When the RTU Itself Is the Weak Link: Why IEC 62443 Certification Matters

Critical infrastructure: power, water and oil & gas facilities

Critical infrastructure has become a cyber target. Power grids, water networks and rail systems now face the same threats as IT, but with far higher stakes. A single compromised remote terminal unit (RTU) can open a path into a substation, a pumping station, or an entire SCADA network.

The problem: security bolted on isn’t security built in

For years, operators treated OT security as something you add around the device: a firewall here, a VPN there. But that approach has a blind spot. If the RTU itself is insecure, no amount of perimeter defence fixes it.

Two things are now changing the game for asset owners and EPCs:

  • Regulation is tightening. Frameworks like NIS2 and IEC 62443 are moving from “nice to have” to mandatory tender requirements.
  • Auditors ask harder questions. It’s no longer enough to say a device is “secure.” You have to prove it, with independent certification.

And here is the catch: most legacy RTUs were designed for reliability, not cyber resilience. They simply can’t answer that question.

What IEC 62443 actually certifies

IEC 62443 is the international standard for industrial cyber security. Two parts matter most for an RTU:

  • IEC 62443-4-1 (the process). It certifies that the product is developed through a secure lifecycle: threat modelling, secure coding and vulnerability management built into every stage.
  • IEC 62443-4-2 (the product). It certifies that the device itself implements the required technical security capabilities.

Together they cover both halves of the equation: how the product is built, and what the product does.

Brodersen RTU32M with redundant CPU and power supply
The Brodersen RTU32M: secure by design, certified by UL.

The solution: an RTU32M certified on both counts

Brodersen’s RTU32M is UL-certified to both IEC 62443-4-1 and IEC 62443-4-2. That means independently verified, not self-declared.

✓ IEC 62443-4-1, secure development. Brodersen was among the first to earn UL certification for its secure development process. Security is designed in from the first line of code.

✓ IEC 62443-4-2, secure product. The RTU32M meets the standard’s technical security requirements at the device level.

For you, that means an RTU that is secure by design, audit-ready and tender-ready, with the certificates to back it up.

Why it matters for your project

Whether you run power transmission, water utilities, renewables or rail, IEC 62443 certification does three things:

  1. Clears audits and tenders where cyber security is now a hard requirement.
  2. Reduces real risk by closing the gap at the device level, where bolt-on security can’t reach.
  3. Future-proofs your investment as regulations like NIS2 continue to tighten.

Cyber security is no longer a feature you add later. With the RTU32M, it is built in and certified.

View our UL certificates Talk to our engineering team

Conclusion - enjoy having a 'future proof' RTU...
Your RTU requirements will evolve over time, so when you need more I/O, comm ports, protocols or RTU functionality - know it can be easily implemented in a Brodersen RTU.
Slide Heading
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
Click Here

Newsletter