Operators securing critical infrastructure face a growing patchwork of overlapping cybersecurity rules, from TSA Pipeline Security Directives to NERC CIP requirements to the EU's NIS2, CER, and Cyber Resilience Act. Much of this creates duplicative compliance work without improving actual security. This paper makes the case for formally recognizing ISA/IEC 62443, the only global consensus-based standard built for the physics of industrial systems, as the foundation for U.S. OT cybersecurity policy.
The paper outlines five recommendations for U.S. policy makers:
Recognize ISA/IEC 62443 as the Global OT Security Standard
Shift from Compliance to Interoperability
Catalyze Market Maturation through Lead-User Adoption
Enhance Sector-Specific Technical Guidance and Capacity Building
Fund Workforce Development for OT Security Competency

