Signature Sponsor
Sandvik Achieves IEC 62443-4-1 Maturity Level 3 Cybersecurity Certification

 

 

September 16, 2026 - Sandvik has achieved IEC 62443-4-1 Maturity Level 3 certification for its Secure Development Lifecycle, marking another step in the company’s efforts to strengthen cybersecurity across its intelligent and connected mining equipment.

The certification covers Sandvik Mining’s Secure Development Lifecycle as implemented through the Sandvik Intelligent Control Architecture (SICA), the common control platform underpinning Sandvik’s i-series intelligent mining equipment.

The achievement advances Sandvik from the IEC 62443-4-1 Maturity Level 2 status it attained in 2025. At Level 3, cybersecurity practices such as threat modeling, secure coding, security testing and vulnerability management are systematically incorporated into day-to-day product development processes.

An independent assessment used evidence from the SICA project to verify that Sandvik’s secure development practices are being applied in real-world product development rather than existing solely as documented procedures.

SICA provides a common control architecture across Sandvik’s i-series intelligent mining equipment, making the certification particularly relevant as mining operations increasingly adopt automation, autonomous equipment and interconnected production systems.

Cybersecurity has become an increasingly important consideration for mines as operational technology, or OT, becomes more closely connected with digital applications and networks. For production-critical mining systems, a cyber incident can potentially affect not only data but equipment availability and mine production.

The latest certification complements Sandvik Mining’s ISO/IEC 27001 certification, achieved in May 2026, covering the information security management system used for its global application delivery environment.

Together, the IEC 62443 and ISO/IEC 27001 certifications provide a broader cybersecurity framework encompassing both the development of mining technology and the information security systems supporting application delivery.

The IEC 62443-4-1 standard focuses specifically on secure product development lifecycle requirements for industrial automation and control systems. Its requirements cover areas including security management, secure design, implementation, verification and validation, management of security-related issues and product updates.

Reaching Maturity Level 3 indicates that these security practices have become established and systematically integrated into Sandvik’s development processes.

The development is also significant for mining companies incorporating cybersecurity requirements directly into equipment specifications and procurement processes. As autonomous and connected fleets become more common, particularly at large underground mines and in brownfield modernization projects, suppliers are increasingly expected to demonstrate that cybersecurity is built into equipment and control systems from the development stage.

For Sandvik, applying the certified Secure Development Lifecycle through SICA provides a common cybersecurity foundation across its intelligent equipment portfolio as mines continue moving toward more automated, connected and digitally integrated operations.