Skip to content
IACS RadarIndustrial Cyber Exposure & Intelligence
Back to knowledge centre

62443-4-1

IEC 62443-4-1 — Secure product development lifecycle

Sets requirements for the development process of products, from requirements and secure design to testing, patch policy and end-of-life policy.

For which role

Product suppliers (manufacturers of PLCs, RTUs, relays, HMIs, etc.).

Key topics

  • Security by design in the development phase
  • Threat modelling and secure coding
  • Vulnerability handling
  • Patch policy and end-of-life communication

Expected results

  • A demonstrably secure development process
  • A structured process for receiving and remedying reported vulnerabilities

Relationship to other parts of the standard

Describes the process by which products are built that can satisfy -4-2.

Practical example from the energy sector

A supplier of protection relays publishes a fixed process and contact point for responsible disclosure of vulnerabilities in its product line.