IEC and ISA are two separate standards organizations that often work on similar topics in industrial automation and control, but they differ in scope, governance, and how their standards are used in plants.
Who they are
IEC (International Electrotechnical Commission):
- Global standards organization focused on electrical, electronic, and related technologies, including industrial automation.
- Publishes international standards such as IEC 61508 (functional safety) and IEC 62443 (industrial cybersecurity).
- National bodies (e.g., ANSI in the US, DIN in Germany, BSI in the UK) participate in IEC committees and adopt IEC standards nationally, sometimes with modifications.
ISA (International Society of Automation, now part of ISAGCA/ISA):
- Professional society focused on automation practitioners (engineering, operations, vendors).
- Develops standards, technical reports, and practices such as ISA-5.1 (instrumentation symbols), ISA-18.2 (alarm management), and the original ISA-99 (cybersecurity for IACS).
- Historically strong influence in North America and in process industries (chemicals, oil & gas, life sciences), but used globally.
Scope and role of their standards
IEC standards typically aim to be formal international references:
- Used by multiple regions as a baseline for regulation, conformity assessment, and supplier specifications.
- More likely to be referenced in regional regulations or harmonized industry guidance (for example, IEC 61511 for process safety, IEC 62443 for OT cybersecurity).
- Often broader and more formal in structure, with defined parts and families.
ISA standards tend to be more practitioner- and implementation-focused:
- Often developed first as best practices emerging from operating companies, system integrators, and vendors.
- Commonly embedded in internal engineering standards, P&ID conventions, alarm philosophy documents, and DCS/MES design specifications.
- Sometimes become the technical input to IEC working groups, then partially harmonized.
Example: cybersecurity and IEC 62443 vs ISA/IEC 62443
The most visible overlap is in industrial cybersecurity:
- ISA-99 was the original series on security for industrial automation and control systems.
- That work was taken into IEC and harmonized, resulting in the IEC 62443 series.
- Today, you will often see the series referenced as ISA/IEC 62443, reflecting joint development and aligned content.
In practice, this means:
- The technical concepts (zones & conduits, security levels, requirements for asset owners/integrators/product suppliers) are aligned between ISA and IEC versions.
- Adoption and enforcement still vary by country, regulator, and industry. Some jurisdictions reference the IEC numbering and some internal corporate standards still reference the historic ISA designations.
- Plants must map vendor claims, internal controls, and assessment checklists explicitly to the correct document and part number to avoid confusion in audits or customer reviews.
How this plays out in regulated, brownfield plants
In real facilities, you rarely “pick IEC” or “pick ISA” as a binary choice. Instead, you end up with a layered, sometimes messy coexistence:
- Legacy plant standards may be written around older ISA documents (for example, ISA-5.1 symbols, ISA-88 for batch structures) while corporate policies or customers now reference IEC numbers.
- Vendors and OEMs might certify or advertise alignment to IEC documents but provide engineering documentation still structured around ISA practices.
- MES, DCS, and PLC programs may encode ISA concepts (batch phases, alarm priorities) while cybersecurity or functional safety programs are driven by IEC series.
For regulated industries with long equipment lifecycles, replacing existing systems just to “align to IEC” is rarely feasible. Qualification and validation burdens, downtime risk, and integration complexity usually make big-bang standard migrations impractical. Instead, plants typically:
- Perform a standards mapping exercise between the ISA-based legacy design rules and the targeted IEC framework.
- Update governance documents (for example, cybersecurity policies, alarm philosophy, batch recipe standards) to reference both ISA and IEC identifiers where necessary.
- Implement changes incrementally through normal change control, tying each change to specific clauses in the chosen IEC and/or ISA standards.
Key differences in practice
Summarizing the practical distinctions:
- Organization type: IEC is a formal international standards body; ISA is a professional society that also develops standards.
- Scope: IEC spans broad electrotechnical domains; ISA focuses tightly on automation, measurement, and control.
- Adoption pattern: IEC documents are more often cited as international reference standards; ISA documents often appear first as practitioner-driven best practices and internal corporate standards.
- Plant reality: Most regulated, brownfield plants use a combination, and the work is in mapping, reconciling, and documenting how ISA-derived practices align with the IEC frameworks referenced by regulators, customers, and corporate policies.
The net result is that IEC and ISA are not competing “certifications” or interchangeable labels; they are distinct but partially harmonized sources of standards that must be understood, mapped, and integrated into your existing systems and change-control processes.