IEC 62443 Compliance Statement
RELIANOID Load Balancer is a secure, enterprise-grade application delivery controller crafted for both on-premises and cloud deployments. While RELIANOID is not formally certified under IEC 62443, our organization and product align with the standard’s principles—especially in delivering robust cybersecurity controls across industrial automation and control systems (IACS) environments. This ensures information integrity, availability, and safety in critical sectors such as finance, healthcare, government, manufacturing, energy, utilities, military, and other regulated or industrial systems.
The latest RELIANOID Security Compliance Report further confirms that our security framework incorporates structured risk management, secure development practices, vulnerability management, access controls, network protection, incident response, third-party risk management, and continuous security testing.
Organizational & Network Security Alignment with IEC 62443
We adopt a risk-based, lifecycle-oriented approach consistent with IEC 62443, integrating guidance from ISO/IEC 27001 and IACS cybersecurity best practices. Key governance elements include:
- Comprehensive Risk Management: A dedicated cyber risk register—mapped to IEC 62443-2-1 requirements—is regularly reviewed, enabling risk identification, treatment, and mitigation.
- Policy Governance: Policies and procedures for incident response, patch management, access control, supplier risk, and lifecycle security are maintained per IEC 62443-2-4 and ISO/IEC 27001 Annex A.
- Secure Engineering Practices: Our secure software development lifecycle (SSDLC) reflects IEC 62443-4-1 “secure product development” principles, including least privilege, vulnerability tracking, and patch release.
- Current Security Risk Management: The 2026Q2 security assessment confirms that identified application security and vulnerability management findings are formally tracked through vulnerability management processes, remediation plans, and development sprint backlogs. Resolved risks are formally closed, while remaining findings are tracked through ongoing remediation activities.
- Policy Review: RELIANOID maintains annual reviews of key security policies, including Business Continuity and Disaster Recovery, Data Processing, Third-Party Risk Management, Incident Response & Reporting, and Service Level Management.
Operational Technology (OT) Use Cases
RELIANOID Load Balancer can be deployed in a wide range of industrial and critical infrastructure environments, including:
- Manufacturing
- Energy and utilities
- Military and defense systems
- Government-regulated environments
The security controls described in the latest report further support deployments requiring secure communications, access control, network protection, vulnerability management, resilience, and continuous security monitoring.
Zone & Conduit Architecture
RELIANOID supports zone-based architectures and communication conduits as defined in IEC 62443-3-2:
- Default setup includes a smart routing system to interconnect networks in one-armed, two-armed, or multi-armed architectures.
- Micro-segmentation, network zoning, and communication conduits can be configured to strengthen isolation and resilience.
- Detailed configuration guidelines are available in our Knowledge Base.
- Private Network Communication: The latest security report confirms that 100% of intra-service communications use private IPs, providing an additional network security control for internal service communication.
Development Lifecycle Controls (IEC 62443-4-1)
Our Secure Software Development Lifecycle (SSDLC) incorporates the following practices:
- User & Access Management: No default users; only root can create users and configure RBAC policies.
- Patch Management: Controlled via multi-step QA process—automated testing → preproduction → integration testing → signed packages → production release.
- Threat Modeling & Design: Internal design reviews and brainstorming ensure security, high availability, and usability from the earliest phase.
- Secure Testing: SAST via
perlcritic integrated in Gitea, DAST via penetration testing tools, quarterly security reporting and improvements. - Dependency Management: All libraries and software validated from official GPG-signed repositories.
- Secure Coding Guidelines: Compliance with OWASP ASVS and CERT recommendations.
- Environment Separation: Dedicated testing, preproduction, and production environments ensure strict separation.
The latest Security Compliance Report confirms that the RELIANOID product has SSDLC enforcement, with automated SAST/DAST scanning on every commit, weekly third-party library vulnerability scanning, and daily automated testing. Test coverage is continuously tracked for both Community and Enterprise editions.
For RELIANOID services, SSDLC enforcement is also in place. Automated SAST/DAST for services is identified as a planned improvement for the current security roadmap.
Product Security Features (IEC 62443-4-2)
RELIANOID Load Balancer includes product-level security aligned with IEC 62443-4-2:
- Authentication: RBAC, LDAP, Active Directory, SSO, and MFA supported.
- Encryption: TLS v1.2 and v1.3 support with strong ciphers, at-rest encryption, and customer-managed keys.
- Logging & Monitoring: Log retention (7 days), customizable log levels, and SIEM integration.
- Security Modules: IPDS module with WAF (OWASP CRS and custom rules), DDoS protection, DNS-BL (RBL), blacklists/whitelists, anomaly detection, and MFA portals (RADIUS, LDAP, AD, Captcha v2, TOTP).
- Hardening Measures: Secure defaults and least-privilege configurations enforced at deployment and in development workflows.
- Current Security Controls: The 2026Q2 report confirms that services support SSL/TLS, network DoS protection and network abuse IP protection are implemented, and Web Application Firewall (WAF) protection is in place.
- Access Protection: 100% of RELIANOID employee accounts are protected by multi-factor authentication.
