Security Levels in IEC 62443 are frequently reported as a single achieved number per zone, which throws away most of their practical value. SL-T (Target) and SL-A (Achieved) are only useful when you track both and treat the gap between them as your prioritized backlog.

SL-T is a risk decision, not a technical default

Setting SL-T should follow directly from your risk assessment: what level of adversary sophistication does this zone realistically need to resist, given the consequence of compromise? A zone that only faces opportunistic, low-sophistication threats does not need the same target as a zone exposed to well-resourced adversaries.

SL-A has to be evidenced, not assumed

Achieved level should be backed by tested evidence -- validated segmentation, confirmed authentication enforcement, verified logging -- not just a list of controls that are believed to be configured correctly. A control that exists on paper but has never been validated should not count toward SL-A.

Use the gap to build your roadmap

Rank zones by the size of the SL-T minus SL-A gap, weighted by consequence. This gives you a defensible, standards-anchored investment order instead of an ad-hoc list of 'things that seemed important.' It also gives leadership a simple, honest metric to track quarter over quarter.