Organizational + Product Dual Compliance | Most Direct CRA CE Marking Path

IEC 62443 OT/ICS Security Integrated Advisory

OT/ICS Organizational Compliance × Product Certification — Full Series

IEC 62443 spans organizational systems and product technology across 5 major sub-standards, with different role combinations applying to different organizations. Winners Consulting diagnoses applicable sub-standards in one assessment to avoid unnecessary effort, and guides in the correct sequence of "4-1 organizational capability → 4-2 product certification" to maximize first-submission certification success rates.

5
Sub-standards
Prerequisite
4-1 → 4-2
Direct Path
CRA Link
SL 1-3
SL Levels
Request Free Sub-Standard Applicability Assessment

Quick Guide: Which Sub-Standards Do I Need?

Q

I manufacture OT/ICS equipment and export

→ 4-1 (first) → 4-2 (product certification)

Q

I integrate OT systems for European factories

→ 2-4 + 3-3

Q

I am a factory/power plant/critical infrastructure

→ 2-1 + 3-3

Q

I provide OT security services (MSSP)

→ 2-4

Q

I develop embedded/IoT (OT use cases)

→ 4-1 (first) → 4-2 (product certification)

Q

European clients require it but I don't know where to start

→ → Free assessment to confirm pathway

What is IEC 62443? Why Must Taiwan OT Vendors Pay Attention?

IEC 62443 is the international cybersecurity standard series for industrial automation and control systems (IACS/OT/ICS), covering the complete security requirements framework from security management systems to specific component products. While EU CRA does not directly mandate IEC 62443 certification, it is the mainstream technical pathway for CRA conformity assessment in industrial, energy, and manufacturing sectors, and is increasingly common in European OEM procurement contracts. Taiwan vendors face triple pressure: CRA 2026/09 reporting obligations are already applicable; European OEMs require 62443-4-1 organizational certification in procurement contracts; NIS2 critical infrastructure clients require equipment meeting 62443-3-3 security level specifications.

IEC 62443 Five Sub-Standards Explained

Understand applicable targets, content scope, and sequential relationships of each sub-standard

Organizational Compliance

IEC 62443-2-1

IACS Security Management System Requirements

Applicable To

Asset owners (factories, power plants, water facilities, etc.)

Scope

Establish IACS Security Management System (SMS) covering policies, procedures, risk assessment, incident response, and supplier management

Prerequisites

No prerequisites

Regulatory/Market Requirements

NIS2 supplier security clauses, factory self-assessment

Organizational Compliance

IEC 62443-2-4

IACS Service Provider Security Requirements

Applicable To

System integrators, maintenance service providers, OT consultants

Scope

Security requirements that service providers must follow when working in client IACS environments, covering remote access, change management, and incident response

Prerequisites

No prerequisites (independently applicable)

Regulatory/Market Requirements

European OEM contractual requirements for system integrators

System Layer (Org/Product Bridge)

IEC 62443-3-3

System Security Requirements and Security Levels

Applicable To

System integrators, asset owners

Scope

Defines IACS system security functional requirements (FR 1-7) and security levels (SL 1-4) as procurement specifications or system design reference

Prerequisites

Organization needs 2-1 or 2-4 foundation

Regulatory/Market Requirements

NIS2 critical infrastructure OT security requirements, CRA system assessment

Organizational Compliance (Product Certification Prerequisite)

IEC 62443-4-1

SDL Security Development Lifecycle

Applicable To

Equipment/component manufacturers (development organizations)

Scope

Defines manufacturer SDL requirements: security requirements, security architecture, secure code review, SAST/DAST, and vulnerability management

Prerequisites

Required prerequisite for 4-2

Regulatory/Market Requirements

CRA Security-by-Design obligations, European OEM supplier requirements

Product Compliance

IEC 62443-4-2

Component Technical Security Requirements

Applicable To

Equipment/component manufacturers (for specific products)

Scope

Defines seven foundational requirements (FR) for OT/ICS component products: identification & authentication, use control, system integrity, data confidentiality, restricted data flow, timely response, resource availability

