CIP IEC-62443-4-1 Assessment Result =================================== .. contents:: **Revision History** .. list-table:: :header-rows: 1 * - Revision No - Date - Change description - Author - Reviewed by * - 001 - 2026-06-10 - CIP IEC-62443-4-1 assessment results - Dinesh Kumar - BV (Bureau Veritas) 1. Overview ----------- This document is based on the CIP IEC-62443-4-1 final assessment results report from BV (Bureau Veritas) . The objective is to share final CIP IEC-62443-4-1 assessment results with CIP users which should help CIP users to make informed decision for their end product IEC-62443-4-1 compliance preparation. As IEC-62443-4-1 is primarily based on secure development process, it varies for different organizations. However, CIP users can use CIP IEC-62443-4-1 artefacts as reference and create customized artefacts for develoment process applicable to end products. 2. CIP reference documents for detailed assessment results ----------------------------------------------------------- Multiple documents were referenced during CIP IEC-62443-4-1 assessment, the primary document can be referenced at `CIP Secure Developmet process `__. In addition, refer other CIP secure development process documents at `CIP Development Process folder `__ 3. CIP IEC-62443-4-1 assessment Results based on BV report ------------------------------------------------------------ CIP IEC-62443-4-1 final assessment for Secure process development was completed with BV in August 2024. During the assessment there were several investigations to fix gaps identified by BV. As CIP relies on several upstream components and Debian development processes. Most of the development processes are met by reusing Debian as well as upsteam developent processes. Though majority of the IEC-62443-4-1 Secure Development Practice areas are met by CIP.However, there are few process areas which are very specific to end product and use cases which are not met by CIP. Following table lists the final results, following is the meaning of PASS and NA. - Some requirements are marked as PASS, it indicates CIP meets the requirement (follows that specific Secure Development Practice) - Some requirements are marked as NA, it indicates CIP does not meet the requirement (for various reasons CIP can not follow the practice) but CIP users may meet the same requirement. 4. CIP IEC-62443-4-1 final assessment results ---------------------------------------------- 4.1 Practice-1 Security Management ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +------------------+--------------------------+ | IEC 62443-4-1 ID | Final assessment results | +==================+==========================+ | SM-1 | PASS | +------------------+--------------------------+ | SM-2 | PASS | +------------------+--------------------------+ | SM-3 | PASS | +------------------+--------------------------+ | SM-4 | PASS | +------------------+--------------------------+ | SM-5 | PASS | +------------------+--------------------------+ | SM-6 | PASS | +------------------+--------------------------+ | SM-7 | PASS | +------------------+--------------------------+ | SM-8 | PASS | +------------------+--------------------------+ | SM-9 | PASS | +------------------+--------------------------+ | SM-10 | NA | +------------------+--------------------------+ | SM-11 | PASS | +------------------+--------------------------+ | SM-12 | PASS | +------------------+--------------------------+ | SM-13 | PASS | +------------------+--------------------------+ 4.2 Practice-2 Specification of security requirements ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +------------------+--------------------------+ | IEC 62443-4-1 ID | Final assessment results | +==================+==========================+ | SR-1 | PASS | +------------------+--------------------------+ | SR-2 | PASS | +------------------+--------------------------+ | SR-3 | PASS | +------------------+--------------------------+ | SR-4 | PASS | +------------------+--------------------------+ | SR-5 | PASS | +------------------+--------------------------+ 4.3 Practice-3 Secure by design ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +------------------+--------------------------+ | IEC 62443-4-1 ID | Final assessment results | +==================+==========================+ | SD-1 | PASS | +------------------+--------------------------+ | SD-2 | NA | +------------------+--------------------------+ | SD-3 | PASS | +------------------+--------------------------+ | SD-4 | NA | +------------------+--------------------------+ 4.4 Practice-4 Secure implementation ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +------------------+--------------------------+ | IEC 62443-4-1 ID | Final assessment results | +==================+==========================+ | SI-1 | NA | +------------------+--------------------------+ | SI-2 | NA | +------------------+--------------------------+ 4.5 Practice-5 Security verification and validation testing ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +------------------+--------------------------+ | IEC 62443-4-1 ID | Final assessment results | +==================+==========================+ | SVV-1 | PASS | +------------------+--------------------------+ | SVV-2 | PASS | +------------------+--------------------------+ | SVV-3 | PASS | +------------------+--------------------------+ | SVV-4 | NA | +------------------+--------------------------+ | SVV-5 | PASS | +------------------+--------------------------+ 4.6 Practice-6 Management of security related issues ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +------------------+--------------------------+ | IEC 62443-4-1 ID | Final assessment results | +==================+==========================+ | DM-1 | PASS | +------------------+--------------------------+ | DM-2 | PASS | +------------------+--------------------------+ | DM-3 | PASS | +------------------+--------------------------+ | DM-4 | PASS | +------------------+--------------------------+ | DM-5 | PASS | +------------------+--------------------------+ | DM-6 | PASS | +------------------+--------------------------+ 4.7 Practice-7 Security update management ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +------------------+--------------------------+ | IEC 62443-4-1 ID | Final assessment results | +==================+==========================+ | SUM-1 | PASS | +------------------+--------------------------+ | SUM-2 | PASS | +------------------+--------------------------+ | SUM-3 | PASS | +------------------+--------------------------+ | SUM-4 | PASS | +------------------+--------------------------+ | SUM-5 | PASS | +------------------+--------------------------+ 4.8 Practice-8 Security guidelines ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +------------------+--------------------------+ | IEC 62443-4-1 ID | Final assessment results | +==================+==========================+ | SG-1 | NA | +------------------+--------------------------+ | SG-2 | NA | +------------------+--------------------------+ | SG-3 | PASS | +------------------+--------------------------+ | SG-4 | NA | +------------------+--------------------------+ | SG-5 | PASS | +------------------+--------------------------+ | SG-6 | PASS | +------------------+--------------------------+ | SG-7 | PASS | +------------------+--------------------------+