Insights

ISASecure and IEC 62443, explained with the numbers

What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.

Filter

52 articles

ACSSADeep dive

How ACSSA assesses IEC 62443-2-1 requirements: 89 composite verdicts from four standards

How ISASecure ACSSA folds IEC 62443-2-4, 3-2 and 3-3 results into one composite verdict per IEC 62443-2-1 requirement, and what makes a verdict fail.

Sep 8, 20269 min readRead
ACSSAIntermediate

After the certificate: ACSSA surveillance in years one and two, recertification in year three

How an ISASecure ACSSA certificate stays valid: 36 months, surveillance in years one and two, recertification in year three, nonconformities and suspension.

Sep 8, 20269 min readRead
ACSSAIntermediate

IEC 62443-2-1 audit evidence in an ACSSA evaluation: documents, interviews and inspection, never testing

How an ISASecure ACSSA evaluator gathers evidence on an installed IACS: documents, interviews and configuration inspection, never testing or device access.

Sep 8, 202610 min readRead
ACSSAIntermediate

The ACSSA assessment process: four phases and the report you receive

How an ISASecure ACSSA evaluation runs: the plan you approve, the four ACSSA-304 phases from risk assessment to report, and how to read the ACSSA-303 report.

Sep 8, 20269 min readRead
ACSSAIntermediate

An asset owner's installed IACS: IEC 62443 asset owner certification scope under ISASecure ACSSA, and the six documents that define it

ISASecure ACSSA certifies an asset owner's installed IACS, bounded by six change-controlled documents: who may apply, what is in scope and what is carved out.

Sep 8, 20269 min readRead
ACSSAIntermediate

IEC 62443-2-1 maturity level 2 vs 3: why ISASecure ACSSA certification needs level 3 on every requirement

In ISASecure ACSSA, maturity level 2 means a requirement is documented and level 3 means it is practised. Certification needs level 3 on every requirement.

Sep 8, 20268 min readRead
ACSSADeep dive

IEC 62443 zone sampling in an ACSSA assessment: how zones, conduits and systems are sampled at maturity level 3

Where ISASecure ACSSA samples zones, device-bearing conduits and systems at maturity level 3, how the evaluator chooses the sample, and what to have ready.

Sep 8, 20268 min readRead
ACSSAIntermediate

IEC 62443 target security levels in ACSSA: the asset owner's level decides what is checked, and nothing is awarded

How ACSSA uses each zone's target security level from the asset owner's IEC 62443-3-2 risk assessment to decide what is checked, and why no level is awarded.

Sep 8, 20268 min readRead
ACSSAIntermediate

Service providers in ACSSA: IEC 62443-2-4, delegated tasks and the VIC shortcut

How ISASecure ACSSA evaluates an asset owner's service providers against IEC 62443-2-4: who counts, delegated tasks, the agreed list, NR-A and the VIC result.

Sep 8, 20269 min readRead
ACSSAIntermediate

ACSSA evaluation results: ten result types, and the one that fails

ACSSA records ten result types across four IEC 62443 parts. Only Not met fails; three others pass only with approved documentation; unsampled zones get none.

Sep 8, 20268 min readRead
ACSSAIntroductory

What ISASecure ACSSA certification actually evaluates

ISASecure ACSSA certifies an asset owner's installed control system against IEC 62443-2-1, 3-2, 3-3 and 2-4 at maturity level 3. Here is the map.

Sep 8, 20268 min readRead
CSAIntermediate

CCSC explained: the four IEC 62443-4-2 constraints that apply to every component

IEC 62443-4-2 has a second axis beyond the seven foundational requirements: four common component security constraints. What each means for a CSA certificate.

Sep 8, 20268 min readRead
CSAIntermediate

The four IEC 62443-4-2 component types, and why the type determination decides your CSA scope

Software application, embedded device, host device or network device: which IEC 62443-4-2 component types apply to your product, and how they set CSA scope.

Sep 8, 20268 min readRead
CSAIntermediate

Independent testing in ISASecure CSA: what the lab must test itself

ISASecure CSA flags 34 of its 166 functional requirements for testing by the lab itself. What the flag means, what happens to the rest, and what to prepare.

Sep 8, 20268 min readRead
CSAIntermediate

SDA-C, FSA-C and VIT-C: what each ISASecure CSA assessment stream proves

The ISASecure CSA assessment process, stream by stream: what SDA-C, FSA-C and VIT-C each prove, the five result outcomes, the pass rule and the certificate.

Sep 8, 20268 min readRead
CSAIntermediate

The SDLA prerequisite: why ISASecure CSA needs it, and what the SDA-C artifact review adds

ISASecure CSA requires a valid SDLA certificate. What the process certificate covers, what the component-level SDA-C review adds, and what to prepare.

Sep 8, 20267 min readRead
CSAIntermediate

CSA security levels 1 to 4: what each level actually adds

IEC 62443 security levels explained through ISASecure CSA: what SL 1 to SL 4 are built to resist, how many requirements each adds, and how to pick a target.

Sep 8, 20268 min readRead
CSAIntermediate

ISASecure vulnerability identification testing: how the pass threshold scales with security level

ISASecure VIT pass criteria: one severity band is added per security level, the scan is identical at every level, and a pass never requires zero findings.

