IEC 62443 and CRA why the standard is the right starting point

IEC 62443-4-1 is available today and covers essential CRA requirements. What manufacturers can do with it and why the EN 40000 series is not yet an alternative.

The answer for many manufacturers in mechanical, plant and equipment engineering is closer than they might think: IEC 62443-4-1 already covers essential CRA requirements and is available today.

The CRA defines, in Annex I, essential requirements for products with digital elements. These include requirements for secure default configurations, protection against unauthorized access, confidentiality and integrity of data, availability of essential functions, and a structured vulnerability handling process across the entire product lifecycle.

At the same time, the CRA deliberately remains technology neutral. The regulation describes what must be achieved, not how. For the “how,” the European legislator points to harmonized standards that are intended to create a presumption of conformity. That means: those who comply with a harmonized standard can assume the corresponding legal requirements are met.

EN 40000 series harmonized standards in development

The EN 40000 series is being developed precisely for that purpose. It is intended to act as a horizontal European family of standards that concretizes the CRA requirements and gives manufacturers a normative framework for conformity assessment. The series will include parts on basic cyber resilience principles, generic security requirements and vulnerability handling.

However, the standards of the EN 40000 series are currently still in draft form. The individual parts exist as prEN drafts, are undergoing comment phases and have not yet been published as final EN standards. That creates a concrete problem for manufacturers who need to prepare for the CRA today: the standard being developed specifically for CRA conformity is not yet available in a stable, citable version.

Relying on a standards series whose final content and requirements may still change carries risks. Processes built today on the basis of a prEN draft may need to be adjusted if the final version differs. For strategic CRA implementation planning, that is an unsatisfactory starting point.

IEC 62443-4-1 an established framework available today

IEC 62443-4-1 defines requirements for a Secure Product Development Lifecycle (SPDL) for industrial automation and control systems. It has been published for years, is internationally recognized and forms the basis for certifications by established testing bodies.

Crucial in the context of the CRA is the substantive overlap. IEC 62443-4-1 addresses a range of topics with its eight practices (from security management through secure implementation to security update management) that map directly to essential CRA requirements. Concretely, this includes the following areas:

  • Risk-based development: IEC 62443-4-1 requires systematic threat modeling and risk analysis as the basis for design decisions — a core principle also required by the CRA.
  • Vulnerability handling: The standard defines processes for identifying, assessing and remediating security issues across the product lifecycle. The CRA requests comparable processes in Annex I, Part II.
  • Security updates: Requirements for providing and managing security updates are anchored in both IEC 62443-4-1 and the CRA.
  • Secure default configurations and documentation: Both frameworks require that products are shipped in a secure configuration and that users receive appropriate security documentation (CRA Annex I, Part I).

These overlaps are no accident: both frameworks draw on the same recognized state of the art for secure product development.

Why IEC 62443-4-1 is the pragmatic starting point

For manufacturers who need to begin CRA preparation today, this constellation leads to a clear course of action: IEC 62443-4-1 provides a stable, tried-and-tested framework with which a large portion of the CRA requirements for the development process can be addressed in a structured way.

This does not mean IEC 62443-4-1 covers the CRA in full. Certain CRA requirements (for example, the EU declaration of conformity, the technical documentation in the sense of the regulation, or specific reporting obligations) go beyond the scope of the standard. Likewise, the future EN 40000 series is likely to represent CRA-specific requirements in more detail than IEC 62443-4-1, which was originally developed for industrial automation.

Nevertheless, those who work according to IEC 62443-4-1 today are building processes and structures that will very likely serve as a robust foundation for later CRA conformity. This applies especially to the Secure Development Lifecycle, vulnerability handling and security verification — areas in which organizational maturity cannot be built quickly.

This article deliberately focuses on IEC 62443-4-1 as an entry standard. How the entire IEC 62443 family interacts in the CRA context is explained in the contribution IEC 62443 as a basis for the CRA.

Understanding the overlaps in detail

If you plan CRA implementation based on IEC 62443-4-1, you first need a clear picture of which CRA requirements are covered by the standard and where gaps remain that must be addressed additionally.

A systematic comparison of the CRA requirements from Annex I with the practices and requirements of IEC 62443-4-1 makes these overlaps and gaps transparent. It shows where existing processes already apply, where additions are necessary and where CRA-specific measures must be implemented independently of the standard.

An initial orientation on how the CRA relates to common standards is available in Mapping des CRA zu Standards. A more in-depth toolkit specifically mapping IEC 62443-4-1 to Annex I is in preparation: contact us if you need such a comparison for your implementation planning.

Conclusion

The CRA sets binding cybersecurity requirements for products with digital elements. The harmonized standards of the EN 40000 series, which are intended to concretize those requirements, are still under development. IEC 62443-4-1, by contrast, is available today and process-proven.

For manufacturers who do not want to wait for the completion of EN 40000 (and given the CRA timelines, should not wait), IEC 62443-4-1 is a reliable entry point for CRA implementation. Investing in a standards-compliant development process pays off regardless of further standards development: as a basis for CRA conformity, as a framework for certifications and as proof of organizational maturity in product security.

IEC 62443-4-1 and CRA together

Talk to us about how you can use your IEC 62443-4-1 processes as a basis for CRA preparation and complement them in a targeted way.