GOST, IEC, and ISA: Which Standard Applies to Your Build

A quick reference for engineers navigating overlapping and sometimes conflicting standards bodies across different markets.

Three standards bodies show up constantly in automation specs, and they don't map onto each other cleanly. This is a working reference, not a substitute for a compliance review on a specific project — standards content and applicability change, and a project with regulatory exposure should always get a current legal/compliance check.

Why this gets confusing

IEC, ISA, and GOST overlap heavily in subject matter — safety instrumented systems, electrical design, cybersecurity — but originate from different regulatory traditions and aren't always reconcilable line-by-line. A facility built to satisfy one doesn't automatically satisfy another, and multinational projects sometimes need to design to the strictest applicable subset of all three.

IEC: the international baseline

The International Electrotechnical Commission's standards are the closest thing to a global default, widely referenced or directly adopted across Europe, much of Asia, and increasingly North America. The ones we reference most in control system work:

  • IEC 61508 / IEC 61511: functional safety and safety instrumented systems — the baseline for SIL (Safety Integrity Level) ratings on safety-critical loops.
  • IEC 62443: industrial automation and control systems cybersecurity, covering the zone-and-conduit network model.
  • IEC 61131-3: the standard defining PLC programming languages (ladder, structured text, function block, etc.) — nearly universal across vendors today.

ISA: the North American practitioner standard

The International Society of Automation produces standards that frequently get adopted into IEC numbering (ISA work often becomes the basis for a corresponding IEC standard) but ISA's own numbering is still the common reference point in US engineering practice:

  • ISA-88: batch control standard, foundational for recipe-driven processes in food, pharma, and chemical batch manufacturing.
  • ISA-95: enterprise-control system integration — the standard most MES/ERP-to-plant-floor data architecture references.
  • ISA/IEC 62443: the joint-numbered cybersecurity standard, reflecting how closely the two bodies now coordinate on this topic.

GOST: requirements for CIS-region facilities

GOST (and the related GOST R and Technical Regulations of the Customs Union/EAEU) standards apply to facilities built or operated in Russia and several other CIS countries, and certification to GOST is frequently a hard legal requirement for equipment sold or installed in that region — not an optional best practice. GOST standards cover similar ground to IEC (electrical safety, EMC, explosion protection) but require their own certification process even when the underlying equipment already holds IEC or UL certification.

Field note We've seen projects assume that CE or UL certification would satisfy GOST requirements during equipment procurement. It doesn't — GOST certification is a separate process, and building it into the procurement timeline late is one of the more common causes of delayed commissioning on CIS-region projects.
Standard bodyPrimary regionMost relevant to automation
IECInternational / EU baseline61508/61511 (safety), 62443 (cyber), 61131-3 (PLC languages)
ISANorth America practice88 (batch), 95 (enterprise integration), 62443 (joint)
GOSTRussia / CIS regionElectrical safety, EMC, explosion protection certification

Choosing for a multi-region build

For any project spanning multiple regulatory regions, the practical approach is to design to the strictest applicable requirement across all relevant standards from the start, rather than designing to one and retrofitting for another — retrofitting safety or cybersecurity architecture after commissioning is dramatically more expensive than designing for the union of requirements up front.

← PreviousReading OEE Dashboards Without Lying to Yourself