Sep 8, 20268 min readRead
Cross-programIntermediate

CSA vs ICSA: which ISASecure scheme fits your device

CSA certifies the four IEC 62443-4-2 component types by security level; ICSA certifies IIoT devices and gateways by Core or Advanced tier. How to choose.

Sep 8, 20269 min readRead
CSAIntroductory

What ISASecure CSA certification actually evaluates

ISASecure CSA certifies a component against IEC 62443-4-2: 166 functional requirements, four component types, three assessment streams and one security level.

Sep 8, 20268 min readRead
CSADeep dive

What it takes to reach SL 3 in ISASecure CSA, by component type

Moving from SL 2 to SL 3 in ISASecure CSA adds 23 IEC 62443-4-2 requirements, 22 of them enhancements. What the step costs by component type and by FR.

Sep 8, 202610 min readRead
CSADeep dive

Where fuzzing, load testing and penetration testing actually live in ISASecure CSA

Suppliers often expect the certification lab to fuzz and pen-test their product. It does not. Who performs each kind of security test in a CSA evaluation, what the lab checks instead, and what to prepare.

Sep 8, 20268 min readRead
ICSAIntermediate

Cloud links, wireless radios and the per-interface rule in ISASecure ICSA

In ISASecure ICSA, cloud and wireless links are ordinary accessible interfaces. How the per-interface rule and the untrusted-network declaration set the effort.

Sep 8, 20268 min readRead
ICSAIntermediate

ISASecure ICSA Core vs Advanced: what the higher tier actually adds

ICSA Core vs Advanced explained: what each tier is for, how 158 requirements become 182, which 24 are added and which the lab tests, and how to choose.

Sep 8, 20267 min readRead
ICSAIntermediate

IIoT device or IIoT gateway: how the two ISASecure ICSA types decide your scope

Which of ISASecure ICSA's two IIoT types your product is, how the IEC 62443-4-2 families split between device and gateway, and why one product can carry both.

Sep 8, 20268 min readRead
ICSAIntermediate

SDA-IC: the 93 lifecycle requirements checked per IIoT component, and the five ICSA-only practices

What ICSA's SDA-IC review checks per IIoT component: 93 of the 118 IEC 62443-4-1 lifecycle requirements, 16 IIoT-specific rows and five ICSA-only practices.

Sep 8, 20268 min readRead
ICSAIntermediate

The Security Maintenance Audit: how an ISASecure ICSA certificate stays valid

How the ISASecure ICSA Security Maintenance Audit works: four IEC 62443-4-1 requirements, four topics, when audits fall, findings, suspension, withdrawal.

Sep 8, 20268 min readRead
ICSAIntermediate

The 24 IIoT-specific requirements ISASecure ICSA adds to IEC 62443-4-2

ISASecure ICSA adds 24 IIoT-specific requirements to the IEC 62443-4-2 base: 18 at both tiers, 6 at Advanced only. What they cover and how to prepare.

Sep 8, 202610 min readRead
ICSADeep dive

Advanced is SL 4, except when it is SL 3: the ISASecure ICSA tier-to-level trap

ICSA Advanced maps to SL 4 in the functional assessment but to SL 3 in vulnerability testing. Why the mappings diverge and how to read the certificate.

Sep 8, 20268 min readRead
ICSAIntermediate

IIoT vulnerability testing: how ISASecure ICSA's two tiers set the pass threshold

ISASecure ICSA vulnerability testing: Core must address critical and high findings, Advanced adds medium. One scan, two filters; a pass is never zero findings.

Sep 8, 20268 min readRead
ICSAIntroductory

What ISASecure ICSA certification actually evaluates

ISASecure ICSA certifies IIoT devices and gateways against IEC 62443-4-2: 182 requirements, two device types, a Core or Advanced tier and a maintenance audit.

Sep 8, 20268 min readRead
ICSAIntermediate

Independent testing in ISASecure ICSA: the 47 requirements the lab exercises

ISASecure ICSA flags 47 of its 182 functional requirements for testing by the lab itself, 40 of them at Core. What the flag means and what to prepare.

Sep 8, 20269 min readRead
SDLAIntermediate

SDLA certificate validity and recertification: how an ISASecure SDLA certificate is kept

How long an ISASecure SDLA certificate lasts, 36 or 12 months, how a recertification audit renews it, and why the scheme has no surveillance or suspension.

Sep 8, 20268 min readRead
SDLAIntermediate

IEC 62443-4-1 defect and update management: the SDLA practices product certifications come back to

How ISASecure SDLA evaluates IEC 62443-4-1 defect and update management: 15 rows, most seen only in the process audit, and the four requirements ICSA revisits.

Sep 8, 20269 min readRead
SDLAIntermediate

Full or readiness evaluation: the SDLA choice that sets your certificate at 36 or 12 months

ISASecure SDLA has two evaluation methods. One requirement passed by readiness evaluation sets the certificate at 12 months, not 36. The 21 rows that decide it.

