Your situation

IEC 62443 consulting for development, components and plants

You want to introduce a secure development process, have an industrial component certified or create a security concept for a plant. We support manufacturers, integrators and operators at the appropriate level of IEC 62443.

Free of charge and without obligation.

  • Co-author of the IEC 62443-4-2 evaluation scheme
  • Project leader for IEC 62443-6-2 at the IEC
  • IEC 62443-4-1 project at MB connect line
Top view of joint map work with notes, compasses and navigation instruments
IEC 62443: security for development, components and plants from a single source.

Your situation

Your customers require evidence according to IEC 62443 – for the development process, a component or a plant?

A plant operator requires certification of your component according to IEC 62443-4-2, an integrator asks about your secure development process according to IEC 62443-4-1, or you want to use the series of standards to meet the requirements of the Cyber Resilience Act (CRA). The open question then is which parts of the standard apply to your role and which evidence is actually required.

IEC 62443 distinguishes between manufacturers, integrators and operators: part 4-1 covers the secure development lifecycle (SDL), part 4-2 the technical requirements for components. For plants, the series provides concepts for risk assessment, zoning, security levels and defence in depth. Since 2025, IEC 62443-6-2 has described the evaluation methodology for components according to 4-2.

We start at the appropriate level – with gap analysis, laboratory testing, pre-evaluation, threat analysis or training. We have contributed to the evaluation methodology ourselves: from the TeleTrusT evaluation scheme for IEC 62443-4-2 to project leadership for IEC 62443-6-2. Individual security tests for components can be found under cybersecurity tests for digital products. Whether another form of evidence is also suitable for your product, we clarify in our consulting for product manufacturers.

Services & results

Development process, component, plant: the entry points to IEC 62443

You receive support at the level of IEC 62443 that applies to you: for the secure development process according to part 4-1, for components according to part 4-2 with laboratory testing and pre-evaluation, for plants with threat analysis and security concept. You define the relevant parts of the standard and the evaluation goals with us in advance – the series of standards also helps with the Cyber Resilience Act.

Which service fits depends on your role. Manufacturers usually start with IEC 62443-4-1 and 4-2, operators and integrators with the plant. The modules can be commissioned individually or combined.

IEC 62443-4-1: kickstarter, gap analysis, implementation

If you are not yet familiar with IEC 62443-4-1, a kickstarter workshop presents the requirements for the secure development process and shows the next steps. If you are already considering certification, a gap analysis is the typical starting point: in a workshop we examine the existing development process, such as the design phase and testing, and identify deviations.

During implementation, we develop your processes further in line with your existing company culture and work out new processes together with your team. How much of the project work lies with you and how much with us is the main factor determining the effort. Experience from secure development processes according to NESAS feeds in – different standards, but large overlaps.

Documented deviations

The results of the gap analysis with the key points for your further work.

Security verification and validation (SVV) according to 4-1

The security verification and validation chapter of IEC 62443-4-1 requires security testing, in the case of pentesting partly with required independence from development. Where your team cannot or may not cover the tests of an industrial component itself, we take over the testing activities.

IEC 62443-4-2: testing or pre-evaluating a component

For a product certification according to IEC 62443-4-2, we offer two entry points.

Option 1 is a standardised test package: we test the component in our laboratory and produce a test report. Afterwards you know the product's security level, among other things in comparison with IEC 62443-4-2. No special project preparation is required. As a BSZ evaluation facility of the BSI, we are particularly qualified for black-box product evaluations.

Option 2 is a pre-evaluation against the benchmark of the later certification. We work according to IEC 62443-6-2, the evaluation methodology for IEC 62443-4-2, to which we made a leading contribution.

Test report or gap analysis

You know the security level of your component or the deviations still to be closed before certification.

Security concept for your plant

A machine, plant or system serves a specific purpose. The analysis determines which risks can prevent this purpose from being achieved. The starting point is typically a threat and risk analysis (TARA), the process of which we have largely standardised.

Building on this, we develop the security concept with you using the IEC 62443 concepts of risk assessment, zoning, security levels and defence in depth. On request, we then work out measures to treat the threats and risks.

Security concept

A security concept for your plant aligned with the key parts of IEC 62443.

