IEC 62443 OT/ICS Security Integrated Advisory
OT/ICS Organizational Compliance × Product Certification — Full Series
IEC 62443 spans organizational systems and product technology across 5 major sub-standards, with different role combinations applying to different organizations. Winners Consulting diagnoses applicable sub-standards in one assessment to avoid unnecessary effort, and guides in the correct sequence of "4-1 organizational capability → 4-2 product certification" to maximize first-submission certification success rates.
Quick Guide: Which Sub-Standards Do I Need?
I manufacture OT/ICS equipment and export
→ 4-1 (first) → 4-2 (product certification)
I integrate OT systems for European factories
→ 2-4 + 3-3
I am a factory/power plant/critical infrastructure
→ 2-1 + 3-3
I provide OT security services (MSSP)
→ 2-4
I develop embedded/IoT (OT use cases)
→ 4-1 (first) → 4-2 (product certification)
European clients require it but I don't know where to start
→ → Free assessment to confirm pathway
What is IEC 62443? Why Must Taiwan OT Vendors Pay Attention?
IEC 62443 is the international cybersecurity standard series for industrial automation and control systems (IACS/OT/ICS), covering the complete security requirements framework from security management systems to specific component products. While EU CRA does not directly mandate IEC 62443 certification, it is the mainstream technical pathway for CRA conformity assessment in industrial, energy, and manufacturing sectors, and is increasingly common in European OEM procurement contracts. Taiwan vendors face triple pressure: CRA 2026/09 reporting obligations are already applicable; European OEMs require 62443-4-1 organizational certification in procurement contracts; NIS2 critical infrastructure clients require equipment meeting 62443-3-3 security level specifications.
IEC 62443 Five Sub-Standards Explained
Understand applicable targets, content scope, and sequential relationships of each sub-standard
IEC 62443-2-1
IACS Security Management System RequirementsApplicable To
Asset owners (factories, power plants, water facilities, etc.)
Scope
Establish IACS Security Management System (SMS) covering policies, procedures, risk assessment, incident response, and supplier management
Prerequisites
No prerequisites
Regulatory/Market Requirements
NIS2 supplier security clauses, factory self-assessment
IEC 62443-2-4
IACS Service Provider Security RequirementsApplicable To
System integrators, maintenance service providers, OT consultants
Scope
Security requirements that service providers must follow when working in client IACS environments, covering remote access, change management, and incident response
Prerequisites
No prerequisites (independently applicable)
Regulatory/Market Requirements
European OEM contractual requirements for system integrators
IEC 62443-3-3
System Security Requirements and Security LevelsApplicable To
System integrators, asset owners
Scope
Defines IACS system security functional requirements (FR 1-7) and security levels (SL 1-4) as procurement specifications or system design reference
Prerequisites
Organization needs 2-1 or 2-4 foundation
Regulatory/Market Requirements
NIS2 critical infrastructure OT security requirements, CRA system assessment
IEC 62443-4-1
SDL Security Development LifecycleApplicable To
Equipment/component manufacturers (development organizations)
Scope
Defines manufacturer SDL requirements: security requirements, security architecture, secure code review, SAST/DAST, and vulnerability management
Prerequisites
Required prerequisite for 4-2
Regulatory/Market Requirements
CRA Security-by-Design obligations, European OEM supplier requirements
IEC 62443-4-2
Component Technical Security RequirementsApplicable To
Equipment/component manufacturers (for specific products)
Scope
Defines seven foundational requirements (FR) for OT/ICS component products: identification & authentication, use control, system integrity, data confidentiality, restricted data flow, timely response, resource availability
Prerequisites
Organization must first comply with 4-1 SDL
Regulatory/Market Requirements
Most direct CRA CE marking path, supply chain product compliance requirements
Sub-standard sequence and certification pathway
⚠️ Organizations must complete 4-1 SDL certification before obtaining 4-2 product certification
Confirm Applicable Sub-Standards by Role
Find your role and confirm the necessary certification combination
Industrial Equipment Manufacturer (exporting to EU)
4-1 establishes development capability, 4-2 achieves product certification, supports CRA CE marking
System Integrator (serving European factories)
2-4 meets service provider security requirements, 3-3 used for system design specifications
Factory/Power Plant/Critical Infrastructure
2-1 establishes own security management, 3-3 defines security level requirements for procured equipment
OT Security Service Provider (MSSP)
2-4 is the core requirement for service providers, ensuring service delivery meets client IACS security standards
Embedded Systems/IoT Device Vendor (OT use cases)
Same path as industrial equipment; CRA + 62443-4-2 dual-track ensures market access
✅ Achieving IEC 62443 Certification
- ✓4-2 product certification becomes the most direct CRA CE marking conformity path
- ✓European OEM procurement contract qualification reviews passed on first attempt; stable orders
- ✓4-1 SDL organizational certification improves development process quality; reduces product vulnerability density
- ✓NIS2 critical infrastructure client procurement specifications automatically satisfied
- ✓3-3 security level assessment serves as a procurement specification tool; leads supplier selection
- ✓Lower EU market entry barriers compared to competitors after certification
- ✓Integrated advisory for multiple sub-standards simultaneously; efficiency maximized
× Risks of Non-Certification
- ×Unable to obtain CE marking before CRA 2027/12 deadline; OT products banned from EU sales
- ×European OEM procurement contracts require 4-1 certification; inability to provide results in disqualification
- ×Pursuing 4-2 without 4-1; certification body rejection wastes 6-12 months
- ×No 2-4 certification; European clients add major breach clauses to system integration contracts
- ×Not knowing which sub-standards are needed; pursuing unnecessary certifications wastes resources
- ×After competitors obtain certification, EU market pricing negotiation capability gap widens
- ×NIS2 supply chain security requirements indirectly force clients to switch to certified suppliers
Winners Consulting IEC 62443 Integrated Advisory Process
Five steps from sub-standard diagnosis to certification
Role Definition & Sub-Standard Applicability Diagnosis
Based on enterprise role (equipment manufacturer/system integrator/service provider/asset owner) and objectives (organizational compliance/product certification/supply chain requirements), diagnose the minimum necessary sub-standard combination to avoid over-investing in unnecessary certifications.
