














Industrial organizations require cybersecurity solutions that not only defend against today’s sophisticated cyberthreats but also meet the industry’s most rigorous security standards. Today, Fortinet is proud to announce that FortiOS v7.6.x has achieved IEC 62443-4-2 Security Level 4 (SL4) certification, reinforcing our commitment to delivering secure-by-design cybersecurity solutions for operational technology (OT), critical infrastructure (CI), and industrial automation and control systems (IACS).
This milestone builds upon Fortinet’s Secure Product Development Lifecycle, previously validated through IEC 62443-4-1 Maturity Level 2 (ML2) certification, demonstrating that both our development processes and the resulting product meet internationally recognized cybersecurity standards and satisfy the highest security requirements defined for secure IACS components.
The IEC 62443 series is the leading international standard for securing industrial automation and control systems. While IEC 62443-4-1 evaluates the security practices used during product development, IEC 62443-4-2 evaluates the technical cybersecurity capabilities implemented in the product.
Achieving SL4 represents the highest assurance level defined in IEC 62443-4-2. It demonstrates that FortiOS v7.6.x incorporates advanced security capabilities to mitigate highly sophisticated cyberthreats and provides independently validated protection for OT and CI environments.
The IEC 62443 Security Levels are defined as follows:
For organizations operating in critical infrastructure, manufacturing facilities, utilities, transportation systems, mining, oil and gas, and other industrial environments, this certification provides independent validation that FortiOS incorporates industry-leading security controls aligned with internationally recognized cybersecurity standards.
As part of the certification, FortiOS v7.6.x successfully satisfied the IEC 62443-4-2 requirements across all seven foundational requirement categories:
| Foundational Requirement | Assessment Results |
|---|---|
| Identification & Authentication Control | All 22 requirements passed |
| Use Control | 20 requirements passed, 1 not applicable |
| System Integrity | All 19 requirements passed |
| Data Confidentiality | All 5 requirements passed |
| Restricted Data Flow | 3 requirements passed, 1 not applicable |
| Timely Response to Events | All 3 requirements passed |
| Resource Availability | 10 requirements passed, 1 not applicable |
In addition to component requirements, FortiOS met all applicable requirements for software application, embedded device, host device, and network device evaluated as part of the certification.
The full certificate is available at Fortinet Trust Resource Center.
Unlike certifications that apply to a single appliance, the certification applies across Fortinet’s NGFW platforms powered by FortiOS v7.6.x, including:
This enables organizations to deploy a consistent, independently validated security platform across enterprise IT and industrial OT sites, including substations, utilities, transportation, manufacturing, and remote industrial environments.
FortiOS has long provided the foundation for Fortinet’s Security Fabric and OT Security Platform. The certification validates numerous security capabilities that help OT organizations secure critical operations while maintaining availability and operational continuity.
The cybersecurity capabilities delivered by FortiOS include:
These capabilities help OT organizations implement defense-in-depth architectures while maintaining operational availability and regulatory compliance. The following section provides a brief overview of these security capabilities.
FortiOS provides comprehensive identity management through strong administrator authentication, multi-factor authentication, certificate-based authentication, password policy enforcement, centralized identity integration, and role-based access control.
Organizations can implement least-privilege access through granular administrative profiles, trusted hosts, policy-based permissions, separation of duties, and secure management interfaces to minimize operational risk.
FortiOS incorporates digitally signed firmware, cryptographic integrity verification, secure update mechanisms, trusted boot technologies, and tamper-resistant protections to help ensure software authenticity throughout the system lifecycle.
FortiOS protects communications using industry-standard cryptographic protocols, including IPsec VPN, TLS, certificate validation, encrypted administrative access, and secure communication among Security Fabric components.
Advanced logging, security analytics, IPS, application control, malware protection, anomaly detection, OT protocol inspection, and Fortinet Security Fabric integration enable organizations to quickly detect and investigate cybersecurity events across IT and OT environments.
Industrial operations require continuous uptime. FortiOS supports high availability, hardware acceleration, session resiliency, denial-of-service protection, redundant operation, and resilient networking capabilities to help maintain critical operations during cyber incidents.
The achievement of IEC 62443-4-2 SL4 certification complements Fortinet’s previously announced IEC 62443-4-1 ML2 certification, demonstrating that security is embedded throughout the product development lifecycle and in the delivered product.
Together, these certifications demonstrate that:
This combination gives OT asset owners and operators greater confidence when deploying Fortinet solutions in mission-critical environments.
Together, these certifications reinforce Fortinet’s commitment to:
Organizations deploying FortiOS v7.6.x benefit from:
As cyberthreats targeting industrial environments continue to evolve, organizations require cybersecurity solutions that combine operational reliability with independently validated security.
The certification demonstrates Fortinet’s continued investment in delivering trusted cybersecurity solutions for the world’s most demanding and critical technology environments.
By combining secure development processes validated under IEC 62443-4-1 ML2 with product capabilities independently certified to IEC 62443-4-2 SL4, Fortinet continues to help organizations strengthen cyber resilience, protect critical operations, and advance secure digital transformation with confidence across operational technology and critical infrastructure sectors.
As industrial organizations accelerate digital transformation and IT/OT convergence, cybersecurity solutions must provide both operational reliability and independently validated security.
The certification underscores Fortinet’s ongoing commitment to helping customers protect critical infrastructure, reduce cyber risk, and meet evolving regulatory and industry requirements.
With independently certified security capabilities across the FortiGate, FortiGate Rugged, FortiWiFi, and FortiGate VM platforms, Fortinet continues to offer one of the industry’s most comprehensive cybersecurity portfolios for operational technology environments.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。