Skip to main content

> iec_62443-4-2:2019

IEC 62443-4-2:2019

Security for Industrial Automation and Control Systems — Part 4-2: Technical Security Requirements for IACS Components

SPEC // INSPECT: IEC 62443-4-2:2019REVIEWED: 2026-09-16
CATEGORYIndustrial & OT Cybersecurity
JURISDICTIONINTERNATIONAL
MANDATORY LEVELCERTIFICATION_STANDARD
LIFECYCLE STATUSCURRENT
EXECUTIVE BRIEF SPECIFICATION PDFDISTRIBUTION LOCKED
Fail-Closed Distribution Policy: Download control is visibly disabled until Cloudflare R2 CDN upload and remote SHA-256 verification complete.
[AI // ARCHITECTURAL SUMMARY]

IEC 62443-4-2 establishes concrete technical security capabilities required for individual automation components. It categorizes components into four types: Embedded Devices (PLCs, sensors), Network Devices (switches, firewalls), Host Devices (industrial PCs, historians), and Software Applications (SCADA HMI software), detailing Component Requirements (CRs) for Security Levels 1 to 4.

Scope & Applicability

Component certification for PLCs, remote terminal units (RTUs), industrial managed switches, SCADA HMI software packages, and historians.

Non-Coverage Boundaries

Does not certify complete plant installations, which require system-level (3-3) and asset-owner (2-1) evaluation.

Key Clauses & Control Requirements

comp-types

Four Component Types

Embedded Device (ED), Network Device (ND), Host Device (HD), and Software Application (SWA).

cr-secure-boot

Hardware Root of Trust & Secure Boot

Cryptographic signature verification on bootloaders and firmware images to prevent unauthorized controller tampering.

[AUDIT // VERIFIABLE EVIDENCE CHECKLIST]

Required Regulatory & Audit Evidence Artifacts

  • [✓]Third-Party Laboratory IEC 62443-4-2 Component Certificate (e.g. exida, TÜV)
  • [✓]Component Security Manual detailing hardening steps and default credential deprecation
  • [✓]Cryptographic Key Storage and Secure Boot validation test reports
[LEADERSHIP TAKEAWAY // CTO & VP OF ENGINEERING DIRECTIVE]
A legacy PLC with hardcoded plaintext telnet passwords cannot achieve IEC 62443-4-2 SL 2. Modernizing procurement specifications protects your OT network at the physical hardware layer.
PRIMARY SOURCES & AUTHORITY

Frequently Asked Questions

Can an existing legacy PLC receive IEC 62443-4-2 certification?

Only if its firmware and hardware architecture satisfy the required component security requirements (such as encrypted sessions and secure credential storage).