
Industrial Automation Compliance Software for IEC 62443 and EU CRA
A ransomware hit on a PLC is not an IT incident — it is a production shutdown and your EU CRA liability. 12% of OT devices carry actively exploitable vulnerabilities.
Industrial automation companies face a convergence of EU obligations. EU CRA classifies industrial control software as Products with Digital Elements. CRA reporting begins September 11, 2026. Full product conformity applies December 11, 2027 — including machine-readable SBOM, secure-by-design documentation and CE marking. Certain industrial control systems—including PLC, DCS, CNC, SCADA and safety-instrumented systems—are CRA Important Class II, requiring third-party conformity assessment.
IEC 62443 certification supports CRA conformity — but is not automatic equivalence. The EU Machinery Regulation applies from January 20, 2027 and requires protection against corruption that could affect machinery safety. A security patch that compromises a safety function fails both.
X-DLM™ connects Siemens Polarion and Black Duck so industrial automation manufacturers can govern open-source risk in OT software, produce IEC 62443-aligned SBOM and vulnerability evidence, and maintain the safety-security co-engineering audit trail — all from one governed system.
and
The OT/ICS vulnerability reality in 2026
OT environments were designed for reliability, not security. EU CRA now requires manufacturers to prove every component in their industrial products is governed — before it ships.
Of OT devices carry known exploitable vulnerabilities (KEVs). 7% are linked to active ransomware campaigns targeting industrial environments. Source: Claroty 2026.
ICS/OT vulnerabilities disclosed in 2025 alone — the highest volume since tracking began. Manufacturing and energy are the top two affected sectors. Source: Forescout / CISA ICS-CERT 2026.
Of OT security incidents are caused by transient devices — USB drives and contractor laptops. The threat enters through the supply chain and the service workflow.
Certain industrial control systems—including PLC, DCS, CNC, SCADA and safety-instrumented systems—are CRA Important Class II, requiring third-party conformity assessment, not self-declaration. IEC 62443 certification supports but does not automatically satisfy CRA.
Sources: Claroty 2026. Forescout / CISA ICS-CERT 2026. IIoT World 2026 OT Security Trends. EU CRA Important Products classification.
CRA reporting Sept 11, 2026 · CRA conformity Dec 11, 2027 · Machinery Regulation Jan 20, 2027 · IEC 62443 Certification Now Baseline
Three EU obligations. Three evidence requirements. One window to get them all right before the market asks for proof. Safety and security must be co-engineered — not bolted on separately.
EU CRA — Important Class II
Third-Party Conformity Assessment
Certain industrial control systems—including PLC, DCS, CNC, SCADA and safety-instrumented systems—are CRA Important Class II, requiring third-party conformity assessment by an accredited notified body. CRA reporting begins September 11, 2026. Full product conformity — SBOM, secure-by-design documentation and CE marking — applies December 11, 2027.
IEC 62443 — Secure Development Lifecycle
Certification Moving from Differentiator to Baseline
IEC 62443-4-1 ML2/ML3/ML4 certification provides the most credible path to CRA conformity for industrial products. Rockwell Automation, Mettler-Toledo, and Microchip Technology already hold certification. For procurement teams at major manufacturers, it is moving from a differentiator to a contract prerequisite.
EU Machinery Regulation — Jan 20, 2027
Protection Against Corruption Affecting Safety
The Machinery Regulation requires protection against corruption that could affect machinery safety. A security patch that compromises a safety function is a regulatory failure. Safety and security evidence must be produced from the same traceable workflow — not maintained in separate systems.
Brand authority buyers recognize
Backed by Siemens lifecycle governance and Black Duck AppSec intelligence.

Siemens Polarion ALM
Polarion provides the lifecycle system of record for requirements, tests, approvals, traceability, workflow automation, audit evidence, and regulated software delivery.

Black Duck Software Composition Analysis
Black Duck identifies open source and third-party components across source, binaries, containers, firmware, snippets, AI-generated code, and C/C++ environments without package managers.
Industrial products now need security proof, not security claims.
IEC 62443. EU CRA. Machinery Regulation. One evidence system.
Book a 15–30 minute discovery call. We show exactly how X-DLM™ connects Black Duck and Siemens Polarion to govern OT software risk, produce IEC 62443-aligned SBOM evidence, and maintain the safety-security co-engineering audit trail required for EU CRA notified body assessment.
The X-DLM™ industrial automation trust equation