IEC 62443 Implementation Toolkit by Kai London
Reading the standard is the easy part. This is the working kit — the registers, worksheets and evidence structures that turn IEC 62443 from a shelf document into a programme a site can actually run and an assessor can actually test.
Available on Amazon. An independent practitioner guide — not affiliated with or endorsed by any standards body or certification scheme.
What is inside
Zone and conduit registers
Templates for defining, documenting and maintaining zones and conduits that survive a plant change and an audit.
Risk assessment worksheets
High-level and detailed risk assessment structures, consequence scaling, and how to keep the results defensible.
Security level planning
Setting target levels, testing achieved levels, and recording the gap with a remediation route rather than an excuse.
Supplier and integrator requirements
Procurement language, acceptance criteria and handover evidence for system integrators and product suppliers.
Policies and procedures
The security programme documents an asset owner needs, written for people who maintain equipment, not lawyers.
Audit evidence packs
How to assemble, version and present the evidence so assessment does not become an archaeology exercise.
Who it is for: asset owners and OT programme managers building to IEC 62443, system integrators proving conformity to clients, and internal auditors testing industrial control environments.
A control you cannot evidence is a control you do not have.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.