IEC 62443 Certification Path: ISA's Four Certificates

The short answer
The IEC 62443 certification path for engineers runs through the International Society of Automation (ISA): you start with the ISA/IEC 62443 Cybersecurity Fundamentals Specialist certificate (course IC32 and its exam), then add the Risk Assessment Specialist (IC33), Design Specialist (IC34) and Maintenance Specialist (IC37) certificates in any order, and ISA awards the ISA/IEC 62443 Cybersecurity Expert certificate automatically once you hold all four. ISA states that these certificates do not need renewing. The Fundamentals Specialist is required before the others, so it is the one to prepare for first, and you can learn its body of knowledge for free before you register and pay for ISA's course and exam.
Facts about ISA's programme were checked on isa.org on 11 October 2026 (October 2026). Certificate names belong to ISA; check ISA's pages before you book.
The four ISA certificates, in order
ISA's ISA/IEC 62443 Cybersecurity Certificate Program page sets out the path. Each certificate needs its ISA course and a passed exam.
Certificate (ISA's name) | ISA course | Formats listed | Prerequisite |
|---|---|---|---|
1. ISA/IEC 62443 Cybersecurity Fundamentals Specialist | IC32 | IC32, IC32V, IC32E, IC32M | None |
2. ISA/IEC 62443 Cybersecurity Risk Assessment Specialist | IC33 | IC33, IC33V, IC33E, IC33M | Certificate 1 |
3. ISA/IEC 62443 Cybersecurity Design Specialist | IC34 | IC34, IC34V, IC34M | Certificate 1 |
4. ISA/IEC 62443 Cybersecurity Maintenance Specialist | IC37 | IC37, IC37V, IC37M | Certificate 1 |
ISA/IEC 62443 Cybersecurity Expert | None | Awarded automatically | All four certificates |
ISA also runs a Fast Track course (IC48) that combines IC33, IC34 and IC37; you must finish IC32 and its exam first. ISA says plainly that you are not required to renew the certificates.

What the Fundamentals Specialist (IC32) involves
ISA's IC32 course page lists four formats: a two-day classroom course (IC32), a two-day virtual classroom (IC32V), an eight-week instructor-guided online course (IC32E) and a self-paced version (IC32M) in fifteen sections of 25 to 65 minutes each. The course registration includes the exam fee, which is paid to ISA.
There are no required prerequisites, but ISA highly recommends one of three things: one to three years of cybersecurity experience with some exposure to an industrial setting, ISA's TS06 and TS12 courses, or equivalent knowledge. ISA's page does not publish the number of exam questions, the time allowed or the pass mark, so be wary of any figure quoted elsewhere and read ISA's current information when you book.
The topics ISA lists for IC32 are the fundamentals body of knowledge:
- Control systems security and why awareness matters
- The ISA/IEC 62443 series, its models and security levels
- The IACS lifecycle
- Security programme requirements for asset owners and for service providers
- Network security basics and industrial protocols
- Patch management
- Risk assessment for system design
- Secure product development, security profiles and the IACS security protection scheme
- Evolving standards and regulations
Which 62443 parts matter for the fundamentals exam?
The series is written for three roles: the asset owner who runs the plant, the service provider who integrates and maintains it, and the product supplier who makes the components. ISA's 62443 series page lists the parts and their current editions.
Part | Subject in plain words | Main user |
|---|---|---|
1-1 (2007) | Terms, concepts and models | Everyone |
2-1 (2024) | Security programme for asset owners | Asset owner |
2-3 (TR, 2015) | Patch management | Asset owner, supplier |
2-4 (2018) | Security programme for service providers | Integrator, maintainer |
3-2 (2020) | Risk assessment for system design | Asset owner, integrator |
3-3 (2013) | System security requirements and security levels | Integrator |
4-1 (2018) | Secure product development lifecycle | Product supplier |
4-2 (2018) | Technical requirements for components | Product supplier |
You do not need to buy the standards to pass the fundamentals exam, but you must know which part answers which question. A useful test: "Who must do this, and at which stage of the lifecycle?" The answer usually names the part.
Worked example: comparing security level vectors
Security levels are the idea candidates find hardest, and they appear in every certificate on the path. The series rates protection from SL 1 (protection against mistakes) to SL 4 (protection against a well-funded, skilled team), per foundational requirement FR1 to FR7. The asset owner sets a target (SL-T) from the risk assessment, the product supplier states a capability (SL-C), and the installed system has an achieved level (SL-A).
Scenario. A control zone on a packaging line has SL-T = {2, 2, 2, 1, 2, 2, 2} for FR1 to FR7. The proposed controller offers SL-C = {2, 1, 2, 1, 1, 2, 3}. Where are the gaps?
- FR1 identification and authentication: 2 - 2 = 0
- FR2 use control: 2 - 1 = 1, a gap
- FR3 system integrity: 2 - 2 = 0; FR4 data confidentiality: 1 - 1 = 0
- FR5 restricted data flow: 2 - 1 = 1, a gap
- FR6 timely response to events: 2 - 2 = 0; FR7 resource availability: 2 - 3 = -1, capability exceeds target
Two gaps of one level each. Compensate for FR2 with role-based access on the HMI and engineering station that talk to the controller, and for FR5 with a firewall at the zone boundary that allows only the named conduits. Then record the compensating countermeasures, because SL-A depends on how the system is built and run, not only on the product's capability.
A second example: the 3-2 risk check
Part 3-2 compares each zone's risk with the tolerable level. On a 5 by 5 matrix with a tolerable line of 8, a USB-borne malware scenario at likelihood 4 and consequence 5 scores 4 x 5 = 20, well above 8. With application allow-listing and USB control, likelihood falls to 1 and the residual risk is 1 x 5 = 5, which is tolerable. Notice that the consequence did not move: technical controls usually lower likelihood, which is why independent safety layers still matter.

