Skip to content
Part 1 ยท Module 3 of 15Course syllabus
Course progress0%
Module 3 of 15Part 1: Foundations

Regulations and Standards Landscape

An orientation to the regulations, standards and guidance commonly encountered in industrial cyber security.

30 minutesFoundationReviewed 15 July 2026
Course progress0%

Learning objectives

  • Distinguish legal duties, regulatory guidance, standards, frameworks and project specifications.
  • Explain how IEC 62443 fits alongside UK and EU law, the NCSC CAF, NIST guidance and ISO/IEC 27001.
  • Build an applicability register for a project.
  • Avoid treating compliance as proof that risk is acceptable.

Introduction

This module maps the principal sources that shape industrial cyber security expectations.

Planned video lesson

Module 03 video lesson

Video lesson coming soon. The written module can be completed without the video.

Planned recording: 7-9 minutes explaining the difference between law, a regulator outcome, a standard and a project โ€œshallโ€ requirement.

Transcript will be added with the video.

Main lesson

Five different types of requirement

Cyber documents do not all have the same authority.

SourceWhat it doesProject question
Law and regulationCreates legal duties and regulatory powersWhich organisation, service and system are in scope?
Regulator or competent-authority guidanceInterprets expected outcomes for a sectorWhich profile, evidence and reporting route apply?
StandardDefines agreed processes, requirements or technical practicesWhich part and edition is contractually invoked?
FrameworkOrganises outcomes and assessmentHow will maturity or resilience be evaluated?
Project specificationConverts the above into deliverable requirementsWho must do what, by when, and provide which evidence?

A standard may become contractually mandatory even when it is not named directly in legislation. Conversely, writing โ€œcomply with IEC 62443โ€ in a specification does not define a usable requirement because the series covers different roles, lifecycles and levels of abstraction.

UK context

For a UK project, establish at least:

  • Whether the operator provides an essential or regulated service.
  • Whether the Network and Information Systems Regulations 2018 or sector-specific duties apply.
  • The relevant competent authority and current sector guidance.
  • Whether an NCSC Cyber Assessment Framework profile or overlay is required.
  • Relevant health, safety, environmental and data-protection duties.
  • Contractual standards, client policies and assurance gates.

The Network and Information Systems Regulations 2018 remain the UK's current cross-sector cyber security regime for operators of essential services and relevant digital service providers. The Cyber Security and Resilience (Network and Information Systems) Bill would amend and extend that regime. As at 15 July 2026, the Bill has passed the House of Commons and completed its second reading in the House of Lords, but it is not yet law. Treat proposed duties as a change to monitor, not as an enacted requirement.

EU context

For systems, services or products within the EU market, also establish:

  • Which Member State's law transposes Directive (EU) 2022/2555 (NIS2) and which competent authority applies. NIS2 is a directive implemented through national law, so the operative duties and procedures must be checked in the relevant jurisdiction.
  • Whether the organisation is an essential or important entity and whether the affected service and supply chain are in scope.
  • Whether a hardware or software product is a product with digital elements under Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA). The CRA's reporting duties apply from 11 September 2026 and its main obligations apply from 11 December 2027.
  • Whether Regulation (EU) 2023/1230 on machinery applies to the delivered machine or related product from 20 January 2027, including protection against corruption of safety-relevant hardware, software and data.
  • Relevant sector legislation, product-conformity duties, data protection and contractual requirements.

EU rules do not automatically become UK law, and UK rules do not establish EU conformity. A UK supplier placing a product on the EU market may need to satisfy both regimes for different reasons.

The legal position and regulatory guidance can change. Record the source, owner, jurisdiction, version or access date, and next review date. Do not freeze a training-page summary into a twenty-year design basis. This module is engineering guidance, not legal advice.

How the common references complement one another

  • IEC 62443 provides role-based industrial security processes and system or component requirements.
  • NCSC CAF provides outcome-focused assessment for cyber resilience, especially around essential functions.
  • NIST SP 800-82 provides accessible OT security guidance, architectures, threats and safeguards.
  • ISO/IEC 27001 provides an organisation-wide information security management system.
  • NIST Cybersecurity Framework provides a common structure for governing and managing cyber risk.

These references overlap, but they are not interchangeable. A CAF assessment does not automatically prove IEC 62443 conformance. An ISO/IEC 27001 certificate does not demonstrate that a particular control system has suitable zones, conduits or recovery arrangements.

Build an applicability register

For every source, record:

  1. Document and edition or current web source.
  2. Reason it applies.
  3. System, service or organisation in scope.
  4. Responsible interpreter.
  5. Required deliverables or evidence.
  6. Conflicts, assumptions and exclusions.
  7. Review date.

This small register prevents standards being cited without ownership or consequence.

Planned original figure โ€” M03-F01

Create a five-layer UK project diagram: law, regulator, assurance framework, engineering standards and project implementation evidence.

Planned asset: /static/training/ot-cyber-security/module-03/figure-01.svg

Engineering example

Riverside application

Riverside needs a traceable applicability register so legal duties, guidance, standards and project requirements are not treated as interchangeable.

Practical activity

Apply what you learned

Create an applicability register with rows for:

  • Client cyber policy.
  • Applicable UK regulation and competent-authority guidance.
  • Applicable EU and Member-State legislation where the service or product is placed on the EU market.
  • NCSC CAF or other assurance framework.
  • IEC 62443-2-1, 2-4, 3-2, 3-3, 4-1 and 4-2 where relevant.
  • Functional-safety and electrical standards affected by cyber decisions.

Do not mark every document โ€œfully applicableโ€. State which role, activity and deliverable each one governs.

Record your reasoning and project notes here. Your response stays in this browser and is not submitted to the website.

Loading saved responseโ€ฆ

0 / 10,000

Do not enter real credentials, confidential network details, sensitive asset information or security-sensitive project data.

Knowledge check

Answer every question correctly to complete this module. If an answer is incorrect, review the explanation and try again. This is not a formal examination.

1. A specification says only โ€œthe solution shall comply with IEC 62443โ€. What is the best correction?
2. A UK supplier will place an industrial controller on the EU market and support it for an EU essential entity. Which approach is correct?
3. What does an in-scope ISO/IEC 27001 certificate provide when assessing a specific OT system?
0 of 3 questions answered correctly.

Key takeaways

Remember these points

  • Law, regulation, standards, frameworks and project specifications have different authority and purposes.

  • An applicability register records scope, ownership, edition, evidence and review expectations.

  • Compliance claims do not replace a system-specific assessment of acceptable risk.

Relevant standards and guidance

This module uses original explanatory language. Consult the applicable editions and project requirements rather than treating this lesson as normative text.

  • UK Network and Information Systems Regulations 2018
  • Directive (EU) 2022/2555 (NIS2)
  • Regulation (EU) 2024/2847 (Cyber Resilience Act)
  • NCSC Cyber Assessment Framework
  • ISA/IEC 62443 series

Further reading

Last reviewed

15 July 2026.

Complete the knowledge check above and answer every question correctly to unlock module completion.

Progress is stored only in this browser and is not a certificate or formal training record.