Recently the second edition of the IEC 62443-2-1:2024 standard has been released by the International Electrotechnical Commission (IEC). This second edition cancels and replaces the first edition published in 2010. This edition constitutes a technical revision.
IEC 62443-2-1 changes in the new edition
This edition includes major technical changes with respect to the previous edition such as
a) A revised requirement structure into SP elements (SPEs),
b) Several revised requirements to eliminate duplication of an information security management system (ISMS), and
c) defined a maturity model for evaluating requirements.
What happened to the CSMS? (Cyber Security Management System)
The new standard is a complete overhaul of the old one and indeed some terms such as CSMS (Cyber Security Management System) that were the core part of the older version do not find any mention in the new version at all. This term has got replaced with a new term, that is referred to as a Security Program (SP). This does not refer to a computer program, but a Management System that is used to implement cybersecurity of an Industrial Automation and Control System.The new version refers to the ISMS (Information Security Management System) and states that the Security Program (SP) should align with the existing ISMS of the organization. Generally most organizations that have large IT systems already have an ISMS in place and this revision aims to prevent duplication.
Where can I learn about IEC 62443 and IEC 62443 updates?
We have published an updated IEC 62443 structure on our site please click here to view it.
Where can I learn more about IEC 62443-2-1: 2024?
If you have enrolled into the Abhisam CICP program (Certified Industrial Cybersecurity Professional) and have a valid current license, you will soon see an updated module on IEC 62443-2- 1 in the course. If you plan on attending the next batch of the Abhisam Understanding OT Cybersecurity and IEC 62443 training workshop, then this updated version will be part of the training program.
What is the CICP?
CICP is Certified Industrial Cybersecurity Professional and is a title that is earned by successful participants in the Abhisam CICP program. This is one of the most comprehensive, yet extremely cost effective training programs related to OT cybersecurity/Industrial Cybersecurity if you compare it with the programs offered by other training providers.
Not only will you learn all about Industrial and OT cybersecurity via a self paced e-learning course that you can take anytime on demand, but will also earn a title of CICP that you can append after your name. e.g. John Smith, CICP.You also earn a digital badge that can be added to your LinkedIn profile
This leads to an immediate elevation of your profile in the eyes of your peers, bosses, employers or clients/customers.
What is IEC 62443?
IEC 62443 is a set of Standards and Technical Reports that are used to implement cybersecurity of Industrial Automation and Control Systems, in other words, OT Systems. OT stands for Operational Technology and refers to computer controlled cyber-physical systems, in contrast to IT systems which are also computer based systems, but have no physical equipment or devices connected.
Some examples of OT Systems:
Industrial Automation and Control Systems (IACS) including those like PLC/SCADA/DCS/SIS
Building Automation Systems/HVAC systems
Warehouse Automation Systems
Ship Steering and Control Systems
Examples of IT Systems:
Payroll processing systems
Airline Ticketing Systems
ERP systems such as SAP or Microsoft Dynamics or Oracle Enterprise



