2026-09-21 · Équipe éditoriale KeXinMaterials

IEC 62443 + NIS2 + EU CRA Industrial Cybersecurity Protective Case B2B Guide

IEC 62443 (Industrial Automation + Control Systems cybersecurity), NIS2 Directive (EU 2022/2555), and EU Cyber Resilience Act (CRA 2024/2847) are the three primary regulations defining industrial + product cybersecurity requirements. Below is the 2026 B2B procurement guide covering IEC 62443 Security Levels, NIS2 sectoral scope, CRA essential + important requirements, zones + conduits, SBOM, secure boot, and protective case correlation.

IEC 62443 Cybersecurite Industrielle

IEC 62443 (Industrial Automation + Control Systems cybersecurity) is the global standard series for industrial cybersecurity. Defines requirements for System Integrators, System Maintainers, Component Vendors, and Asset Owners.

IEC 62443 scope: Industrial Automation + Control Systems (IACS) cybersecurity. Applies to industrial process automation (SCADA, DCS), discrete manufacturing (PLC, robotics), critical infrastructure (energy, water, transport), building automation, and Industrial IoT.

IEC 62443 standards: 14 parts across 4 categories - (1) General (62443-1-1 to 62443-1-5) - terminology, concepts, metrics. (2) Policies + Procedures (62443-2-1 to 62443-2-4) - patch management, system integration. (3) System (62443-3-1 to 62443-3-3) - security levels, zones, conduits. (4) Component (62443-4-1 to 62443-4-2) - secure product development lifecycle, component security requirements.

IEC 62443-3-3 System Security Requirements + Security Levels: Defines 7 foundational requirements (FR 1 Identification + Authentication, FR 2 Use Control, FR 3 System Integrity, FR 4 Data Confidentiality, FR 5 Restricted Data Flow, FR 6 Timely Response to Events, FR 7 Resource Availability). Each FR has multiple requirements (SR) with 4 security levels (SL 1-4): SL 1 casual / coincidental attack, SL 2 intentional with simple means + low resources, SL 3 sophisticated with moderate resources + IACS knowledge, SL 4 sophisticated with extensive resources IACS knowledge.

IEC 62443-3-2 Zones + Conduits: Partition system into zones (group of assets with common security requirements) and conduits (communication paths between zones). Each zone has target SL-T (target). Each conduit has SL-C (capability). For protective case: case is zone boundary, cable gland is conduit boundary.

IEC 62443-3-2 Security Risk Assessment + System Security Requirements: Assess security risks (likelihood x impact), determine SL-T per zone, define SL-T to SL-A (achieved) gap remediation, document in zone-security policy.

IEC 62443-4-1 Product Development Lifecycle: Secure Development Lifecycle (SDL) per IEC 62443-4-1. Requirements: security risk assessment per development phase, secure coding practices, security testing (SAST, DAST, fuzz), vulnerability management, patch management, security update policy.

IEC 62443-4-2 Component Security Requirements: Component security functional requirements per FR + SL. For software components: SBOM per IEC 62443-4-1 + CRA, secure boot per IEC 62443, signed firmware updates, identity + authentication per FR 1.

IEC 62443-2-4 Service Provider Security: Requirements for system integrators + service providers per IEC 62443-2-4. Customer + service provider responsibilities per SP (Service Provider) + OC (Organization Customer).

IEC 62443 + protective case: Case is a physical security zone boundary. Provides: (1) Physical access control (padlock-compatible latches). (2) Tamper evidence (security seals, intrusion detection sensors). (3) Environmental protection (IP rating for dust + water + temperature). (4) Asset protection (shock, drop, vibration). (5) Optional RFID tag integration for asset tracking.

IEC 62443 conformance certification: Issued by IECEE CB Scheme + certification bodies. Includes process certification (62443-2-4, 62443-4-1) + product certification (62443-4-2).

B2B relevance: For B2B manufacturers supplying industrial customers, IEC 62443-4-1 process certification + IEC 62443-4-2 product certification required by Siemens, Rockwell, Schneider Electric, ABB. EU NIS2 + CRA add compliance requirements.

B2B recommendation: For 2026 B2B orders targeting IEC 62443 customers, target protective case with: (1) IEC 62443-4-1 process certification (or aligned). (2) IEC 62443-4-2 component security baseline (FR 1, FR 3, FR 4). (3) SBOM per CRA. (4) Tamper-evident features + RFID tracking support. (5) IP54+ environmental protection.

Directive NIS2 (UE 2022/2555)

NIS2 Directive (Directive (EU) 2022/2555, Network and Information Security 2) replaced original NIS Directive (2016/1148). Significantly expands cybersecurity obligations for EU essential + important entities. Transposed into national law by October 2024.

NIS2 scope: Cybersecurity obligations for EU essential + important entities. Essential entities: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, public administration, space. Important entities: postal services, waste management, chemicals, food, medical devices, electronics + optics, electrical equipment, machinery, motor vehicles, digital providers, research organizations.

