If you build automation products for the EU market, the CRA and IEC 62443 now sit on the same desk: the Cyber Resilience Act sets the legal duties, and IEC 62443 is the engineering standard most industrial vendors already use. So does IEC 62443 help? Yes, considerably. A mature IEC 62443-4-1 development process and 4-2 component controls map to much of what Annex I of the CRA asks for.
But help is not legal cover. As of October 2026, no harmonized standard has been cited in the Official Journal under the CRA, so an IEC 62443 certificate does not give you presumption of conformity. Several CRA duties, including 24-hour reporting, a minimum support period and a machine-readable SBOM, have no direct IEC 62443 counterpart.
This guide covers the dates, the presumption mechanism, the M/606 standardization work, an indicative mapping of the CRA and IEC 62443, and what manufacturers and asset owners should do now.
Free gap assessment
Where do you stand on the Article 21 measures?
Score scope, all ten measures, the management-body duties and the reporting clocks, free.
Run the free NIS2 gap assessment → or View premium report sample
The CRA dates that matter in 2026 and 2027
Regulation (EU) 2024/2847 entered into force on 10 December 2024 and applies in stages. Two of those stages are already behind us.
| Date | What applies | What it means for manufacturers |
|---|---|---|
| 10 Dec 2024 | Entry into force | The transition clock starts |
| 11 Jun 2026 | Chapter IV (Articles 35 to 51) | Rules for notifying conformity assessment bodies apply |
| 11 Sep 2026 | Article 14 reporting | Report actively exploited vulnerabilities and severe incidents |
| 11 Dec 2027 | Full application | Annex I requirements, conformity assessment and CE marking |
The reporting date catches people out. Under Article 69(3), Article 14 also covers in-scope products placed on the market before 11 December 2027, not only new ones. If you sell controllers, gateways or HMIs into the EU today, your reporting process should already be running. This is also the first place the CRA and IEC 62443 part ways: 4-1 covers how you receive and handle security issues, but it sets no regulatory reporting clock. Our post on the CRA reporting deadline walks through the 24-hour, 72-hour and final-report stages.
Presumption of conformity: where the CRA and IEC 62443 stand today
Article 27 of the CRA says a product that conforms to harmonized standards, or parts of them, whose references are published in the Official Journal is presumed to meet the Annex I requirements those standards cover. The citation creates the legal effect. An excellent standard that has not been cited is good evidence, nothing more.
IEC 62443 is an international standard, and its European adoptions (EN IEC 62443) were not written against the CRA. With no CRA harmonized standard cited as of October 2026, an ISASecure or other IEC 62443 certificate does not currently give presumption of conformity. It still strengthens your risk assessment and technical documentation.
Free ISO 27001 risk assessment
Which of your risks sit above your appetite line?
Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.
Run the free risk assessment → or View premium report sample
The consequence is sharpest for important products. Under Article 32(2), an Annex III Class I product (for example routers, switches and network management systems) can use internal control (Module A) only where the manufacturer has applied in full harmonized standards, common specifications or a European cybersecurity certification scheme at assurance level at least “substantial”. Otherwise it must use Module B+C or Module H, both of which involve a notified body. Class II products, such as firewalls and intrusion detection or prevention systems, cannot use Module A at all. Whether a product falls in a class depends on the technical descriptions in Implementing Regulation (EU) 2025/2392. Our guide to CRA conformity assessment routes explains each module.
Products outside Annexes III and IV keep the Module A option either way. For them, the lack of cited standards changes how you argue conformity, not who signs it off.
M/606 and the EN IEC 62443 adaptation work
The Commission’s standardization request M/606 (Decision C(2025)618 of 3 February 2025) covers 41 standards supporting the CRA. CEN, CENELEC and ETSI accepted it on 3 April 2025. It mixes horizontal standards, such as vulnerability handling processes, with vertical standards for product categories. The Commission summarizes the program on its CRA standardisation page.
For industrial products, the group to watch is CLC/TC 65X WG 3. CEN-CENELEC reported in September 2025 that this group is adapting EN IEC 62443-4-1:2018 and EN IEC 62443-4-2:2019 for the CRA through “A11:2026” amendments. As CEN-CENELEC described it:
- The 4-2 amendment adapts existing requirements, adds rationales, fills gaps with new requirement enhancements, and defines applicability and security-level-based acceptance criteria.
- The 4-1 amendment aims at clearer documentation of intended use and security context, plus more detail on expected development artifacts.
This adaptation is the main formal link being developed between the CRA and IEC 62443. What nobody can tell you yet is whether, when or in what form any of this work will be cited in the Official Journal. Unless and until a citation appears, treat the amendments as a signal of where assessors are likely to look, not as a legal safe harbor.
Mapping the CRA and IEC 62443, obligation by obligation
The table below is indicative, not a legal crosswalk. It pairs CRA duties from Annex I, Article 13 and Article 14 with the nearest IEC 62443 reference, and flags the gap we typically find when a 62443-mature vendor checks CRA readiness. For a refresher on each part, see IEC 62443 parts explained.