Sep 8, 20269 min readRead
SDLAIntermediate

What counts as a major nonconformity in an IEC 62443-4-1 audit: the 31 SDLA minimum requirements

In an ISASecure SDLA audit a finding is major when no evidence exists, or when one of 31 minimum requirements is applied inconsistently. The full list.

Sep 8, 202610 min readRead
SDLAIntermediate

IEC 62443-4-1 certification levels: why ISASecure SDLA has none and every requirement must pass

ISASecure SDLA carried certification levels until 2018. Today it has none, and no maturity level either: every applicable IEC 62443-4-1 requirement must pass.

Sep 8, 20268 min readRead
SDLAIntermediate

The SDLA prerequisite for CSA, ICSA and SSA: one process audit, three product schemes

ISASecure CSA, ICSA and SSA each require a valid SDLA certificate. What the process audit settles once, what every product scheme re-checks, and how to plan.

Sep 8, 20269 min readRead
SDLAIntermediate

IEC 62443-4-1 security guidelines and hardening: the SDLA practice with the most minimum requirements

ISASecure SDLA and the IEC 62443-4-1 security guidelines practice: 7 requirements, 17 rows, 10 minimum requirements, no mandatory artifacts, examined twice.

Sep 8, 20269 min readRead
SDLADeep dive

Fuzz, load, penetration and abuse-case testing: what the IEC 62443-4-1 SVV practice asks of a supplier

The SVV practice is where ISASecure SDLA is strictest: five IEC 62443-4-1 requirements, 20 assessable rows and a named test type behind most of them.

Sep 8, 20269 min readRead
SDLAIntroductory

What is ISASecure SDLA, and what does the certificate actually certify?

ISASecure SDLA certifies a development organisation and a versioned development process against IEC 62443-4-1: eight practices, 47 requirements, no levels.

Sep 8, 20268 min readRead
SDLADeep dive

IEC 62443-4-1 process audit: the 23 SDLA rows no product evaluation examines

23 ISASecure SDLA-312 rows are checked only in the SDLA process audit, on Perseus's reading of its activity columns: defect handling, coding rules, pen testing.

Sep 8, 20269 min readRead
SSAIntermediate

One certificate, several levels: how ISASecure SSA assigns a capability security level per zone

How ISASecure SSA assigns an IEC 62443 capability security level to each zone of a system, why one certificate can carry several levels, and how to specify it.

Sep 8, 20268 min readRead
SSAIntermediate

IEC 62443-3-3 requirements: how ISASecure SSA evaluates all 100 clauses in FSA-S

ISASecure SSA's FSA-S stream covers every clause of IEC 62443-3-3: 51 system requirements and 49 enhancements, laid out as 116 rows and scored zone by zone.

Sep 8, 20268 min readRead
SSAIntermediate

How to read an ISASecure SSA certificate and report: zones, levels and user-enforced mitigations

How to read an ISASecure SSA certificate and its SSA-303 report: capability levels per zone, the ten report sections, and the mitigations the user must apply.

Sep 8, 20269 min readRead
SSADeep dive

Reference layouts and scalable systems: how one ISASecure SSA certificate covers a family of configurations

How ISASecure SSA certifies a scalable IEC 62443-3-3 system: zone specifications, layouts in scope, the reference layout the lab tests, and nine submissions.

Sep 8, 202610 min readRead
SSAIntermediate

SSA SDA-S artifacts: the 74 lifecycle rows ISASecure checks for a system, and why fuzz and load results are among them

ISASecure SSA's SDA-S stream re-checks 74 assessable rows of the SDLA-312 lifecycle catalogue for the system as sold, fuzz and load coverage included.

Sep 8, 20268 min readRead
SSAIntermediate

A system as sold: IEC 62443-3-3 system certification scope under ISASecure SSA, and what falls outside it

ISASecure SSA certifies a control-system product as sold, at a version, in a fixed or scalable layout: the four eligibility criteria and what falls outside.

Sep 8, 20268 min readRead
SSAIntermediate

ISASecure SSA vulnerability testing: the scan where each zone sets its own pass threshold

How VIT-S works in ISASecure SSA: one known-vulnerability scan of every IP-addressed component, with the pass threshold set per component by its zone's level.

Sep 8, 20268 min readRead
SSAIntroductory

What ISASecure SSA certification actually evaluates

ISASecure SSA certifies a control system as sold against IEC 62443-3-3, with a capability security level per zone. Four elements, 116 functional rows: the map.

Sep 8, 20268 min readRead
SSADeep dive

What it takes to move a zone from SL 2 to SL 3 in ISASecure SSA

Raising a zone from SL 2 to SL 3 in ISASecure SSA adds 30 IEC 62443-3-3 rows: two base requirements and 28 enhancements, two of them lab-tested. All 30, by FR.

Sep 8, 202610 min readRead
SSAIntermediate

Independent testing in ISASecure SSA: eleven flagged requirements, one scan, one reference system

ISASecure SSA flags 11 of its 116 assessable rows for lab testing, plus one vulnerability scan on one reference system. What the lab tests and reviews.

Sep 8, 20269 min readRead

Have a product or system to certify?

Talk to the assessors who wrote these articles about what applies to you.