- Security Testing: Product security is supported by automated SAST/DAST scanning on every commit, daily automated testing, and weekly third-party library vulnerability scanning.
Security Levels (SL) Alignment
RELIANOID Load Balancer supports IEC 62443 Security Levels (SL-1 through SL-4):
- Default: SL-2 (protection against unintentional misuse and basic attack attempts).
- Advanced: Configurations and policies can achieve SL-3 or SL-4 depending on industry requirements (protection against highly skilled or state-sponsored adversaries).
Third-Party IACS Integration
RELIANOID collaborates with OT/IACS vendors and integrators to ensure seamless, secure integration in industrial environments. All partnerships are governed under strict security policies and supplier risk management frameworks.
The latest security assessment confirms that RELIANOID maintains a structured Third-Party Risk Management process covering critical ICT suppliers, including assessment of security certifications, risks, SLA and resilience commitments, and contingency plans.
Third-party resilience measures include backup systems, redundant infrastructure, alternative providers, and contingency mechanisms designed to reduce the impact of supplier outages or service disruptions.
Vulnerability Management and Security Testing
The latest RELIANOID Security Compliance Report provides additional evidence of continuous vulnerability management and security testing relevant to secure industrial and critical infrastructure deployments.
- Product Vulnerability Monitoring: On 29 June 2026, RELIANOID reported 104 vulnerabilities fixed and 15 vulnerabilities to fix.
- Service and Product Testing: A total of 1,007 tests were launched during the latest service and product security testing cycle.
- Findings: Testing identified 16 high-risk, 12 medium-risk, 43 low-risk, and 89 informational findings.
- False Positives: 15 high-risk findings and one medium-risk finding were identified as false positives.
- Remediation: Findings are tracked through the vulnerability management and remediation process, with remediation review scheduled for 1 October 2026.
Data Protection and Resilience
In addition to network and product security controls, the 2026Q2 report confirms additional resilience measures relevant to critical infrastructure environments:
- Encryption in Transit: Data is protected through encryption in transit.
- Backup & Restoration: Backup and restoration processes are tested quarterly.
- Data Classification: Data classification and retention policies are maintained according to the Data Processing Agreement.
- Service Availability: Last 30-days services uptime was reported at 99.934%.
Monitoring, Detection & Incident Response
RELIANOID maintains alert accuracy and escalation procedures, as well as incident review and near-miss processes.
The current security roadmap identifies several areas for continued enhancement:
- SIEM: Centralized log correlation through a Security Information and Event Management platform is planned.
- DLP: Data Loss Prevention tooling and effectiveness are planned as a future improvement.
- Incident Response Testing: Formal review and testing of the Incident Response Plan is planned.
- Lessons Learned: Formal documentation and implementation of lessons learned from incidents is planned as a further improvement.
- Security Exercises: Tabletop or blue team exercises are planned.
Security Awareness & Training
RELIANOID maintains security awareness and training activities to support organizational security culture and secure operational practices.
The current security report confirms that security awareness training is delivered and training completion is tracked. Future improvements include phishing simulation analysis and incorporation of new threat intelligence into security awareness content.
Continuous Enhancement & Future Objectives
In 2025, we plan to advance compliance by:
- Implementing explicit zone and conduit isolation to align with IEC 62443-3-2 in industrial contexts.
- Formalizing alignment with IEC 62443-3-3 security levels (SL-C) per deployment risk profiles.
- Strengthening supply chain controls and integration governance per IEC 62443-2-4.
- Extending secure development lifecycle elements to demonstrate IEC 62443-4-2 technical compliance.
Based on the latest 2026Q2 security assessment, RELIANOID’s ongoing security improvement roadmap additionally includes:
- Centralized SIEM log correlation and monitoring.
- Data Loss Prevention (DLP) tooling and effectiveness.
- Formal review and testing of the Incident Response Plan.
- Tabletop or blue team security exercises.
- Systematic documentation and implementation of lessons learned.
- Phishing simulation analysis and enhanced security awareness content incorporating new threat intelligence.
- Continued remediation of identified security vulnerabilities.
Commitment to Secure Industrial Operations
By aligning RELIANOID Load Balancer with the foundational principles of IEC 62443, we ensure resilient and secure infrastructure for industrial and regulated environments. Our ongoing enhancements reinforce our mission to provide compliance-ready, safe, and reliable networking for all clients operating in critical systems.
The latest security assessment demonstrates an active security lifecycle encompassing risk management, vulnerability remediation, secure development, automated testing, access controls, network protection, backup and restoration, third-party resilience, and incident response.
Document Reviews
| Date | Comment |
| 10th July 2025 | Document creation |
| 4th September 2025 | Expanded with OT use cases, zone/conduit architecture, SSDLC (Part 4-1), product controls (Part 4-2), SL levels, and IACS integration details |
| 30th June 2026 | Updated with security risk management, vulnerability management, network and application security controls, access controls, resilience, third-party risk management, incident response, security awareness, and continuous improvement measures from the RELIANOID Security Compliance Report 2026Q2 |
Contact and Assurance
We welcome requests for detailed security documentation, risk mapping matrices, or compliance disclosures.
Contact our Compliance & Security Team
Download Latest Security Report