---
title: "IEC 62443-3-3 SL2 Requirements — CAN Quick Reference"
canonical_url: https://can-security.net/resources/iec-62443-sl2-requirements/
description: "Quick-reference matrix mapping the CAN-relevant IEC 62443-3-3 system requirements at Security Level 2 to the defensive controls available for CAN products."
last_updated: 2026-08-27
---
# IEC 62443-3-3 SL2 Requirements

[IEC 62443](https://can-security.net/resources/terms-and-definitions/#term-iec-62443)-3-3 defines a set of system requirements (SRs), grouped under seven Foundational Requirements (FRs), and specifies which SRs and which requirement enhancements apply at each Security Level (SL1 to SL4). The matrix below covers **only the CAN-relevant SRs at SL2**, mapped to the primary and secondary defensive measures available for CAN-based products on this site. SRs that govern human-user account management, session locks, mobile code, portable device controls, and PKI-style authentication apply to the surrounding control system rather than to the CAN bus and are deliberately omitted here. Wording in the second column is a short paraphrase for matrix use; the binding text is the standard itself.

## Requirement-to-Measure Matrix

Each row names an IEC 62443-3-3 SR identifier, the Foundational Requirement it belongs to, a short paraphrase of the SL2 obligation, and the controls that address it on CAN. Primary is the most direct control; secondary is the most common complement. Full text and the exact SL1-to-SL4 enhancement pattern are in IEC 62443-3-3 itself.

*CAN-relevant IEC 62443-3-3 system requirements at Security Level 2, mapped to defensive measures available for CAN-based products.*

| SR | Requirement (short) | Measures |
| --- | --- | --- |
| **SR 1.2** | Identify and authenticate every device and process | Primary: [SOFA](https://can-security.net/solutions/secure-object-fieldbus-access/) Secondary: [Frame Security](https://can-security.net/solutions/frame-security/) |
| **SR 1.5** | Manage authenticators across full lifecycle | Primary: [SOFA](https://can-security.net/solutions/secure-object-fieldbus-access/) Secondary: [Secure Bootloader](https://can-security.net/solutions/secure-bootloader/) |
| **SR 1.13** | Authenticate access via untrusted networks | Primary: [Secure Gateways](https://can-security.net/risk-assessment/secure-gateways/) Secondary: [Access Limitation](https://can-security.net/risk-assessment/access-limitation/) |
| **SR 2.1** | Enforce authorization on all use | Primary: [SOFA](https://can-security.net/solutions/secure-object-fieldbus-access/) Secondary: [Frame Security](https://can-security.net/solutions/frame-security/) |
| **SR 2.8** | Generate audit records for security events | Primary: [Anomaly Event Monitoring](https://can-security.net/solutions/anomaly-event-monitoring/) |
| **SR 2.11** | Timestamp audit records reliably | Primary: [Anomaly Event Monitoring](https://can-security.net/solutions/anomaly-event-monitoring/) |
| **SR 2.12** | Non-repudiation of security-relevant actions | Primary: [Frame Security](https://can-security.net/solutions/frame-security/) Secondary: [Anomaly Event Monitoring](https://can-security.net/solutions/anomaly-event-monitoring/) |
| **SR 3.1** | Protect integrity of transmitted information | Primary: [Frame Security](https://can-security.net/solutions/frame-security/) Secondary: [Local Injection Detection](https://can-security.net/solutions/local-injection-detection/) |
| **SR 3.4** | Protect software and information integrity | Primary: [Secure Bootloader](https://can-security.net/solutions/secure-bootloader/) Secondary: [SOFA](https://can-security.net/solutions/secure-object-fieldbus-access/) |
| **SR 3.8** | Protect session integrity including replay | Primary: [Frame Security](https://can-security.net/solutions/frame-security/) Secondary: [Anomaly Event Monitoring](https://can-security.net/solutions/anomaly-event-monitoring/) |
| **SR 4.1** | Protect confidentiality of information | Primary: [Frame Security](https://can-security.net/solutions/frame-security/) Secondary: [SOFA](https://can-security.net/solutions/secure-object-fieldbus-access/) |
| **SR 4.3** | Use recognized cryptographic mechanisms | Primary: [Frame Security](https://can-security.net/solutions/frame-security/) Secondary: [SOFA](https://can-security.net/solutions/secure-object-fieldbus-access/) |
| **SR 5.1** | Partition system into zones and conduits | Primary: [Zoning and Segmentation](https://can-security.net/solutions/zoning-segmentation/) |
| **SR 5.2** | Protect each zone boundary | Primary: [Secure Gateways](https://can-security.net/risk-assessment/secure-gateways/) |
| **SR 6.2** | Continuously monitor security events | Primary: [Anomaly Event Monitoring](https://can-security.net/solutions/anomaly-event-monitoring/) |
| **SR 7.1** | Protect against denial of service | Primary: [Bus Load Monitoring](https://can-security.net/solutions/bus-load-monitoring/) Secondary: [Anomaly Event Monitoring](https://can-security.net/solutions/anomaly-event-monitoring/) |
| **SR 7.6** | Minimize network and security exposure | Primary: [Secure Gateways](https://can-security.net/risk-assessment/secure-gateways/) Secondary: [Access Limitation](https://can-security.net/risk-assessment/access-limitation/) |

