Overview
IEC TS 62443-6-1:2024 defines a security evaluation methodology to assess conformity to IEC 62443-2-4 requirements. It provides a structured approach to achieve repeatable and reproducible evaluation results for security programs of Industrial Automation and Control Systems (IACS) service providers. The Technical Specification is intended for first‑party, second‑party and third‑party conformity assessment activities (e.g., product suppliers, service providers, asset owners, conformity assessment bodies).
Keywords: IEC TS 62443-6-1:2024, security evaluation methodology, IEC 62443-2-4, IACS, conformity assessment, security program.
Key Topics
- Scope and purpose: Establishes evaluation steps and evidence expectations to support conformity assessment against IEC 62443-2-4 (security program requirements for IACS service providers).
- Scoping the Subject under Evaluation (SuE): Defines minimum scope information required to start an evaluation (security program, processes, projects, or systems under review).
- Conformity statements and conformance evidence: Guidance on what a conformity statement should contain and examples of acceptable evidence.
- Evaluation process: Systematic methodology covering examination, verification and judgement to generate repeatable verdicts.
- Maturity Levels (ML 1–ML 4): Evaluation criteria and examples of evidence tailored to each maturity level; Clause 5.4 addresses particular requirements for ML‑4.
- Table of evaluation criteria (Table 1): Cross-references requirements to acceptable evaluation criteria and example conformance evidence.
- Terminology and artifacts: Definitions and abbreviations used (e.g., EoE - evidence of existence, PoE - proof of execution, KPI).
Applications
- Service providers: Use the methodology to prepare and demonstrate their security program conformity to IEC 62443-2-4 during bids, audits or certifications.
- Asset owners/operators: Evaluate or audit third‑party service providers’ security programs consistently and objectively.
- Conformity assessment bodies / auditors: Apply the standardized evaluation steps and Table 1 to produce repeatable assessment results.
- Integrators and maintenance teams: Align internal processes and evidence collection (EoE, PoE, KPIs) with the expectations described to meet client requirements.
Practical value: enables consistent, reproducible assessments; clarifies evidence types; supports maturity-based benchmarking and continuous improvement of IACS security programs.
Related Standards
- IEC 62443-2-4:2015 (including AMD1:2017) - normative reference for security program requirements.
- Other parts of the IEC 62443 series - broader guidance on IACS security.
- ISO/IEC 17000 - definitions for conformity assessment terminology referenced in this TS.
For implementers and evaluators, IEC TS 62443-6-1:2024 is a practical companion to IEC 62443-2-4 that standardizes how security programs are scoped, evidenced and judged across ML 1–ML 4.