IACS / Industrial

Your operators are regulated.
Now your products are too.

NIS2 made your customers demand security evidence. The CRA makes it law for your components, and the Machinery Regulation adds safety-critical cybersecurity in January 2027. IEC 62443 is the thread that ties all three together — if you use it right.

PLANT & OT 62443 EVIDENCE CERTIFICATION

The landscape

What applies to you

OT security went from best practice to legal obligation in three regulations. The short version:

You build PLCs, DCS, SCADA or industrial network gear

Your portfolio lands in the CRA’s important product classes — much of it facing notified-body assessment, all of it facing the essential requirements by December 2027 and reporting obligations this September. IEC 62443-4-1/-4-2 is the recognised path to demonstrating most of it — and it is being aligned with the CRA as a European standard right now.

CRA

62443-4-1/-4-2

You operate critical infrastructure or manufacturing

NIS2 applies — and national transpositions keep landing, each with its own registration duties, deadlines and enforcement style. Article 21 expects state-of-the-art risk management across your OT estate; supervisors increasingly read that as IEC 62443-shaped programmes. The board is personally liable. That tends to focus minds.

NIS2 ART. 21

NATIONAL LAWS

You ship machinery with safety functions

The new Machinery Regulation applies from January 2027 and pulls cybersecurity into safety conformity: a corrupted control system is now a safety defect. Safety and security assessments can no longer be run by two teams that never meet — the technical file must show protection of safety functions against corruption.

MACHINERY REG.

JAN 2027

You supply operators as a service provider or integrator

NIS2 entities must manage supply-chain risk, and they discharge it downwards: security questionnaires, contract clauses, audit rights. IEC 62443-2-4 defines what a credible service-provider security programme looks like. Answering fifty bespoke questionnaires a year is the expensive alternative to one certification.

62443-2-4

SUPPLY CHAIN

You want a certificate the market recognises

ISASecure and IECEE CB certifications against IEC 62443 are the established currencies — SDLA for your development lifecycle, CSA/EDSA-style component and system certifications for products. They pre-position you for CRA conformity and cut through customer due diligence in one move.

ISASECURE

IECEE CB

The clock is running

OT compliance dates are stacking up

The overlap is the point: work done for one regulation should be evidence for the next.

Since Oct 2024 ROLLING

NIS2 national transpositions take effect

Member State laws keep landing — Belgium's enters into force October 2026. Registration and evidence duties differ per country; multi-site operators carry a patchwork.

11 Sep 2026 WEEKS AWAY

CRA reporting obligations begin

Actively exploited vulnerabilities in your products become reportable — 24-hour early warning to ENISA and CSIRTs. For OT vendors with 15-year product lifetimes, this is an operational transformation, not a form.

Late 2026

IEC 62443 lands as European CRA standard

CEN/CENELEC work to align EN IEC 62443 with CRA essential requirements targets the late-2026 window. When it is harmonised, 62443 evidence becomes presumption of conformity — the cheapest CRA route an OT vendor will get.

20 Jan 2027

Machinery Regulation applies

Cybersecurity of safety functions becomes part of machinery conformity assessment.

11 Dec 2027

CRA applies in full

CE marking requires cybersecurity conformity for every product with digital elements — PLCs included.

How we work

One 62443 backbone, three regulatory outcomes

1

Regulatory mapping

Your portfolio against CRA classes, NIS2 exposure and Machinery Regulation scope. One matrix, one sequencing decision.

2

62443 gap assessment

Development lifecycle against 4-1, components against 4-2, systems against 3-3, services against 2-4 — with maturity levels that survive an auditor.

3

Secure development programme

An SDL that produces CRA Annex I evidence as a by-product of engineering, not a documentation sprint before each audit.

4

Zones, conduits & system evidence

Reference architectures and security-level rationale your integrators and operators can reuse in their own NIS2 files.

5

Certification support

ISASecure, IECEE CB or notified-body routes — file preparation, lab liaison, and someone on your side of the table.

6

PSIRT & lifecycle compliance

Vulnerability handling and September 2026 reporting readiness, built for products that live in the field for decades.

One evidence base, three regulations

A 62443-structured security programme feeds your CRA technical file, your customers’ NIS2 supply-chain files and the Machinery Regulation safety case. Build it once, cite it three times.

IEC 62443 EVIDENCE CRA Annex I ISASecure / IECEE Machinery Reg. Customer NIS2 files Security questionnaires Tenders & frameworks

For the specialists

The detail behind the summary

If you already speak 62443, start here.

62443 as the CRA backbone

The mapping is good but not free: 62443-4-1 covers most CRA process requirements (vulnerability handling, secure development), 4-2 covers a large share of Annex I product requirements — but CRA adds elements 62443 never asked for, notably SBOM expectations, EU-specific reporting flows and support-period declarations.

CEN/CENELEC alignment work targets late 2026 for the European versions. Until harmonised references are cited in the OJEU, 62443 evidence supports conformity but does not presume it.

Our position: run the 62443-to-Annex-I delta explicitly and close it in your SDL now. Vendors waiting for the harmonised text are betting their 2027 market access on a standards committee’s calendar.

The 62443 security-level system only works when target levels come from a real risk assessment (3-2), not from marketing. SL2 is the de-facto floor for most modern tenders; SL3 claims trigger hard questions about resistance to intentional, skilled attacks — and component SL ratings mean little outside a zone-and-conduit architecture that supports them.

The recurring failure: certified components assembled into an uncertifiable system, because nobody owned the system-level security rationale.

Our position: we write SL rationales an assessor can test — and we tell you when SL3 is a tender requirement worth challenging rather than engineering for.

Article 21 measures — risk analysis, incident handling, supply-chain security, encryption policy — read differently in a plant with 20-year-old controllers and no patch windows. Supervisors accept compensating controls when they are documented as risk decisions; they do not accept “legacy” as a category of exemption. Multi-country operators face divergent national transpositions with different registration and reporting mechanics.

Our position: an OT security programme structured on 62443-2-1 and 3-2, with explicit residual-risk acceptance, answers both the auditor and the regulator. Compliance theatre structured on spreadsheets answers neither.

From January 2027, Machinery Regulation essential requirements cover protection against corruption of safety functions — the technical file must show that a cyber attack cannot silently defeat a safety loop. That pulls IEC 62443 analysis into IEC 61508/13849 territory: shared fault models, security levels justified against safety integrity levels, coordinated conformity assessment.

Our position: merge the risk assessments, keep the disciplines. One team, one threat-and-hazard model, two normative vocabularies — anything else produces contradictions a notified body will find.

Talk to people who know both the standard and the plant floor

No sales rep. Thirty minutes with an OT certification expert and a straight answer on where your portfolio stands.

Contact us

Request this document

We’ll send you access by email.