lang icon English
Dec. 6, 2025, 5:21 a.m.
128

IIC and ISA Release IoT Security Maturity Model with ISA/IEC 62443 Mappings

Brief news summary

On August 22, 2022, the Industry IoT Consortium (IIC) and the International Society of Automation (ISA) released the IoT Security Maturity Model (SMM) with 62443 Mappings, aimed at asset owners, product suppliers, and service providers. This enhanced model expands the original IoT SMM by including service providers and aligning with the IEC/ISA 62443 standards for industrial automation and control systems (IACS) security. While 62443 provides a risk-based framework for managing IACS vulnerabilities, it lacks practical guidance for achieving security maturity. The new mappings bridge this gap by enabling organizations to assess and improve their security maturity through actionable steps tied to recognized standards. Contributors highlight that this approach facilitates efficient, risk-based security implementation without unnecessary controls. Supporting Industry 4.0, the model fosters customized security frameworks that increase resilience and protect critical infrastructure amid growing digital integration. Future updates plan to further clarify service providers’ roles to keep pace with the evolving IoT landscape.

The Industry IoT Consortium (IIC) and the International Society of Automation (ISA) have jointly released the IoT Security Maturity Model (SMM): 62443 Mappings for Asset Owners, Product Suppliers, and Service Suppliers. Announced on August 22, 2022, in Boston, Massachusetts, this guidance document extends the earlier IoT Security Maturity Model Practitioner’s Guide by incorporating the service provider role alongside asset owners and product suppliers, along with updated mappings to the ISA/IEC 62443 standards. Ron Zahavi, Microsoft’s Chief Strategist for IoT Standards and co-author of the IoT SMM, highlighted that these standards serve as a critical global framework for industrial automation and control systems (IACS) security, established through the International Electrotechnical Commission (IEC). The IoT SMM enables organizations to assess their current security maturity against target goals and identify improvement opportunities over time. The ISA99 committee developed the 62443 series to address vulnerabilities in Industrial Automation and Control Systems through a systematic risk mitigation approach. Although these standards focus on the maturity of security programs, they do not provide direct practical guidance for achieving the maturity levels. Frederick Hirsch, co-chair of the IIC ISA/IIC Contributing Group, observed that achieving security maturity targets is difficult without such guidance.

The new 62443 mappings align the comprehensiveness levels in the IIC IoT SMM with ISA/IEC 62443 requirements, helping asset owners and product suppliers in IACS to reach appropriate maturity levels aligned with their security needs. Eric Cosman, co-chair of the ISA99 Committee, emphasized the necessity of combining standards with actionable guidance, noting that while ISA/IEC 62443 codifies proven engineering practices, standards alone are insufficient. This joint initiative by IIC and ISA offers the practical direction needed to promote widespread adoption. Pierre Kobes, a member of ISA99 and IEC Technical Committee 65, added that the model assists companies in selecting security measures proportional to their assessed risks, promoting risk-based rather than indiscriminate security enhancements. The detailed IoT Security Maturity Model document, covering 62443 mappings for asset owners, product suppliers, and service providers, is available for download from both the IIC and ISA websites. It includes a full list of contributing authors and notes ongoing efforts to further refine the model with expanded role definitions and guidance for service providers. This development highlights the increasing need for tailored security frameworks in the evolving IoT landscape, particularly as industrial systems adopt complex digital technologies. By aligning practical maturity models with established international standards, organizations can better manage risk, bolster security resilience, and ensure the safe, reliable operation of critical infrastructure in Industry 4. 0 settings.


Watch video about

IIC and ISA Release IoT Security Maturity Model with ISA/IEC 62443 Mappings

Try our premium solution and start getting clients — at no cost to you

I'm your Content Creator.
Let’s make a post or video and publish it on any social media — ready?

Language

Hot news

Dec. 6, 2025, 5:22 a.m.

Microsoft Faces Market Anxiety Amid AI Sales Targ…

Recent developments in the technology sector have caused significant concern among investors and analysts due to doubts about the sustainability of growth in the artificial intelligence (AI) market.

Dec. 6, 2025, 5:19 a.m.

After Leaving Meta, French AI Pioneer Yann LeCun …

Yann LeCun, a leading figure in artificial intelligence and former chief AI scientist at Meta, has announced the creation of a new global AI startup headquartered in Paris, revealed at the AI-Pulse conference on December 4.

Dec. 6, 2025, 5:18 a.m.

AI News Video Generator – Turn Market News into Q…

Medeo has launched an innovative AI-driven news video generator aimed at transforming complex financial news and market reports into concise, engaging video updates.

Dec. 6, 2025, 5:13 a.m.

MindFuse: Towards GenAI Explainability in Marketi…

The future of digital marketing is rapidly transforming through the integration of human creativity with generative artificial intelligence, signaling a major shift in how marketing strategies are designed and implemented.

Dec. 6, 2025, 5:10 a.m.

Profound Raises $35 Million Series B to Scale AI …

Profound, a leading company specializing in AI search visibility solutions, has successfully closed a $35 million Series B funding round to accelerate its enterprise sales efforts and reinforce its standing in the expanding AI-driven search technology sector.

Dec. 5, 2025, 1:16 p.m.

Meta Strikes Multiple AI Deals with News Publishe…

Meta, the parent company of Facebook, Instagram, WhatsApp, and Messenger, has recently achieved significant progress in advancing its artificial intelligence capabilities by securing multiple commercial agreements with prominent news organizations.

Dec. 5, 2025, 1:15 p.m.

A safety report card ranks AI company efforts to …

Are AI companies adequately protecting humanity from the risks of artificial intelligence? According to a new report card by the Future of Life Institute, a Silicon Valley nonprofit, the answer is likely no.

All news

AI Company

Launch your AI-powered team to automate Marketing, Sales & Growth

and get clients on autopilot — from social media and search engines. No ads needed

Begin getting your first leads today