You develop products with digital or networked components and want to understand how to use IEC 62443 in a targeted way to meet the requirements of the Cyber Resilience Act (CRA) reliably, both technically and organisationally? Perhaps you are asking yourself which requirements your products have to meet, how to integrate security by design reliably into your development processes, or how to apply IEC 62443 in practice in product development.
CRA training based on IEC 62443: knowledge your development team can apply straight away.
Your situation
You need to develop your products in compliance with the CRA and want to use IEC 62443 to do so?
The Cyber Resilience Act (CRA) requires manufacturers of products with digital elements to demonstrate their cybersecurity across the entire lifecycle. The reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026, the remaining obligations apply from 11 December 2027. Many product teams then have open questions: which requirements apply to their own product, how security by design can be built reliably into the development process, and how standards and CRA obligations interact.
For manufacturers in industry and automation, the IEC 62443 series of standards provides a basis for this: Part 4-1 describes the secure development process (secure development lifecycle), Part 4-2 the technical security requirements for components. The training shows which parts of the standard are relevant to your product and process requirements and how to apply them in the CRA context.
The trainers work on the standard themselves: secuvera drove the TeleTrusT test scheme for IEC 62443-4-2 forward as coordinator and plays a leading role in the standard part IEC 62443-6-2. Assessing the specific CRA requirements for your product is a separate step, for example in a CRA gap analysis.
Services & results
Four modules: from the series of standards to your own TARA
Afterwards, you know which parts of IEC 62443 apply to your product and process requirements and where the series of standards covers CRA requirements – with a focus on the secure development process under Part 4-1 and the component requirements under Part 4-2. The trainers are people who evaluate components against these requirements; we assume basic knowledge of automation technology.
Alongside the fundamentals, the focus is on examples from projects, typical pitfalls and proven methods. The trainers address participants' own questions during the training. Online, each module takes half a day; on site, the four modules are typically delivered over two full days.
01
Module 1: Introduction to IEC 62443 and mapping to the CRA
Structure, target groups and approaches of the series of standards – and which sections apply to operators, integrators and manufacturers. Then the mapping: where does IEC 62443 cover CRA requirements?
Structure, target groups and approaches of the series of standards
Relevant sections for operators, integrators and manufacturers
Overview of the CRA and mapping to IEC 62443
02
Module 2: IEC 62443-4-2 – requirements for components
The technical security requirements for industrial components, explained by trainers who evaluate components against these requirements.
Component requirements (CR) for industrial components
Security levels and how they interact with other parts of the standard
Example implementation on industrial components
03
Module 3: IEC 62443-4-1 – secure development lifecycle
The requirements for the secure development process, practice by practice. The practical examples come from projects in which we accompany manufacturers towards certification under IEC 62443-4-1.
Requirements for the secure development lifecycle (SDL)
All eight practices and their implementation in development processes
Practical examples of process requirements and typical pitfalls
04
Module 4: Practical application – TARA and threat modelling
We present our own methods for threat and risk analysis (TARA) and carry out an example threat model together – through discussion and group exercises.
secuvera methods for TARA
Example threat modelling
Proven approaches and test concepts
Result
Your team can classify and apply IEC 62443-4-1 and 4-2. The certificate of attendance supports the training obligations under IEC 62443-4-1; the show notes record your questions together with references and practical tips.
Our expertise
The training is delivered by trainers who contribute to IEC 62443 and evaluate against it. Sebastian Fritsch heads secuvera's BSI evaluation facility for Common Criteria and has more than ten years of experience as an evaluator, auditor and consultant in Common Criteria (EAL4+) and IEC 62443 projects. He is a project leader in ISO and IEC and chairs the working groups DIN NA 043-01-27-03 “IT security evaluation criteria” and DKE AK 931.1.4 “Evaluation Methods”. Luise Werner advises on secure development lifecycles and OT security, accompanies manufacturers towards certification under IEC 62443-4-1 and is a member of the TeleTrusT working group Smart Grids / Industrial Security.
secuvera drove the TeleTrusT test scheme for IEC 62443-4-2 forward as coordinator, plays a leading role in the standard part IEC 62443-6-2 (evaluation methodology for IEC 62443-4-2) and was involved in the TeleTrusT use cases. We successfully accompanied Red Lion Europe to certification under IEC 62443-4-1. As a BSZ evaluation facility of the BSI, we also evaluate products in the laboratory.
Getting started
Put together four modules for your product team
Agree on duration and delivery
We typically deliver in-house training with four modules over two days. Online, we teach the modules in half-day blocks, on site in full days. Alternatively, we agree on the delivery individually with you.
Continue working with the materials
No separate handouts are produced. The slides allow you to follow up independently. Certificates of attendance are available on request.
Training modules tailored to your team and your products.
Basic technical knowledge as a prerequisite
Prerequisites: basic knowledge of automation technology and a basic understanding of the benefits of security.
Questions about the training “IEC 62443 for the CRA”
Who is “IEC 62443 for the CRA in practice” intended for?
For specialists at product manufacturers who have to implement or demonstrate security requirements under the CRA and IEC 62443 in the field of industrial security: product managers, heads of development, system architects, security testers, test and QA teams, technical writers and documentation teams, and those responsible for security, compliance and quality. Basic knowledge of automation technology and a basic understanding of the benefits of security are assumed.
How much time do we need to plan for the four modules?
In-house, the four modules are typically delivered over two days. Online, we split the content into half-day blocks. Other formats are agreed with you.
Does the training confirm our product's CRA compliance?
No. It provides an understanding of the standard and methods for further work. Assessing the specific CRA requirements, implementation and any necessary product evaluations remain separate steps.
Do you also offer the training in English?
Yes. As in-house training, we deliver the IEC 62443 training in German or English.
Is the training also available for individual participants?
Yes. Through our partner heise conferences, we offer a shortened version of the IEC 62443 practical training as an open online workshop: “IEC 62443: Industrial Security für Produkthersteller” (industrial security for product manufacturers), covering IEC 62443-4-1, IEC 62443-4-2 and the overlaps with the CRA. This is suitable if you only have a few participants or want to exchange views with other manufacturers. The workshop takes place regularly; dates and registration are available from heise conferences.