Prerequisites

Organization must first comply with 4-1 SDL

Regulatory/Market Requirements

Most direct CRA CE marking path, supply chain product compliance requirements

Sub-standard sequence and certification pathway

2-1 Security MgmtAsset owners
/
2-4 Service ProviderIntegrators
→
3-3 System SLSystem layer
→
4-1 SDL (first)Org certification
→
4-2 ComponentProduct (CRA)

⚠️ Organizations must complete 4-1 SDL certification before obtaining 4-2 product certification

Confirm Applicable Sub-Standards by Role

Find your role and confirm the necessary certification combination

Industrial Equipment Manufacturer (exporting to EU)

4-14-23-3(Optional)

4-1 establishes development capability, 4-2 achieves product certification, supports CRA CE marking

System Integrator (serving European factories)

2-43-32-1(Optional)

2-4 meets service provider security requirements, 3-3 used for system design specifications

Factory/Power Plant/Critical Infrastructure

2-13-32-4(Optional)

2-1 establishes own security management, 3-3 defines security level requirements for procured equipment

OT Security Service Provider (MSSP)

2-42-1(Optional)3-3(Optional)

2-4 is the core requirement for service providers, ensuring service delivery meets client IACS security standards

Embedded Systems/IoT Device Vendor (OT use cases)

4-14-23-3(Optional)

Same path as industrial equipment; CRA + 62443-4-2 dual-track ensures market access

✅ Achieving IEC 62443 Certification

  • ✓4-2 product certification becomes the most direct CRA CE marking conformity path
  • ✓European OEM procurement contract qualification reviews passed on first attempt; stable orders
  • ✓4-1 SDL organizational certification improves development process quality; reduces product vulnerability density
  • ✓NIS2 critical infrastructure client procurement specifications automatically satisfied
  • ✓3-3 security level assessment serves as a procurement specification tool; leads supplier selection
  • ✓Lower EU market entry barriers compared to competitors after certification
  • ✓Integrated advisory for multiple sub-standards simultaneously; efficiency maximized

× Risks of Non-Certification

  • ×Unable to obtain CE marking before CRA 2027/12 deadline; OT products banned from EU sales
  • ×European OEM procurement contracts require 4-1 certification; inability to provide results in disqualification
  • ×Pursuing 4-2 without 4-1; certification body rejection wastes 6-12 months
  • ×No 2-4 certification; European clients add major breach clauses to system integration contracts
  • ×Not knowing which sub-standards are needed; pursuing unnecessary certifications wastes resources
  • ×After competitors obtain certification, EU market pricing negotiation capability gap widens
  • ×NIS2 supply chain security requirements indirectly force clients to switch to certified suppliers

Winners Consulting IEC 62443 Integrated Advisory Process

Five steps from sub-standard diagnosis to certification

01

Role Definition & Sub-Standard Applicability Diagnosis

Based on enterprise role (equipment manufacturer/system integrator/service provider/asset owner) and objectives (organizational compliance/product certification/supply chain requirements), diagnose the minimum necessary sub-standard combination to avoid over-investing in unnecessary certifications.

02

4-1 SDL Security Development Capability (Organizational Prerequisite)

If 4-2 product certification is needed, must first establish SDL security development process per 4-1: security requirements management, security architecture design, secure code review, security testing, and vulnerability management.

03

2-1/2-4 Security Management System

Build organizational security management policies per 2-1 (IACS security management system) or 2-4 (service provider security requirements), Zone & Conduit model design, risk assessment procedures, and supplier security management.

04

3-3/4-2 Technical Requirements Assessment & Implementation

Assess system-level security level targets (SL-T) and capability (SL-C) per 3-3, conduct gap analysis against the seven foundational requirements (FR) for product components per 4-2, implement technical hardening and test verification.

05

Conformity Assessment & Third-Party Certification

Arrange conformity self-assessment or commission third-party certification from Notified Bodies such as TÜV/SGS based on target certification level; prepare technical documentation package; confirm if concurrent CRA CE marking is needed.

