Component Requirements

IEC 62443-4-2:2019 is the component requirements part. It defines technical requirements for IACS components and component security capability levels through the seven foundational requirements.

Component boundary

A component is not the whole IACS. The component claim should name the component type, product version, intended IACS use, interfaces, assumptions, excluded functions, and SL-C(component) being claimed. Without that boundary, the same product can appear to support a wider claim than the assessment actually covers.

Foundational requirements

IEC public material lists seven foundational requirements used by IEC 62443-4-2. They are the requirement families used to organise component requirements and capability levels. They should not be treated as seven generic security slogans.

  • identification and authentication control (IAC);
  • use control (UC);
  • system integrity (SI);
  • data confidentiality (DC);
  • restricted data flow (RDF);
  • timely response to events (TRE);
  • resource availability (RA).

Capability limit

IEC states that IEC 62443-4-2 is about SL-C(component), not SL-T or SL-A. That distinction matters. A component may have a claimed capability level, but a deployed system still needs a system under consideration, zones, conduits, risk assessment, operational procedures, and validation of the actual configuration.

4-1 remains linked

Component evidence is stronger when the supplier can also show that the product was developed and maintained under an IEC 62443-4-1 lifecycle.

System placement remains open

The system designer still decides how the component is placed in a zone, what conduits it uses, and which controls surround it.

CEN-CENELEC CRA material describes work on EN IEC 62443-4-2:2019/A11:2026 for CRA alignment, including applicability criteria and evaluation artefacts. That planned European work should not be collapsed into a claim that every existing 4-2 certificate is a CRA harmonised-standard result.

Sources