Is the path worth it for engineers in India?
IEC 62443 increasingly appears in specifications for oil and gas, power, water and large manufacturing projects in India and the Gulf, and system integrators are asked to show that their people know it. For a control, instrumentation or automation engineer, the Fundamentals Specialist is a sensible first step because it is required for everything else on ISA's path. The free US guide NIST SP 800-82 Revision 3, published in September 2023, is useful reading alongside it.
Before you spend on ISA's course, make sure the fundamentals make sense to you. Our posts on SCADA cybersecurity and IEC 62443 basics and IEC 62443 zones and conduits are good starting points.
Free preparation before you book with ISA
The free IEC 62443 Cybersecurity Fundamentals Exam Prep course maps fourteen study modules to the topics ISA lists for IC32, with lessons from ICSBit Labs, ISA, exida and others, original notes, worked problems like the two above and original practice questions. Never use "exam dumps": they break ISA's rules and teach you nothing you can use on a plant.
It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page. It is not an ISA or IEC certificate, and EDWartens is not affiliated with ISA. After it, book ISA's IC32 in the format that suits you, or go on to our free OT and ICS Cybersecurity with ISA/IEC 62443 course for the practical side. Start with the IEC 62443 fundamentals exam prep course.
For a classroom route that puts topics like this next to PLC programming, see industrial automation course in Bangalore.
Frequently asked questions
Q: What is the IEC 62443 certification path?
A: ISA's ISA/IEC 62443 Cybersecurity Certificate Program has four certificates: Fundamentals Specialist (IC32), Risk Assessment Specialist (IC33), Design Specialist (IC34) and Maintenance Specialist (IC37). The Fundamentals Specialist comes first; the other three follow in any order, and holding all four earns the Cybersecurity Expert certificate automatically.
Q: Which IEC 62443 certificate should I take first?
A: The ISA/IEC 62443 Cybersecurity Fundamentals Specialist. ISA requires it before the Risk Assessment, Design and Maintenance Specialist certificates.
Q: Do ISA/IEC 62443 certificates expire?
A: No. ISA's certificate programme page, read on 11 October 2026, states that you are not required to renew your ISA/IEC 62443 certificates.
Q: Is the IC32 exam fee included in the course?
A: Yes. ISA's IC32 page says the course registration includes the exam fee, which is paid to ISA.
Q: How many questions are on the ISA 62443 fundamentals exam?
A: ISA's IC32 page does not publish the question count, time or pass mark. Read ISA's current information when you book rather than trusting a figure quoted on another site.
Q: Is there a free IEC 62443 course with a certificate?
A: Yes. EDWartens' IEC 62443 Cybersecurity Fundamentals Exam Prep is a free course with a verifiable certificate of completion, mapped to the topics ISA lists for IC32. It is not the ISA certificate.
Learn this, free
The courses that teach this
Every lesson, the written notes and the practice are free with an account. Only the certificate is optional and paid.




