Cybersecurity for digital hardware and software products

What is the IEC 62443-4-1 standard, and what is the significance for companies?
The IEC 62443-4-1 standard applies to products for industrial automation and control systems. It specifies the requirements for a secure development process and for the entire product lifecycle. These include, among other things, security requirements and updates, as well as the handling of potential security vulnerabilities.
The certificate issued by TÜV Rheinland confirms that E-T-A has implemented processes that comply with this standard. We have reached maturity level 2, which means that our security requirements and processes are documented and verifiable. The next step is to roll out the processes across the entire company.
With the Cyber Resilience Act (CRA), the EU has now also established binding cybersecurity requirements for digital hardware and software products. Manufacturers must address security vulnerabilities and ensure that security updates are provided.
E-T-A had already applied for and obtained the certificate before the EU regulation took effect. Why is this issue so important to E-T-A?
In doing so, we are taking responsibility towards our customers. By adhering to this standard, we commit to dealing responsibly with any security breaches should they arise. Any vulnerabilities that are discovered or reported are analysed internally as quickly as possible, resolved, and the appropriate solutions made available to customers.
In addition, we provide security updates and publish security guidelines containing information on how to configure and use our products securely.
How does E-T-A ensure compliance with the requirements specified in the CRA?
Among other things, we have set up our E-T-A Product Security Incident Response Team (PSIRT) Experts from all development departments coordinate the reporting, handling and disclosure of potential security vulnerabilities in our products.
The requirements of the law apply not only to new products, but to all products with a digital interface. That is why we also check our existing products to ensure they meet all legal requirements. The knowledge and experience we gained through our IEC 62443-4-1 certification are proving valuable in this area. For example, we have implemented various access and control mechanisms and provide regular updates for our digitally networked, intelligent power distribution systems from the ControlPlex® product group – to ensure that security vulnerabilities are prevented in the first place.