NIS2 entity classification: Large entities (>250 employees OR > 50 million EUR revenue) = essential. Medium entities (>50 employees OR > 10 million EUR revenue) = important. Small entities exempt unless critical.

NIS2 risk management obligations (Art. 21): Essential + important entities must implement appropriate + proportionate technical + organizational measures including: (1) Risk assessment + information system security policies. (2) Incident handling. (3) Business continuity + crisis management. (4) Supply chain security. (5) Vulnerability handling + disclosure. (6) Effectiveness assessment. (7) Basic cyber hygiene + training. (8) Cryptography + encryption. (9) HR security + access control. (10) Multi-factor authentication + secured communications.

NIS2 incident reporting obligations: Entities must notify CSIRT (Computer Security Incident Response Team) without undue delay of any incident with significant impact on service continuity. Initial notification within 24 hours, final notification within 1 month.

NIS2 supply chain security (Art. 21(2)(d)): Must assess + ensure security of supplier + service provider relationships. For B2B protective case suppliers: customers will request SOC2 / IEC 62443 / ISO 27001 documentation + SBOM.

NIS2 enforcement: National supervisory authorities + fines. Essential entities: max 10 million EUR or 2% annual global turnover. Important entities: max 7 million EUR or 1.4% annual global turnover. Plus management liability.

NIS2 + protective case: B2B customers in NIS2 scope (energy, health, transport, chemicals, food, machinery) require cybersecurity-aligned protective case supply. Case provides physical security baseline supporting cybersecurity controls (access control, tamper evidence, asset tracking).

NIS2 deadline: Transposed into national law by October 17, 2024. Compliance required from October 2024 onwards. National supervisory authorities in each EU member state.

NIS2 + UK: UK NIS Regulations 2018 + NIS 2.0 amendments. Similar scope + obligations for relevant digital service providers + essential services.

NIS2 + USA: USA does not have direct equivalent. Closest: US SEC Cybersecurity Disclosure Rule (cybersecurity incident disclosure 4 days). CISA + NIST CSF (voluntary framework).

B2B relevance: For B2B manufacturers exporting to EU, customers in NIS2 scope will require cybersecurity documentation + certifications. Protective case is part of supply chain security baseline.

B2B recommendation: For 2026 B2B orders targeting NIS2-scope customers, target protective case with: (1) IEC 62443-4-1 process certification (or aligned). (2) SBOM. (3) Tamper-evident features. (4) Documented supply chain (Tier 1 + Tier 2 supplier list). (5) Manufacturer SOC2 Type 2 (or aligned).

UE Cyber Resilience Act (CRA 2024/2847)

EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) is the EU cybersecurity regulation for products with digital elements (PDEs). CRA establishes essential + important cybersecurity requirements, vulnerability handling, SBOM, conformity assessment.

CRA scope: All products with digital elements (PDEs) - hardware with software, software, remote data processing solutions. Excludes: medical devices (MDR), medical in-vitro diagnostics (IVDR), automotive (Reg. 2018/858), aviation (Reg. 2018/1139), military products. Both EU + non-EU manufacturers targeting EU market must comply.

CRA product classification: Critical products (Annex I) - identity management, password management, privileged access management, standalone browsers, password managers, software to delete/transfer data, anti-virus, VPNs, network management systems, SIEM, boot managers, container runtimes, key management, PKI, smart meter gateways, smart meters. Important products: any other PDE not in Annex I + not exempt.

CRA essential requirements (Annex I Part 1): PDEs must be designed + manufactured + delivered with: (1) Secure by default configuration + least privilege. (2) Vulnerability remediation + secure updates. (3) Identity + access management. (4) Data confidentiality + integrity. (5) Data minimization. (6) Resilience + DoS protection. (7) Attack surface minimization. (8) Recording + monitoring of relevant security events.

CRA vulnerability handling (Annex I Part 2): Manufacturers must: (1) Document software components in SBOM. (2) Address vulnerabilities without delay. (3) Apply security updates separately from functionality updates. (4) Provide security update at least 5 years (or per product lifetime if shorter). (5) Public disclosure of fixed vulnerabilities (after patch deployment). (6) Coordinated vulnerability disclosure policy.

CRA SBOM: Per Annex I Part 2(7), SBOM must include all software components + dependencies + version + supplier. Free + open-source software excluded from CRA compliance obligation but should be documented for transparency.

CRA conformity assessment: Critical products require third-party conformity assessment (Annex VII or VIII). Important products require self-assessment (Annex IX) or simplified assessment.

CRA CE marking: PDEs compliant with CRA must carry CE marking + EU Declaration of Conformity (Annex IV or V). Manufacturer or authorized representative signs DoC.

CRA timeline: CRA entered into force December 10, 2024. Full application: December 11, 2027 (36 months). Vulnerability handling (Annex I Part 2): September 11, 2026 (21 months). CE marking required: December 11, 2027. SMEs extended by 12 months.

