Skip to main content

Overview

IEC 62443 is the international standard series for security in Industrial Automation and Control Systems (IACS). It defines security requirements for operators (asset owners), system integrators, and product suppliers across operational technology (OT) environments - including SCADA systems, PLCs, DCS, and industrial networking equipment. IEC 62443 is directly referenced in NIS2 for operators of essential services with OT/ICS infrastructure, and in national regulations across the EU, US, and Asia-Pacific for critical infrastructure sectors. A core requirement across multiple IEC 62443 parts is data integrity - ensuring that sensor readings, control commands, operational events, and audit logs have not been tampered with between generation and analysis. This is precisely the problem ROOTKey is designed to solve.

Standard Structure and Coverage

IEC 62443 is structured as a series of parts, grouped into four series:

Security Requirements Coverage

IEC 62443-3-3: System Security Requirements and Security Levels

The most operationally relevant part for asset owners. Security Requirements (SR) addressed by ROOTKey:

IEC 62443-2-1: Security Management System


OT Deployment Architecture

IEC 62443 requirements apply to environments where installing new software on devices is often not possible, and where network changes carry significant operational risk. ROOTKey’s MQTT-based deployment is designed specifically for this constraint:

No device modification required

Devices publish to their existing MQTT topics. ROOTKey’s bridge subscribes at the OT/IT boundary - devices are unaware of anchoring.

OT network isolation preserved

The bridge handles outbound connectivity at the defined OT/IT boundary - no new network paths into the OT zone required.

No latency impact

Anchoring is asynchronous - device operation and response times are unaffected.

Protocol native

MQTT is the native protocol of most OT environments - no protocol translation required in the OT zone.
→ See also: MQTT Deployment Guide · IoT & Industrial use case

Security Level Coverage

IEC 62443 defines Security Levels (SL 1–4) based on the sophistication of the threat actor being defended against. ROOTKey’s data integrity layer supports:

Applicable Sectors


Request an OT integration consultation

Our team will assess your OT topology, MQTT infrastructure, and IEC 62443 scope - and design a ROOTKey integration that fits without disruption.

IoT & Industrial use case

Full implementation guide for IEC 62443-aligned OT data integrity anchoring.