Title Cybersecurity requirements and certification standards in industrial automation systems: a systematic review
Authors Zulfigarzada, Said ; Gadirli, Aysun ; Karimov, Javid ; Cerneckas, Danas ; Rackiene, Rima ; Azubalis, Mindaugas
DOI 10.3390/computers15060364
Full Text Download
Is Part of Computers.. Basel : MDPI. 2026, vol. 15, iss. 6, art. no. 364, p. 1-27.. ISSN 2073-431X
Keywords [eng] industrial automation ; cybersecurity requirements ; certification standards ; IEC 62443
Abstract [eng] Industrial automation systems are increasingly cyber-physical, interconnected, and software-dependent, which expands both their operational capability and their cybersecurity exposure. This article reports a systematic literature review, conducted following the PRISMA 2020 guidelines, of cybersecurity requirements and certification standards in industrial automation, with emphasis on Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA), Programmable Logic Controllers (PLCs), and Industry 4.0 contexts. From 3570 records identified across five academic databases, 75 studies were retained after duplicate removal, title and abstract screening, and full-text eligibility assessment. The included studies were analyzed along three dimensions: cybersecurity requirements, standards and certification, and application context. Quantitative synthesis shows that network segmentation, intrusion detection, secure communication, access control, lifecycle security, and safety–security coordination are the six most frequently emphasized requirement categories, and that ISA/IEC 62443, ISO/IEC 27001, NIST SP 800-82, and NERC-CIP are the four dominant certification frameworks. The review identifies four critical gaps between technical cybersecurity requirements and certification practice and proposes an integrated mapping framework linking requirement categories, standards, and application contexts. The findings indicate that effective industrial cybersecurity assurance depends on a layered compliance architecture rather than on dependence on any single framework.
Published Basel : MDPI
Type Journal article
Language English
Publication date 2026
CC license CC license description