Skip to content

COMPARISON · Standards

IEC 62443 vs ISO/SAE 21434

Choosing between the two, or applying both, depends on the sector and where in the supply chain the product sits.

LAST REVIEWED

What is different

  • Sector: IEC 62443 targets industrial automation and control systems (IACS) across process, manufacturing and critical infrastructure; ISO/SAE 21434 targets road vehicles specifically.
  • Structure: IEC 62443 is a multi-part series addressing policies (62443-2-x), system requirements (62443-3-x) and component/product requirements (62443-4-x) separately; ISO/SAE 21434 is a single standard covering the full vehicle cybersecurity lifecycle.
  • Security levels: IEC 62443 defines target, achieved and capability Security Levels (SL 0–4) against defined threat capabilities; ISO/SAE 21434 uses a risk-based approach without an equivalent tiered security-level scale, relying instead on impact and attack feasibility ratings.
  • Regulatory linkage: ISO/SAE 21434 is closely tied to UN Regulation No. 155 on cybersecurity management systems for vehicle type approval; IEC 62443 is not tied to a single regulation but is widely referenced by industrial cybersecurity regulation and increasingly by CRA harmonised standards work for industrial products.

What overlaps

Both standards require a documented cybersecurity management system or process, both require risk assessment tied to the specific product or system rather than generic best practice, both require secure development lifecycle practices, and both expect the same kind of ongoing vulnerability monitoring and response after deployment. Both are also referenced, directly or indirectly, as credible bases of conformity for CRA essential requirements in their respective domains, since the CRA expects manufacturers to apply a recognised, risk-based secure development process.

Organisations that supply components into both automotive and industrial markets — for example, embedded controllers used in both — often find that a single underlying secure development lifecycle can be mapped to both standards' documentation requirements, provided the risk assessment method is applied consistently against each standard's specific criteria.

Which applies to you

  • You design or integrate industrial control systems, SCADA, PLCs or related components: IEC 62443 is the relevant standard, with the specific part depending on your role as asset owner, integrator or product supplier.
  • You design components or systems for road vehicles: ISO/SAE 21434 applies, alongside UN R155 if you are a vehicle manufacturer seeking type approval.
  • You supply the same underlying product into both industrial and automotive markets: expect to demonstrate conformity against both standards separately, built from one internal secure development process.
  • You are unsure which applies: identify the end-use sector of the product first — the standard follows the sector, not the technology.

Frequently asked questions

Can ISO/SAE 21434 evidence be reused for IEC 62443?

The underlying secure development process and much of the supporting evidence can often be reused, but the specific risk assessment outputs cannot be transferred directly, because the two standards use different risk and impact criteria suited to their respective sectors.

Is IEC 62443 mandatory?

IEC 62443 is not itself a law, but it is widely referenced by regulators, asset owners and procurement requirements in industrial and critical infrastructure sectors, and it is a credible technical basis for demonstrating cybersecurity conformity under the CRA and NIS2 for industrial products.

What are IEC 62443 Security Levels?

Security Levels (SL 0 to SL 4) describe the strength of security measures needed to resist an attacker of a given capability, ranging from casual or coincidental violation (SL 1) to attackers with extended resources and sophisticated means (SL 4).

Does ISO/SAE 21434 cover software updates?

Yes. It covers the vehicle cybersecurity lifecycle including post-development phases such as production, operation, maintenance and decommissioning, which includes managing vulnerabilities and updates for the operational life of the vehicle.