OT and IIoT testing

We document threats to OT components and industrial automation and control systems (IACS) through threat modelling and propose mitigations. We verify through testing whether these are effective and whether further vulnerabilities exist – on individual components or entire IACS before they go into production. We combine automated tools with manual tests and design the tests specifically for your component or system.

Training course “IEC 62443 for the CRA in practice”

The training course is aimed primarily at component manufacturers and consists of four modules. As an in-house course, we usually run it in German or English over two days, or online in half-day blocks.

For individual participants, our partner heise conferences offers the online workshop “IEC 62443: Industrial Security für Produkthersteller” (in German): two mornings, a maximum of 20 participants, with an overview of the requirements of the Cyber Resilience Act.

  • Introduction to IEC 62443 and comparison with the CRA
  • Fundamentals of IEC 62443-4-2: component requirements and security levels
  • Fundamentals of IEC 62443-4-1: all eight practices of the secure development lifecycle
  • Practical application: secuvera methods for TARA and example threat modelling

Certificate of attendance

Supports the training obligations under IEC 62443-4-1.

Our expertise

We contribute to the evaluation methodology of IEC 62443 ourselves. We drove the TeleTrusT evaluation scheme for IEC 62443-4-2 forward as coordinator. This initiative gave rise to the standard part IEC 62443-6-2, the evaluation methodology for components according to IEC 62443-4-2. Sebastian Fritsch, head of our evaluation facility, played a key role in driving the standardisation project forward at the IEC as project leader and is co-editor of IEC 62443-6-2. He presented the evaluation methodology and the status of the IEC project at the EU Cybersecurity Act conference in 2021 and 2022. He also chairs the DKE working group 931.1.4 “Evaluation Methods”. We were involved in the TeleTrusT use cases for IEC 62443-4-2.

As a TeleTrusT member, our colleague Luise Werner contributed to a profile proposal for an industrial firewall based on IEC 62443. In atp magazin we described how such profiles make the CRA technically implementable.

In practice, we supported MB connect line up to certification according to IEC 62443-4-1. As a BSZ evaluation facility of the BSI, we are qualified for black-box product evaluations, and we bring experience in threat modelling from the OVVL research project.

Getting started

Determining your role in the industrial value chain

A first conversation about IEC 62443

In the free IEC 62443 workshop we discuss your starting point and technical questions. We tailor the session at our premises to your project.

Starting with a gap analysis

You are considering certification and want to know how far you are from the requirements. In the workshop we look at your development process, including the design phase and testing. We document deviations and name the key next tasks.

Clarify your IEC 62443 evaluation level
Dividers fixing a position on the world map
Your role in the supply chain clearly defined, the effort matched to it.

The statement applies to the evaluated level

Process certification, component evaluation and plant assessment are different tasks. We define the relevant parts of the standard and the evaluation goals in advance. A security level cannot be assessed independently of the product, the requirements and the operational environment.

Questions about parts of the standard and evaluations according to IEC 62443

Which parts of IEC 62443 are relevant for us?

First we clarify your role and the evaluation object. For component manufacturers, the development process and product security are often the focus. Operators and integrators, by contrast, need an assessment of the specific plant, its zones, communication relationships and risks.

What is the difference between IEC 62443-4-1 and IEC 62443-4-2?

Part 4-1 deals with the secure development process. Part 4-2 describes technical security requirements for components. A process certification and a component evaluation therefore answer different questions and are planned separately.

How can component manufacturers determine whether they are ready for evaluation?

A gap analysis shows deviations of your development process from IEC 62443-4-1. For components, there are two routes: a technical laboratory test or a pre-evaluation according to IEC 62443-6-2. The latter is based on the later certification according to IEC 62443-4-2. We choose the route according to your evidence goal.

What does IEC 62443 consulting offer operators?

We support the threat and risk analysis, zoning and the development of a security concept for the plant. The components used are considered in the context of their use. If required, measures to treat the identified risks follow.

Who issues certificates according to IEC 62443?

Certificates according to IEC 62443 are issued by a certification body, for example TÜV NORD. We prepare you for this with a gap analysis, laboratory testing or pre-evaluation according to IEC 62443-6-2. Whether a certificate according to IEC 62443, Common Criteria, the BSZ or a penetration test fits your product, we compare in the free workshop for manufacturers.

Articles on this topic (in German)

All 56 articles on the topic (in German)

How can we support you with IEC 62443?