← Back to blog
Fundamentals

IEC 62443 Security Levels Are Not a Number

Most OT programs set a target security level and stop there. The standard asks for three levels, and the gap between two of them is where the real work is.

Ask a plant what IEC 62443 security level they are at and you will usually get a single number. "We are SL 2." That answer is where most OT security programs quietly go wrong, because the standard does not define one level. It defines three, and they answer different questions.

The Target level, SL-T, is what a zone needs. It comes from risk: what you are protecting, what happens if it is compromised, and who is likely to try. The Capability level, SL-C, is what your devices and architecture are designed to reach. The Achieved level, SL-A, is what is actually in place right now, after configuration drift, unpatched firmware, shared passwords, and the remote access path someone opened for a vendor in 2023.

A program that only names its SL-T has set a goal and never measured against it. The work is in the gap between SL-T and SL-A, and closing that gap honestly is the whole point of the standard.

Cesar Giraldo, our founder, put the full method on one page: the eight steps from risk assessment to verification, an example zoned OT environment, where capability actually comes from, and the controls that close gaps in practice.

Read the full guide: IEC 62443: From Security Levels to Real OT Security

If you are not sure what your SL-A actually is, that is the conversation we have on site, zone by zone. Schedule a call.

Ready to see your OT network as it actually is?

A per-plant OT Topology Assessment returns documented topology — asset inventory, network segmentation evidence, and security-level capability mapping — delivered to a named owner on your team.