Manufacturing
Quality systems and operational technology compliance
Manufacturing organizations operate complex OT environments alongside traditional IT systems, creating unique cybersecurity challenges. Thalorin supports manufacturers with compliance infrastructure addressing OT security, quality management integration, and the supply chain security requirements of modern manufacturing.
NIST IR 8183 Revision 1, the profile written specifically for manufacturing, published in October 2020 and still maps to Cybersecurity Framework version 1.1 — the version NIST replaced with CSF 2.0 in February 2024, when the Govern function arrived. SP 800-82 Revision 3, Guide to Operational Technology (OT) Security, is the newer reference, published September 2023, and is still the current final revision with a Revision 4 draft in circulation. The documents a plant is pointed at run on different clocks, and a plant aligned to the Manufacturing Profile is reporting against a framework version the rest of the organisation has left.
ISA/IEC 62443 is not a standard but a series that assigns duty by role, and its parts are not on one edition. 62443-2-1, the security programme requirements for asset owners, was reissued in 2024. 62443-3-3, the system security requirements and security levels, still carries 2013. 62443-4-1 and 62443-4-2, which bind product suppliers, date from 2018, and 62443-3-2, the risk assessment that partitions a system into zones and conduits, from 2020. A contract clause reading "compliant with IEC 62443" names none of this, and the argument that follows is about which role it binds.
The certificate a machine builder supplies is the most misread artifact on the plant floor. ISASecure CSA certifies a component against 62443-4-2 and SDLA certifies the supplier development lifecycle against 62443-4-1; neither says anything about the cell as installed, which is judged against 62443-3-3. The second thing consistently underestimated is access. OEM maintenance tunnels into drives, robots and controllers are usually written into the service agreement, terminate below the corporate identity system, and are discovered during an assessment rather than declared before it.
What the platform holds is the zone, not the checklist. Every zone and conduit from the 62443-3-2 partition carries its target security level, the assets inside it and the evidence those assets produce, so a firmware change, a new historian interface or an added remote-access path raises the affected requirements in 62443-3-3 and in the SP 800-82 Revision 3 control set at the moment it happens, rather than waiting for an audit to notice.
Manufacturing faces evolving cyber risks
A manufacturing profile stuck on CSF 1.1
NIST IR 8183 Revision 1 dates from October 2020 and maps to Framework version 1.1. CSF 2.0 arrived in February 2024 with a Govern function the older mapping has no counterpart for, so sector view and enterprise reporting no longer agree.
62443 parts on different edition clocks
Asset-owner requirements were reissued in 2024 while the system security requirements still carry 2013 and the product-supplier parts 2018. Reading the series as one document produces obligations belonging to a role the organisation does not occupy.
Supplier certificates read as system assurance
An ISASecure component certificate covers the device against 62443-4-2 in the configuration tested. The installed cell, with its engineering workstation, its historian link and its service contract, is a different object assessed against a different part.
OEM remote access inside the warranty
Machine builders retain maintenance paths into drives and controllers as a condition of service cover. Those paths sit outside the corporate identity system and rarely appear on the asset inventory a 62443 assessment starts from.
How Thalorin helps
OT/ICS security controls
Assess against the system security requirements in ISA/IEC 62443-3-3 and the operational technology control set in NIST SP 800-82 Revision 3, with each requirement bound to the zone and the specific devices that satisfy it.
Quality management integration
A firmware or configuration change on a qualified line is a quality change before it is a security one, so control evidence binds to the change record and to the part numbers the line was running.
Manufacturing execution security
The execution system is where the IT and OT boundary actually sits. Its interfaces, from order release to batch reporting, are modelled as conduits with their own target security level rather than as internal traffic.
Plant floor cybersecurity
Inventory is assembled from passive capture, engineering project files and controller backups instead of active scanning, because a discovery scan that halts a programmable logic controller is an outage with a production cost attached.
Supply chain traceability
Component and firmware provenance is carried against the equipment that runs it, so a newly disclosed vulnerability in an embedded controller resolves to specific machines and to the lots those machines produced.
Industry 4.0 security
Gateways, brokers and edge nodes added for connected production enter the zone model on installation, and supplier claims are read against the 62443-4-2 component requirements they were actually certified to.
Manufacturing: common questions
Which part of IEC 62443 applies to us as the plant operator rather than the machine builder?
62443-2-1, the security programme requirements for IACS asset owners, reissued in 2024. Machine builders and component vendors are bound by 62443-4-1 for their development lifecycle and 62443-4-2 for the components themselves; integrators and maintenance providers by 62443-2-4, the requirements for IACS service providers. The system in front of you is assessed against 62443-3-3, once 62443-3-2 has partitioned it into zones and conduits with a target security level for each. Most disputes over a 62443 clause are really disputes about which role it binds.
Does our machine vendor's ISASecure certificate make our production line compliant?
No. ISASecure CSA certifies a component against ISA/IEC 62443-4-2, and SDLA certifies the supplier's development process against 62443-4-1. Both are statements about what arrived on the pallet. The installed line, with its engineering workstation, its historian connection and whatever remote access the service contract grants, is a system judged against 62443-3-3. The ISASecure scheme that reaches an operating automation control system is ACSSA, which covers 62443-2-1, 2-4, 3-2 and 3-3 together.
Is the NIST Manufacturing Profile still usable now that CSF 2.0 is published?
It remains a useful sector view of what matters in a plant, but read it for what it is. NIST IR 8183 Revision 1 published in October 2020 and maps to Cybersecurity Framework version 1.1. CSF 2.0 replaced that version in February 2024 and introduced Govern, which the older mapping has no equivalent for. If the wider organisation reports against CSF 2.0, the profile's categories need re-pointing before plant and enterprise evidence describe the same posture.
How do we build an OT asset inventory without stopping production?
Passively, and from records. Port-mirrored capture on cell and plant networks identifies what is talking; engineering project files, controller backups and drive parameter sets identify what is installed but silent; maintenance records identify what has been swapped since commissioning. Active scanning is the method to avoid, because older controllers and safety devices have been knocked offline by ordinary port scans, and an outage caused by a security tool costs you standing on the plant network.
Does a security patch on a qualified line need to go through quality change control?
Treat it as though it does. A change to controller firmware, to an operator interface image, or to a network path on a line whose output is qualified is a change to the production process, and the quality system is entitled to see it. The consequence is that vulnerability response on the plant floor runs at the speed of change control rather than the speed of the advisory, which is why compensating controls carry most of the actual risk reduction.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Manufacturing.
See how one evidence artifact satisfies Manufacturing requirements alongside every other framework you carry.