> iec_62443-4-2:2019
IEC 62443-4-2:2019
Security for Industrial Automation and Control Systems — Part 4-2: Technical Security Requirements for IACS Components
IEC 62443-4-2 establishes concrete technical security capabilities required for individual automation components. It categorizes components into four types: Embedded Devices (PLCs, sensors), Network Devices (switches, firewalls), Host Devices (industrial PCs, historians), and Software Applications (SCADA HMI software), detailing Component Requirements (CRs) for Security Levels 1 to 4.
Scope & Applicability
Component certification for PLCs, remote terminal units (RTUs), industrial managed switches, SCADA HMI software packages, and historians.
Non-Coverage Boundaries
Does not certify complete plant installations, which require system-level (3-3) and asset-owner (2-1) evaluation.
Key Clauses & Control Requirements
Four Component Types
Embedded Device (ED), Network Device (ND), Host Device (HD), and Software Application (SWA).
Hardware Root of Trust & Secure Boot
Cryptographic signature verification on bootloaders and firmware images to prevent unauthorized controller tampering.
Required Regulatory & Audit Evidence Artifacts
- [✓]Third-Party Laboratory IEC 62443-4-2 Component Certificate (e.g. exida, TÜV)
- [✓]Component Security Manual detailing hardening steps and default credential deprecation
- [✓]Cryptographic Key Storage and Secure Boot validation test reports
“A legacy PLC with hardcoded plaintext telnet passwords cannot achieve IEC 62443-4-2 SL 2. Modernizing procurement specifications protects your OT network at the physical hardware layer.”
Cross-Surface Ecosystem Relationships
- IEC 62443-4-2:2019 Technical security requirements for IACS components ↗(International Electrotechnical Commission)
Frequently Asked Questions
Can an existing legacy PLC receive IEC 62443-4-2 certification?
Only if its firmware and hardware architecture satisfy the required component security requirements (such as encrypted sessions and secure credential storage).
