Industrial Automation

IEC 62443 Certification Path: ISA's Four Certificates

EDWartens Engineering Team
8 min read
IEC 62443 Certification Path: ISA's Four Certificates

The short answer

The IEC 62443 certification path for engineers runs through the International Society of Automation (ISA): you start with the ISA/IEC 62443 Cybersecurity Fundamentals Specialist certificate (course IC32 and its exam), then add the Risk Assessment Specialist (IC33), Design Specialist (IC34) and Maintenance Specialist (IC37) certificates in any order, and ISA awards the ISA/IEC 62443 Cybersecurity Expert certificate automatically once you hold all four. ISA states that these certificates do not need renewing. The Fundamentals Specialist is required before the others, so it is the one to prepare for first, and you can learn its body of knowledge for free before you register and pay for ISA's course and exam.

Facts about ISA's programme were checked on isa.org on 11 October 2026 (October 2026). Certificate names belong to ISA; check ISA's pages before you book.

The four ISA certificates, in order

ISA's ISA/IEC 62443 Cybersecurity Certificate Program page sets out the path. Each certificate needs its ISA course and a passed exam.

Certificate (ISA's name)
ISA course
Formats listed
Prerequisite
1. ISA/IEC 62443 Cybersecurity Fundamentals Specialist
IC32
IC32, IC32V, IC32E, IC32M
None
2. ISA/IEC 62443 Cybersecurity Risk Assessment Specialist
IC33
IC33, IC33V, IC33E, IC33M
Certificate 1
3. ISA/IEC 62443 Cybersecurity Design Specialist
IC34
IC34, IC34V, IC34M
Certificate 1
4. ISA/IEC 62443 Cybersecurity Maintenance Specialist
IC37
IC37, IC37V, IC37M
Certificate 1
ISA/IEC 62443 Cybersecurity Expert
None
Awarded automatically
All four certificates

ISA also runs a Fast Track course (IC48) that combines IC33, IC34 and IC37; you must finish IC32 and its exam first. ISA says plainly that you are not required to renew the certificates.

Diagram of ISA's IEC 62443 certificate path from Fundamentals Specialist to Expert
Diagram of ISA's IEC 62443 certificate path from Fundamentals Specialist to Expert

What the Fundamentals Specialist (IC32) involves

ISA's IC32 course page lists four formats: a two-day classroom course (IC32), a two-day virtual classroom (IC32V), an eight-week instructor-guided online course (IC32E) and a self-paced version (IC32M) in fifteen sections of 25 to 65 minutes each. The course registration includes the exam fee, which is paid to ISA.

There are no required prerequisites, but ISA highly recommends one of three things: one to three years of cybersecurity experience with some exposure to an industrial setting, ISA's TS06 and TS12 courses, or equivalent knowledge. ISA's page does not publish the number of exam questions, the time allowed or the pass mark, so be wary of any figure quoted elsewhere and read ISA's current information when you book.

The topics ISA lists for IC32 are the fundamentals body of knowledge:

  • Control systems security and why awareness matters
  • The ISA/IEC 62443 series, its models and security levels
  • The IACS lifecycle
  • Security programme requirements for asset owners and for service providers
  • Network security basics and industrial protocols
  • Patch management
  • Risk assessment for system design
  • Secure product development, security profiles and the IACS security protection scheme
  • Evolving standards and regulations

Which 62443 parts matter for the fundamentals exam?

The series is written for three roles: the asset owner who runs the plant, the service provider who integrates and maintains it, and the product supplier who makes the components. ISA's 62443 series page lists the parts and their current editions.

Part
Subject in plain words
Main user
1-1 (2007)
Terms, concepts and models
Everyone
2-1 (2024)
Security programme for asset owners
Asset owner
2-3 (TR, 2015)
Patch management
Asset owner, supplier
2-4 (2018)
Security programme for service providers
Integrator, maintainer
3-2 (2020)
Risk assessment for system design
Asset owner, integrator
3-3 (2013)
System security requirements and security levels
Integrator
4-1 (2018)
Secure product development lifecycle
Product supplier
4-2 (2018)
Technical requirements for components
Product supplier

You do not need to buy the standards to pass the fundamentals exam, but you must know which part answers which question. A useful test: "Who must do this, and at which stage of the lifecycle?" The answer usually names the part.

Worked example: comparing security level vectors

Security levels are the idea candidates find hardest, and they appear in every certificate on the path. The series rates protection from SL 1 (protection against mistakes) to SL 4 (protection against a well-funded, skilled team), per foundational requirement FR1 to FR7. The asset owner sets a target (SL-T) from the risk assessment, the product supplier states a capability (SL-C), and the installed system has an achieved level (SL-A).

