"Our controllers are IEC 62443 certified, so we are CRA-ready." Of all the misconceptions in this series, this is the most likeable, because whoever voices it has usually genuinely invested in product security. All the more reason to be precise: the groundwork is valuable, the conclusion is wrong.
What does IEC 62443 mean and what does it deliver?
The IEC 62443 series is the internationally established framework of standards for cybersecurity in industrial automation. For product manufacturers, two parts are especially relevant: 62443-4-1 describes a secure development process, and 62443-4-2 defines technical security requirements for components such as controllers, sensors, or gateways.
Anyone who develops and certifies their products to these parts has implemented a substantial part of what the Cyber Resilience Act means by security by design, that is, security anchored in the development process from the start. In machinery and plant engineering in particular, the standard is the one that manufacturers and operators have agreed on.
Why the certificate still creates no CRA conformity
The CRA follows the New Legislative Framework, the EU legal framework for product safety. In this system there is a precise mechanism: the harmonised standard. Only standards drafted on behalf of the EU Commission and listed in the EU Official Journal create a presumption of conformity. Anyone who develops and assesses against them may assume they meet the corresponding requirements.
This is exactly where the formal catch lies: the 62443 series is currently not a listed harmonised standard under the CRA. The European standardisation organisations, led by CENELEC, are working on transposing parts of the series into harmonised European standards. Until that work is complete and the standards are listed, a 62443 certificate creates no automatic presumption effect. The status can change, which is why harmonisation belongs on your watch list. I deliberately flag this as a moving target.
On top of that comes the substantive part: even with full 62443 implementation, CRA duties remain open that the standard does not address:
- SBOM: the CRA requires an SBOM (Software Bill of Materials), that is, a complete inventory of all software components, as part of the technical documentation per product. How to build one is shown in the SBOM guide.
- Reporting duties: from 11 September 2026, actively exploited vulnerabilities must be reported within 24 hours via the ENISA Single Reporting Platform. The standard knows processes for handling vulnerabilities, but no regulatory report with EU deadlines. Details are in the post on the 24-hour deadline.
- Support period: the CRA obliges manufacturers to provide free security updates over a defined period, per product placed on the market.
- Conformity assessment and CE marking: the CRA requires a formal assessment procedure with an EU declaration of conformity. For many industrial products classified as important products of class I or class II, stricter procedures apply, some involving notified bodies. More on this is in the article on CE marking under the CRA.
An example from practice: a PLC manufacturer hands its sales team the 62443-4-2 certificate as "CRA-compliant." In the next supplier audit, a major customer asks for the EU declaration of conformity and the SBOM for the product family. Neither exists. The frustrating part: the company has walked 80 percent of the way and fails, in communication terms, on the missing 20 percent.
Myth vs. Fact
Myth: A certification to IEC 62443 means CRA conformity.
Fact: The 62443 series is currently not listed as a harmonised standard under the CRA and creates no presumption of conformity. It also does not cover the SBOM duty, ENISA reporting duties, support period, and the formal conformity assessment procedure. It is the best groundwork, but not a substitute.
Concrete consequences for industrial manufacturers
1. Map your 62443 evidence against Annex I of the CRA. A structured mapping shows which of the essential requirements you can already substantiate with existing evidence from 62443-4-1 and 62443-4-2. Experience shows this covers a large part of the technical requirements. The rest becomes a concrete work list rather than a diffuse mega-project.
2. Close the four structural gaps as their own work packages. SBOM creation per product line, a reporting process with 24-hour capability, definition and safeguarding of the support period, preparation of the conformity assessment procedure. These four points do not arise as a by-product of the standards work, they need their own owners and deadlines.
3. Watch the harmonisation actively. As soon as parts of the 62443 series are listed as harmonised standards, the value of your certificates rises considerably, up to the presumption of conformity for the covered requirements. Anyone who follows the development can align their conformity assessment procedure with it and avoid duplicated work. Until then: advertise 62443 as a quality credential, not as CRA conformity.
What does this mean for your CRA roadmap?
On 11 September 2026 the reporting duties enter into force, independently of any certification status. Your 62443 vulnerability process is the basis, the ENISA reporting path comes on top.
On 11 December 2027 full CRA applicability follows. For products newly placed on the market, that is, products made available on the EU market for the first time, full conformity including CE marking is then required.
How to get from the standards basis to full conformity is shown in the CRA compliance roadmap 2026/2027. What is at stake for breaches is covered in the article on CRA fines and penalties.
Frequently asked questions
Is a 62443 certification even worth it then? Yes, more than ever. The standard is the most likely basis for the coming harmonised standards for industrial products. Anyone working to 62443 today is investing in exactly the evidence that should carry the presumption of conformity tomorrow.
Our certificate comes from an accredited body. Does that change anything? For the quality of the evidence, yes; for the CRA legal effect, no. As long as the standard is not listed as a harmonised standard, even the best certificate creates no presumption of conformity.
Does this also apply to other standards, such as ETSI EN 303 645 for consumer IoT? The logic is the same: what matters is whether a standard is listed as a harmonised standard under the CRA. Existing security standards are valuable groundwork, but only the listing in the EU Official Journal creates the presumption effect.
Our components are 62443 certified, but the machine as a whole is not. What applies? The CRA attaches to the product with digital elements that you place on the market. Certified bought-in components help you in the supply chain, but they do not release you from the conformity of the overall product. Note in addition the Machinery Regulation, which applies in parallel.
When will the harmonised CRA standards be available? The standardisation work is running at full speed, staggered by product category. Do not rely on a specific date: plan your conformity assessment so that it works even without the presumption effect, and use the standards as soon as they are listed.
Conclusion
IEC 62443 is the best groundwork an industrial manufacturer can do for the CRA, and at the same time not a free pass. Without a listing as a harmonised standard there is no presumption of conformity, and SBOM, reporting duties, support period, and the CE process remain your task in any case.
An SBOM analysis and a structured gap mapping with a platform like Kunnus help you transpose the existing standards basis into CRA conformity systematically, before the deadline tips from theory into practice. A starting point is our free CRA compliance check.
Every Friday I debunk a CRA myth here.