Security verification completed ahead of CRA implementation
Congatec has obtained IEC 62443-4-1:2018 certification for its embedded building blocks and technology stack development and support processes, taking steps to secure supply chain reliability capable of responding to strengthening cybersecurity regulations. This certification is significant in that it validates the company's security and compliance capabilities during the embedded product development phase ahead of the full implementation of the EU Cyber Resilience Regulation (CRA).
Congatec announced on the 10th that its entire development and support for embedded building blocks and technology stacks has obtained IEC 62443-4-1:2018 certification. The certification was conducted by the German certification body TÜV NORD.
IEC 62443-4-1 is an international standard that specifies the systematic operation of defining security requirements, designing, implementing, verifying, responding to vulnerabilities, and managing patches during the development process of industrial control systems and embedded products. It is also linked to supply chain reliability in that it verifies the security management system throughout the entire development lifecycle rather than the functionality of a single product.
Through this certification, Congatec has verified the security of the development and support processes applied to the Computer-on-Module (COM), Application-Ready Building Blocks, and aReady.COM technology stacks. The technology stacks include licensed operating systems such as Ubuntu Pro and CtrlX OS, and software building blocks such as conga-connect and conga-zones.
This certification is expected to serve as a foundation for reducing the development burden on client companies in industries facing stricter regulations, such as automation and robotics, healthcare, energy, and transportation. Based on the certified process, clients can more clearly present security requirements, vulnerability management, and systems for patching and obsolescence response.
In particular, the EU CRA, which is set to be fully implemented in December 2027, requires products containing digital elements to include security design, vulnerability management, and the provision of updates. Accordingly, OEMs intending to supply electronic devices and embedded systems to the European market must secure security grounds not only for product functions but also for the entire development and supply chain.
Konrad Garhamer, COO and CTO of Congatec, stated, “This certification validates that we have consistently integrated cybersecurity throughout our entire development and support process,” adding, “We will support customer application integration, security verification, and the establishment of a foundation for CRA response.”
Dominic Lessing, CEO of Congatec, said, “Our technology stack, including licensed operating systems, hypervisors, and IoT connectors, helps customers build their own compliance foundations more efficiently.”