Assessment 02
IEC 62443-4-1 Gap Assessment
A practice-by-practice gap assessment against all eight practices of IEC 62443-4-1, scored against the maturity levels used by certification bodies during audit.
- Length
- 15–25 minutes
- Questions
- 42 questions
What it covers
- SM — Security management
- SR — Specification of security requirements
- SD — Secure by design
- SI — Secure implementation
- SVV — Security verification and validation testing
- DM — Management of security-related issues
- SUM — Security update management
- SG — Security guidelines
Built for
Development leads, quality managers, certification project owners
What you get back
A maturity score per practice, the specific evidence artefacts you are missing, and a sequenced remediation plan toward audit readiness.
Complete the questionnaire
Answer as your product stands today rather than as you intend it to be. An accurate baseline produces a usable remediation plan.
No email address. No registration. No account.
You get your full results immediately. Nothing is gated, nothing is emailed to you, and nothing is asked of you in exchange. Every question is scored in your browser, so your answers are never sent to us or to anyone else.
IEC 62443-4-1 Gap Assessment
Forty questions across the eight practices of the standard, plus two questions to set your target. You will get a maturity level for each practice, the evidence you are missing, and a prioritised list of what to fix first.
Your answers stay in this browser and are scored here. We never see them.
Your answers are kept in this browser tab while you work, so a reload will not lose them. Closing the tab clears them.
The questions are written in plain English on purpose. Each one also shows the professional term behind it, so you can answer with confidence and still recognise the wording an auditor will use.
Other assessments
Assessment 01
CRA Readiness Assessment
A structured self-assessment against the essential cybersecurity requirements in Annex I of Regulation (EU) 2024/2847, plus the vulnerability handling and reporting obligations that apply from September 2026.
OpenAssessment 03
Product Classification Check
A short triage questionnaire that determines whether your product falls in scope of the CRA, and if so, whether it is a default, important class I, important class II, or critical product.
OpenAssessment 04
SBOM Readiness Assessment
A focused assessment of the software bill of materials your product ships with, reporting separately on what Annex I Part II(1) actually requires and how much operational use you get from the SBOM you have.
Open