A CISO at a regulated utility told me his team had spent eighteen months mapping every control to a single unified framework, on the theory that one framework covering everything would simplify audits. It didn't. NERC CIP compliance still required its own evidence package, IEC 62443 vendor conformance still required its own attestations, and the federal side of the business still needed controls traced to NIST SP 800-53 through 800-82. The unification project produced a longer document, not a shorter workload. The three frameworks are not competing translations of the same idea. They are answering different questions, for different audiences, under different legal weight.

This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.

What each one actually is

NERC CIP is law, in every practical sense. The Critical Infrastructure Protection standards are mandatory for owners and operators of the North American bulk electric system, enforced by the North American Electric Reliability Corporation under authority delegated by the Federal Energy Regulatory Commission. Miss a requirement and the exposure is not reputational, it is financial and structural. FERC's enforcement framework allows civil penalties up to one million dollars per violation, per day. The standard set runs from CIP-002, which requires entities to identify and categorize their bulk electric system assets by impact level, through CIP-014, covering physical security at substations. In between sit requirements most CISOs in other sectors never think about in these terms, security patches applied on a 35-day cycle under CIP-007, vulnerability assessments on a set schedule under CIP-010, supply chain risk management plans under CIP-013. None of it is optional for an entity above the applicability threshold. All of it is auditable, and the audits have teeth.

IEC 62443 is the opposite kind of document. It is a voluntary international standard, developed jointly by ISA and IEC, and it applies to industrial automation and control systems broadly, not to the electric grid specifically. A water treatment plant, a pharmaceutical manufacturer, and an automaker's factory floor can all use it, because it was written for that breadth. It is also structured around three distinct audiences rather than one. The 62443-2 series addresses asset owners and how they run a security program. The 62443-3 series addresses system integrators and defines the zones-and-conduits architecture, where a zone groups assets sharing common security requirements and a conduit is the controlled channel connecting zones. The 62443-4 series addresses component and product suppliers, setting requirements for what a PLC or HMI vendor has to build in before the product ships. Security levels, from SL 0 to SL 4, describe the sophistication of attacker a zone is designed to resist, and the standard distinguishes the target level an asset owner wants, the capability level a product natively provides, and the achieved level actually measured after deployment. No regulator enforces IEC 62443 by itself in the United States. Its influence comes from adoption, procurement language, and increasingly from other regulations that point to it as a baseline.

NIST SP 800-82, now in its third revision published in September 2023, is a guidance document, not a standard in the IEC sense and not a mandate in the NERC sense. It is written specifically to help organizations apply security controls to operational technology while respecting OT's own constraints, the fact that a control system cannot simply be patched on a Tuesday maintenance window the way a laptop can, the fact that availability and safety often outrank confidentiality in a way that inverts the usual CIA priority. Its real value is as a bridge. It maps OT-specific guidance back to the broader NIST SP 800-53 control catalog that federal agencies and their contractors already have to satisfy, with overlays specific to industrial control systems, SCADA, distributed control systems, and building automation. For a federal contractor going through an authorization to operate, or a private company that has adopted the NIST Cybersecurity Framework as its baseline, 800-82 is the document that tells you how the general-purpose IT controls translate to a control room.

Why the differences matter more than the similarities

The instinct to treat these as three flavors of the same soup misses the structural point. NERC CIP answers a jurisdictional question, are you a bulk electric system entity above a defined impact threshold, and if yes, compliance is not a choice. IEC 62443 answers a supply chain question, what should an asset owner require of an integrator, and what should an integrator require of a component vendor, regardless of what industry any of them are in. NIST 800-82 answers a mapping question, how does an OT environment satisfy the control expectations a federal framework already imposes on the rest of the organization.

A single company can face all three at once and need all three satisfied differently. Consider an industrial group that owns a natural gas-fired power plant connected to the bulk electric system, operates a separate chemical manufacturing site with no NERC exposure at all, and holds a federal contract requiring an authorization to operate under the Risk Management Framework. The power plant's control systems fall under NERC CIP, full stop, with mandatory patch cycles, mandatory vulnerability assessments, and an auditor who will show up and check evidence. The chemical plant has no NERC obligation whatsoever, but its PLC and HMI vendors can be held to IEC 62443-4-2 component requirements in the procurement contract, and the site's own security program can be built against 62443-2-1 regardless of what sector it sits in. The federal contract's OT-adjacent systems need their controls traced to NIST 800-53 through the 800-82 overlays, because that is what the authorizing official will actually be checking against during assessment. Building one CISO program for that company means running three parallel evidence trails, not merging them into one document, because merging them does not change what each auditor is legally required to check.

The honest counterargument

The strongest case against maintaining three separate compliance postures is genuinely strong, and it comes from CISOs who have lived through framework fatigue. If IEC 62443 is comprehensive enough to cover asset owner practices, system architecture, and component requirements in a single, well-structured international standard, and if NIST 800-82 already tells you how to map OT to a control catalog, why not simply adopt IEC 62443 as the operating standard everywhere, treat NIST 800-82 as reference material, and let NERC CIP compliance ride on top as a documented subset. Fewer frameworks to train staff on, fewer audit cycles, one architecture language for zones, conduits, and security levels across every site the company owns, and a defensible position that the strongest available international standard is being applied consistently.

This is a reasonable operating philosophy for the technical architecture, and plenty of well-run OT security programs do exactly this at the design level. But it cannot substitute for CIP compliance where CIP applies, because IEC 62443 conformance and NERC CIP compliance are not legally interchangeable. A FERC auditor does not accept an IEC 62443 security level as evidence that CIP-007's 35-day patch cycle was met, because CIP-007 specifies its own evidence requirements, its own timelines, and its own reporting obligations that IEC 62443 was never written to satisfy. The two can align in practice. They do not align in law. Any company treating IEC 62443 as a full substitute for NERC CIP on bulk electric system assets is one audit away from finding that out at a cost of up to one million dollars per violation, per day.

Monday questions for leadership and the board

Ask which of the company's OT assets actually meet the NERC bulk electric system impact threshold, and get the answer in writing from someone who can defend it to a FERC auditor, not a summary from a slide.

Ask whether the procurement team has ever required IEC 62443-4-2 conformance from a control system vendor, or whether component security requirements are being negotiated informally, site by site.

Ask how OT controls are currently mapped to NIST SP 800-53, if the company has any federal contract or RMF obligation, and who owns keeping that mapping current as 800-82 guidance evolves.

Ask what would happen, specifically, if the three frameworks were consolidated into one internal document next quarter. If the honest answer is that the audit evidence packages barely change, that tells leadership and the board the consolidation was cosmetic, not structural.

The line that matters

These three documents were never competing for the same job. NERC CIP tells you what the law requires. IEC 62443 tells you what good architecture and supply chain discipline look like. NIST 800-82 tells you how to speak both languages to a federal auditor. Treat any one of them as a replacement for the others and you have not simplified your compliance program, you have found the exact gap an incident or an audit will land in.