IEC 62443 Compliance Checklist
Assess your industrial automation and control system security controls, evidence, gaps, and remediation status using an IEC 62443-aligned checklist.
Organization and Assessment Context
Organization Name
*
Site or Facility Name
*
Department or Business Unit
Primary Contact Name
*
First Name
Middle Name
Last Name
Job Title
Email Address
*
example@example.com
Assessment Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
System, Line, or Plant Name
*
Assessment Scope and Asset Boundaries
*
Assessment Type
*
Self-assessment
Internal audit
Supplier assessment
Readiness review
Scope Exclusions or Notes
IEC 62443 Scope and Architecture
ICS/OT environment type
*
Please Select
Manufacturing
Utilities
Oil and Gas
Transportation
Water/Wastewater
Building Automation
Other
System criticality level
*
Low
Moderate
High
Mission Critical
In-scope asset categories
*
PLCs
HMIs
Engineering Workstations
Historians
Servers
Switches
Firewalls
Remote Access Gateways
Other
In-scope assets and components
Network segmentation architecture summary
*
Remote access methods used
VPN
Jump Server/Bastion Host
Remote Desktop Services
Vendor Remote Support
Modem/Dial-up
Zero Trust Access
Other
Current segmentation maturity
*
Ad hoc
Basic
Defined
Managed
Optimized
Governance and Policy Controls
Security roles and responsibilities are defined
*
Rows
Not in place
Partially in place
Mostly in place
Fully in place
Defined and assigned for OT/ICS environment
1
2
3
4
ICS security policy exists and is reviewed
*
Rows
Not in place
Partially in place
Mostly in place
Fully in place
Policy documented and periodically reviewed
5
6
7
8
Risk assessments are performed for OT/ICS assets and processes
*
Rows
Not in place
Partially in place
Mostly in place
Fully in place
Assessment process defined and executed
9
10
11
12
Change management is documented for OT/ICS environments
*
Rows
Not in place
Partially in place
Mostly in place
Fully in place
Changes are controlled, approved, and recorded
13
14
15
16
Incident response procedures exist for OT environments
*
Rows
Not in place
Partially in place
Mostly in place
Fully in place
OT-specific response procedures are documented and available
17
18
19
20
ICS security policy name
Document ID or reference
Evidence link or location
Technical Control Checklist
Technical control status checklist
*
Rows
Status
Evidence reference
Comments
Authentication / authorization
21
Account management
22
Least privilege
23
Password or credential handling
24
Logging / monitoring
25
Patching / vulnerability management
26
Backup / restore
27
Malware protection
28
Secure remote access
29
Boundary protection
30
Removable media controls
31
Authentication / authorization status
Please Select
Implemented
Partially implemented
Planned
Not implemented
N/A
Authentication / authorization evidence reference
Account management status
Please Select
Implemented
Partially implemented
Planned
Not implemented
N/A
Account management evidence reference
Least privilege status
Please Select
Implemented
Partially implemented
Planned
Not implemented
N/A
Least privilege evidence reference
Password or credential handling status
Please Select
Implemented
Partially implemented
Planned
Not implemented
N/A
Password or credential handling evidence reference
Logging / monitoring status
Please Select
Implemented
Partially implemented
Planned
Not implemented
N/A
Logging / monitoring evidence reference
Patching / vulnerability management status
Please Select
Implemented
Partially implemented
Planned
Not implemented
N/A
Risk, Findings, and Corrective Actions
Overall risk rating
*
Low
Moderate
High
Critical
Findings and corrective actions
*
Affected assets
Identified gaps
Recommended remediation
Action owner
Target completion date
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Additional observations
Review and Completion
Reviewer name
*
First Name
Middle Name
Last Name
Reviewer role
*
Review date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Overall compliance verdict
*
Compliant
Partially compliant
Non-compliant
Needs further review
Final comments
Submit Checklist
Should be Empty: