Skip to content

Tags

compliance

19 min read

IEC 62443-4-2 Primer — A Map of FR1-7 and Component Requirements

A primer map for anyone new to IEC 62443-4-2. Covers why the 62443 series is divided by audience rather than topic, the four faces of SL and the three faces of SL 0, the Component Requirements (CR) of the seven Foundational Requirements (FR1-7), the SAR/EDR/HDR/NDR component types, and the distinctly industrial-security idea of "maintain degraded mode instead of preventing DoS."

Read full article
13 min read

Why "IEC 62443-4-2 Certified" Means Nothing on Its Own

When a manufacturer says "we're IEC 62443-4-2 SL2 certified," the sentence alone tells you nothing about what was actually verified. This post dissects the arithmetic behind the three numbers (RA, NAR, TR) printed on a certificate, the decisive difference between N/A and out-of-scope, and why confusing SL-T/SL-C/SL-D/SL-A ruins any reading of the certificate.

Read full article
11 min read

What the CRA Changes in 2027 — How 62443 Became the Baseline Standard for CE Marking

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the world's first law to mandate cybersecurity for physical products with digital elements. This post lays out the incoming timeline (reporting obligations on 2026-09-11, full application on 2027-12-11), how 62443 becomes the basis of CE marking as a harmonised standard, and the 6 CRA-specific requirements 62443 does not cover.

Read full article