
The certification confirms that Mikron Switzerland AG, Boudry and Mikron Corporation Denver (USA) have established structured and auditable processes aligned with IEC 62443-4-1, covering cybersecurity management, security requirements, secure design, secure implementation, verification and validation, defect management, security update management and vulnerability handling.
This success story presents the certification as a practical reference for industrial organizations considering a similar path. It explains why IEC 62443-4-1 matters, how the certification process supports trustworthy secure development practices, and how it can contribute to broader cybersecurity readiness.
Strengthening Cybersecurity in Industrial Automation
Cybersecurity has become an essential component of modern industrial automation. Achieving IEC 62443-4-1 certification demonstrates our commitment to developing secure solutions that our customers can trust throughout their operational lifecycle. It validates the work of our teams to integrate cybersecurity into our development processes while continuing to deliver innovative, reliable and scalable automation solutions.
[Jean-Charles Authier, Head of Technology, Mikron Automation]
As industrial systems become more connected, cybersecurity has become a strategic requirement for machine builders, automation providers and manufacturers. Customers increasingly expect suppliers to demonstrate that cybersecurity is managed across the full lifecycle of the products and solutions they develop.
For Mikron Automation, IEC 62443-4-1 certification was seen an independent recognition of secure development lifecycle capability. It also reinforces the companyโs position as a trusted partner for advanced assembly and test systems used in demanding industrial sectors such as pharma and medtech, automotive, consumer goods, and electrical and industrial manufacturing.
The certification project was completed through close collaboration between Mikron Automation and CertX. The assessment combined technical cybersecurity expertise, process evaluation and certification discipline to verify that secure development lifecycle practices are implemented in a structured and repeatable manner.
What is IEC 62443-4-1?
The IEC 62443 series is organized into four main parts (numbered 1 through 4) and spans over a dozen specific standards, technical reports, and technical specifications.
The fourth part, and especially IEC 62443-4-1, defines secure product development lifecycle requirements for industrial automation and control system products. It addresses the organizational and process capabilities needed to develop and maintain products securely across their lifecycle.
- Security requirements management
- Secure design and implementation practices
- Verification and validation of security requirements
- Defect management and security update management
- Vulnerability handling and lifecycle maintenance
Benefits of IEC 62443-4-1 Certification
- Supports customer trust and supplier qualification activities
- Improves readiness for cybersecurity-related regulatory expectations, including CRA-related lifecycle requirements
- Supports a more consistent approach to vulnerability handling, security updates and lifecycle cybersecurity management
- Demonstrates that secure development processes are implemented and auditable
- Creates a scalable foundation for future IEC 62443-4-2 product or component certification
The certification gives our development teams a solid framework to strengthen security throughout the product lifecycle, while increasing cybersecurity awareness and embedding security thinking into everyday development decisions
[Julien Epiney, Software Development Manager, Mikron Automation]
The certification journey

The IEC 62443-4-1 certification process follows a structured approach designed to evaluate both the documented secure development lifecycle and its practical implementation. The process begins with an independent assessment of the organization’s cybersecurity policies, procedures, and supporting evidence to determine readiness and identify potential gaps.
Following this initial review, CertX conducts an implementation audit to verify that cybersecurity activities are consistently applied across the product development lifecycle. Interviews with key stakeholders and sampling of evidence provide assurance that secure development practices are embedded in day-to-day operations. Any identified nonconformities are addressed before the certification decision is taken.
Once certification is granted, periodic surveillance activities help organizations demonstrate continued conformity and maintain confidence in their secure development processes throughout the certification cycle.
A First Step Toward CRA Readiness and Further IEC 62443 Certification
The relevance of IEC 62443-4-1 is particularly evident as regulatory requirements for product cybersecurity continue to develop. The European Cyber Resilience Act introduces mandatory cybersecurity requirements for products with digital elements, including secure design, secure development, vulnerability handling, security updates and lifecycle maintenance. While IEC 62443-4-1:2018 certification is not a complete CRA conformity assessment on its own, it provides a practical and internationally recognized foundation for demonstrating that cybersecurity is managed systematically during product development.
For industrial manufacturers, IEC 62443-4-1 can be a logical first step in a broader cybersecurity certification roadmap. Once secure development lifecycle processes are established, organizations can progress toward component-level certification according to IEC 62443-4-2 and system-level security assessment according to IEC 62443-3-3. This creates a structured path from secure processes, to secure components, to secure industrial systems as detailed in the table below
Industrial organizations are facing increasing cybersecurity and regulatory expectations. Mikron Automationโs achievement shows how manufacturers can proactively address these challenges through internationally recognized standards and robust secure development practices. IEC 62443-4-1 provides a strong foundation for secure industrial innovation and for future cybersecurity assurance activities across the product and system lifecycle.
[Loan Bรฉtend, Head of Cybersecurity, CertX]
| Certification step | Focus | Value for customers |
|---|---|---|
| IEC 62443-4-1 | Secure product development lifecycle processes | Confidence that cybersecurity is integrated into development and maintenance activities |
| IEC 62443-4-2 | Technical security capabilities of IACS components | Evidence that products or components include defined security capabilities |
| IEC 62443-3-3 | System-level security requirements and security levels | Assessment of complete industrial automation and control systems against security requirements |
About Mikron Automation
Mikron Automation, a division of the Mikron Group. delivers advanced assembly solutions for the pharmaceutical and medtech industries, as well as the automotive, electrical, industrial, and consumer goods sectors.
The delivered assembly solutions incorporate complex manufacturing processes, control functions, software applications, industrial communication interfaces, and the associated engineering artefacts and services required to support a secure development lifecycle and ensure efficient operation throughout the system’s lifetime.
With more than 1,000 employees across sites in Switzerland, Germany, Lithuania, the USA, China, and Singapore, Mikron Automation leverages a global network of engineering and manufacturing expertise to support customers from initial concept through production ramp-up and long-term operational excellence.
About CertX
CertX, part of SGS group, is a Swiss certification body supporting organizations in cybersecurity, functional safety and digital trust.
We provide manufacturers, technology providers and industrial organizations with independent cybersecurity assessment and certification services. Combining technical expertise in product cybersecurity with certification discipline and international market understanding.
Our experts support customers across standards and regulatory frameworks including IEC 62443, ISO/SAE 21434, the Cyber Resilience Act, RED Delegated Act, Machinery Regulation and related product cybersecurity certification schemes.
Get in touch: cybersecurity@certx.com or Contact form