When IEC 62443-3-2 partitions a system under consideration into zones and conduits (ZCR 3), the output is a drawing plus a register of characteristics for every zone and conduit. Most practitioners build both by hand in Visio or draw.io. This tool is a purpose-built, free alternative: draw zones (nestable, with grey subsystem groupings), connect them with gateway, filtering or unidirectional data-diode conduits in the visual style of the CLC/TS 50701 figures, lay optional Purdue level bands behind the diagram, and record the attributes the standard asks for as you go - accountable organisation, boundaries, safety designation, access points, data flows, assets, and a target security level (SL-T) as the seven-value vector over the foundational requirements.
Everything runs in your browser: work autosaves to local storage, nothing is uploaded, and the Tables view turns the diagram into an asset register and a zone and conduit characteristics register, each downloadable as CSV. Export the drawing as a native Visio .vsdx, a draw.io file, SVG or PNG, and as lossless XML you can re-import or share. A worked example (a small water treatment plant) loads on first visit.
It is the drawing produced when a system under consideration (SuC) is partitioned per IEC 62443-3-2. Zones group assets that share common security requirements; conduits group the communication channels that connect zones. The partitioning step is ZCR 3 of the standard, and the diagram, together with the documented characteristics of each zone and conduit, forms part of the cybersecurity requirements specification.
The standard asks for a name and unique identifier, the accountable organisation, the logical boundary, the physical boundary where applicable, a safety designation, all logical and physical access points, the data flows at those access points, the connected zones or conduits, and the list of assets. The detailed risk assessment then adds a target security level (SL-T) for each zone and conduit. This tool records all of these and exports them as a CSV register.
SL-T is the target security level assigned to a zone or conduit by the risk assessment, on a scale of 0 to 4. It is properly a vector of seven values, one per foundational requirement from IEC 62443-3-3: identification and authentication control (IAC), use control (UC), system integrity (SI), data confidentiality (DC), restricted data flow (RDF), timely response to events (TRE) and resource availability (RA). A zone can also have no SL-T, for example when its risk is covered by a code of practice.
No. The tool is plain static HTML and JavaScript with no server component, no accounts and no analytics beyond standard web logs. Work autosaves to your browser's local storage on your own machine, and every export file is generated locally in the browser.
Yes. Export as a native Visio .vsdx file or a draw.io .drawio file and keep editing there, or as SVG and PNG for reports and slides. The XML export keeps every attribute losslessly and can be re-imported into the tool or shared with a colleague.
No. It is an independent free tool, not affiliated with or endorsed by the IEC, ISA or CENELEC. It draws the documentation the standards describe; it is not a substitute for the standards themselves or for performing a risk assessment.
CLC/TS 50701 applies the IEC 62443 approach to railway applications, and its zone and conduit partitioning follows IEC 62443-3-2. The diagrams this tool draws follow the visual conventions of the TS 50701 figures: dark rounded zones, grey subsystem groupings, pale conduit links and Purdue level bands, so they read naturally in both rail and general OT contexts.