Scenario. A control zone on a packaging line has SL-T = {2, 2, 2, 1, 2, 2, 2} for FR1 to FR7. The proposed controller offers SL-C = {2, 1, 2, 1, 1, 2, 3}. Where are the gaps?

  1. FR1 identification and authentication: 2 - 2 = 0
  2. FR2 use control: 2 - 1 = 1, a gap
  3. FR3 system integrity: 2 - 2 = 0; FR4 data confidentiality: 1 - 1 = 0
  4. FR5 restricted data flow: 2 - 1 = 1, a gap
  5. FR6 timely response to events: 2 - 2 = 0; FR7 resource availability: 2 - 3 = -1, capability exceeds target

Two gaps of one level each. Compensate for FR2 with role-based access on the HMI and engineering station that talk to the controller, and for FR5 with a firewall at the zone boundary that allows only the named conduits. Then record the compensating countermeasures, because SL-A depends on how the system is built and run, not only on the product's capability.

A second example: the 3-2 risk check

Part 3-2 compares each zone's risk with the tolerable level. On a 5 by 5 matrix with a tolerable line of 8, a USB-borne malware scenario at likelihood 4 and consequence 5 scores 4 x 5 = 20, well above 8. With application allow-listing and USB control, likelihood falls to 1 and the residual risk is 1 x 5 = 5, which is tolerable. Notice that the consequence did not move: technical controls usually lower likelihood, which is why independent safety layers still matter.

Checklist for preparing for the ISA/IEC 62443 Fundamentals Specialist exam
Checklist for preparing for the ISA/IEC 62443 Fundamentals Specialist exam

Is the path worth it for engineers in India?

IEC 62443 increasingly appears in specifications for oil and gas, power, water and large manufacturing projects in India and the Gulf, and system integrators are asked to show that their people know it. For a control, instrumentation or automation engineer, the Fundamentals Specialist is a sensible first step because it is required for everything else on ISA's path. The free US guide NIST SP 800-82 Revision 3, published in September 2023, is useful reading alongside it.

Before you spend on ISA's course, make sure the fundamentals make sense to you. Our posts on SCADA cybersecurity and IEC 62443 basics and IEC 62443 zones and conduits are good starting points.

Free preparation before you book with ISA

The free IEC 62443 Cybersecurity Fundamentals Exam Prep course maps fourteen study modules to the topics ISA lists for IC32, with lessons from ICSBit Labs, ISA, exida and others, original notes, worked problems like the two above and original practice questions. Never use "exam dumps": they break ISA's rules and teach you nothing you can use on a plant.

It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page. It is not an ISA or IEC certificate, and EDWartens is not affiliated with ISA. After it, book ISA's IC32 in the format that suits you, or go on to our free OT and ICS Cybersecurity with ISA/IEC 62443 course for the practical side. Start with the IEC 62443 fundamentals exam prep course.

For a classroom route that puts topics like this next to PLC programming, see industrial automation course in Bangalore.

Frequently asked questions

Q: What is the IEC 62443 certification path?
A: ISA's ISA/IEC 62443 Cybersecurity Certificate Program has four certificates: Fundamentals Specialist (IC32), Risk Assessment Specialist (IC33), Design Specialist (IC34) and Maintenance Specialist (IC37). The Fundamentals Specialist comes first; the other three follow in any order, and holding all four earns the Cybersecurity Expert certificate automatically.

Q: Which IEC 62443 certificate should I take first?
A: The ISA/IEC 62443 Cybersecurity Fundamentals Specialist. ISA requires it before the Risk Assessment, Design and Maintenance Specialist certificates.

Q: Do ISA/IEC 62443 certificates expire?
A: No. ISA's certificate programme page, read on 11 October 2026, states that you are not required to renew your ISA/IEC 62443 certificates.

Q: Is the IC32 exam fee included in the course?
A: Yes. ISA's IC32 page says the course registration includes the exam fee, which is paid to ISA.

Q: How many questions are on the ISA 62443 fundamentals exam?
A: ISA's IC32 page does not publish the question count, time or pass mark. Read ISA's current information when you book rather than trusting a figure quoted on another site.

Q: Is there a free IEC 62443 course with a certificate?
A: Yes. EDWartens' IEC 62443 Cybersecurity Fundamentals Exam Prep is a free course with a verifiable certificate of completion, mapped to the topics ISA lists for IC32. It is not the ISA certificate.

Learn this, free

The courses that teach this

Every lesson, the written notes and the practice are free with an account. Only the certificate is optional and paid.

Start Your Engineering Career at EDWartens

Join as a Junior Engineer at Wartens Automation Pvt Ltd. Learn PLC and SCADA in our Electronic City classroom on wired PLC panels, and earn a Wartens Experience Certificate. Job guarantee or programme fee refunded (conditions apply). It runs for the six months after you complete the programme. See the placement policy.