OT Security Compliance: IEC 62443, NIST 800-82, and NERC CIP Explained
The three frameworks that govern industrial cybersecurity, what each one covers, who must comply, and how they fit together, written for anyone preparing for an OT or GRC certification.
Compliance is where OT security gets funded
Engineers secure OT because a compromised process can hurt people. Organisations *fund* OT security because a framework, an auditor, or a regulator requires it. Understanding the three frameworks below is therefore both a technical and a career skill: they are the language OT security programmes are written and budgeted in, and they appear on the CISSP, GICSP, CISA, and our ot_security exam.
IEC 62443 — the dedicated OT standard
If IT security has ISO 27001, OT security has IEC 62443. It is a *series* of standards covering the whole ecosystem, and it is built around two ideas worth memorising:
Zones and conduits. You group assets with similar security requirements into **zones**, and the pathways between them into **conduits**. Every conduit is a place to put a control. This is the formal version of "segment the network," and it maps directly onto the Purdue Model.
Security Levels (SL 1-4). Each zone is assigned a target SL based on the *capability of the attacker it must resist*: SL 1 (casual/accidental), SL 2 (intentional, low resources), SL 3 (sophisticated, moderate resources), SL 4 (nation-state). You then select controls that meet the zone's SL.
IEC 62443 also uniquely assigns responsibility across the whole supply chain, the asset owner, the system integrator, and the product supplier each have their own parts of the standard. That shared-responsibility model is why it works where IT-only standards struggle.
Who uses it: everyone, globally. It is voluntary but has become the de facto expectation for industrial environments and procurement.
NIST SP 800-82 Rev. 3 — the practical guide
NIST SP 800-82 is not a certification standard; it is the U.S. government's *guide* to securing OT. Revision 3 (2023) broadened its scope from "ICS" to "OT" generally and re-aligned it with the NIST Cybersecurity Framework and the SP 800-53 control catalogue.
Its value is translation. It takes the familiar NIST controls and explains how they change in an OT context, why you cannot run an aggressive vulnerability scan against a live PLC, how patching becomes compensating controls, how incident response must account for safety. If your organisation already speaks NIST CSF or 800-53, 800-82 is how you extend that vocabulary to the plant floor.
Who uses it: U.S. federal operators and contractors by default, and countless private organisations that have standardised on NIST.
NERC CIP — the one with teeth
NERC CIP (Critical Infrastructure Protection) is different in kind from the other two: it is mandatory and enforceable, with financial penalties, for entities that operate the North American bulk electric system. Where IEC 62443 and 800-82 guide, NERC CIP *requires*.
Its standards (CIP-002 through CIP-014 and beyond) walk through categorising BES Cyber Systems by impact, then applying controls, electronic security perimeters, physical security, systems security management, incident reporting, recovery plans, and supply-chain risk. Audits are real and non-compliance is expensive, which makes CIP the framework that most directly turns OT security into a budget line.
Who uses it: North American electric utilities, mandatorily.
How they fit together
They are complementary, not competing:
|---|---|---|---|
A mature utility might use NERC CIP as its compliance floor, IEC 62443 to architect zones and conduits, and NIST SP 800-82 to translate its existing NIST control set to OT. On top of these, regional regulation is tightening fast, the EU's NIS2 Directive and Cyber Resilience Act now pull many industrial operators and product makers into scope, so the direction of travel is *more* mandatory OT security, not less.
For the exam and the job
Examiners love to test the *distinctions*: which framework is mandatory (NERC CIP), which introduces zones and conduits and security levels (IEC 62443), which is NIST-aligned guidance (800-82). Get those three anchors right and most questions resolve themselves. Our [ot_security practice bank](/certifications/ot_security) drills these frameworks in scenario form, and if your path is governance-focused, the [CISA](/certifications/cisa) and [ISO 27001](/certifications/iso_27001) banks cover the audit and ISMS skills that OT compliance work leans on. The [free domain summaries](/domain-summaries) show how heavily each exam weights the compliance material.
Sources & References
Michael Torres
CISA, CRISC, ISO 27001 Lead Auditor
Michael is a GRC consultant specializing in compliance frameworks and risk management. He has conducted 50+ ISO 27001 audits and writes about governance, risk, and certification preparation.
Ready to start practicing?
85 certifications. 153,000+ questions. 20 free per cert.