CRA penalties: Administrative fines up to 15 million EUR or 2.5% annual global turnover (whichever higher). Critical products: 15M EUR / 2.5%. Important products: 7.5M EUR / 1.4%. Plus measures (withdraw, recall).

CRA + IEC 62443: CRA essential requirements reference international standards. IEC 62443-4-1 (secure product development) + IEC 62443-4-2 (component security) align with CRA Annex I.

CRA + protective case: Protective case may contain digital elements (sensors, RFID, GPS tracker). If so, case falls under CRA scope. Manufacturer must comply with CRA essential + important requirements.

B2B relevance: For B2B manufacturers exporting PDEs to EU, CRA compliance is mandatory from December 2027. Pre-compliance advisable for 2026 orders.

B2B recommendation: For 2026 B2B orders targeting EU customers, target protective case with: (1) SBOM (free + open-source + commercial components). (2) IEC 62443-4-1 process documentation. (3) 5-year security update commitment. (4) Vulnerability handling policy. (5) CE marking + EU Declaration of Conformity per CRA.

Liste de verification cybersecurite B2B

Comprehensive B2B procurement checklist for cybersecurity-aligned protective cases. Covers IEC 62443, NIS2, CRA, SBOM, secure boot, tamper evidence.

IEC 62443 baseline: (1) IEC 62443-4-1 process certification (or aligned). (2) IEC 62443-4-2 component security baseline (FR 1 identification, FR 3 integrity, FR 4 confidentiality, FR 5 restricted data flow, FR 7 availability).

Tamper evidence: (1) Padlock-compatible latches. (2) Security seals (numbered, tamper-evident). (3) Optional intrusion detection sensor integration. (4) Optional RFID tag integration for asset tracking. (5) Optional GPS tracker compartment.

SBOM: (1) List of all software components (commercial + free + open-source). (2) Version + supplier per component. (3) Updateable / SBOM lifecycle. (4) Compatible with CRA + EO 14028 US SBOM requirements.

Secure boot + signed firmware (for PDE cases): (1) Hardware root of trust. (2) Secure boot per IEC 62443-4-2 FR 3. (3) Signed firmware updates per IEC 62443-4-2 FR 3 + FR 7. (4) Secure update delivery per IEC 62443-4-2 FR 7.

Physical access control: (1) Padlock-compatible latches. (2) Optional biometric access (fingerprint, RFID). (3) Optional keypad combination. (4) Multi-factor access for high-security.

Environmental protection: (1) IP54+ for general factory. (2) IP65 for dusty / wet. (3) IP67 for outdoor / wet. (4) Operating temperature range aligned with electronics.

Asset tracking integration: (1) RFID tag compartment (UHF passive, NFC, BLE). (2) GPS tracker compartment (cellular, satellite). (3) Tamper-evident seal with unique ID + audit trail.

Documentation: (1) IEC 62443 conformance documentation. (2) SBOM per CRA. (3) Vulnerability handling policy. (4) Security update policy. (5) Manufacturer SOC2 Type 2 (or aligned).

Supply chain transparency: (1) Tier 1 supplier list. (2) Tier 2 supplier (where available). (3) Country of origin per material. (4) Conflict mineral status per Dodd-Frank / EU CMR. (5) Anti-counterfeit features.

Manufacturer credentials: (1) IEC 62443-4-1 process certification (or aligned to ISA/IEC 62443-4-1). (2) ISO 27001 (information security). (3) SOC2 Type 2. (4) ISO 9001 (quality).

Customer-facing compliance: (1) EU Declaration of Conformity per CRA. (2) CE marking (when required). (3) Test reports (IP rating per IEC 60529). (4) Material certificates.

B2B recommendation: For 2026 B2B orders targeting NIS2 / CRA-scope customers, target IEC 62443 + CRA + NIS2-aligned protective case: IEC 62443-4-1 process + IEC 62443-4-2 component security + SBOM + tamper evidence + 5-year security update + EU DoC, FOB Shenzhen/Ningbo/EXW delivery 30-45 days.

Points clés

  • IEC 62443 = 14-part industrial cybersecurity standard with 4 Security Levels (SL 1-4) + 7 foundational requirements.
  • NIS2 Directive (EU 2022/2555) = EU essential + important entity cybersecurity with max 10M EUR / 2% turnover penalty.
  • EU Cyber Resilience Act (CRA 2024/2847) = mandatory for products with digital elements; SBOM + 5-year security update + CE marking.
  • Protective case cybersecurity baseline: IEC 62443-4-1 process + IEC 62443-4-2 component + SBOM + tamper evidence + EU DoC.
  • B2B procurement checklist: IEC 62443 + CRA + NIS2 aligned, SBOM, tamper evidence, 5-year security update, manufacturer credentials.

FAQ

q

a

q

a

q

a

q

a

q

a

q

a

Demander maintenant · 30-45 Day Delivery