| CRA obligation | Nearest IEC 62443 reference | Typical gap |
|---|---|---|
| Art. 13(2)–(4): documented cybersecurity risk assessment | 4-1 practice 2 (specification of security requirements) | Must sit in the technical documentation, with a justification for each Annex I requirement you treat as not applicable |
| Annex I Part I(2)(a): no known exploitable vulnerabilities at release | 4-1 practices 5 and 6 | Certification checks the process; the CRA judges each product you place on the market |
| Part I(2)(b): secure by default, reset to original state | 4-1 practices 3 and 8 | A hardening guide shows how to secure a product; it does not prove the product ships secured |
| Part I(2)(c): security updates, automatic where applicable | 4-2 update support (FR 3); 4-1 practice 7 | Recital 56 notes industrial users may not expect automatic updates; record your reasoning |
| Part I(2)(d)–(f), (h)–(k): access, confidentiality, integrity, availability, attack surface | 4-2 FR 1 to FR 7 at your SL-C | Usually strong; keep per-release evidence |
| Part I(2)(g), (l), (m): data minimization, logging with user opt-out, secure erasure | 4-2 FR 2, FR 4 and FR 6 (partial) | Data minimization and user opt-out have no direct equivalent |
| Part II(1): machine-readable SBOM, at least top-level dependencies | 4-1 practice 1 (externally provided components) | 4-1:2018 does not explicitly require an SBOM or a format |
| Part II(2)–(6): remediation, testing, disclosure, CVD policy, contact point | 4-1 practices 5 and 6 | Close match; check disclosure and contact point against the CRA wording |
| Part II(7)–(8): secure, free, timely update distribution | 4-1 practice 7 (security update management) | 62443 does not address free-of-charge updates |
| Art. 13(8) and (19): support period of at least five years (or expected use time if shorter) | None | Define, justify and show the end date at purchase |
| Art. 14: report to the coordinating CSIRT and ENISA | None (4-1 practice 6 covers internal handling, not regulator notification) | Regulatory clock starting with a 24-hour early warning |
Gaps a CRA and IEC 62443 mapping will expose
The pattern is consistent. IEC 62443 is strong on how you engineer and maintain a secure component. The CRA adds legal and market duties that no engineering standard was written to cover:
- A machine-readable SBOM per release, which an ISASecure-hosted presentation on 4-1 supply chain requirements notes IEC 62443 does not explicitly require.
- A declared support period and free security updates for its full length.
- External reporting deadlines to the CSIRT and ENISA, plus informing impacted users.
- The legal file: Annex II user information, Annex VII technical documentation, the EU declaration of conformity and CE marking.
What manufacturers should do now
Whatever happens with citations, this work pays off. Run the CRA and IEC 62443 as one program with one evidence base, not two parallel projects.
- Classify every product. Default, Annex III Class I or II, or Annex IV decides whether self-assessment is even possible.
- Run reporting today. Connect your 4-1 practice 6 process to a 24-hour decision path, named owners and the notification route to your coordinating CSIRT and ENISA. Rehearse it.
- Convert 4-1 evidence into CRA documentation. Reuse threat models, test reports and security guidelines, then add the Annex I applicability justification.
- Generate SBOMs in your build pipeline. Pick a commonly used machine-readable format and cover at least top-level dependencies.
- Set support periods per product. Article 13(8) ties the period to expected use time, and industrial equipment usually stays in service well beyond the five-year floor.
- Budget for a notified body where needed. For Class I products, plan for Module B+C or H unless cited harmonized standards, common specifications or a qualifying EU certification scheme exist and you apply them in full.
- Track M/606 and the A11 amendments. When published, run a delta review against your 4-1 process and 4-2 component evidence.
In our experience, vendors with an audited 4-1 process close the CRA gap faster than those starting cold, because the hard part is already a habit. The remaining work is mostly legal documentation and reporting discipline.
The asset owner angle: buying CRA-ready components
The CRA places its duties on manufacturers, importers and distributors, not on plant operators that use the products. Still, it changes what an asset owner can reasonably ask for when buying components for the EU market. Write these into specifications and contracts:
- The EU declaration of conformity and the support period end date for products placed on the market from 11 December 2027.
- Access to the SBOM. The CRA does not oblige manufacturers to publish it, so secure it contractually.
- The supplier’s CVD policy, vulnerability contact point and advisory channel.
- IEC 62443-4-2 capability (SL-C) against the target level (SL-T) of the zone the component will sit in.
Do not drop IEC 62443 from your requirements, because for buyers the CRA and IEC 62443 answer different questions. CRA conformity shows a horizontal baseline, not whether a component meets the security level your zone needs. The CRA also regulates products, not integration services, so IEC 62443-2-4 remains your tool for integrators.
If you are building the manufacturer-side documentation, the EU CRA Toolkit from Governance Docs ($99) provides 74 editable templates (61 Word, 13 Excel) in 13 sections for manufacturers of products with digital elements. It includes a “CRA to IEC 62443 and Secure Development Interface” document. Templates supply the documented layer; your teams still operate the processes and keep the records.
CRA and IEC 62443 FAQs
Does IEC 62443 certification make a product CRA compliant?
No. A certificate is strong evidence, but presumption of conformity comes only from harmonized standards cited in the Official Journal, and none had been cited under the CRA as of October 2026. You still need the CRA technical documentation, conformity assessment, declaration and CE marking.
Will EN IEC 62443-4-1 and 4-2 become harmonized standards for the CRA?
CEN-CENELEC has reported that both are being adapted for the CRA through A11 amendments. Whether and when they are cited is not settled, so plan to demonstrate conformity directly against Annex I, with your mapping of the CRA and IEC 62443 as supporting evidence.
Do CRA reporting obligations apply to products we already sell?
Yes. Article 14 has applied since 11 September 2026, and Article 69(3) extends it to in-scope products placed on the market before 11 December 2027. Actively exploited vulnerabilities and severe incidents need an early warning within 24 hours.
Does the CRA require us to use IEC 62443?
No. The CRA sets essential requirements and leaves the method open. Harmonized standards are a voluntary route to presumption of conformity. For industrial vendors, aligning the CRA and IEC 62443 is often the most efficient path because much of the evidence may already exist.