Searching for the IEC 62443 latest version? You have come to the right place, but since IEC 62443 is not one single document but a set of several documents, there is no single latest version. You can read about the latest changes here.
What is IEC 62443?
IEC 62443 is a set of standards, technical specifications and reports that deal with OT cyber security also known as Industrial Cybersecurity. This is one of the few globally used standards for protecting Industrial Control Systems and other OT systems from cyber threats. IEC stands for the International Electrotechnical Commission.
——————————-Announcement——————————————
Interested in learning more and qualifying as a Certified Professional without breaking the bank? Join the Abhisam CICP program and earn the title of CICP (Certified Industrial Cybersecurity Professional) when you complete the course and pass the exam.

———————————————————————————————–
What are the IEC 62443 latest version changes in the year 2026?
This standard earlier had 4 categories and there were different documents in each category. The categories were earlier numbered as IEC 62443-1, IEC 62443-2 and so on. A standard or a technical report in the IEC 62443 series has the number IEC 62443-x-y where x is the Category number and y is the document number. For example IEC 62443-2-3 deals with Patch Management and is the third document in Category 2.
These categories have now been expanded and we have now six categories ranging from IEC 62443-1 to IEC 62443-6.
You can see from the updated diagram below that there have been new parts published, such as IEC 62443-6-2 which is a Security Evaluation Methodology for IEC 62443-4-1. So if you are an auditor who wishes to evaluate a supplier for IEC 62443-4-1 conformity assessment, this is useful for you.
It is also useful for suppliers themselves to know the criteria that they would be evaluated against after they claim implementation of IEC 62443-4-1 for their products.

IEC 62443-1-6 published- Industrial IoT devices now covered
Secondly, IEC 62443-1-6 (which was in draft mode) is now published. This is very important as it deals with IIoT devices (Industrial Internet of Things devices). There has been an huge surge of these devices in industrial environments. Recall that the traditional Purdue Model, cleanly divided layers from Level 0 (the process) upwards until Layer 5 (Management Information Systems/ERP systems/similar). The model assumes that the sensors/transmitters and other devices close to the process have lesser computational power than the higher level devices and are connected only upwards via the vertical chain of command.
However IIoT devices shatter this pattern. A low level temperature sensor may have onboard computational capability (it is smart) and also may directly connect to outside Cloud services like AWS, Azure or similar. Or a group of such sensors & actuators might connect to an edge device and connect to the cloud, it may even accept configuration updates and commands from the cloud. IEC 62443-1-6 deals with these.

Until now IEC 62443 had nothing on this, now it has. So if you are having IIoT devices in your plant or facility and want to secure them, you can refer to IEC 62443-1-6.
The below sections are worth reading if you are not familiar with OT cybersecurity.
What do we mean by OT Systems?
OT Stands for Operational Technology and include Industrial Automation and Control Systems (IACS for short) that are based on various technologies. These systems could be of many types including analog, electro-mechanical, pneumatic, hydraulic or programmable electronic type that are based on microprocessors.
The programmable microprocessor based systems are vulnerable to cyber attacks. These could be of DCS (Distributed Control System), PLC (Programmable Logic Controller), SCADA (Supervisory Control and Data Acquisition system), PC based systems and others. All of these systems are computer based systems that are used to monitor and control many types of processes that could be industrial processes or transportation equipment (such as airplanes, ships and spacecraft) or warehouses or medical equipment or industrial robots and so on. In other words any cyber-physical system that uses computer control.
These systems are susceptible to cyber attacks from many entities including cyber criminals such as ransomware gangs, state hackers wanting to disrupt a country’s manufacturing or critical infrastructure, or even non state actors, such as environmental hacktivists.
Summary of changes in IEC 62443 as of the year 2026.
1. The number of categories have changed from the earlier 4 to now 6. However there is no document that is in Category 5, it is just reserved for use later. So there is no IEC 62443-5-1 or anything like that.
2. IEC 62443-4-3 which was in draft mode and was for Industrial Internet of Things (IIoT) devices has been put in category 1 with a new number as IEC 62443-1-6. It is now published.
3. IEC 62443-6-1 has been released. It is an evaluation guide for third party assessors to examine compliance to IEC 62443-2-4.
4. IEC 62443-8-2 has been released. It is an evaluation guide for third party assessors to examine conformity to IEC 62443-4-1.
4. IEC 62443-1-5 has been released. It deals with Security Profiles. In future, typical security profiles for different applications, will be released with the nomenclature of IEC 62443-5-x, where x could be 1,2, 3, etc for different application or industry profile documents.
Why are there changes in IEC 62443?
IEC 62443 is a set of standards, technical specifications and reports that deal with cyber security for Industrial Automation. The various IEC committees deliberated on whether the current structure is good enough to meet today’s requirements and apparently concluded that it needs to have more categories.
Where to learn more?
When you join the Abhisam CICP course, you not only learn about the different IEC 62443 parts, but also learn a lot of other important stuff such as MITRE ATT&CK for ICS, Supply Chain cybersecurity and more. Get immediate access to this Industrial Cybersecurity training course now.