The full IEC 62443-3-3 text, including the binding wording of every SR and the exact SL1-to-SL4 enhancement pattern, is published by the IEC. The series overview is at [iec.ch/cyber-security](https://www.iec.ch/cyber-security). For methodology context on how these system requirements relate to the risk-assessment process that produces a target SL, see [IEC 62443-Style Assessment](https://can-security.net/risk-assessment/iec-62443/).

## Component Requirements (IEC 62443-4-2)

The matrix above lists system requirements from IEC 62443-3-3. IEC 62443-4-2 states the parallel *component* requirements that a single device must meet, and the Key Management section refers to these by their CR identifiers. The CAN-relevant ones at Security Level 2 are collected here so those references resolve to a definition. The numbering mirrors the system requirements, so CR 1.2 corresponds to SR 1.2, and so on.

*CAN-relevant IEC 62443-4-2 component requirements at Security Level 2, with the Key Management pages that cover each.*

| CR | Requirement (short) | Covered under |
| --- | --- | --- |
| **CR 1.2** | Identify and authenticate the device | [Regulations & Standards](https://can-security.net/key-management/regulations-standards/) |
| **CR 1.5** | Manage authenticators across the lifecycle | [Symmetric Key Management](https://can-security.net/key-management/symmetric-key-management/) |
| **CR 1.8** | PKI certificates, when a PKI is used | [Asymmetric Key Management](https://can-security.net/key-management/asymmetric-key-management/) |
| **CR 1.9** | Strength of public-key authentication | [Asymmetric Key Management](https://can-security.net/key-management/asymmetric-key-management/) |
| **CR 1.14** | Symmetric-key authentication | [Symmetric vs Asymmetric](https://can-security.net/key-management/symmetric-vs-asymmetric/) |
| **CR 3.1** | Communication integrity | [Frame Security](https://can-security.net/solutions/frame-security/) |
| **CR 4.2** | Zeroize keys at end of life | [Symmetric Key Management](https://can-security.net/key-management/symmetric-key-management/) |
| **CR 4.3** | Use of proven cryptography | [Symmetric vs Asymmetric](https://can-security.net/key-management/symmetric-vs-asymmetric/) |

> ### EmSA Security Consulting

> For the two cases not covered by the off-the-shelf catalog and the courses, we review how the CAN-relevant SRs map to your risk-assessment record, or customize a Solutions shell where the SL2 baseline needs reinforcement at SL3 with cryptographic frame authentication.

> [Talk to ESAcademy →](https://www.esacademy.com/en/security.html)

## Frequently Asked Questions

### Which SRs from IEC 62443-3-3 are shown on this page?

Only the system requirements at Security Level 2 that have a meaningful application to CAN or CAN FD bus security. IEC 62443-3-3 also includes SRs about human-user account management, session locks, mobile code, portable device controls, and PKI-style authentication that do not apply at the bus level and are out of scope for this reference. The skipped SRs remain relevant for the surrounding control system, just not for the CAN-specific shells cataloged on this site.

### What does Security Level 2 mean?

IEC 62443 SL2 is the second of four Security Levels. SL1 protects against incidental misuse; SL2 protects against intentional violation using simple means with low resources, generic skills, and low motivation. SL3 raises the bar to moderate resources with technology-specific skills, and SL4 to extended resources. For most industrial CAN products, SL2 is the practical baseline; reaching SL3 typically requires cryptographic frame authentication via [Frame Security](https://can-security.net/solutions/frame-security/).

### Are these mappings binding?

No. The mappings are guidance derived from the EmSA reference architecture. [IEC 62443-3-3](https://www.iec.ch/cyber-security) itself is the binding text; compliance is the responsibility of the manufacturer or integrator and, where applicable, the certifying body. Use this matrix to scope the design discussion, not as a substitute for a documented [Risk Assessment](https://can-security.net/risk-assessment/).
