To combat regulatory fragmentation, the Operational Technology Cybersecurity Coalition (OTCC) advocates for a single, horizontal standard to govern industrial and operational technology (OT) cybersecurity. Policy should prioritize one globally interoperable framework over a patchwork of sector-specific mandates. Established frameworks such as ISA/IEC 62443, a globally recognized set of standards for securing industrial control systems, are leading options for this type of formal recognition and adoption. This approach reduces regulatory sprawl, simplifies compliance for critical infrastructure owners and operators, and strengthens national resilience through a unified defensive baseline.
- OTCC supports cybersecurity policies that are cohesive, adaptable, risk-based and interoperable at a global level. We advocate for the creation and use of consensusbased technical standards, guidelines, practices, processes and definitions that facilitate the management of cyber risks.
- OTCC supports legislation and regulations that recommend and recognize the use of leading global standards. These standards provide consistency and promote fair competition and international trade.
Today, many countries and governments are developing their own unique standards and regulations for their country or industries. This has led to an influx of regulations with which an organization must comply, creating an acute burden for global companies.
Governments should focus on adopting requirements aligned to standards that take a holistic approach and are developed by global experts in industrial automation cybersecurity. Such an approach aligns with the last two Administrations’ National Cyber Strategies, which advocated for the harmonization and elimination of duplicative regulations.
ISA/IEC 62443 is uniquely positioned as the only global consensus-based standard currently developed, tailored and in use for the physics-based requirements of OT. A policy grounded in interoperable, consensus-based standards offers the dual benefits of securing critical infrastructure and industrial operations while ensuring consistent application across the globe.
This paper outlines the following OTCC recommendations to harmonize OT cybersecurity standards and regulations:
1. Recognize ISA/IEC as the Global OT Security Standard
2. Shift from Compliance to Interoperability
3. Catalyze Market Maturation through Lead-User Adoption
4. Enhance Sector-Specific Technical Guidance and Capacity Building; and
5. Fund Workforce Development for OT Security Competency

