Portwell Achieves IEC 62443-4-1 Certification, Strengthening Secure-by-Design Development and Implementing CRA Readiness

Portwell, a global provider of industrial PCs and embedded computing solutions, announced that it has achieved IEC 62443-4-1 Maturity Level 2 (ML2) certification by Bureau Veritas (BV). The certification covers the secure product development lifecycle and associated development processes for industrial computing products at Portwell’s Taiwan R&D organization.

IEC 62443-4-1 is an internationally recognized cybersecurity standard that defines requirements for a secure product development lifecycle for Industrial Automation and Control Systems (IACS). The certification validates Portwell’s development processes rather than certifying individual products, and does not constitute product-level certification or conformity with the European Union Cyber Resilience Act (CRA).

Achieving ML2 demonstrates that Portwell has established and documented managed processes for incorporating cybersecurity into product development. These processes provide a structured framework for addressing security requirements throughout the development and product lifecycle.

Integrating Cybersecurity into the Product Development Lifecycle

Under IEC 62443-4-1, cybersecurity is addressed systematically across the product development lifecycle rather than being treated solely as a product-level verification activity.

Portwell’s certified development framework incorporates key practices including security requirements management, secure architecture and design, secure implementation, security verification and validation, vulnerability handling, and security update management. These practices enable cybersecurity requirements and potential risks to be considered from the early stages of product development and managed through subsequent development and lifecycle activities.

With more than 30 years of experience in industrial computing, Portwell provides industrial embedded systems, industrial computer motherboards and comprehensive Design & Manufacturing Services (DMS). Incorporating IEC 62443-4-1 practices into its development framework further supports Portwell’s ability to work with customers whose projects increasingly require defined cybersecurity processes, documentation, verification and lifecycle support.

Supporting Portwell’s Ongoing CRA Preparation

IEC 62443-4-1 certification also provides an important foundation for Portwell’s ongoing alignment with applicable requirements of the European Union Cyber Resilience Act (CRA).

The CRA establishes cybersecurity requirements for products with digital elements placed on the EU market and introduces responsibilities for manufacturers across the product lifecycle, including cybersecurity risk assessment, vulnerability handling, security updates, technical documentation and regulatory reporting. Portwell recognizes that CRA readiness is an ongoing process rather than a one-time certification. The secure development, vulnerability management and security update processes established under IEC 62443-4-1 provide a solid foundation for Portwell’s ongoing alignment with applicable CRA requirements.

The CRA’s Article 14 reporting obligations for actively exploited vulnerabilities and severe security incidents will become applicable on September 11, 2026, ahead of the CRA’s full application on December 11, 2027. To prepare for these requirements, Portwell has engaged an external consulting firm to support its CRA implementation program. Preparations related to Article 14 vulnerability and severe incident reporting requirements are nearing completion, while Portwell will continue working with the consulting firm on the broader CRA requirements scheduled to become fully applicable in December 2027. These activities include continued development of product cybersecurity management processes, vulnerability handling and reporting mechanisms, security documentation, and other applicable lifecycle practices required under the CRA.

Subscribe

Press Releases Subscribe Form