The agreement links ISA’s industrial cybersecurity standards work with OTCC’s policy and industry engagement, reinforcing ISA/IEC 62443 as a reference point for asset owners, integrators and product suppliers.

Key takeaways

  • ISA and OTCC announced their memorandum of understanding on August 25, 2026.
  • The collaboration is intended to increase OT cybersecurity awareness, technical engagement and recognition of ISA/IEC 62443.
  • The MOU is a collaboration announcement, not a new government mandate or a new certification requirement.
  • For project teams, ISA/IEC 62443 can provide a common structure for defining asset-owner, integrator, service-provider and product-supplier cybersecurity responsibilities.
  • Procurement language should connect required security capabilities and lifecycle evidence to a project risk assessment rather than rely on a generic claim of standards alignment.

A standards group and an OT coalition formalize collaboration

The International Society of Automation (ISA) and the Operational Technology Cybersecurity Coalition (OTCC) have signed a memorandum of understanding aimed at advancing operational technology cybersecurity across critical infrastructure. Both organizations announced the agreement on August 25, 2026.

According to the announcements, the MOU covers joint efforts to raise awareness of OT cyber risks and solutions, examine strategic issues of common interest, and enable technical engagement among the organizations’ members. A central objective is to encourage better implementation and recognition of the ISA/IEC 62443 family of industrial automation and control systems cybersecurity standards. ([isa.org](https://www.isa.org/news-press-releases/2026/august/isa-and-operational-technology-cybersecurity-coali))

What the agreement does—and does not—change

The agreement is a framework for collaboration rather than a new regulatory rule. Neither organization’s public announcement identifies a mandatory adoption date, a new conformity-assessment scheme, a shared technical specification, or a list of required products and controls.

That distinction matters for industrial buyers. The MOU does not itself alter an owner’s contractual cybersecurity obligations or replace requirements imposed by a sector regulator, customer specification, insurer, or internal security program. Its immediate significance is its potential to bring standards specialists, OT security vendors, integrators and policy participants into closer technical and policy discussion. ([isa.org](https://www.isa.org/news-press-releases/2026/august/isa-and-operational-technology-cybersecurity-coali))

Why ISA/IEC 62443 is relevant to project delivery

ISA/IEC 62443 is a series of standards and technical reports for securing industrial automation and control systems throughout their lifecycle. ISA describes the series as assigning responsibilities across key stakeholder groups, including asset owners, product suppliers, system integrators and service providers.

The series is broader than a component checklist. For example, published documents cover asset-owner security programs, risk assessment and system design, system security requirements and security levels, secure product development lifecycle practices, component technical security requirements, and service-provider security programs. This structure can help a project team connect governance, engineering decisions, product selection and post-installation support rather than treating them as separate exercises. ([isa.org](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards?utm_source=openai))

Procurement implications for owners, integrators and installers

For asset owners, a practical starting point is to document the system under consideration, assess risk, establish target security levels where applicable, and translate the resulting requirements into the bid package. ISA-62443-3-2 addresses risk assessment, zone and conduit partitioning, target security levels, and documentation of security requirements for a system design.

System integrators can use those requirements to clarify boundaries of responsibility: who provides network segmentation, identity administration, secure remote access, backup and recovery procedures, vulnerability handling, patch planning, acceptance testing, and turnover documentation. Product suppliers should be asked for evidence relevant to the equipment’s intended role, such as supported security capabilities, secure configuration guidance, vulnerability disclosure channels, update and support practices, and—in cases where it is appropriate—independent certification evidence.

A requirement that a device or project is simply ‘62443 compliant’ can be too imprecise. Procurement teams are better served by identifying the applicable part of the series, the expected security capabilities, the project’s target security objectives, required lifecycle documentation, and the party accountable for each deliverable. That approach makes bids more comparable and reduces the chance that an otherwise capable control, networking or security product is deployed without the engineering and operating practices needed to use it securely. ([isa.org](https://www.isa.org/getmedia/661c718f-8e64-446d-acf9-2c6286db1b33/isa-62443-3-2-preview.pdf?utm_source=openai))

Policy alignment is part of OTCC’s stated agenda

The partnership follows OTCC’s July 23, 2026 position paper calling for ISA/IEC 62443 to be recognized as a foundational global OT cybersecurity standard. The coalition argues that overlapping sector-specific requirements can create duplicative compliance work and recommends greater interoperability, sector guidance, workforce development and lead-user adoption.

That policy position is advocacy, not a government determination. Still, the MOU gives OTCC’s policy focus a direct connection to the standards organization behind the 62443 series. For operators and suppliers, it is a reason to track how customers, agencies and sector bodies reference consensus-based OT standards in future guidance and procurement language. ([otcybercoalition.org](https://www.otcybercoalition.org/otcc-resources/a-unified-approach-to-ot-cybersecurity%3A-isa%2Fiec-62443-position-paper))

Bottom line

ISA and OTCC have verified a formal collaboration intended to support more consistent use of ISA/IEC 62443 in OT cybersecurity discussions and practice. The agreement creates no immediate compliance obligation, but it reinforces the value of using a shared, lifecycle-oriented framework when specifying, integrating and maintaining industrial control environments.

Teams planning new automation, modernization or network-segmentation work should treat the news as an opportunity to review whether their cybersecurity requirements are measurable, role-specific and connected to the actual risk assessment—not merely labeled with a standard name.