• ISA provides technical resources and standards to help industrial automation professionals advance their careers and the field. We enable automation professionals worldwide to solve problems and enhance their skills by bringing people together to create new technologies and share best practices with future automation professionals.
    • Industry Insights

  • We attract over 140,000 unique automation professionals monthly, making us the premier online content provider and the only dedicated electronic magazine in the automation industry.

    Monthly Magazine

    Back
    Back
  • M logo for Automation.com Monthly. Link to current issue.

An Opportunity for Simultaneous Business Growth and Reduction of Cybersecurity-Related Risks

By: Carlos Montes Portela
09 October, 2026
5 min read
The words Cyber Resilience Act - CRA on a blue background with stars, representing European cybersecurity regulations and legal compliance.
Manufacturers who build ISA/IEC 62443 into their secure development lifecycle can turn the EU Cyber Resilience Act into a passport to the European market and a stronger position worldwide.

Introduction

The Cyber Resilience Act (CRA) was, is and will long remain a necessary regulation. Its purpose is simple: products with digital elements placed on the European market must be designed, built and maintained with appropriate cybersecurity measures. The first obligations already apply. Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents, and the regulation applies in full beginning 11 December 2027.

For an engineer, “appropriate cybersecurity measures” can sound fuzzy. What is appropriate for a smart sensor, a programmable logic controller or a complex piece of industrial equipment? The legal text deliberately describes outcomes rather than engineering recipes.

Think about it a little longer, though, and the answer is largely already on the shelf. The ISA/IEC 62443 series has spent nearly two decades defining what good security looks like for industrial automation and control systems. Its product-focused parts, ISA/IEC 62443-4-1 and ISA/IEC 62443-4-2, map closely to what the CRA asks of manufacturers. CENELEC is now developing European versions of these standards aligned with the CRA, giving engineers a familiar and concrete route to compliance.

The compliance architecture: What is the CRA all about?

Each standards family plays a different role.

The CRA is best understood as three layers that work together, each playing a different role. The regulation sets the legal obligations. European horizontal standards translate them into a common structure. Engineering standards such as IEC 62443 show how to build the products.  

 

Layer What it covers
CRA (Regulation (EU) 2024/2847) Essential cybersecurity requirements, vulnerability handling, manufacturer duties and technical documentation
prEN 40000 series Vocabulary, principles, risk management, lifecycle activities, vulnerability handling and generic security requirements
ISA/IEC 62443 Secure development lifecycle, component requirements and system-level security requirements
Advertisement

The legal framework. The CRA defines what manufacturers must achieve. Annex I lists the essential cybersecurity requirements for products and the vulnerability handling obligations that apply throughout a product’s support period. Manufacturers must also assess risks, keep technical documentation and issue an EU declaration of conformity before applying the CE marking.

The common practices. The prEN 40000 series, developed by joint CEN-CENELEC committee JTC 13, gives the regulation a shared vocabulary and structure. Its parts cover principles for cyber resilience, generic security requirements and vulnerability handling. These horizontal standards apply to all products with digital elements, from consumer devices to industrial equipment.

The engineering part. For automation products, ISA/IEC 62443 is where the work becomes concrete. Part 4-1 defines the processes of a secure development lifecycle. Part 4-2 defines technical security capabilities for components such as embedded devices, network devices, host devices and software applications.

For products classified as “important” or “critical” under the CRA, additional requirements apply. These products face stricter conformity assessment routes, which may involve a notified body or, for critical products, European cybersecurity certification. Knowing early which category a product falls into is essential for planning.

Engineering practice: From fuzzy obligations to engineering practice

The strength of ISA/IEC 62443 is that it speaks the language of engineers. Instead of asking whether a product is “appropriately secure,” it asks concrete, testable questions.

ISA/IEC 62443-4-1 addresses the process side. It requires a defined security management approach, threat modeling and security requirements at the start of development, secure design and implementation practices, verification and validation testing, and structured management of security defects and updates. These practices line up naturally with the CRA’s expectations on risk assessment, secure-by-design development and vulnerability handling over the product lifecycle.

Advertisement

ISA/IEC 62443-4-2 addresses the product side. It defines component requirements grouped under foundational requirements such as identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events and resource availability. Security levels allow a manufacturer to match capabilities to the threat environment a product is expected to face. That maps well to the CRA’s risk-based approach.

The practical consequence is significant. A manufacturer that already runs a development process certified or assessed against ISA/IEC 62443-4-1 and designs components against 4-2 has much of the evidence the CRA asks for. That includes threat models, security requirements, test results, defect records and user documentation. Compliance then becomes a matter of filling gaps and mapping evidence rather than starting from zero.

This is also why the European adoption of these standards matters. CENELEC technical committee TC 65X is developing European versions of IEC 62443-4-1 and 4-2 aligned with the CRA. Once these are published and cited in the Official Journal, they are expected to help achieve conformity for the requirements they cover. Engineers who already work with 62443 will be building on familiar ground. These European versions pay special attention to the evaluation of the selected and implemented requirements from IEC 62443-4-2, as well as how the risk assessment led to including and excluding specific requirements.

Business value: More than a legal checkbox

It is tempting to treat the CRA purely as a legal exercise, owned by the compliance department and handled with documentation at the end of a project. That approach misses the bigger picture, and it is usually the most expensive way to comply.

The CRA opens a single market of roughly 450 million people with one set of cybersecurity rules. Before the CRA, a manufacturer could face a patchwork of national expectations and customer-specific security questionnaires. With the CRA, a product that meets the essential requirements and carries the CE marking can be sold across all member states. Customers, especially operators of critical infrastructure and industrial plants, increasingly ask for demonstrable security. CRA conformity gives suppliers a common, credible answer: a common ground to start with. When necessary, these operators of critical infrastructure and industrial plants will ask for additional assurance (on top of CRA) based on the outcome of their respective risk assessments.

At the same time, the CRA regulation reduces real risk. Building security into the development lifecycle means fewer exploitable vulnerabilities in the field, faster and more structured responses when issues are found and fewer costly emergency patches and reputational incidents. For customers, it means more resilient operations. For manufacturers, it means lower long-term cost of ownership for their own products.

Advertisement

The value extends beyond Europe. ISA/IEC 62443 is recognized internationally and is referenced in many regulatory and procurement frameworks for critical infrastructure and industrial automation. A manufacturer that anchors its development process in 62443 builds once and can reuse that work to address requirements in many markets. For product suppliers operating on a global scale, that is a strong business case: one engineering approach supporting compliance and customer trust across regions.

Takeaway

The message for manufacturers is straightforward. Use ISA/IEC 62443-4-1 and 4-2 as the backbone of your secure development lifecycle today. Plan to incorporate the European versions once they are published, expected around Q4 2026 or Q1 2027, and track the prEN 40000 series as it matures.

Most of all, do not look at the CRA only from a legal perspective. Treated as an engineering discipline, it reduces cybersecurity risk for both suppliers and their customers. Treated as a strategic opportunity, it opens an entire continent to your products, and through ISA/IEC 62443, it supports your position in markets around the world.

References

Advertisement

Trending Articles

Advertisement

Related Articles

View all Articles and News
Advertisement
Advertisement