Contents
What's in the package?
A curated set of 70+ documents covering the full scope of IEC 62443 — policies, procedures, registers and records, grouped into four implementation packs. Plus an Excel self-assessment for your SRs and FRs.
Policies, procedures, registers & records
All in .docx, with a consistent structure, headings and placeholders. Replace [organisation], [site], [zone] and [owner] and you're off.
Self-assessment for SRs & FRs
Score per System Requirement from IEC 62443-3-3, automatic heatmap per Foundational Requirement, gap analysis and SL determination. One file to track your progress.
The toolkit uses a consistent naming convention. Each abbreviation refers to a document type:
Pack 1
CSMS Governance & System Foundation
Scope, governance, policies, roles and the core registers of the management system.
Use first.
Master Index & Customer User Guide
IEC ref: All clauses
CSMS Manual & Process Map
IEC ref: 62443-2-1: 4–7
IEC 62443 Coverage Map
IEC ref: 62443-2-1; 3-3
CSMS Context & Scope Statement
IEC ref: 4.1; 4.3
OT Cyber Security Policy
IEC ref: 4.3.2
Data Confidentiality Policy
IEC ref: FR4
Identification & Access Policy
IEC ref: FR1; FR2
OT Security Objectives & KPI Tracker
IEC ref: 4.3.4
Roles & Responsibilities (RACI)
IEC ref: 4.3.2.3
Stakeholders & Requirements Register
IEC ref: 4.2
Legal & Regulatory Obligations Register (incl. NIS2)
IEC ref: 4.2; 4.4
Document Register & Retention Periods
IEC ref: 4.4
IACS Asset Inventory
IEC ref: 4.2.3
Documented Information Control Procedure
IEC ref: 4.4
CSMS Communication Plan
IEC ref: 4.3.2.5
Policy Review Record
IEC ref: 4.4.3.7
Pack 2
Risk, Zones & Conduits, Applicability
Risk criteria, ZCR 2-7 partitioning, SL-T assignment and Statement of Applicability.
After scope + asset inventory.
Cyber Security Risk Assessment Procedure
IEC ref: 62443-3-2 ZCR 1–7
Initial High-Level Risk Assessment
IEC ref: ZCR 2
Zone & Conduit Definition
IEC ref: ZCR 3; 7
Detailed Risk Assessment per Zone
IEC ref: ZCR 5
SL-T Determination per Zone
IEC ref: ZCR 4–6
OT Risk Register
IEC ref: 4.2.3
Statement of Applicability (SR & RE)
IEC ref: 62443-2-1; 3-3
Network Segmentation & Zoning Policy
IEC ref: FR5
Conduit Specification
IEC ref: FR5
Pack 3
IACS Lifecycle, Patching & Operational Controls
Change, patch, FAT/SAT, hardening, monitoring, removable media.
For each IACS project.
Change Management Procedure (IACS)
IEC ref: FR3
Patch & Vulnerability Management Procedure
IEC ref: FR3
Backup & Recovery Procedure
IEC ref: FR7
Removable Media & Mobile Device Procedure
IEC ref: FR3; FR5
FAT / SAT Plan
IEC ref: 62443-4-1
FAT / SAT Test Report
IEC ref: FR7
OT Monitoring & Logging Plan
IEC ref: FR6
Identification & Authentication Specification
IEC ref: FR1
Access Control & Account Management
IEC ref: FR1; FR2; FR4
System Hardening Baseline
IEC ref: FR3
Anti-malware Configuration Standard
IEC ref: FR3
System Integrity Verification Procedure
IEC ref: FR3
OT Patch Register
IEC ref: FR3
Remote Access Policy (OT)
IEC ref: FR1; FR5
Removable Media Policy
IEC ref: FR3
Pack 4
Assurance, Suppliers & Continual Improvement
62443-2-4 supplier, incident response, audit, management review and CAPA.
To operate and improve.
Supplier / Integrator Evaluation Procedure
IEC ref: 62443-2-4
OT Vendor Questionnaire & Evaluation
IEC ref: 62443-2-4; 4-1
Supplier / Integrator Responsibility Matrix
IEC ref: 62443-2-4
OT Supplier Register
IEC ref: 62443-2-4
OT Cyber Incident Response Procedure
IEC ref: FR6
NIS2 Notification Plan
IEC ref: NIS2 Art. 23
OT Cyber Incident Register
IEC ref: FR6
Post-Incident Review Report
IEC ref: FR6
Competence Matrix & Training Plan
IEC ref: 4.3.2.4
Training & Awareness Record
IEC ref: 4.3.2.4
Internal Audit Programme
IEC ref: 4.4.3.4
Internal Audit Plan
IEC ref: 4.4.3.4
IEC 62443 Internal Audit Checklist
IEC ref: 62443-2-1; 3-3
Internal Audit Report
IEC ref: 4.4.3.4
Audit Findings Register
IEC ref: 4.4.3.4
Management Review Agenda & Minutes
IEC ref: 4.4.3.7
Nonconformity & Corrective Action Procedure
IEC ref: 4.4.3.6
CAPA Register
IEC ref: 4.4.3.6
Continual Improvement Register
IEC ref: 4.4.3.7
Ready to start using these documents?
One-time €199 — instantly downloadable.