인피니언 8월20일부터
This page was machine-translated and may differ from the original. View original

Moxa Obtains IEC 62,443-4-1 ML3 Dual Certification

Google 우선 소스Published2026.07.15 13:07


Security development lifecycle capabilities officially verified through bilateral certification by IECEE and ISASecure
Moxa, an industrial communication and networking solutions company, has obtained dual IEC 62,443-4-1 Maturity Level 3 (ML3) certification in the field of OT cybersecurity.
It has been simultaneously recognized by two organizations, the IECEE CB Scheme and ISCI/ISASecure, as a result of verifying the level of implementation of the entire Security Development Lifecycle (SDL) through an independent audit.

Moxa announced on the 15th that it has obtained IEC 62,443-4-1 ML3 dual certification.

ML3 is an advanced maturity level within the standard, meaning that the organization has internalized SDL enterprise-wide and is continuously reviewing and strengthening it.

The scope of certification includes SDL management framework, threat modeling and risk traceability, Product Security Incident Response Team (PSIRT) operations, vulnerability and patch management, and supply chain security integration.

ISASecure SDLA (Security Development Lifecycle Due Diligence) certification confirms through an independent audit that SDL is not limited to regulatory levels but is being implemented in the field.

Moxa explained that it is capable of managing vulnerabilities and providing security patches throughout a product lifecycle spanning decades.

Andy Tsai, Senior Director for Taiwan at UL Solutions, “IEC 62,443-4-1 ML3 is considered the fundamental basis of critical infrastructure security and is an achievement that requires a company-wide and deep commitment to cybersecurity,” he said. “Moxa’s rigorous secure-by-design approach and security management capabilities throughout the product lifecycle have been proven.”

John Chang, Director of the R&D Management and Product Security Center at Moxa, stated, “This certification is an achievement that confirms our evidence-based security practices and expertise,” adding that it “demonstrates our strategic commitment to designing the future of OT cybersecurity from the ground up.”

Moxa explained that this certification provides a practical foundation for responding to strengthening regulatory requirements, such as the European Union Cyber Resilience Act (CRA).

New regulations, including CRA, require proof throughout the entire product lifecycle, such as patch management, vulnerability response, and post-market security maintenance.

Moxa has been investing in the IEC 62,443 framework since 2016, and stated that through this certification, customers can streamline procurement procedures, shorten security due diligence cycles, and secure trust in long-term (10-20 year) asset deployment environments.

Detailed information regarding CRA can be found on the official Moxa CRA portal.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
배종인 기자
배종인 기자