CIP IEC-62443-4-1 Assessment Result
Revision History
Revision No |
Date |
Change description |
Author |
Reviewed by |
|---|---|---|---|---|
001 |
2026-06-10 |
CIP IEC-62443-4-1 assessment results |
Dinesh Kumar |
BV (Bureau Veritas) |
1. Overview
This document is based on the CIP IEC-62443-4-1 final assessment results report from BV (Bureau Veritas) . The objective is to share final CIP IEC-62443-4-1 assessment results with CIP users which should help CIP users to make informed decision for their end product IEC-62443-4-1 compliance preparation.
As IEC-62443-4-1 is primarily based on secure development process, it varies for different organizations. However, CIP users can use CIP IEC-62443-4-1 artefacts as reference and create customized artefacts for develoment process applicable to end products.
2. CIP reference documents for detailed assessment results
Multiple documents were referenced during CIP IEC-62443-4-1 assessment, the primary document can be referenced at CIP Secure Developmet process.
In addition, refer other CIP secure development process documents at CIP Development Process folder
3. CIP IEC-62443-4-1 assessment Results based on BV report
CIP IEC-62443-4-1 final assessment for Secure process development was completed with BV in August 2024. During the assessment there were several investigations to fix gaps identified by BV. As CIP relies on several upstream components and Debian development processes. Most of the development processes are met by reusing Debian as well as upsteam developent processes.
Though majority of the IEC-62443-4-1 Secure Development Practice areas are met by CIP.However, there are few process areas which are very specific to end product and use cases which are not met by CIP. Following table lists the final results, following is the meaning of PASS and NA.
Some requirements are marked as PASS, it indicates CIP meets the requirement (follows that specific Secure Development Practice)
Some requirements are marked as NA, it indicates CIP does not meet the requirement (for various reasons CIP can not follow the practice) but CIP users may meet the same requirement.
4. CIP IEC-62443-4-1 final assessment results
4.1 Practice-1 Security Management
IEC 62443-4-1 ID |
Final assessment results |
|---|---|
SM-1 |
PASS |
SM-2 |
PASS |
SM-3 |
PASS |
SM-4 |
PASS |
SM-5 |
PASS |
SM-6 |
PASS |
SM-7 |
PASS |
SM-8 |
PASS |
SM-9 |
PASS |
SM-10 |
NA |
SM-11 |
PASS |
SM-12 |
PASS |
SM-13 |
PASS |
4.2 Practice-2 Specification of security requirements
IEC 62443-4-1 ID |
Final assessment results |
|---|---|
SR-1 |
PASS |
SR-2 |
PASS |
SR-3 |
PASS |
SR-4 |
PASS |
SR-5 |
PASS |
4.3 Practice-3 Secure by design
IEC 62443-4-1 ID |
Final assessment results |
|---|---|
SD-1 |
PASS |
SD-2 |
NA |
SD-3 |
PASS |
SD-4 |
NA |
4.4 Practice-4 Secure implementation
IEC 62443-4-1 ID |
Final assessment results |
|---|---|
SI-1 |
NA |
SI-2 |
NA |
4.5 Practice-5 Security verification and validation testing
IEC 62443-4-1 ID |
Final assessment results |
|---|---|
SVV-1 |
PASS |
SVV-2 |
PASS |
SVV-3 |
PASS |
SVV-4 |
NA |
SVV-5 |
PASS |
4.7 Practice-7 Security update management
IEC 62443-4-1 ID |
Final assessment results |
|---|---|
SUM-1 |
PASS |
SUM-2 |
PASS |
SUM-3 |
PASS |
SUM-4 |
PASS |
SUM-5 |
PASS |
4.8 Practice-8 Security guidelines
IEC 62443-4-1 ID |
Final assessment results |
|---|---|
SG-1 |
NA |
SG-2 |
NA |
SG-3 |
PASS |
SG-4 |
NA |
SG-5 |
PASS |
SG-6 |
PASS |
SG-7 |
PASS |