4-1 SDL Security Development Capability (Organizational Prerequisite)
If 4-2 product certification is needed, must first establish SDL security development process per 4-1: security requirements management, security architecture design, secure code review, security testing, and vulnerability management.
2-1/2-4 Security Management System
Build organizational security management policies per 2-1 (IACS security management system) or 2-4 (service provider security requirements), Zone & Conduit model design, risk assessment procedures, and supplier security management.
3-3/4-2 Technical Requirements Assessment & Implementation
Assess system-level security level targets (SL-T) and capability (SL-C) per 3-3, conduct gap analysis against the seven foundational requirements (FR) for product components per 4-2, implement technical hardening and test verification.
Conformity Assessment & Third-Party Certification
Arrange conformity self-assessment or commission third-party certification from Notified Bodies such as TÜV/SGS based on target certification level; prepare technical documentation package; confirm if concurrent CRA CE marking is needed.
Frequently Asked Questions
What is IEC 62443? What is its relationship with CRA?▾
IEC 62443 is the international cybersecurity standard series for industrial control systems (ICS/IACS/OT). While EU CRA does not directly mandate IEC 62443 certification, it is the most widely recognized technical standard for proving CRA conformity in industrial automation, energy, and manufacturing. IEC 62443 certification significantly simplifies CRA conformity assessment.
What sub-standards does IEC 62443 have? Which does my enterprise need?▾
Key IEC 62443 sub-standards: 2-1 (IACS security management system, organizational), 2-4 (service provider security requirements, organizational), 3-3 (system security requirements and security levels, system layer), 4-1 (SDL security development, organizational, product certification prerequisite), 4-2 (component technical security requirements, product). Logic: manufacturers must comply with 4-1 before 4-2; system integrators need 2-4; asset owners need 2-1. Winners Consulting provides free sub-standard applicability diagnosis.
What is the difference between IEC 62443-4-1 and 4-2? Why is 4-1 a prerequisite for 4-2?▾
IEC 62443-4-1 defines "manufacturer security development lifecycle (SDL)" organizational capability requirements; it is organizational compliance. 4-2 defines "component product technical security requirements" and is product compliance. Prerequisite relationship: if the development organization hasn't established 4-1 SDL capability, developed products lack security assurance at the design source; Notified Bodies typically verify 4-1 compliance before certifying 4-2.
What are security levels (SL)? What are the differences between SL 1 and SL 3?▾
IEC 62443 defines four security levels: SL 0 (no specific cybersecurity requirements); SL 1 (protection against casual or unintentional attacks); SL 2 (protection against skilled, motivated attackers like industrial spies); SL 3 (protection against sophisticated attackers with specialized tools and resources like nation-state threats). Taiwan industrial equipment exported to the EU typically requires SL 1-2; energy/power critical infrastructure requires SL 2-3.
How can Taiwan OT/ICS equipment vendors enter the EU market through IEC 62443?▾
Compliance pathway for Taiwan OT/ICS vendors: (1) CRA conformity: industrial control equipment typically falls under CRA Class I/II; IEC 62443-4-2 certification is the most direct conformity proof pathway; (2) EU supply chain requirements: European OEMs increasingly require 4-1 organizational certification; (3) NIS2 supply chain obligations: critical infrastructure clients may require equipment meeting 62443-3-3 security level specifications.
How long does IEC 62443 certification take? What are the costs?▾
IEC 62443-4-1 SDL organizational certification typically takes 6-9 months; 4-2 product certification takes 4-8 months (excluding 4-1 build time); 2-1 management system takes 4-6 months; 2-4 service provider certification takes 3-5 months. Winners Consulting provides free applicability diagnosis to confirm minimum necessary certification combination before estimating timeline and cost.
How is Winners' IEC 62443 advisory different from going directly to a certification body?▾
Notified Bodies conduct certification testing and issue certificates but don't provide institution-building advisory. Winners Consulting as advisory consultant: (1) diagnoses applicable sub-standard combination; (2) builds SDL processes/management systems/technical documents per standard requirements; (3) conducts pre-certification review to maximize first-submission pass rates; (4) coordinates Notified Body communication. Winners Consulting has relationships with multiple Notified Bodies.
