Your situation

Training: IEC 62443 for the CRA in practice

You develop products with digital or networked components and want to understand how to use IEC 62443 in a targeted way to meet the requirements of the Cyber Resilience Act (CRA) reliably, both technically and organisationally? Perhaps you are asking yourself which requirements your products have to meet, how to integrate security by design reliably into your development processes, or how to apply IEC 62443 in practice in product development.

Free of charge and without obligation.

  • Co-author of the IEC 62443-4-2 evaluation scheme
  • Contribution to the Industrial Firewall Profile
  • CRA article published in iX
A secuvera consultant explaining the joint plan to her team at a map
CRA training based on IEC 62443: knowledge your development team can apply straight away.

Your situation

You need to develop your products in compliance with the CRA and want to use IEC 62443 to do so?

The Cyber Resilience Act (CRA) requires manufacturers of products with digital elements to demonstrate their cybersecurity across the entire lifecycle. The reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026, the remaining obligations apply from 11 December 2027. Many product teams then have open questions: which requirements apply to their own product, how security by design can be built reliably into the development process, and how standards and CRA obligations interact.

For manufacturers in industry and automation, the IEC 62443 series of standards provides a basis for this: Part 4-1 describes the secure development process (secure development lifecycle), Part 4-2 the technical security requirements for components. The training shows which parts of the standard are relevant to your product and process requirements and how to apply them in the CRA context.

The trainers work on the standard themselves: secuvera drove the TeleTrusT test scheme for IEC 62443-4-2 forward as coordinator and plays a leading role in the standard part IEC 62443-6-2. Assessing the specific CRA requirements for your product is a separate step, for example in a CRA gap analysis.

Services & results

Four modules: from the series of standards to your own TARA

Afterwards, you know which parts of IEC 62443 apply to your product and process requirements and where the series of standards covers CRA requirements – with a focus on the secure development process under Part 4-1 and the component requirements under Part 4-2. The trainers are people who evaluate components against these requirements; we assume basic knowledge of automation technology.

Alongside the fundamentals, the focus is on examples from projects, typical pitfalls and proven methods. The trainers address participants' own questions during the training. Online, each module takes half a day; on site, the four modules are typically delivered over two full days.

Module 1: Introduction to IEC 62443 and mapping to the CRA

Structure, target groups and approaches of the series of standards – and which sections apply to operators, integrators and manufacturers. Then the mapping: where does IEC 62443 cover CRA requirements?

  • Structure, target groups and approaches of the series of standards
  • Relevant sections for operators, integrators and manufacturers
  • Overview of the CRA and mapping to IEC 62443

Module 2: IEC 62443-4-2 – requirements for components

The technical security requirements for industrial components, explained by trainers who evaluate components against these requirements.

  • Component requirements (CR) for industrial components
  • Security levels and how they interact with other parts of the standard
  • Example implementation on industrial components

Module 3: IEC 62443-4-1 – secure development lifecycle

The requirements for the secure development process, practice by practice. The practical examples come from projects in which we accompany manufacturers towards certification under IEC 62443-4-1.

  • Requirements for the secure development lifecycle (SDL)
  • All eight practices and their implementation in development processes
  • Practical examples of process requirements and typical pitfalls

Module 4: Practical application – TARA and threat modelling

We present our own methods for threat and risk analysis (TARA) and carry out an example threat model together – through discussion and group exercises.

  • secuvera methods for TARA
  • Example threat modelling
  • Proven approaches and test concepts

Result

Your team can classify and apply IEC 62443-4-1 and 4-2. The certificate of attendance supports the training obligations under IEC 62443-4-1; the show notes record your questions together with references and practical tips.

Our expertise

The training is delivered by trainers who contribute to IEC 62443 and evaluate against it. Sebastian Fritsch heads secuvera's BSI evaluation facility for Common Criteria and has more than ten years of experience as an evaluator, auditor and consultant in Common Criteria (EAL4+) and IEC 62443 projects. He is a project leader in ISO and IEC and chairs the working groups DIN NA 043-01-27-03 “IT security evaluation criteria” and DKE AK 931.1.4 “Evaluation Methods”. Luise Werner advises on secure development lifecycles and OT security, accompanies manufacturers towards certification under IEC 62443-4-1 and is a member of the TeleTrusT working group Smart Grids / Industrial Security.

secuvera drove the TeleTrusT test scheme for IEC 62443-4-2 forward as coordinator, plays a leading role in the standard part IEC 62443-6-2 (evaluation methodology for IEC 62443-4-2) and was involved in the TeleTrusT use cases. We successfully accompanied Red Lion Europe to certification under IEC 62443-4-1. As a BSZ evaluation facility of the BSI, we also evaluate products in the laboratory.

Getting started

Put together four modules for your product team

Agree on duration and delivery

We typically deliver in-house training with four modules over two days. Online, we teach the modules in half-day blocks, on site in full days. Alternatively, we agree on the delivery individually with you.

Continue working with the materials

No separate handouts are produced. The slides allow you to follow up independently. Certificates of attendance are available on request.

Plan CRA training
A navigation instrument being explained in a joint discussion
Training modules tailored to your team and your products.

Basic technical knowledge as a prerequisite

Prerequisites: basic knowledge of automation technology and a basic understanding of the benefits of security.

Questions about the training “IEC 62443 for the CRA”

Who is “IEC 62443 for the CRA in practice” intended for?

For specialists at product manufacturers who have to implement or demonstrate security requirements under the CRA and IEC 62443 in the field of industrial security: product managers, heads of development, system architects, security testers, test and QA teams, technical writers and documentation teams, and those responsible for security, compliance and quality. Basic knowledge of automation technology and a basic understanding of the benefits of security are assumed.

How much time do we need to plan for the four modules?

In-house, the four modules are typically delivered over two days. Online, we split the content into half-day blocks. Other formats are agreed with you.

Does the training confirm our product's CRA compliance?

No. It provides an understanding of the standard and methods for further work. Assessing the specific CRA requirements, implementation and any necessary product evaluations remain separate steps.

Do you also offer the training in English?

Yes. As in-house training, we deliver the IEC 62443 training in German or English.

Is the training also available for individual participants?

Yes. Through our partner heise conferences, we offer a shortened version of the IEC 62443 practical training as an open online workshop: “IEC 62443: Industrial Security für Produkthersteller” (industrial security for product manufacturers), covering IEC 62443-4-1, IEC 62443-4-2 and the overlaps with the CRA. This is suitable if you only have a few participants or want to exchange views with other manufacturers. The workshop takes place regularly; dates and registration are available from heise conferences.

How can we support you with IEC 62443 for the CRA?