惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
WordPress大学
WordPress大学
博客园 - 【当耐特】
The Cloudflare Blog
B
Blog
Last Week in AI
Last Week in AI
小众软件
小众软件
量子位
S
SegmentFault 最新的问题
V
Visual Studio Blog
博客园 - 叶小钗
美团技术团队
阮一峰的网络日志
阮一峰的网络日志
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
宝玉的分享
宝玉的分享
A
About on SuperTechFans
雷峰网
雷峰网
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
腾讯CDC
MongoDB | Blog
MongoDB | Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Martin Fowler
Martin Fowler

Fortinet All Blogs

FortiEndpoint Earns Certified Leader Status in the 2026 AV-Comparatives EPR Test | Fortinet Blog From Intelligence to Disruption: Strengthening the Fight Against Cybercrime in Latin America | Fortinet Blog FortiSOAR 8.0 Unites Agentic AI and Automation to Revolutionize Security Operations | Fortinet Blog The Cybersecurity Hiring Challenge | Fortinet Blog Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | FortiGuard Labs FortiManagement Cloud: Centralized Network and Security Control for Distributed SMB Operations | Fortinet Blog Fortinet Joins Project Watershed 250 to Strengthen National Water Cybersecurity Infrastructure | Fortinet Blog Fortinet and FIRST: Strengthening Cyber Resilience through Global Collaboration | Fortinet Blog Someone Else Is Using Your AI | FortiGuard Labs The Industrialization of Cybercrime in Africa | Fortinet Blog Join the 2026 SASE Summit: Building Autonomous Trust for the AI Era | Fortinet Blog Defending Critical Infrastructure in the Age of Internet-Connected Facilities | Fortinet Blog Black Hat and DEF CON 2026: When Autonomous AI Became Operational | Fortinet Blog Public-Private Partnership Must Move at the Speed of Cyber Risk | Fortinet Blog Secure by Design: Fortinet’s Continued Commitment and the Work Ahead | CISO Collective From Awareness to Action: Building A Behavior-Based Security Program | Fortinet Blog Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs Cybersecurity Skills Gap: More Than Just a Workforce Challenge | Fortinet Blog QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | FortiGuard Labs From Threat Intelligence to Action: The First Cybercrime Bounty Is Now Live | Fortinet Blog While External Threats Are Driving Security Awareness, Internal Risks Are Growing | Fortinet Blog Canada Signs the UN Cybercrime Convention: Turning Global Agreement into Coordinated Action | Fortinet Blog Expert Density as Strategy: How 2F-IT Built One of Germany’s Deepest Fortinet Practices | Fortinet Blog From Awareness to Action: Helping Organizations Prepare for Post-Quantum Cryptography | Fortinet Blog A Conversation with Crime Stoppers International About Our Shared Cybercrime Bounty Initiative | Fortinet Blog Inside a TrickBot Variant Using DNS Tunneling for C2 | FortiGuard Labs Meeting the European Central Bank’s AI Cybersecurity Mandate | Fortinet Blog The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | FortiGuard Labs Helping Law Enforcement Keep Pace with the Future of Cybercrime | Fortinet Blog FortiEndpoint Expands Security for the AI Era | Fortinet Blog
Fortinet Achieves IEC 62443-4-2 Security Level 4 Certific...
Aasef Iqbal · 2026-08-05 · via Fortinet All Blogs

Industrial organizations require cybersecurity solutions that not only defend against today’s sophisticated cyberthreats but also meet the industry’s most rigorous security standards. Today, Fortinet is proud to announce that FortiOS v7.6.x has achieved IEC 62443-4-2 Security Level 4 (SL4) certification, reinforcing our commitment to delivering secure-by-design cybersecurity solutions for operational technology (OT), critical infrastructure (CI), and industrial automation and control systems (IACS).

This milestone builds upon Fortinet’s Secure Product Development Lifecycle, previously validated through IEC 62443-4-1 Maturity Level 2 (ML2) certification, demonstrating that both our development processes and the resulting product meet internationally recognized cybersecurity standards and satisfy the highest security requirements defined for secure IACS components.

Independently Validated to the Highest IEC 62443 Security Level

The IEC 62443 series is the leading international standard for securing industrial automation and control systems. While IEC 62443-4-1 evaluates the security practices used during product development, IEC 62443-4-2 evaluates the technical cybersecurity capabilities implemented in the product.

Achieving SL4 represents the highest assurance level defined in IEC 62443-4-2. It demonstrates that FortiOS v7.6.x incorporates advanced security capabilities to mitigate highly sophisticated cyberthreats and provides independently validated protection for OT and CI environments.

The IEC 62443 Security Levels are defined as follows:

For organizations operating in critical infrastructure, manufacturing facilities, utilities, transportation systems, mining, oil and gas, and other industrial environments, this certification provides independent validation that FortiOS incorporates industry-leading security controls aligned with internationally recognized cybersecurity standards.

