← Back

ENGINEERING NOTES · Jun 2026

Why NERC-CIP and IEC 62443 don't compete, they complement each other

One is the law. The other is the engineering. I've seen teams lose months treating them as alternatives.

This is a mistake I see often, even from well-intentioned teams: treating NERC CIP and IEC 62443 as two alternative paths to 'doing OT security', when they actually answer different questions.

CIP answers 'what am I legally required to do if I operate North America's bulk electric system?'. It's sector- and region-specific, and non-compliance has real regulatory consequences.

62443 answers 'how do I technically design a secure industrial control architecture?'. It's sector- and region-agnostic — it works just as well for a power plant in Quito as for a manufacturing site in Bavaria.

The right way to use them together: CIP defines the mandatory what (asset categorization, electronic perimeter, change management), and 62443 provides the technical how to implement it rigorously — zones and conduits, security levels, component requirements. Designing the architecture by looking only at CIP tends to produce compliance that's valid on paper but fragile in practice.