A primer map for anyone new to IEC 62443-4-2. Covers why the 62443 series is divided by audience rather than topic, the four faces of SL and the three faces of SL 0, the Component Requirements (CR) of the seven Foundational Requirements (FR1-7), the SAR/EDR/HDR/NDR component types, and the distinctly industrial-security idea of "maintain degraded mode instead of preventing DoS."
When a manufacturer says "we're IEC 62443-4-2 SL2 certified," the sentence alone tells you nothing about what was actually verified. This post dissects the arithmetic behind the three numbers (RA, NAR, TR) printed on a certificate, the decisive difference between N/A and out-of-scope, and why confusing SL-T/SL-C/SL-D/SL-A ruins any reading of the certificate.
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the world's first law to mandate cybersecurity for physical products with digital elements. This post lays out the incoming timeline (reporting obligations on 2026-09-11, full application on 2027-12-11), how 62443 becomes the basis of CE marking as a harmonised standard, and the 6 CRA-specific requirements 62443 does not cover.