OT security for energy plants: IEC 62443 and the Cyber Resilience Act from 2026
The Cyber Resilience Act gets serious on 11 September 2026, and IEC 62443 becomes the technical bridge between operator duty and product duty. This article orders the deadlines, the product classes and the standard with its zones and security levels, and shows what to do now. The organisational base is covered in the piece on NIS2 and the KRITIS umbrella law , and the grid-code angle in the piece on the NCCS network code cybersecurity obligations .
Energy plants gain a two-tier cybersecurity framework from 2026. Until now the legislator mainly regulated the operator, who has to demonstrate an information security management system. The Cyber Resilience Act (Regulation (EU) 2024/2847) arrives as a second layer and makes the manufacturer of a connected product responsible, from inverters and remote terminal units to control software. The CRA entered into force on 10 December 2024. From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours and a full notification within 72 hours through the ENISA platform. From 11 December 2027 every product in scope needs CE marking, technical documentation, a risk assessment and a software bill of materials. The technical language for all this comes from IEC 62443, the international standard for the security of industrial control systems. It splits duties across manufacturer, integrator and operator, grades measures into four security levels from SL1 to SL4, and divides plants into zones and conduits. IEC 62443 is expected to be listed as a harmonised standard under the CRA, so meeting it creates a presumption of conformity. The harmonised version, though, is expected only at the end of 2026, a year before the CRA fully applies. For grid operators, municipal utilities and plant builders this is a procurement and architecture decision, and it is being made now.
Why energy plants get a second rulebook
Energy plants get a second rulebook in 2026 because the first one only reaches the operator, not the device. Anyone running a critical plant already has to show an information security management system. That organisational duty stays. But it secures the frame, not the individual inverter.
A certified management system says nothing about whether the installed remote terminal unit was built securely in the first place. That is exactly the gap the Cyber Resilience Act closes. It makes the manufacturer of the product responsible, not just the operator of the plant. For energy plants a two-tier framework emerges: an operator level and a product level that have to mesh.
The operator level is already spelled out. National IT security catalogues under energy law require operators of critical energy plants to run an ISMS aligned with ISO 27001 and ISO 27019. On top come the reporting and governance duties from NIS2 and the KRITIS umbrella law . What was missing was the product level. The CRA fills it, and IEC 62443 connects the two.
The Cyber Resilience Act and its deadlines from 2026
The Cyber Resilience Act is the first EU-wide product regulation for cybersecurity. It covers products with digital elements, meaning almost any connected hardware or software inside an energy plant. The duties apply in stages, and the first hard date falls in September 2026.
CRA in force
Regulation (EU) 2024/2847 enters into force. From here the staggered transition period for manufacturers runs.
Conformity assessment bodies
The rules on notified bodies apply. Assessment bodies can get notified so that products checked more strictly find a body in time.
Reporting duties start
Manufacturers must report actively exploited vulnerabilities and severe incidents through the ENISA platform. This is the first date that really bites.
Full application
Every product in scope needs CE marking, technical documentation, a risk assessment and a software bill of materials.
The 11 September 2026 is the date that hurts first. From then an actively exploited vulnerability starts a hard clock. A manufacturer without the processes for it reports too late.
Important and critical products: what gets checked harder
Not every product goes through the same procedure. The CRA grades requirements by risk, and many components in energy plants fall into the stricter classes. That decides whether a manufacturer may self-assess or has to bring in a notified body.
| Product class | Examples | Conformity assessment |
|---|---|---|
| Standard product | The bulk of connected products without a special security function | Manufacturer self-assessment |
| Important, class I | Network components, password managers, VPN, routers | Self-assessment with a harmonised standard, or a notified body |
| Important, class II | Firewalls, intrusion detection systems, industrial safety functions | Usually assessment by a notified body |
| Critical | Products with particularly high risk, set by legal act | Strictest procedure, in part a European certificate |
Industrial control systems, network technology and security functions typically sit in the more strictly checked categories. For an energy plant that means a large share of the installed technology does not land in the simple self-assessment.
IEC 62443: the technical bridge between operator and manufacturer
The CRA says what has to be achieved, but not how. IEC 62443 fills that gap, the established series of standards for the security of industrial control systems. It is the only widely accepted standard that addresses every role along the supply chain, which is why it is expected to be listed as a harmonised standard under the CRA.
