Knoxville, TN — Softing Inc., today announced it has achieved IEC 62443-4-1 certification for its Secure Development Lifecycle (SDL), earning Certificate No. FI-68623 following a rigorous independent assessment by an accredited third-party certification body. The certification confirms that Softing’s product development process meets IEC 62443-4-1:2018, the internationally recognized standard for cybersecurity in industrial automation and control system (IACS) product development.
This achievement reflects years of disciplined investment in cybersecurity engineering. Softing’s SDL now operates under a certified framework that spans the full product lifecycle, from initial threat modeling and security requirements through secure design, implementation, verification, vulnerability management, and post-release security response. Every phase has been independently assessed against documented standard requirements. That is what certification means in practice.
"The industrial controls industry has been shifting toward more secure installations in response to growing global threats. We recognized years ago that we needed to prove our products are designed with cybersecurity in mind from the very first concept through every stage of development. We also know that security doesn't stop at the point of purchase. It requires ongoing vulnerability monitoring, threat mitigation, and continuous testing. This certification is the result of more than two years of work to demonstrate that we operate a certifiable SDLC and to give our customers independent confirmation that our products will serve them well in their ongoing cybersecurity defenses."
— Steven Bunch, VP of Engineering at Softing Inc.
A Certification Industrial Customers Can Rely On
Softing’s customers operate in some of the most demanding cybersecurity environments in industry: critical infrastructure, regulated manufacturing, energy, and defense-adjacent OT networks. They need suppliers who can demonstrate security rigor, not just describe it. IEC 62443-4-1 certification gives them exactly that. Certificate No. FI-68623, issued March 26, 2026,is independently verified proof that Softing’s development practices meet the leading international standard for IACS product security.
The certification covers eight practice areas required by the standard: security management, specification of security requirements, secure design, secure implementation, security verification and validation testing, management of security-related issues, security update management, and security guidelines. Each area required documented evidence reviewed by an independent assessor.
For system integrators building defense-in-depth architectures, specifying components from a certified supplier strengthens the entire system's security posture. When a vulnerability is discovered post-deployment, Softing has a practiced, audited process for response and disclosure. Customers are not waiting for an improvised reaction. They have a partner with verified protocols in place.
Scope clarification: This certification applies to Softing’s SDL process (v1.0), not to individual products. Products developed under this certified SDL benefit from an independently audited cybersecurity-by-design process. Certificate No. FI-68623 is available upon request.
IEC 62443-4-1 and the EU Cyber Resilience Act: Why Timing Matters
The EU Cyber Resilience Act represents a major regulatory shift for industrial product manufacturers, requiring demonstrable cybersecurity-by-design and formally documented processes for vulnerability management and security updates across the entire product lifecycle. Non-compliance carries substantial penalties.
Certification to IEC 62443-4-1 directly supports Cyber Resilience Act readiness by establishing a secure development lifecycle aligned with the Act’s essential cybersecurity requirements for products with digital elements. For Softing customers pursuing compliance, products developed under this certified lifecycle provide a credible, independently validated foundation for technical documentation and conformity assessment.
Beyond the Cyber Resilience Act, operational technology cybersecurity requirements continue to expand globally, including critical infrastructure regulations in the United States, the Network and Information Security Directive in the European Union, and increasing scrutiny from insurance underwriters. Suppliers able to demonstrate certified, audited security processes are gaining a measurable advantage in procurement. Softing’s certification positions the company to meet these requirements across regulated markets.
Certificate Details
IEC 62443-4-1 is part of the IEC 62443 series, a global framework for securing industrial automation and control systems. The series covers asset owners, system integrators, and product suppliers. Part 4-1 specifically addresses product suppliers, defining what a mature, repeatable, and independently verifiable Secure Development Lifecycle looks like.
Standard: IEC 62443-4-1:2018
Scope: Softing, Inc. Secure Development Lifecycle (SDL) Process, v1.0
Certificate Number: FI-68623
Certificate Date: March 26, 2026
About Softing Inc.
Softing Inc. is a leading provider of industrial communication and connectivity solutions, delivering innovative technologies that enable seamless data exchange across industrial networks. As part of the global Softing Group, the company supports customers in industrial automation, IT networks, and OEM/ODM markets with high-quality products and services designed to ensure reliability, efficiency, and long-term performance.
Media Contact:
Mahrissa Arrington Marketing/Communications Manager
Office Phone: +1 865.200.4123
Softing Inc. 2332 News Sentinel Drive, Suite 120, Knoxville, TN 37921 USA