COMPARISON · Standards
IEC 62443-4-1 vs 62443-4-2
Suppliers are usually asked for both, and confusing them is the fastest way to fail a customer security assessment.
LAST REVIEWED
What is different
- Subject: 4-1 assesses the organisation's development process; 4-2 assesses the technical capability of a specific component.
- Structure: 4-1 defines eight practices — security management, specification of security requirements, secure by design, secure implementation, security verification and validation testing, management of security-related issues, security update management, and security guidelines. 4-2 defines component requirements grouped by the seven foundational requirements, with additional requirements per security level.
- Component types: 4-2 differentiates embedded devices, host devices, network devices and software applications, so the applicable requirement set depends on what the component is.
- Evidence: 4-1 evidence is process records — plans, reviews, test reports, issue handling history. 4-2 evidence is product capability — implemented controls, configuration, test results demonstrating the capability security level.
- Certification: 4-1 is typically certified once per development organisation or product line and maintained; 4-2 assessment is tied to a specific component version and its claimed capability security level.
What overlaps
Both derive from the same risk-based model and the same seven foundational requirements, and in practice 4-1 is what makes a credible 4-2 claim repeatable: a component can be built to a capability security level once by accident, but sustaining that level across releases requires the lifecycle 4-1 describes. Certification schemes reflect this by expecting a 4-1 aligned process behind a 4-2 component claim, and asset owners increasingly ask for both in procurement.
Both also feed the same downstream artefacts. The security guidelines required by 4-1 become the documentation an integrator needs to place the component in a zone with the right compensating controls, and the capability security level from 4-2 is what makes that placement decision possible.
Which applies to you
- You develop products or components used in industrial automation: 4-1 applies to how you develop, and 4-2 applies to what you ship. Expect to address both.
- You are asked by a customer for '62443 certification' without a part number: clarify whether they want process certification (4-1), component capability (4-2), or system-level requirements from 62443-3-3.
- You integrate other suppliers' components into systems: 62443-3-3 and 62443-2-4 are your primary parts, but you rely on suppliers' 4-2 capability claims to justify zone design.
- You are preparing for the CRA with an industrial product: 4-1 gives you the secure development process evidence, and 4-2 gives you a defensible technical requirement baseline for the essential requirements.
Frequently asked questions
Can a component be assessed against 62443-4-2 without a 4-1 process?
Technically yes, since 4-2 assesses the component's capabilities, but most certification schemes and industrial customers expect an underlying 4-1 aligned lifecycle, because without it the capability cannot be shown to persist across releases.
What is a capability security level?
It is the security level a component can achieve when correctly configured and integrated, independent of the environment. It differs from target security level, which the asset owner sets for a zone, and achieved security level, which describes the installed system.
Does 62443-4-1 cover vulnerability handling after release?
Yes. Management of security-related issues, security update management and security guidelines are explicit practices, which is why 4-1 maps closely to the CRA's vulnerability handling and support-period obligations.
Which part should a supplier start with?
Start with 4-1 if the gap is process and evidence, which is the common case, because the 4-1 practices generate the records needed for both customer assessments and CRA technical documentation. Start with 4-2 if a specific customer requires a stated capability security level for a named component.