IEC 62443-4-1:2018 — Security for industrial automation and control systems – Part 4-1: Secure product development lifecycle requirements, published by the IEC in January 2018 (ISBN 978-2-8322-5239-0) — is the standard product suppliers use to demonstrate a secure development lifecycle for components going into industrial automation and control systems

Threat Modeling for IEC 62443-4-1: OT and Product Security

IEC 62443-4-1 doesn’t ask for a threat model as a best practice. It names it as a requirement: SR-2.

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

What “deployment scope” means for OT product suppliers

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

Where the requirement extends past SR-2

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

TMaaS and the maturity model

  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /
  • /

What this doesn’t mean

Frequently Asked Questions

Yes, explicitly. Requirement SR-2, within Practice 2 (Specification of Security Requirements), requires a process ensuring every product has a threat model specific to its current deployment scope, used to identify, communicate, and understand threats and mitigations.
SR-2 (“Threat model”) is a requirement in IEC 62443-4-1:2018 that products have a documented threat model tied to their deployment scope. It directly informs SR-3, which requires security requirements to be reviewed and validated against that threat model.
Yes. Guidance on applying IEC 62443-4-1 to legacy products recognizes creating a threat model (SR-2) retroactively for an existing product as a valid approach, even when other SDL processes weren’t followed during original development.
PCI DSS and FDA guidance describe threat modeling as a recommended method for satisfying a broader requirement. IEC 62443-4-1’s SR-2 names threat modeling as a specific, standalone requirement within the standard’s Security Requirements Specification practice.
No. Certification is issued by accredited certification bodies evaluating a supplier’s complete secure development lifecycle across all of the standard’s practices. A threat model satisfies SR-2 specifically, not the standard as a whole.