STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
IEC 62443 (series)

IEC 62443

IEC 62443 is the reference series for the security of industrial automation and control systems (IACS). Its security-level and requirement structure gives industrial buyers a familiar frame for a robot policy’s adversarial-robustness evidence.

Series of standards; referenced by industrial-security assessors.Evidence, not certification.
What it is

The framework

  • A multi-part series covering IACS security across asset owners, integrators and product suppliers.
  • It defines Security Levels (SL 1-4) reflecting resistance to increasingly capable adversaries.
  • It is the de-facto expectation for OT/industrial security in many procurement processes.
The hook

Where a red-team result fits

Security levels

IEC 62443 separates SL-T (the level a zone is required to reach, set by the operator’s risk assessment), SL-C (the level a component can reach when correctly configured) and SL-A (the level the deployed system actually reaches). A measured ASR under defined attack channels is an input to assessing SL-A for the policy layer against those channels — not a target, not a capability claim, and not a determination of any SL.

What Provael maps to it

Evidence produced

  • Adversarial-robustness evidence framed against attacker capability (the SL model).
  • A per-channel breakdown mapping to distinct threat vectors.
  • Reproducible artifacts an integrator can fold into a 62443-3-3 system assessment.
Timing

Dates (verified 19 Aug 2026)

Series status
Actively maintained (multi-part)
Sources

Primary references

How to read this mapping

What it is - and isn’t

  • adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
  • evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case - The measured result uses templated, auditable attacks; the search-based families (optimized, universal_patch, gradient_patch) have only met the CPU fixture. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.