Frequently Asked Questions

What is IEC 62443? What is its relationship with CRA?▾

IEC 62443 is the international cybersecurity standard series for industrial control systems (ICS/IACS/OT). While EU CRA does not directly mandate IEC 62443 certification, it is the most widely recognized technical standard for proving CRA conformity in industrial automation, energy, and manufacturing. IEC 62443 certification significantly simplifies CRA conformity assessment.

What sub-standards does IEC 62443 have? Which does my enterprise need?▾

Key IEC 62443 sub-standards: 2-1 (IACS security management system, organizational), 2-4 (service provider security requirements, organizational), 3-3 (system security requirements and security levels, system layer), 4-1 (SDL security development, organizational, product certification prerequisite), 4-2 (component technical security requirements, product). Logic: manufacturers must comply with 4-1 before 4-2; system integrators need 2-4; asset owners need 2-1. Winners Consulting provides free sub-standard applicability diagnosis.

What is the difference between IEC 62443-4-1 and 4-2? Why is 4-1 a prerequisite for 4-2?▾

IEC 62443-4-1 defines "manufacturer security development lifecycle (SDL)" organizational capability requirements; it is organizational compliance. 4-2 defines "component product technical security requirements" and is product compliance. Prerequisite relationship: if the development organization hasn't established 4-1 SDL capability, developed products lack security assurance at the design source; Notified Bodies typically verify 4-1 compliance before certifying 4-2.

What are security levels (SL)? What are the differences between SL 1 and SL 3?▾

IEC 62443 defines four security levels: SL 0 (no specific cybersecurity requirements); SL 1 (protection against casual or unintentional attacks); SL 2 (protection against skilled, motivated attackers like industrial spies); SL 3 (protection against sophisticated attackers with specialized tools and resources like nation-state threats). Taiwan industrial equipment exported to the EU typically requires SL 1-2; energy/power critical infrastructure requires SL 2-3.

How can Taiwan OT/ICS equipment vendors enter the EU market through IEC 62443?▾

Compliance pathway for Taiwan OT/ICS vendors: (1) CRA conformity: industrial control equipment typically falls under CRA Class I/II; IEC 62443-4-2 certification is the most direct conformity proof pathway; (2) EU supply chain requirements: European OEMs increasingly require 4-1 organizational certification; (3) NIS2 supply chain obligations: critical infrastructure clients may require equipment meeting 62443-3-3 security level specifications.

How long does IEC 62443 certification take? What are the costs?▾

IEC 62443-4-1 SDL organizational certification typically takes 6-9 months; 4-2 product certification takes 4-8 months (excluding 4-1 build time); 2-1 management system takes 4-6 months; 2-4 service provider certification takes 3-5 months. Winners Consulting provides free applicability diagnosis to confirm minimum necessary certification combination before estimating timeline and cost.

How is Winners' IEC 62443 advisory different from going directly to a certification body?▾

Notified Bodies conduct certification testing and issue certificates but don't provide institution-building advisory. Winners Consulting as advisory consultant: (1) diagnoses applicable sub-standard combination; (2) builds SDL processes/management systems/technical documents per standard requirements; (3) conducts pre-certification review to maximize first-submission pass rates; (4) coordinates Notified Body communication. Winners Consulting has relationships with multiple Notified Bodies.

One Assessment to Confirm Which IEC 62443 Sub-Standards You Need

Free sub-standard applicability assessment: confirm minimum necessary certification combination based on enterprise role and target market, plan correct 4-1 → 4-2 sequence, integrate CRA conformity assessment, provide shortest-path timeline.

