Control room of a regional grid operator, an engineer stands at a desk of industrial control panels and matte monitors, a large dim network overview on the wall behind
ENERGY & SUSTAINABILITY

OT security for energy plants: IEC 62443 and the Cyber Resilience Act from 2026

Energy plants have become computers with switchgear. Every inverter, every remote terminal unit hangs on the grid and on the internet. From 2026 it is no longer enough to regulate the operator. Now the manufacturer of the product is liable too.

The Cyber Resilience Act gets serious on 11 September 2026, and IEC 62443 becomes the technical bridge between operator duty and product duty. This article orders the deadlines, the product classes and the standard with its zones and security levels, and shows what to do now. The organisational base is covered in the piece on NIS2 and the KRITIS umbrella law , and the grid-code angle in the piece on the NCCS network code cybersecurity obligations .

Summary

Energy plants gain a two-tier cybersecurity framework from 2026. Until now the legislator mainly regulated the operator, who has to demonstrate an information security management system. The Cyber Resilience Act (Regulation (EU) 2024/2847) arrives as a second layer and makes the manufacturer of a connected product responsible, from inverters and remote terminal units to control software. The CRA entered into force on 10 December 2024. From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours and a full notification within 72 hours through the ENISA platform. From 11 December 2027 every product in scope needs CE marking, technical documentation, a risk assessment and a software bill of materials. The technical language for all this comes from IEC 62443, the international standard for the security of industrial control systems. It splits duties across manufacturer, integrator and operator, grades measures into four security levels from SL1 to SL4, and divides plants into zones and conduits. IEC 62443 is expected to be listed as a harmonised standard under the CRA, so meeting it creates a presumption of conformity. The harmonised version, though, is expected only at the end of 2026, a year before the CRA fully applies. For grid operators, municipal utilities and plant builders this is a procurement and architecture decision, and it is being made now.

Why energy plants get a second rulebook

Energy plants get a second rulebook in 2026 because the first one only reaches the operator, not the device. Anyone running a critical plant already has to show an information security management system. That organisational duty stays. But it secures the frame, not the individual inverter.

A certified management system says nothing about whether the installed remote terminal unit was built securely in the first place. That is exactly the gap the Cyber Resilience Act closes. It makes the manufacturer of the product responsible, not just the operator of the plant. For energy plants a two-tier framework emerges: an operator level and a product level that have to mesh.

The operator level is already spelled out. National IT security catalogues under energy law require operators of critical energy plants to run an ISMS aligned with ISO 27001 and ISO 27019. On top come the reporting and governance duties from NIS2 and the KRITIS umbrella law . What was missing was the product level. The CRA fills it, and IEC 62443 connects the two.

The Cyber Resilience Act and its deadlines from 2026

The Cyber Resilience Act is the first EU-wide product regulation for cybersecurity. It covers products with digital elements, meaning almost any connected hardware or software inside an energy plant. The duties apply in stages, and the first hard date falls in September 2026.

10 December 2024

CRA in force

Regulation (EU) 2024/2847 enters into force. From here the staggered transition period for manufacturers runs.

11 June 2026

Conformity assessment bodies

The rules on notified bodies apply. Assessment bodies can get notified so that products checked more strictly find a body in time.

11 September 2026

Reporting duties start

Manufacturers must report actively exploited vulnerabilities and severe incidents through the ENISA platform. This is the first date that really bites.

11 December 2027

Full application

Every product in scope needs CE marking, technical documentation, a risk assessment and a software bill of materials.

The 11 September 2026 is the date that hurts first. From then an actively exploited vulnerability starts a hard clock. A manufacturer without the processes for it reports too late.

24 h
Early warning
after becoming aware of the vulnerability
72 h
Full notification
to the responsible body via ENISA
14 days
Final report
after a corrective measure is available

Important and critical products: what gets checked harder

Not every product goes through the same procedure. The CRA grades requirements by risk, and many components in energy plants fall into the stricter classes. That decides whether a manufacturer may self-assess or has to bring in a notified body.

Product class Examples Conformity assessment
Standard product The bulk of connected products without a special security function Manufacturer self-assessment
Important, class I Network components, password managers, VPN, routers Self-assessment with a harmonised standard, or a notified body
Important, class II Firewalls, intrusion detection systems, industrial safety functions Usually assessment by a notified body
Critical Products with particularly high risk, set by legal act Strictest procedure, in part a European certificate

Industrial control systems, network technology and security functions typically sit in the more strictly checked categories. For an energy plant that means a large share of the installed technology does not land in the simple self-assessment.

Software bill of materials (SBOM) is a structured list of all software components in a product, much like an ingredient list. It shows which libraries and third-party components are included. The CRA makes the SBOM mandatory, because a large share of vulnerabilities enter a product through embedded third-party libraries. Without an SBOM, in an incident you cannot say whether a newly disclosed flaw affects your own device.

IEC 62443: the technical bridge between operator and manufacturer

The CRA says what has to be achieved, but not how. IEC 62443 fills that gap, the established series of standards for the security of industrial control systems. It is the only widely accepted standard that addresses every role along the supply chain, which is why it is expected to be listed as a harmonised standard under the CRA.

Diagram: operator duty from NIS2 and the IT security catalogue and product duty from the Cyber Resilience Act meet in the secure energy plant, with IEC 62443 below as the shared technical language
Operator and product duties meet in the plant, and IEC 62443 is the shared technical language underneath.

