RT-Labs Passes Independent IEC 62443-4-1 Security Evaluation

Assessment supports EU Cyber Resilience Act compliance

In our previous article, Cybersecurity Readiness Starts Now, we shared how RT-Labs is strengthening its approach to cybersecurity as requirements for industrial product manufacturers continue to evolve.

As part of this work, our secure development process underwent a formal assessment by RISE, Research Institutes of Sweden, in accordance with IEC 62443-4-1.

We are pleased to share that RT-Labs passes independent security evaluation. This is an important milestone for RT-Labs and a valuable independent validation of the secure development practices that are an integral part of how we develop products.

Putting our approach to the test

The assessment gave us an opportunity to take a close look at how cybersecurity is integrated throughout our development process. This included areas such as maintaining and supporting a product throughout its entire lifecycle, security management, requirements specification, secure design and implementation, verification and validation, as well as vulnerability and update management.

The assessment also provided valuable input that we can use to further strengthen and improve our development processes.

More than compliance

One of the key lessons from the accredited report is that IEC 62443-4-1 is about more than simply meeting a set of requirements. It provides a structured framework for integrating cybersecurity throughout the secure product development lifecycle.

The accredited RISE report provides documentation of our secure product development approach in accordance with the requirements of IEC 62443-4-1.

IEC 62443-4-1, Secure Product Development Lifecycle Requirements, defines how cybersecurity should be managed throughout the entire product lifecycle. It covers areas such as security requirements, secure design and development, testing and validation, vulnerability management, updates, and security documentation.

What this means for our customers

The Cyber Resilience Act (CRA) introduces requirements that make it increasingly critical for companies to ensure that their technology partners can demonstrate how cybersecurity is managed throughout the entire product lifecycle. The accredited RISE report provides the secure development processes we have established at RT-Labs.

When we work with a customer on a new product or project, cybersecurity is considered as part of the engineering process rather than added as a separate task later.

Our experience with IEC 62443-4-1 can be applied directly to customer projects, providing a practical way to address cybersecurity alongside the other requirements of the product.

From assessment to practice

The RISE assessment and the resulting accredited report mark an important milestone for RT-Labs, while also supporting our continued focus on strengthening our secure development processes. As technology, threats, and requirements evolve, we will continue to develop and improve our approach.

Our work across the broader IEC 62443 framework is also progressing. The IEC 62443-4-1 assessment is now complete and documented in an accredited RISE report, while we continue our work towards IEC 62443-4-2.

At RT-Labs, secure development is an integral part of our way of working, and we continuously strengthen our practices to meet the evolving cybersecurity requirements introduced by regulations such as the Cyber Resilience Act (CRA).

More about RISE

RISE, Research Institutes of Sweden, is Sweden’s research institute and innovation partner, and one of Europe’s largest research institutes. As an independent government research institute, RISE works to develop processes, services, products, and technologies. RISE collaborates with industry, academia, and the public sector and performs accredited testing and evaluation of cybersecurity for IACS components. Cybersecurity testing is conducted according to the product parts of the IACS based on 62443-4 standards, SS-EN IEC 62443-4-1 and SS-EN IEC 62443-4-2.