Skip to main content
ControlBirdControlBird
  • Features
  • Use Cases
  • Pricing
  • Docs
  • Blog
  • Log in Get Started
  • Dark Mode
Log in Get Started
← All standards
Designed to support

ISA/IEC 62443

Security for Industrial Automation & Control Systems

Overview

ISA/IEC 62443 is the leading framework for securing industrial automation and control systems across their lifecycle. It divides responsibility between the asset owner, the system integrator, and the product supplier, and organises technical security into a set of foundational requirements, the idea of splitting a system into zones with controlled conduits between them, and graded security levels. Tenders for OT and critical infrastructure increasingly ask for components that can be deployed into a 62443-aligned architecture. ControlBird provides the identity, access-control, encryption, and resilience building blocks a component contributes; the surrounding security programme and any certification belong to the operator and integrator.

Key requirements

Identification and authentication
Uniquely identify and authenticate every user and device before granting access to the control system.
Use control
Once authenticated, enforce least-privilege authorisation over what each user or service is allowed to do.
Data confidentiality and integrity
Protect data in transit and at rest against disclosure and tampering.
Restricted data flow and availability
Segment the system into zones with controlled conduits, and keep the control system available and recoverable under stress.

How ControlBird aligns

Identification and authentication
Users sign in with native accounts (strong password hashing, a configurable password policy, and lockout after repeated failures) or through your existing directory over LDAP and Active Directory, or an OAuth 2.0 provider. Delegating sign-in to your identity provider also lets that provider apply multi-factor authentication, which ControlBird does not perform itself.
Least-privilege use control
Access control is enforced in the data layer on every read and write, not only in the interface. Permissions can be role-based and attribute-based: each rule grants a scope (read-only, read/write, or full) down to the entity type, the individual field, and a specific branch of the tree, and can carry a condition evaluated at access time, so access depends on attributes and context rather than role alone. A separate set of interface permissions governs what each user sees in the apps.
Confidentiality in transit
TLS 1.2 and 1.3 protect the web and API layer and the OPC UA, MQTT, Modbus TCP, and DNP3 protocols, with certificates issued, renewed, and monitored by a built-in Certificate Manager that includes ACME and Let’s Encrypt. Encryption at rest is the operator’s responsibility through disk or volume encryption, and some legacy or serial protocols cannot be encrypted, so place those in a trusted segment or tunnel.
Availability and recovery
Leader election, multi-node replication, and client failover keep services running when a node fails, and point-in-time snapshots with write-ahead-log replay restore state. This matches the resource availability the framework prioritises for control systems.
What the operator and integrator own
62443 is a programme shared across the asset owner, integrator, and product supplier, not a product setting. ControlBird supplies component-level controls — including writes that are attributed to the authenticated user and can be recorded as a queryable change history for accountability — while the zones and conduits, network segmentation, security-level targets, the wider monitoring programme, and certification are defined and owned by your team. ControlBird is not 62443 certified.

Need this for a tender?

We can provide deployment-specific detail and supporting documentation for procurement and security reviews.

Talk to our teamBack to all standards
ControlBirdControlBird

Real-time automation platform for smart devices and industrial equipment.

Product

  • Pricing
  • Release Notes

Resources

  • Documentation
  • Walkthrough
  • Blog
  • Compare
  • Standards & Compliance
  • Status
  • GitHub

Company

  • Contact Sales
  • Support
  • Careers

Legal

  • Terms of Service
  • Privacy Policy

© 2026 Qureshi Enterprise Inc. All rights reserved.