The standard splits duties across three roles. The component manufacturer supplies devices and software, the system integrator builds the plant from them, the operator runs it. Each role has its own parts of the standard, from organisational management systems to technical product properties.

Part Role Content
IEC 62443-2-1 Operator Security programme for the plant's control systems
IEC 62443-3-3 Integrator Security requirements for the overall system
IEC 62443-4-1 Manufacturer Secure development process for the product
IEC 62443-4-2 Manufacturer Technical security requirements for individual components

Part 62443-4-2 is the one that matters for the CRA. CEN-CENELEC is adapting the European version EN IEC 62443-4-2 to the CRA requirements right now. Once the standard is harmonised and listed, meeting it creates a presumption of conformity for the corresponding CRA obligations. The catch is in the timeline. The final harmonised version is expected only at the end of 2026, leaving manufacturers less than twelve months until the CRA fully applies.

Zones, conduits and security levels in practice

The practical heart of IEC 62443 is an architecture principle that maps straight onto an energy plant. Instead of protecting a flat network, the plant is broken into areas that only talk through controlled connections. That keeps an attack on one zone contained.

Female automation technician in a grey work jacket crouched in the equipment room of a substation in front of an open control cabinet with industrial network switches, guiding a patch cable to a port
Zones and conduits get concrete in the cabinet: controlled data paths instead of one continuously flat network.
Zone and conduit are the two building blocks of IEC 62443. A zone groups plant elements with the same protection needs, for example the remote control technology of a substation separated from office communication. A conduit is the only controlled data path between two zones and carries its own security requirements. The model comes from IEC 62443-3-2. Segmenting a plant this way keeps an attack inside one zone instead of letting it run through the whole network.

Each zone and conduit gets a security level. It grades measures by the strength of the attacker to defend against. A substation at a critical grid node needs a higher level than a single inverter in the distribution grid.

SL1
Protection against chance
accidental or casual violation
SL2
Simple attacks
simple means, low resources
SL3
Targeted attacks
sophisticated means, moderate resources
SL4
High-effort attacks
sophisticated means, extended resources

Under the security levels sit seven foundational requirements. They order the technical measures: identification and authentication, use control, system integrity, data confidentiality, restricted data flow, timely response to events and resource availability. For each zone you can then pin down exactly how strongly it is protected against each of these seven categories. That is more work than a firewall at the plant edge. It is also the only path that survives an auditor and a CRA procedure.

What grid operators, utilities and plant builders should do now

The timeline leaves little room. The harmonised version of IEC 62443 arrives only at the end of 2026, the full CRA application a year later. Start in 2027 and you negotiate contracts and build architecture under time pressure. Better to read both rulebooks together now. Four steps make the difference.

Fenced outdoor yard of a medium-voltage substation with a grey switchgear building, disconnector structures and a cable cabinet, an overhead line tower in the background
From the outdoor yard to the control system: OT security runs through the whole energy plant, not just the IT.

Four steps for OT security

  1. Change procurement

    Ask suppliers for proof of CRA conformity and of IEC 62443-4-2, including a software bill of materials and a documented vulnerability process. What is not in the contract today is missing in 2027.

  2. Split the plant into zones

    Segment existing plants into zones and conduits and set a security level per zone, instead of running a flat network. This is the base every later assessment builds on.

  3. Build reporting processes

    Build reporting and response processes so the 24- and 72-hour deadlines hold in an incident. From 11 September 2026 this is no longer optional.

  4. Mesh the levels

    Connect the product level with the existing ISMS duty from the IT security catalogue, so operator and manufacturer duties are not managed separately. One team, two rulebooks, one standard.

Further reading

Frequently asked questions

What is the Cyber Resilience Act and when does it apply to energy plants? +

The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first EU-wide product regulation for cybersecurity. It covers products with digital elements, meaning almost any connected hardware or software in an energy plant. It entered into force on 10 December 2024. From 11 September 2026 the reporting duties for actively exploited vulnerabilities and severe incidents apply, and from 11 December 2027 the full manufacturer obligations including CE marking.

What is IEC 62443? +

IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems, meaning operational technology (OT). It addresses every role along the supply chain: the component manufacturer, the system integrator and the plant operator. At its core are four security levels from SL1 to SL4, seven foundational requirements and the zones and conduits model that segments a plant into areas with the same protection needs.

What reporting deadlines does the CRA require? +

From 11 September 2026 a manufacturer must report an actively exploited vulnerability or a severe security incident in three stages: an early warning within 24 hours of becoming aware, a full notification within 72 hours and a final report no later than 14 days after a corrective measure is available, or within a month for severe incidents. Reports go through the central reporting platform run by ENISA.

How do IEC 62443 and the Cyber Resilience Act relate? +

The CRA says what has to be achieved, but not how. IEC 62443 fills that gap as the technical standard. It is expected to be listed as a harmonised standard under the CRA. If a manufacturer meets the relevant IEC 62443 parts, such as 62443-4-2 for components, that creates a presumption of conformity for the corresponding CRA obligations. The harmonised version is expected only at the end of 2026.

What are zones and conduits in an energy plant? +

A zone groups plant elements with the same protection needs, for example the remote control technology of a substation separated from office communication. A conduit is the only controlled data path between two zones and carries its own security requirements. Each zone and conduit gets a security level from SL1 to SL4 that grades measures by attacker strength. This keeps an attack contained in one zone instead of spreading through a flat network.