Contents
What's in the package?
A curated set of 69 documents covering the full scope of IEC 62443 — policies, procedures, registers and records, grouped into four implementation packs. Plus an AI Assistant Skill for your AI assistant and an Excel self-assessment for your SRs and FRs.
What's not included: the IEC 62443 standard itself
This package contains implementation templates and tools only. The IEC 62443 series is copyrighted by IEC / ISA and must be purchased separately under licence from IEC, ISA, NEN, NBN, BSI or DIN. Our documents reference the standard by clause, ZCR number, FR/SR/CR or Annex only — they do not reproduce its text.
Policies, procedures, registers & records
All in .docx, with a consistent structure, headings and placeholders. Replace [organisation], [site], [zone] and [owner] and you're off.
Self-assessment for SRs & FRs
Score per System Requirement from IEC 62443-3-3, automatic heatmap per Foundational Requirement, gap analysis and SL determination. One file to track your progress.
AI Assistant Skill — implement the kit with your AI assistant
An installable skill for AI assistants such as Claude. It knows the 69 documents, the recommended fill-in sequence, the cross-references (TPL-04 → REG-06 → SOA-01 → MAT-01), the placeholder rules, and the audit checklist. Ask the assistant to fill CTX-01, justify an SL-T, or prepare for an audit — it stays inside the IEC 62443 vocabulary and never fabricates safety or owner fields.
The toolkit uses a consistent naming convention. Each abbreviation refers to a document type:
The kit is delivered as 4 packs to be implemented in order: Governance → Risk → Lifecycle → Assurance. A 00. Start Here – Master Index folder ships alongside, containing the welcome guide, the ebook "The OT Cybersecurity Blueprint", and the AI Assistant Skill.
Pack 1
CSMS Governance & System Foundation
Scope, governance, policies, roles and the core registers of the management system.
Use first.
Master Index & Customer User Guide
IEC ref: All clauses
CSMS Context & Scope Statement
IEC ref: 4.1; 4.3
CSMS Manual & Process Map
IEC ref: 62443-2-1: 4–7
IEC 62443 Coverage Map
IEC ref: 62443-2-1; 3-3
OT Cybersecurity Policy
IEC ref: 4.3.2
OT Acceptable Use Policy
IEC ref: A.9 family
OT Remote Access Policy
IEC ref: FR1; FR5
OT Change & Patch Management Policy
IEC ref: FR3
OT Logging & Monitoring Policy
IEC ref: FR6
OT Data Classification & Handling Policy
IEC ref: FR4
OT Identification & Access Management Policy
IEC ref: FR1; FR2
OT Security Objectives & KPI Tracker
IEC ref: 4.3.4
Interested Parties & Requirements Register
IEC ref: 4.2
Legal & Regulatory Obligations Register (incl. NIS2)
IEC ref: 4.2; 4.4
Document Register & Retention Schedule
IEC ref: 4.4
IACS Asset Register
IEC ref: 4.2.3
Document Control Template
IEC ref: 4.4
Roles, Responsibilities & RACI Matrix
IEC ref: 4.3.2.3
Pack 2
Risk, Zones & Conduits, Applicability
Risk criteria, ZCR 2-7 partitioning, SL-T assignment and Statement of Applicability.
After scope + asset inventory.
OT Risk Assessment Procedure
IEC ref: 62443-3-2 ZCR 1–7
OT Risk Criteria & Risk Appetite
IEC ref: ZCR 4
Zone & Conduit Definition
IEC ref: ZCR 3; ZCR 7
OT Threat Catalogue & Modelling Template
IEC ref: ZCR 2; ZCR 5
Initial High-Level Risk Assessment Worksheet
IEC ref: ZCR 2
Detailed Zone-and-Conduit Risk Assessment Worksheet
IEC ref: ZCR 5
OT Risk Treatment Plan
IEC ref: 4.3.4
OT Vulnerability Register
IEC ref: FR3
OT Risk Register
IEC ref: 4.2.3
Statement of Applicability (SR & RE)
IEC ref: 62443-2-1; 3-3
SL-T / SL-C / SL-A Tracking Matrix
IEC ref: ZCR 4; FR1–7
Cybersecurity Requirements Specification (CRS)
IEC ref: ZCR 6
Pack 3
IACS Lifecycle, Patching & Operational Controls
Change, patch, FAT/SAT, hardening, monitoring, removable media.
For each IACS project.
IACS Lifecycle Procedure
IEC ref: 62443-2-1: 4.4; 4.5
OT Change Management Procedure
IEC ref: FR3
OT Patch Management Procedure
IEC ref: 62443-2-3; FR3
OT Backup & Recovery Procedure
IEC ref: FR7
OT Removable Media Procedure
IEC ref: FR3; FR5
FAT / SAT Plan (Cybersecurity)
IEC ref: 62443-4-1; ZCR 6
OT Monitoring Plan & KPI Tracker
IEC ref: FR6
OT Account Lifecycle Template (Joiner / Mover / Leaver)
IEC ref: FR1; FR2
OT Hardening Checklist
IEC ref: FR3
OT Configuration Records & Baseline
IEC ref: FR3
OT Logging Specification
IEC ref: FR6
IACS Intake Form
IEC ref: 62443-2-1: 4.4
OT Cybersecurity Design Documentation
IEC ref: ZCR 6
OT Awareness & Training Plan
IEC ref: 4.3.2.4
FAT / SAT Cybersecurity Test Record
IEC ref: 62443-4-1; FR3
OT Access Record
IEC ref: FR1; FR2
Change Log
IEC ref: FR3
OT Patch Register
IEC ref: 62443-2-3; FR3
Pack 4
Assurance, Suppliers & Continual Improvement
62443-2-4 supplier, incident response, audit, management review and CAPA.
To operate and improve.
Internal Audit Programme
IEC ref: 4.4.3.4
Internal Audit Plan
IEC ref: 4.4.3.4
IEC 62443 Internal Audit Checklist
IEC ref: 62443-2-1; 3-3
Internal Audit Report
IEC ref: 4.4.3.4
Audit Findings Register
IEC ref: 4.4.3.4
Management Review Agenda & Minutes
IEC ref: 4.4.3.7
Management Review Action Log
IEC ref: 4.4.3.7; 10.1
Third-Party OT Risk Management Procedure
IEC ref: 62443-2-4
Vendor OT Security Questionnaire
IEC ref: 62443-2-4; 4-1
Third-Party OT Register
IEC ref: 62443-2-4
Supplier / Integrator / Customer Responsibility Matrix
IEC ref: 62443-2-4
OT Incident Response Procedure
IEC ref: FR6; 10.2
OT Incident Register
IEC ref: FR6
Post-Incident Review Report
IEC ref: 10.2; 9.3
Corrective Action (CAPA) Procedure
IEC ref: 10.2
CAPA Register
IEC ref: 10.2
Continual Improvement Register
IEC ref: 10.1; 9.3
IACS Decommissioning Procedure
IEC ref: 4.4
Commissioning / Go-Live Plan
IEC ref: 4.5
NIS2 Significant-Incident Reporting Path
IEC ref: NIS2 Art. 23
Ready to start using these documents?
One-time €199 — instantly downloadable.