The standard splits duties across three roles. The component manufacturer supplies devices and software, the system integrator builds the plant from them, the operator runs it. Each role has its own parts of the standard, from organisational management systems to technical product properties.
| Part | Role | Content |
|---|---|---|
| IEC 62443-2-1 | Operator | Security programme for the plant's control systems |
| IEC 62443-3-3 | Integrator | Security requirements for the overall system |
| IEC 62443-4-1 | Manufacturer | Secure development process for the product |
| IEC 62443-4-2 | Manufacturer | Technical security requirements for individual components |
Part 62443-4-2 is the one that matters for the CRA. CEN-CENELEC is adapting the European version EN IEC 62443-4-2 to the CRA requirements right now. Once the standard is harmonised and listed, meeting it creates a presumption of conformity for the corresponding CRA obligations. The catch is in the timeline. The final harmonised version is expected only at the end of 2026, leaving manufacturers less than twelve months until the CRA fully applies.
Zones, conduits and security levels in practice
The practical heart of IEC 62443 is an architecture principle that maps straight onto an energy plant. Instead of protecting a flat network, the plant is broken into areas that only talk through controlled connections. That keeps an attack on one zone contained.
Each zone and conduit gets a security level. It grades measures by the strength of the attacker to defend against. A substation at a critical grid node needs a higher level than a single inverter in the distribution grid.
Under the security levels sit seven foundational requirements. They order the technical measures: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely response to events and resource availability. For each zone you can then pin down exactly how strongly it is protected against each of these seven categories. That is more work than a firewall at the plant edge. It is also the only path that survives an auditor and a CRA procedure.
What grid operators, utilities and plant builders should do now
The timeline leaves little room. The harmonised version of IEC 62443 arrives only at the end of 2026, the full CRA application a year later. Start in 2027 and you negotiate contracts and build architecture under time pressure. Better to read both rulebooks together now. Four steps make the difference.
Four steps for OT security
-
Change procurement
Ask suppliers for proof of CRA conformity and of IEC 62443-4-2, including a software bill of materials and a documented vulnerability process. What is not in the contract today is missing in 2027.
-
Split the plant into zones
Segment existing plants into zones and conduits and set a security level per zone, instead of running a flat network. This is the base every later assessment builds on.
-
Build reporting processes
Build reporting and response processes so the 24- and 72-hour deadlines hold in an incident. From 11 September 2026 this is no longer optional.
-
Mesh the levels
Connect the product level with the existing ISMS duty from the IT security catalogue, so operator and manufacturer duties are not managed separately. One team, two rulebooks, one standard.
Further reading
Frequently asked questions
The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first EU-wide product regulation for cybersecurity. It covers products with digital elements, meaning almost any connected hardware or software in an energy plant. It entered into force on 10 December 2024. From 11 September 2026 the reporting duties for actively exploited vulnerabilities and severe incidents apply, and from 11 December 2027 the full manufacturer obligations including CE marking.
IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems, meaning operational technology (OT). It addresses every role along the supply chain: the component manufacturer, the system integrator and the plant operator. At its core are four security levels from SL1 to SL4, seven foundational requirements and the zones and conduits model that segments a plant into areas with the same protection needs.
From 11 September 2026 a manufacturer must report an actively exploited vulnerability or a severe security incident in three stages: an early warning within 24 hours of becoming aware, a full notification within 72 hours and a final report no later than 14 days after a corrective measure is available, or within a month for severe incidents. Reports go through the central reporting platform run by ENISA.
The CRA says what has to be achieved, but not how. IEC 62443 fills that gap as the technical standard. It is expected to be listed as a harmonised standard under the CRA. If a manufacturer meets the relevant IEC 62443 parts, such as 62443-4-2 for components, that creates a presumption of conformity for the corresponding CRA obligations. The harmonised version is expected only at the end of 2026.
A zone groups plant elements with the same protection needs, for example the remote control technology of a substation separated from office communication. A conduit is the only controlled data path between two zones and carries its own security requirements. Each zone and conduit gets a security level from SL1 to SL4 that grades measures by attacker strength. This keeps an attack contained in one zone instead of spreading through a flat network.