Related Deep Insights

In-depth analysis by Winners consultants, 6,000+ words per article

auto

The Autonomous Driving Trust Case: A Complete Safety Argument Framework Beyond ISO/SAE 21434 Compliance

A 2023 Norwegian study found trust and safety are statistically unrelated, revealing that an ISO/SAE 21434 cybersecurity case alone cannot build public trust in autonomous driving. The research proposes a supplementary 'Trust Case' framework to present AI transparency and organizational accountability in layperson's terms. Taiwanese suppliers must build a complete, customer-facing safety argument beyond TISAX certification and UNECE WP.29 compliance to address this critical gap.

auto

Team Structure Insights from ISO/SAE 21434 Development: The Organizational Key to Automotive Cybersecurity Compliance in Taiwan

Using the ISO/SAE 21434 development process as a case study, Zhang Hengwei's research reveals that team structure is the most critical IPO factor affecting international standard quality. For Taiwan's automotive suppliers, this means the success of TISAX certification and ISO/SAE 21434 implementation hinges on establishing a cross-functional cybersecurity governance team.

auto

Optimizing Early-Stage Automotive Cybersecurity Process Design: A Practical Analysis of ISO/SAE 21434 and TISAX Compliance

Research by Christine Jakobs (2023) reveals systemic gaps in the early design phase of the automotive cybersecurity V-Model, leading to an incomplete ISO/SAE 21434 compliance evidence chain. The study proposes a function-oriented risk analysis method to identify threats before system architecture is finalized. This approach is crucial for Taiwanese suppliers preparing for TISAX certification and complying with UNECE WP.29 UN-R155 regulations, offering a practical framework to strengthen early-stage security practices and ensure robust compliance.

auto

Proposing HEAVENS 2.0: An Automotive Risk Assessment Model – Winners Consulting Services Insights

Winners Consulting Services Co., Ltd. highlights HEAVENS 2.0 as the vehicle risk assessment model that most closely aligns with ISO/SAE 21434 requirements. The research team systematically identified 17 model updates—12 to address compliance gaps and 5 to remediate weaknesses—fully aligning the original HEAVENS framework with mandatory UN R155 regulations. This provides a clear gap analysis checklist for Taiwanese automotive suppliers navigating TISAX certification and ISO/SAE 21434 implementation.

auto

AMCSF: New Cloud Compliance Requirements for ISO 21434 and TISAX

Geol Kang's 2025 Automotive Multi-Cloud Security Framework (AMCSF) reveals that in the era of Software-Defined Vehicles, the primary attack surface has shifted from the vehicle to the cloud backend. The five-layer defense architecture integrates the ISO/SAE 21434 lifecycle and emphasizes the necessity of CSPM tools. Taiwanese OEMs and Tier-1/Tier-2 suppliers must incorporate cloud security into their TISAX assessment preparations to meet these evolving compliance demands and secure their position in the supply chain.

auto

ISO/SAE 21434 Gap Analysis: Systematically Strengthening TARA Management and Incident Handling

A 2023 arXiv paper reveals systemic gaps in ISO/SAE 21434 concerning cross-supply chain TARA management and vulnerability incident handling, proposing 13 new terms and 4 new process steps. Taiwanese automotive suppliers, during TISAX certification and UNECE WP.29 compliance, should prioritize strengthening post-production incident response and TARA lifecycle management. Winners Consulting Services offers a 90-day implementation plan to address these critical areas and ensure robust compliance.

auto

Quantifying Systemic Cybersecurity Impacts of Connected Vehicles: A Key Extension for ISO 21434 TARA

The current ISO/SAE 21434 TARA framework, limited to a single-vehicle boundary, fails to quantify the cascading impacts of connected vehicles on the entire traffic system. A new study simulates three attack scenarios, introducing for the first time systemic operational and safety impact vectors to provide an objective basis for TARA impact ratings. Taiwanese automotive suppliers pursuing TISAX certification and UNECE WP.29 compliance must incorporate this systemic risk perspective into their threat analysis to meet evolving OEM requirements and enhance the defensibility of their cybersecurity management systems.

auto

An Adaptable Security-by-Design Approach — Winners Consulting Services Insights

Winners Consulting Services Co., Ltd. highlights a 2025 study by UK scholar Jeremy Bryans et al., which is the first to systematically apply the Security-by-Design concept from ISO/SAE 21434 to the entire lifecycle of vehicle OTA updates. The research integrates Threat Analysis and Risk Assessment (TARA) with UNECE WP.29 mitigation requirements, offering a practical framework for Taiwanese automotive suppliers navigating TISAX certification and ISO/SAE 21434 compliance.