Comprehensive Assessment Across Every IEC 62443-4-2 Security Requirement

As part of the certification, FortiOS v7.6.x successfully satisfied the IEC 62443-4-2 requirements across all seven foundational requirement categories:

Foundational RequirementAssessment Results
Identification & Authentication ControlAll 22 requirements passed
Use Control20 requirements passed, 1 not applicable
System IntegrityAll 19 requirements passed
Data ConfidentialityAll 5 requirements passed
Restricted Data Flow3 requirements passed, 1 not applicable
Timely Response to EventsAll 3 requirements passed
Resource Availability10 requirements passed, 1 not applicable

In addition to component requirements, FortiOS met all applicable requirements for software application, embedded device, host device, and network device evaluated as part of the certification.

The full certificate is available at Fortinet Trust Resource Center.

Broad Product Coverage

Unlike certifications that apply to a single appliance, the certification applies across Fortinet’s NGFW platforms powered by FortiOS v7.6.x, including:

This enables organizations to deploy a consistent, independently validated security platform across enterprise IT and industrial OT sites, including substations, utilities, transportation, manufacturing, and remote industrial environments.

Security Designed for Operational Resilience

FortiOS has long provided the foundation for Fortinet’s Security Fabric and OT Security Platform. The certification validates numerous security capabilities that help OT organizations secure critical operations while maintaining availability and operational continuity.

The cybersecurity capabilities delivered by FortiOS include:

  • Strong identity and authentication controls
  • Granular role-based authorization and least-privilege access
  • Secure communications using industry-standard cryptography
  • System integrity verification and trusted software updates
  • Event logging, auditing, and security monitoring
  • Resource availability and resiliency protections
  • Network segmentation and restricted data flows
  • Secure management interfaces and administrative controls

These capabilities help OT organizations implement defense-in-depth architectures while maintaining operational availability and regulatory compliance. The following section provides a brief overview of these security capabilities.

Strong identification and authentication

FortiOS provides comprehensive identity management through strong administrator authentication, multi-factor authentication, certificate-based authentication, password policy enforcement, centralized identity integration, and role-based access control.

Granular authorization and least privilege

Organizations can implement least-privilege access through granular administrative profiles, trusted hosts, policy-based permissions, separation of duties, and secure management interfaces to minimize operational risk.

System integrity protection

FortiOS incorporates digitally signed firmware, cryptographic integrity verification, secure update mechanisms, trusted boot technologies, and tamper-resistant protections to help ensure software authenticity throughout the system lifecycle.

Secure communications

FortiOS protects communications using industry-standard cryptographic protocols, including IPsec VPN, TLS, certificate validation, encrypted administrative access, and secure communication among Security Fabric components.

Continuous event detection and monitoring

Advanced logging, security analytics, IPS, application control, malware protection, anomaly detection, OT protocol inspection, and Fortinet Security Fabric integration enable organizations to quickly detect and investigate cybersecurity events across IT and OT environments.

Resource availability and resilience

Industrial operations require continuous uptime. FortiOS supports high availability, hardware acceleration, session resiliency, denial-of-service protection, redundant operation, and resilient networking capabilities to help maintain critical operations during cyber incidents.

Built on a Secure Development Foundation

The achievement of IEC 62443-4-2 SL4 certification complements Fortinet’s previously announced IEC 62443-4-1 ML2 certification, demonstrating that security is embedded throughout the product development lifecycle and in the delivered product.

Together, these certifications demonstrate that:

  • Products are developed using independently validated secure development practices.
  • Product cybersecurity capabilities have been independently evaluated against IEC 62443-4-2.
  • Customers receive both a secure development process and a technically validated product.

This combination gives OT asset owners and operators greater confidence when deploying Fortinet solutions in mission-critical environments.

Together, these certifications reinforce Fortinet’s commitment to:

Benefits for OT Organizations

Organizations deploying FortiOS v7.6.x benefit from:

  • Independent validation against the industry’s highest component security level
  • Increased confidence in securing critical infrastructure and industrial operations
  • Simplified compliance with regulatory and procurement requirements referencing IEC 62443
  • Enhanced protection against advanced cyberthreats targeting OT environments
  • Reduced cybersecurity risk through defense-in-depth security capabilities
  • Stronger support for zero-trust architectures across converged IT and OT networks    

Continuing Our Commitment to OT Security

As cyberthreats targeting industrial environments continue to evolve, organizations require cybersecurity solutions that combine operational reliability with independently validated security.

The certification demonstrates Fortinet’s continued investment in delivering trusted cybersecurity solutions for the world’s most demanding and critical technology environments.

By combining secure development processes validated under IEC 62443-4-1 ML2 with product capabilities independently certified to IEC 62443-4-2 SL4, Fortinet continues to help organizations strengthen cyber resilience, protect critical operations, and advance secure digital transformation with confidence across operational technology and critical infrastructure sectors.

As industrial organizations accelerate digital transformation and IT/OT convergence, cybersecurity solutions must provide both operational reliability and independently validated security.

The certification underscores Fortinet’s ongoing commitment to helping customers protect critical infrastructure, reduce cyber risk, and meet evolving regulatory and industry requirements.

With independently certified security capabilities across the FortiGate, FortiGate Rugged, FortiWiFi, and FortiGate VM platforms, Fortinet continues to offer one of the industry’s most comprehensive cybersecurity portfolios for operational technology environments.