NIS2 made your customers demand security evidence. The CRA makes it law for your components, and the Machinery Regulation adds safety-critical cybersecurity in January 2027. IEC 62443 is the thread that ties all three together — if you use it right.
The landscape
OT security went from best practice to legal obligation in three regulations. The short version:
Your portfolio lands in the CRA’s important product classes — much of it facing notified-body assessment, all of it facing the essential requirements by December 2027 and reporting obligations this September. IEC 62443-4-1/-4-2 is the recognised path to demonstrating most of it — and it is being aligned with the CRA as a European standard right now.
CRA
62443-4-1/-4-2
NIS2 applies — and national transpositions keep landing, each with its own registration duties, deadlines and enforcement style. Article 21 expects state-of-the-art risk management across your OT estate; supervisors increasingly read that as IEC 62443-shaped programmes. The board is personally liable. That tends to focus minds.
NIS2 ART. 21
NATIONAL LAWS
The new Machinery Regulation applies from January 2027 and pulls cybersecurity into safety conformity: a corrupted control system is now a safety defect. Safety and security assessments can no longer be run by two teams that never meet — the technical file must show protection of safety functions against corruption.
MACHINERY REG.
JAN 2027
NIS2 entities must manage supply-chain risk, and they discharge it downwards: security questionnaires, contract clauses, audit rights. IEC 62443-2-4 defines what a credible service-provider security programme looks like. Answering fifty bespoke questionnaires a year is the expensive alternative to one certification.
62443-2-4
SUPPLY CHAIN
ISASecure and IECEE CB certifications against IEC 62443 are the established currencies — SDLA for your development lifecycle, CSA/EDSA-style component and system certifications for products. They pre-position you for CRA conformity and cut through customer due diligence in one move.
ISASECURE
IECEE CB
The clock is running
The overlap is the point: work done for one regulation should be evidence for the next.
Member State laws keep landing — Belgium's enters into force October 2026. Registration and evidence duties differ per country; multi-site operators carry a patchwork.
Actively exploited vulnerabilities in your products become reportable — 24-hour early warning to ENISA and CSIRTs. For OT vendors with 15-year product lifetimes, this is an operational transformation, not a form.
CEN/CENELEC work to align EN IEC 62443 with CRA essential requirements targets the late-2026 window. When it is harmonised, 62443 evidence becomes presumption of conformity — the cheapest CRA route an OT vendor will get.
Cybersecurity of safety functions becomes part of machinery conformity assessment.
CE marking requires cybersecurity conformity for every product with digital elements — PLCs included.
How we work
Your portfolio against CRA classes, NIS2 exposure and Machinery Regulation scope. One matrix, one sequencing decision.
Development lifecycle against 4-1, components against 4-2, systems against 3-3, services against 2-4 — with maturity levels that survive an auditor.
An SDL that produces CRA Annex I evidence as a by-product of engineering, not a documentation sprint before each audit.
Reference architectures and security-level rationale your integrators and operators can reuse in their own NIS2 files.
ISASecure, IECEE CB or notified-body routes — file preparation, lab liaison, and someone on your side of the table.
Vulnerability handling and September 2026 reporting readiness, built for products that live in the field for decades.
A 62443-structured security programme feeds your CRA technical file, your customers’ NIS2 supply-chain files and the Machinery Regulation safety case. Build it once, cite it three times.
For the specialists
If you already speak 62443, start here.
The mapping is good but not free: 62443-4-1 covers most CRA process requirements (vulnerability handling, secure development), 4-2 covers a large share of Annex I product requirements — but CRA adds elements 62443 never asked for, notably SBOM expectations, EU-specific reporting flows and support-period declarations.
CEN/CENELEC alignment work targets late 2026 for the European versions. Until harmonised references are cited in the OJEU, 62443 evidence supports conformity but does not presume it.
Our position: run the 62443-to-Annex-I delta explicitly and close it in your SDL now. Vendors waiting for the harmonised text are betting their 2027 market access on a standards committee’s calendar.
The 62443 security-level system only works when target levels come from a real risk assessment (3-2), not from marketing. SL2 is the de-facto floor for most modern tenders; SL3 claims trigger hard questions about resistance to intentional, skilled attacks — and component SL ratings mean little outside a zone-and-conduit architecture that supports them.
The recurring failure: certified components assembled into an uncertifiable system, because nobody owned the system-level security rationale.
Our position: we write SL rationales an assessor can test — and we tell you when SL3 is a tender requirement worth challenging rather than engineering for.
Article 21 measures — risk analysis, incident handling, supply-chain security, encryption policy — read differently in a plant with 20-year-old controllers and no patch windows. Supervisors accept compensating controls when they are documented as risk decisions; they do not accept “legacy” as a category of exemption. Multi-country operators face divergent national transpositions with different registration and reporting mechanics.
Our position: an OT security programme structured on 62443-2-1 and 3-2, with explicit residual-risk acceptance, answers both the auditor and the regulator. Compliance theatre structured on spreadsheets answers neither.
From January 2027, Machinery Regulation essential requirements cover protection against corruption of safety functions — the technical file must show that a cyber attack cannot silently defeat a safety loop. That pulls IEC 62443 analysis into IEC 61508/13849 territory: shared fault models, security levels justified against safety integrity levels, coordinated conformity assessment.
Our position: merge the risk assessments, keep the disciplines. One team, one threat-and-hazard model, two normative vocabularies — anything else produces contradictions a notified body will find.
No sales rep. Thirty minutes with an OT certification expert and a straight answer on where your portfolio stands.
We’ll send you access by email.