IEC 62443 certified foundation
IEC 62443: Secure industrial networks start with secure products.
EtherWAN combines an IEC 62443-4-1 certified development process with IEC 62443-4-2 certified industrial Ethernet switches—helping customers build more secure, resilient, and lifecycle-ready OT networks.
IEC 62443 in one sentence
One standard family.
Four layers of OT security.
IEC 62443 defines how industrial organizations, systems, and products should manage cybersecurity throughout their lifecycle.
The family is organized into four parts. Parts 1–3 establish the shared concepts, organizational practices, and system requirements. Part 4 focuses on the secure development and security capabilities of industrial products—including Ethernet switches.
Common foundation
Shared terminology, concepts, and security models.
Organizations
Security policies and lifecycle practices for asset owners and service providers.
Industrial systems
Risk assessment, secure system design, and system-level requirements.
Industrial products
Secure product development and technical security capabilities for devices and software.
IEC 62443-4-1 vs. IEC 62443-4-2
Process requirements vs.
product capabilities.
Use the comparison table to see which standard applies, what it requires, and what evidence it gives industrial network buyers.
| Comparison | IEC 62443-4-1 | IEC 62443-4-2 |
|---|---|---|
| Primary focus | How a product is securely developed and maintained. | What technical security capabilities an IACS component provides. |
| Applies to | Product suppliers and their secure development lifecycle. | Components such as network devices, embedded devices, host devices, and software applications. |
| Key requirements | Security requirements, threat modeling, secure design, verification, defect management, updates, and end-of-life processes. | Identification, authentication, use control, integrity, confidentiality, restricted data flow, event response, and availability. |
| Customer value | A repeatable and auditable security process throughout the product lifecycle. | Independent evidence of defined component-level security capabilities. |
| EtherWAN evidence | IEC 62443-4-1 certified secure development process. | Selected IEC 62443-4-2 certified industrial Ethernet switch families. |
IEC 62443 security levels
Four levels. Increasing threat capability.
Security Levels SL1–SL4 describe progressively stronger protection against different attacker capabilities. The appropriate target level is determined through system risk assessment—not by choosing a component in isolation.
Important: a component certification or capability level does not automatically establish the Security Level of an entire OT system.
Security that supports operations
Built for the realities of OT.
Controlled access
Support authenticated management and role-based use of critical network functions.
System integrity
Help protect configurations, firmware, and device operation from unauthorized change.
Event visibility
Provide security-relevant information to support monitoring and timely response.
Network resilience
Maintain essential connectivity and resource availability in demanding environments.
For practical implementation guidance, read four phases for creating and maintaining a secure industrial network.
EtherWAN security evidence
From certified development to coordinated response.
EtherWAN supports product security with an IEC 62443-4-1 certified development process, selected IEC 62443-4-2 certified switch families, documented security updates, and coordinated vulnerability handling through its PSIRT.
Certified development processSecurity requirements, threat analysis, verification, and controlled release under IEC 62443-4-1.
Certified product capabilitiesSelected switch families independently assessed to IEC 62443-4-2.
Updates and coordinated responsePSIRT support for vulnerability intake, mitigation, security updates, and communication.
Certified industrial Ethernet switches
Find the right switch for your OT application.
Choose certified options for 10G backbones, high-power PoE, utility and substation networks, Layer 3 segmentation, resilient rings, and harsh industrial environments.
Or compare requirements with the EtherWAN Product Selector
EXPLORE THE PORTFOLIOIEC 62443-4-2 certified switchesView products Frequently asked questions
IEC 62443, clearly explained.
Quick answers for product selection and OT security planning.
01What is the difference between IEC 62443-4-1 and IEC 62443-4-2?
IEC 62443-4-1 defines secure product development lifecycle requirements for product suppliers. IEC 62443-4-2 defines technical security requirements for individual IACS components, including industrial Ethernet switches.
02Does IEC 62443-4-2 certify an entire OT system?
No. IEC 62443-4-2 addresses component security capabilities. Secure system design still requires risk assessment, appropriate zones and conduits, secure configuration, operational controls, and lifecycle management.
03Why does IEC 62443 matter for industrial Ethernet switches?
Industrial switches connect critical OT assets and support management access, segmentation, secure configuration, event visibility, and resilient communications. Certification provides independent evidence that defined component requirements have been assessed.
04Which EtherWAN switches are IEC 62443-4-2 certified?
EtherWAN offers selected certified managed switch families for 10G backbones, high-power PoE, utility and substation networks, segmented OT environments, and hardened deployments. Refer to the certified portfolio for the current series and scope.
05Does IEC 62443 certification automatically mean CRA compliance?
No. IEC 62443 provides an important process and technical foundation, but CRA conformity also depends on product scope, risk assessment, technical documentation, vulnerability handling, reporting, support periods, and the applicable conformity-assessment route.
06What do IEC 62443 Security Levels SL1 to SL4 mean?
Security Levels describe increasing protection against different threat capabilities, from casual or accidental misuse at SL1 to sophisticated attackers with extensive resources and IACS-specific expertise at SL4. The appropriate target level depends on system risk assessment; a component certification does not establish the Security Level of an entire OT system.
Continue learning
Explore industrial cybersecurity resources.
Use these related EtherWAN resources to move from standards knowledge to product evaluation and lifecycle action.
Review switch security functions related to access, integrity, monitoring, and resilience.
Read the guide IMPLEMENTATIONFour phases of industrial network securityConnect assessment, deployment, detection, recovery, and remediation.
Learn the framework PRODUCTSIEC 62443-4-2 certified switchesCompare certified options for secure, resilient industrial connectivity.
View the portfolio LIFECYCLE SUPPORTEtherWAN Product Security Incident Response TeamFind vulnerability reporting and coordinated product security information.
Visit PSIRTSecure industrial connectivity