One Assessment to Confirm Which IEC 62443 Sub-Standards You Need
Free sub-standard applicability assessment: confirm minimum necessary certification combination based on enterprise role and target market, plan correct 4-1 → 4-2 sequence, integrate CRA conformity assessment, provide shortest-path timeline.
Related Deep Insights
In-depth analysis by Winners consultants, 6,000+ words per article
The Autonomous Driving Trust Case: A Complete Safety Argument Framework Beyond ISO/SAE 21434 Compliance
A 2023 Norwegian study found trust and safety are statistically unrelated, revealing that an ISO/SAE 21434 cybersecurity case alone cannot build public trust in autonomous driving. The research proposes a supplementary 'Trust Case' framework to present AI transparency and organizational accountability in layperson's terms. Taiwanese suppliers must build a complete, customer-facing safety argument beyond TISAX certification and UNECE WP.29 compliance to address this critical gap.
autoTeam Structure Insights from ISO/SAE 21434 Development: The Organizational Key to Automotive Cybersecurity Compliance in Taiwan
Using the ISO/SAE 21434 development process as a case study, Zhang Hengwei's research reveals that team structure is the most critical IPO factor affecting international standard quality. For Taiwan's automotive suppliers, this means the success of TISAX certification and ISO/SAE 21434 implementation hinges on establishing a cross-functional cybersecurity governance team.
autoOptimizing Early-Stage Automotive Cybersecurity Process Design: A Practical Analysis of ISO/SAE 21434 and TISAX Compliance
Research by Christine Jakobs (2023) reveals systemic gaps in the early design phase of the automotive cybersecurity V-Model, leading to an incomplete ISO/SAE 21434 compliance evidence chain. The study proposes a function-oriented risk analysis method to identify threats before system architecture is finalized. This approach is crucial for Taiwanese suppliers preparing for TISAX certification and complying with UNECE WP.29 UN-R155 regulations, offering a practical framework to strengthen early-stage security practices and ensure robust compliance.
autoProposing HEAVENS 2.0: An Automotive Risk Assessment Model – Winners Consulting Services Insights
Winners Consulting Services Co., Ltd. highlights HEAVENS 2.0 as the vehicle risk assessment model that most closely aligns with ISO/SAE 21434 requirements. The research team systematically identified 17 model updates—12 to address compliance gaps and 5 to remediate weaknesses—fully aligning the original HEAVENS framework with mandatory UN R155 regulations. This provides a clear gap analysis checklist for Taiwanese automotive suppliers navigating TISAX certification and ISO/SAE 21434 implementation.
autoAMCSF: New Cloud Compliance Requirements for ISO 21434 and TISAX
Geol Kang's 2025 Automotive Multi-Cloud Security Framework (AMCSF) reveals that in the era of Software-Defined Vehicles, the primary attack surface has shifted from the vehicle to the cloud backend. The five-layer defense architecture integrates the ISO/SAE 21434 lifecycle and emphasizes the necessity of CSPM tools. Taiwanese OEMs and Tier-1/Tier-2 suppliers must incorporate cloud security into their TISAX assessment preparations to meet these evolving compliance demands and secure their position in the supply chain.
autoISO/SAE 21434 Gap Analysis: Systematically Strengthening TARA Management and Incident Handling
A 2023 arXiv paper reveals systemic gaps in ISO/SAE 21434 concerning cross-supply chain TARA management and vulnerability incident handling, proposing 13 new terms and 4 new process steps. Taiwanese automotive suppliers, during TISAX certification and UNECE WP.29 compliance, should prioritize strengthening post-production incident response and TARA lifecycle management. Winners Consulting Services offers a 90-day implementation plan to address these critical areas and ensure robust compliance.
autoQuantifying Systemic Cybersecurity Impacts of Connected Vehicles: A Key Extension for ISO 21434 TARA
The current ISO/SAE 21434 TARA framework, limited to a single-vehicle boundary, fails to quantify the cascading impacts of connected vehicles on the entire traffic system. A new study simulates three attack scenarios, introducing for the first time systemic operational and safety impact vectors to provide an objective basis for TARA impact ratings. Taiwanese automotive suppliers pursuing TISAX certification and UNECE WP.29 compliance must incorporate this systemic risk perspective into their threat analysis to meet evolving OEM requirements and enhance the defensibility of their cybersecurity management systems.
autoAn Adaptable Security-by-Design Approach — Winners Consulting Services Insights
Winners Consulting Services Co., Ltd. highlights a 2025 study by UK scholar Jeremy Bryans et al., which is the first to systematically apply the Security-by-Design concept from ISO/SAE 21434 to the entire lifecycle of vehicle OTA updates. The research integrates Threat Analysis and Risk Assessment (TARA) with UNECE WP.29 mitigation requirements, offering a practical framework for Taiwanese automotive suppliers navigating TISAX certification and ISO/SAE 21434 compliance.