likely to be satisfiable at the endpoint and most likely to require boundary design.

## Where physical controls contribute

Restricted data flow is the requirement family where physical measures deserve explicit consideration. A conduit that is only required occasionally, for maintenance, data extraction or recovery, does not necessarily need to exist as a standing connection. Whether that is appropriate is a safety, availability and process question first, and never a security preference.

Firevault works on two specific questions raised by that analysis. **Control by Firevault** is a suite of nine purpose-built tools and techniques that give an organisation physical control over the paths into and across its estate, applied through Blueprints that treat a specific risk. Where a conduit is periodic or exceptional, that allows the state of the path itself to be governed and evidenced, alongside rather than instead of firewalling, authentication, protocol restriction and monitoring. **[Offline Secure Storage](/offline-secure-storage)®** addresses the recovery side, holding known-good configurations, engineering files and project data on storage that is physically disconnected when not in use, so that a recovery copy does not share a reachable failure domain with the zone it may be required to restore.

Neither is a route to a Security Level. Security Levels are achieved by a documented risk assessment, a designed set of zones and conduits, and demonstrable operation.

## Frequently asked questions

### Can an organisation be certified to 62443?

Certification schemes exist for products, for development processes under 62443-4-1, and for asset owner security programmes under 62443-2-1. There is no single certificate covering an entire operating site.

### Is 62443 only for manufacturing?

No. It applies to industrial automation and control systems generally, including utilities, transport, buildings and process industries.

### Does 62443 replace the Purdue Model?

They answer different questions. Purdue describes functional layers; 62443 defines security domains, permitted communication and required rigour.

### Do we need SL 3?

Only where the risk assessment justifies an adversary with IACS-specific skills and moderate resources. Set target levels per zone, and be prepared to fund what you set.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### MITRE ATT&CK Guide: Mapping Controls to Real Adversary Behaviour
    
    How to use MITRE ATT&CK properly: tactics, techniques and sub-techniques, the Enterprise and ICS matrices, coverage mapping without self-deception, and why version changes matter.
    
    Read guide ](/learn/guides/mitre-attack-mapping-guide)
-   [
    
    ### NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence
    
    A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.
    
    Read guide ](/learn/guides/ncsc-caf-guide)
-   [
    
    ### NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence
    
    A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.
    
    Read guide ](/learn/guides/nist-csf-2-0-guide)

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up