design.iec62443.au Zone & Conduit Designer

Zone and conduit diagrams, straight from the standard

When IEC 62443-3-2 partitions a system under consideration into zones and conduits (ZCR 3), the output is a drawing plus a register of characteristics for every zone and conduit. Most practitioners build both by hand in Visio or draw.io. This tool is a purpose-built, free alternative: draw zones (nestable, with grey subsystem groupings), connect them with gateway, filtering or unidirectional data-diode conduits in the visual style of the CLC/TS 50701 figures, lay optional Purdue level bands behind the diagram, and record the attributes the standard asks for as you go - accountable organisation, boundaries, safety designation, access points, data flows, assets, and a target security level (SL-T) as the seven-value vector over the foundational requirements.

Everything runs in your browser: work autosaves to local storage, nothing is uploaded, and the Tables view turns the diagram into an asset register and a zone and conduit characteristics register, each downloadable as CSV. Export the drawing as a native Visio .vsdx, a draw.io file, SVG or PNG, and as lossless XML you can re-import or share. A worked example (a small water treatment plant) loads on first visit.

Frequently asked questions

What is a zone and conduit diagram?

It is the drawing produced when a system under consideration (SuC) is partitioned per IEC 62443-3-2. Zones group assets that share common security requirements; conduits group the communication channels that connect zones. The partitioning step is ZCR 3 of the standard, and the diagram, together with the documented characteristics of each zone and conduit, forms part of the cybersecurity requirements specification.

What should be documented for each zone and conduit?

The standard asks for a name and unique identifier, the accountable organisation, the logical boundary, the physical boundary where applicable, a safety designation, all logical and physical access points, the data flows at those access points, the connected zones or conduits, and the list of assets. The detailed risk assessment then adds a target security level (SL-T) for each zone and conduit. This tool records all of these and exports them as a CSV register.

What is SL-T and what do IAC, UC, SI, DC, RDF, TRE and RA mean?

SL-T is the target security level assigned to a zone or conduit by the risk assessment, on a scale of 0 to 4. It is properly a vector of seven values, one per foundational requirement from IEC 62443-3-3: identification and authentication control (IAC), use control (UC), system integrity (SI), data confidentiality (DC), restricted data flow (RDF), timely response to events (TRE) and resource availability (RA). A zone can also have no SL-T, for example when its risk is covered by a code of practice.

Does my diagram leave my browser?

No. The tool is plain static HTML and JavaScript with no server component, no accounts and no analytics beyond standard web logs. Work autosaves to your browser's local storage on your own machine, and every export file is generated locally in the browser.

Can I open the diagrams in Visio or draw.io?

Yes. Export as a native Visio .vsdx file or a draw.io .drawio file and keep editing there, or as SVG and PNG for reports and slides. The XML export keeps every attribute losslessly and can be re-imported into the tool or shared with a colleague.

Is this an official IEC or ISA tool?

No. It is an independent free tool, not affiliated with or endorsed by the IEC, ISA or CENELEC. It draws the documentation the standards describe; it is not a substitute for the standards themselves or for performing a risk assessment.

How does CLC TS 50701 relate to IEC 62443?

CLC/TS 50701 applies the IEC 62443 approach to railway applications, and its zone and conduit partitioning follows IEC 62443-3-2. The diagrams this tool draws follow the visual conventions of the TS 50701 figures: dark rounded zones, grey subsystem groupings, pale conduit links and Purdue level bands, so they read naturally in both rail and general OT contexts.

File


Export

Visio and draw.io exports carry the shapes, names and colours; the full attribute set (SL-T vectors, boundaries, asset lists) always survives in the XML export.

Settings

Default colours
Purdue level bands

Drag the dashed band dividers on the canvas to move them.

Canvas

About

A free designer for zone and conduit diagrams in the style of IEC 62443-3-2 and CLC/TS 50701. Partition a system under consideration into zones, group them into subsystems, connect them with conduits, and record the attributes the standard asks for: accountable organisation, logical and physical boundaries, safety designation, access points, data flows, asset list, and a target security level (SL-T) as the seven-value vector over the foundational requirements (IAC, UC, SI, DC, RDF, TRE, RA).

Everything runs in this browser tab: work is autosaved to this browser's local storage and never uploaded. Export to Visio (.vsdx), draw.io, SVG or PNG for reports, and to XML for a lossless save you can re-import or share.

Keyboard: V select, Z zone, S subsystem, C conduit, Del delete, Ctrl+Z/Ctrl+Y undo/redo, arrow keys nudge, Esc cancel.

Not affiliated with or endorsed by the IEC, ISA, CENELEC or the ISA Global Cybersecurity Alliance. IEC 62443 is the property of the IEC and ISA; CLC/TS 50701 of CENELEC - referenced here only to describe what the diagrams depict. This tool draws the documentation; it is not a substitute for the standards or for a risk assessment.