Skip to content
Crest Technologies
IEC 62443 · SL/ML

Cybersecurity & IEC 62443 Compliance

IACS cybersecurity delivered as an engineering discipline — gap assessment through certification readiness with accredited external certification bodies.

  • IEC 62443-4-1
  • IEC 62443-4-2
  • IEC 62443-2-4
  • IEC 62443-3-3
  • TS 50701
  • ISO 27001 (interface)
Overview

Industrial automation and control system (IACS) cybersecurity for asset owners, system integrators and product suppliers. We run gap assessments against the relevant IEC 62443 part, build the Cybersecurity Management System and Configuration Management Plans, and take you to certification readiness — with an accredited, independent certification body issuing the certificate.

Scope

What this service covers

Gap assessment against IEC 62443

Structured assessment of your product, system or organisation against the applicable standard part — 62443-4-1/4-2 for product suppliers, 62443-2-4/3-3 for integrators and systems — with findings mapped to specific requirements and security levels (SL) or maturity levels (ML), not generic observations.

Cybersecurity Management System (CSMS)

Design and implementation of the policies, secure development lifecycle processes and organisational controls that IEC 62443 requires — sized for your organisation rather than copied from a template.

Configuration Management Plans (CMP)

CMPs that hold up under audit: baseline definition, change control, patch and vulnerability management for IACS components, and the linkage between configuration state and security posture.

Certification readiness

We prepare the evidence, run internal audits, and manage the certification engagement with an accredited external certification body — Crest prepares you; an independent third party certifies you.

Rail cybersecurity (TS 50701 / EN 50701)

Application of IEC 62443 in the railway context: security context definition for on-board and trackside systems, zone and conduit modelling, and cybersecurity cases aligned to TS 50701.

Method

The path to certification

The numbering below maps to actual engagement stages — each stage has an entry criterion, a deliverable and a decision point.

  1. Stage 01

    Scoping & applicability

    Which parts of IEC 62443 apply, to what product or system boundary, at what target SL/ML. Getting this wrong is the most expensive mistake in a certification programme, so it comes first.

  2. Stage 02

    Gap assessment

    Requirement-by-requirement assessment producing a findings register with severity, effort estimates and an ordered remediation plan — a document you can budget from.

  3. Stage 03

    Remediation & CSMS build

    We close the gaps with you: SDL processes, CMPs, vulnerability handling, supplier security requirements. Where engineering changes are needed, our embedded and software teams do the work rather than leaving you a recommendations deck.

  4. Stage 04

    Internal audit & evidence assembly

    Dry-run audit against the certification criteria, evidence pack assembly, and correction of anything that would surface as a nonconformity.

  5. Stage 05

    Certification & surveillance

    We manage the engagement with the accredited certification body through stage audits to certificate issue, and set up the surveillance-audit cadence so the certificate survives year two.

Outcomes

What you walk away with

  • A findings register and remediation plan mapped to specific IEC 62443 requirements
  • An operating CSMS with CMPs, SDL and vulnerability-handling processes your teams follow
  • Certification by an accredited third party — not a self-declaration
  • In rail contexts: a cybersecurity case aligned to TS 50701 that plugs into your safety case
Next step

Discuss a cybersecurity & iec 62443 engagement

Tell us where you are — a tender requirement, a gap assessment finding, a product that needs building — and we'll respond with a concrete view on scope, approach and effort.