Why a generic security certification is the wrong question on a plant floor
When selecting support for a plant or control environment, examine the work and its operational consequences alongside general security assurance. An IT certificate may be relevant, but its scope alone may not address the industrial system, engineering role or safety constraints involved. ISA: the ISA/IEC 62443 series and its component parts
What IEC 62443 actually covers
IEC 62443 is a series of standards specifically for industrial automation and control system security, developed to address the reality that a factory floor or a utility’s control environment cannot be secured the same way as an office network. It covers system design, component-level security requirements, and the operational processes needed to maintain security in an environment where uptime, safety and physical consequences carry a different weight than they do in a typical IT setting.
A general IT security certification does not, by itself, establish competence for a particular industrial system. Check the certified scope alongside operational experience, change controls and the safety constraints of the proposed work.
What to ask a prospective OT partner, specifically
Ask which parts of IEC 62443 their work aligns to — the standard covers different roles (asset owners, system integrators, product suppliers) and different levels of security assurance, and a credible partner should be able to name which parts apply to what they are proposing to do for you, rather than citing the standard as a general badge.
Ask how they handle the IT/OT boundary in practice — not as a policy statement, but as an operational question: how do they propose to make changes, patch, or monitor without introducing the downtime or safety risk that generic IT practices would create in this environment.
Ask how segmentation and remote access will be assessed without disrupting operations. Require the proposed method, authorisation boundaries and recovery plan; neither an IT background nor an OT label alone demonstrates that the approach is suitable.
Depending on the requirement, not the badge
A certification is a starting signal, not a substitute for scoping the actual requirement. Depending on your environment and the work in question, the right next step is usually a dependency map that identifies where OT and IT boundaries actually sit before any partner’s specific capability is evaluated against it.
Match the proposed role to evidence
ISA/IEC 62443 is a standards series, not a single badge. The following part-to-role guide is a starting point; confirm the edition, certification scheme and actual scope before relying on a claim. ISA: the ISA/IEC 62443 series and its component parts
- Asset-owner security programme: examine the relevance of IEC 62443-2-1. Ask who owns the programme after the engagement and how site operations will maintain the required processes. A project handover should identify the continuing responsibilities.
- Integration or maintenance service: examine IEC 62443-2-4. Request the service scope and a sample method statement showing how engineering changes, remote work and personnel responsibilities will be controlled for this site.
- System assessment and design: examine IEC 62443-3-2 for risk assessment and IEC 62443-3-3 for system requirements. Ask for traceability from the operational risk assessment to proposed zones, conduits and acceptance criteria.
- Product development and components: distinguish IEC 62443-4-1 development-lifecycle evidence from IEC 62443-4-2 component requirements. A development-process certificate does not certify every deployed system that contains the supplier’s product.
- Operational acceptance: agree the permitted environment, maintenance window, stop authority, rollback evidence and unresolved limitations. Check any certificate with the issuer and distinguish organisational certification from an individual’s course completion.
Use a short design review before commissioning field work. Present one real dependency, such as a vendor maintenance connection, and ask the candidate to explain how it will be assessed and handed back safely. Judge the documented method and its fit to the site rather than asking for confidential client reports or accepting an unsupported claim of experience.

