IEC 62443 vs NIST SP 800-82 vs NERC CIP: Which Applies to You?
Updated: a few seconds ago
Ask three people which OT security standard your organization should follow and you may get three answers: IEC 62443, NIST SP 800-82 and NERC CIP. They are not competitors: one is an international consensus standard, one is free government guidance, and one is a mandatory regulation for a specific industry. Knowing the difference helps you decide what you must do, what you should do and how to avoid doing the same work three times.
IEC 62443: the international consensus standard
ISA/IEC 62443 is a series of international standards for securing industrial automation and control systems, developed by the ISA99 committee and published with the IEC. It covers the full life of a control system: the asset owner's security program, the service provider's practices, risk assessment through zones and conduits, system-level requirements and the development practices of product vendors.
A few things set it apart:
It is voluntary by default. No law requires 62443 in most jurisdictions. It becomes binding when a regulator references it, when a customer writes it into a contract, or when your own corporate policy adopts it.
It is certifiable. Products, product development processes and some service provider capabilities can be certified against specific parts by accredited schemes. That makes it useful in procurement, because you can ask suppliers for evidence instead of promises.
It is international. Because it is recognized across many countries, it works well as a common language for global operators, multinational vendors and integrators working across borders.
NIST SP 800-82: free, practical guidance
NIST Special Publication 800-82 Revision 3, "Guide to Operational Technology (OT) Security," was published by the US National Institute of Standards and Technology in September 2023. Earlier editions focused on industrial control systems; Revision 3 widened the scope to operational technology more broadly, including building automation, physical access control and other systems that interact with the physical world.
What it offers:
Free access. Anyone can download and use it.
Explanation, not just requirements. It describes typical OT architectures, threats and vulnerabilities, and walks through how to build an OT security program.
An OT overlay for NIST controls. It tailors the NIST SP 800-53 security controls to OT environments, which is helpful for organizations already using NIST's broader framework.
Alignment with the NIST Cybersecurity Framework, so OT work can be reported in the same terms as enterprise security.
NIST SP 800-82 is guidance. It is not mandatory for private companies, although US federal agencies and some contracts may reference it. It is often the most approachable starting point for teams new to OT security.
NERC CIP: mandatory rules for the bulk power system
The NERC Critical Infrastructure Protection (CIP) standards are different in kind. They are mandatory, enforceable reliability standards for entities that own or operate parts of the bulk electric system in North America. In the United States they are approved and enforced under the authority of the Federal Energy Regulatory Commission. In Canada, they apply in the provinces that have adopted them through their own regulatory arrangements, and they also apply in the part of Baja California, Mexico, that is connected to the Western Interconnection.
The standards follow a logical structure. CIP-002 requires entities to identify and categorize their BES Cyber Systems as high, medium or low impact, and the remaining standards set requirements scaled to that categorization. Topics include security management controls, personnel and training, electronic security perimeters, physical security, system security management, incident reporting and response, recovery planning, configuration change management, information protection and supply chain risk management.
Non-compliance can lead to significant financial penalties, and audits are evidence-driven. If you are a registered entity, NERC CIP is not optional, and it will define much of your documentation and change control effort.
Other sector and national rules
The picture does not stop there. Several jurisdictions have introduced sector-specific requirements, particularly since 2021.
In the United States, the Transportation Security Administration issued security directives for pipeline owners and operators following the 2021 Colonial Pipeline ransomware incident, requiring measures such as incident reporting, segmentation and cybersecurity implementation plans.
In Canada, Bill C-8 received Royal Assent in June 2026, enacting the Critical Cyber Systems Protection Act. It covers federally regulated sectors including interprovincial and international pipelines and power lines, and its obligations begin to apply as the Act is brought into force and specific classes of operators are named by regulation.
In the European Union, the NIS2 Directive has broadened cybersecurity obligations across energy, water, manufacturing and other sectors.
How they fit together

The simplest way to think about it:
Regulations tell you what you must do. NERC CIP, TSA directives and national laws are the floor for the organizations they cover.
IEC 62443 tells you how to build a complete, defensible program and gives you a shared vocabulary with vendors and integrators.
NIST SP 800-82 helps you understand and implement it, with free explanatory material and control mappings.
These frameworks overlap heavily. Asset inventory, segmentation, access control, monitoring, incident response and recovery appear in all of them, just organized differently.
A practical approach for multi-country operators
If you operate facilities in several countries, avoid running a separate program for each rulebook.
Map your obligations. List, by site and asset, which regulations actually apply. Many sites will have none beyond general law; some will have several.
Choose one backbone. IEC 62443 is usually the best fit for a multinational operator because it is international and covers asset owners, integrators and suppliers.
Build a control crosswalk. Map your backbone controls to each applicable regulation, so a single control satisfies several requirements and you can see where local rules add something extra.
Meet the strictest requirement once. Where rules differ, implement to the strictest and document how it satisfies the others.
Keep evidence in one place. Regulators and auditors want proof. A common evidence library saves enormous effort at audit time.
Push requirements into contracts. Reference 62443-2-4 for service providers and 62443-4-1 and 4-2 for product suppliers, wherever you operate.
How QBits Networks can help
Our IEC 62443 gap assessments can include a crosswalk to the regulations that apply at each of your sites, so one program covers your obligations instead of several. We also develop policies and procedures that hold up to both audits and day-to-day operations. Tell us what you need through our contact page and we'll scope it with you.