Standards
IEC 62443: what it covers and how it relates to the CRA
IEC 62443 is the international series of standards for the security of industrial automation and control systems, covering operators, integrators and component manufacturers. It is not a harmonised standard under the Cyber Resilience Act, but the EU's own mapping found it covers many CRA requirements for industrial products.
Free plan, no card required.
What is IEC 62443?
The series is published by IEC technical committee 65 and was developed together with the ISA99 committee of the International Society of Automation, which is why it is often written ISA/IEC 62443. It organises security around roles: the asset owner who operates a plant, the integrator who builds the system, and the product supplier who makes the components.
For manufacturers, two parts matter most. They describe how a product should be developed and what security capabilities it should have.
| Part | Title | For whom |
|---|---|---|
| IEC 62443-4-1:2018 | Secure product development lifecycle requirements | Product suppliers: the development process |
| IEC 62443-4-2:2019 | Technical security requirements for IACS components | Product suppliers: component capabilities |
| IEC 62443-3-3:2013 | System security requirements and security levels | Integrators and system designers |
How the series is organised
The documents are grouped in four families, so each role can find the parts written for it. Product makers usually start with the component family and read the system family to understand how their product will be integrated.
- 1-x, general: concepts, terminology and models used across the series.
- 2-x, policies and procedures: security programmes for asset owners and requirements for service providers.
- 3-x, system: risk assessment with zones and conduits, and system security requirements.
- 4-x, component: secure development lifecycle and technical requirements for components.
Security levels and certification
IEC 62443 grades protection in security levels, from protection against casual violation up to sophisticated attacks with extended resources. A component can be designed for a target security level and assessed against it.
Certification is available through schemes such as the IECEE industrial cyber security programme, which lists 62443-4-1 since 2018 and 62443-4-2 since 2019, and ISASecure. Certification is voluntary and separate from the CE marking under EU law.
How IEC 62443 relates to the Cyber Resilience Act
The CRA is law; IEC 62443 is a voluntary standard. A presumption of conformity with the CRA comes from harmonised standards published in the Official Journal, and the Commission's standardisation request M/606 of February 2025 asks European standards bodies for new CRA standards without referencing IEC 62443.
Even so, the series is useful evidence. A joint analysis by the European Commission's Joint Research Centre and ENISA, published in April 2024, found that the EN IEC 62443 family offers quite good coverage of the CRA requirements but is specifically devoted to industrial control systems, and that no single standard covers all of Annex I.
Where the two overlap in practice
Teams that already follow 62443-4-1 have much of the process the CRA's vulnerability-handling requirements expect. The gaps are usually in the artefacts the CRA names explicitly and in the reporting deadlines.
- Secure development lifecycle (4-1) supports the CRA's security-by-design and testing requirements.
- Defect and vulnerability management in 4-1 maps to Annex I Part II vulnerability handling.
- Component security capabilities (4-2) support Annex I Part I requirements such as access control and integrity.
- The CRA adds an SBOM in a machine-readable format, a support period, free security updates and Article 14 reporting.
What to do if you follow IEC 62443 today
Keep going, and map your existing evidence to the CRA's Annex I requirements rather than starting a second programme. Add the pieces the CRA asks for explicitly: an SBOM per release, a coordinated vulnerability disclosure policy with a contact address, a support period and an Article 14 reporting procedure. Watch for harmonised standards being published, because they will define the easiest route to conformity.
Available in KROMSE today
KROMSE does not assess or certify IEC 62443 conformity; it supplies vulnerability evidence that such programmes need.
- Known vulnerabilities in the software and Linux-based firmware of a component, with evidence and coverage limits.
- CycloneDX and SPDX SBOMs for every scan.
- Recorded decisions and a signed audit-log export for defect and vulnerability management records.
- On paid plans, internal Article 14 drafts for the CRA's reporting deadlines.
Coming next
On the roadmap, not available yet. Dates are targets, not promises; this page changes the day a capability is live.
- Coming · Q4 2026CRA conformity assessment. A guided workflow will map your evidence to the Annex I requirements, for a person to review and complete.
- Coming · Q1 2027Machinery Regulation evidence. KROMSE will collect evidence for the cybersecurity-related requirements of the EU Machinery Regulation (EU) 2023/1230, next to your CRA record.
- Coming · Q1 2027Bare-metal and RTOS firmware. KROMSE will identify components in firmware without a Linux file system, such as bare-metal and RTOS images built on FreeRTOS or Zephyr.
Frequently asked questions
Is IEC 62443 mandatory in the EU?
No. IEC 62443 is a voluntary international standard. EU law such as the Cyber Resilience Act sets binding requirements, and harmonised European standards published in the Official Journal give a presumption of conformity. IEC 62443 can still serve as evidence of good practice.
Does IEC 62443 certification mean CRA compliance?
No. Certification shows conformity with the standard, not with the Regulation. The JRC and ENISA mapping found good but incomplete coverage, and the CRA adds explicit obligations such as an SBOM, a support period, free security updates and Article 14 reporting.
Which part of IEC 62443 applies to product manufacturers?
Mainly IEC 62443-4-1, on the secure product development lifecycle, and IEC 62443-4-2, on technical security requirements for components. System integrators typically work with IEC 62443-3-3 and related parts.
What are security levels in IEC 62443?
Security levels describe how strong the protection should be, from level 1, against casual or coincidental violation, to level 4, against intentional attacks using sophisticated means with extended resources and high motivation. A system's zones are given target levels, and components are designed to meet them.
Does KROMSE certify IEC 62443?
No. KROMSE does not certify against any standard. It finds known vulnerabilities in software and Linux-based firmware, produces SBOMs and records decisions, which can support an IEC 62443 or CRA programme run by your organisation.