An ACSSA certificate is a statement about a running control system, and running systems change: equipment is replaced, service providers come and go, procedures are rewritten, people move on. So the grant is not the end of the evaluation. ISASecure ACSSA-300, in its section on maintaining certification, sets out how long the certificate lasts, what is checked each year, how later nonconformities are graded and what happens when they are not fixed.
This article walks through those rules for the asset owner that holds the certificate. They belong to the certification scheme only; an inspection report speaks to the state of the IACS on its date.
Valid to the end of the 36th month
A certificate granted after an initial evaluation runs to the end of the 36th month after the grant, provided the asset owner stays in good standing. Good standing has a specific meaning: any open major nonconformity is inside its agreed grace period, no minor nonconformity has been left open from one audit to the next, and every correction plan has been accepted on time.
Within that period the certification body audits the IACS in each of the first two years. In the third year a recertification audit takes the place of surveillance. If it passes, the certificate is extended by 36 months counted from the previous expiry date, not from the day the audit closed, and the cycle begins again, so recertification falls every third year for as long as the certificate is held.
| Year after grant | Audit | What it covers |
|---|---|---|
| Year 1 | Surveillance | General surveillance (6 items) and detailed surveillance (30 asset-owner security-program requirements: 10 risk-based, 20 random) |
| Year 2 | Surveillance | General and detailed surveillance again |
| Year 3 | Recertification | General surveillance plus every maturity-level-3 activity again; a new certificate and report are issued |
A certificate is valid to the end of the 36th month. Surveillance audits fall in years one and two; a recertification audit in year three extends the certificate 36 months from the prior expiry. Source: ISASecure ACSSA-300 v1.5 §5.
What a surveillance audit covers
Every surveillance audit has two parts.
General surveillance is a fixed set of six checks that run every year:
- Changes since the last audit. What changed in the IACS as its change log records it: assets, equipment under control, policies and procedures, service-provider tasks, the people assigned to the system. Separately, whether the log is complete: the evaluator sets aside time to look for changes that were never written down.
- Risk-assessment updates. Whether the IEC 62443-3-2 risk assessment has been revisited on the schedule the asset owner's own policy sets.
- Security-program updates. Whether revised policies and procedures still conform to IEC 62443-2-1. A revised procedure already carried out is checked at maturity level 3; one not yet exercised is checked as documented now and as practised at the next audit.
- Earlier nonconformities. Progress on anything raised before.
- The asset owner's own reviews. The periodic security-program reviews that ORG 2.4 calls for, over the period since the last audit.
- Two event-management requirements. EVENT 1.1 and EVENT 1.8, re-validated at maturity level 3 together with the system capabilities associated with them.
Detailed surveillance goes deeper on selected requirements. First, any requirement that passed the previous evaluation on evidence other than live operation, such as a tabletop exercise or a lab demonstration used because nothing had yet happened in the live IACS to exercise it, is re-checked against live operation. Then thirty further asset-owner security-program requirements are selected: ten on a risk basis, drawn from at least seven of the eleven categories the evaluation workbook uses, and twenty at random, with at least one from every category. Those categories are an ISA99 proposal for organising the IEC 62443 foundational requirements, not the standard's clause structure, and a requirement drawn at random one year may be drawn again the next.
Around the thirty, the certification body samples unchanged elements to confirm they still conform, re-evaluates at level 3 any result the IACS changes may have moved, including capability requirements on a sample of affected zones, and looks at conformity across the whole period, not only on the day of the visit.
One point of precision: surveillance selects requirements, not zones; it is not a rotation through zones.
Recertification in year three
The recertification audit performs general surveillance and then repeats every maturity-level-3 activity of the initial evaluation across the sampled zones, device-bearing conduits and systems under consideration. The certification body sets out a sampling strategy for checking that the evidence is consistent with what the previous audit saw, and picks up any requirement added by the version of ACSSA then in force. A pass produces a new certificate and a new report.
Maturity-level-2 results for policies and procedures shared across an asset owner's systems may be reused for a second IACS while the first remains certified, and a level-2 check performed at surveillance may be reused within three months.
Nonconformities after the certificate
A nonconformity in ACSSA is any "Not met" result. What differs after the certificate is how it is graded and how fast it must move.
For nonconformities found during the initial evaluation, ACSSA-300 gives a clock: a correction plan must be accepted by the certification body within 30 days of the nonconformity report, and the pass criteria must be satisfied, in full or in substance, within 90 days.
Its major-and-minor classification is stated for surveillance and recertification: each nonconformity found there is classed against a list of 13 occurrence types. For eight of them the class is fixed at major and for two at minor; the remaining three are for the certification body to weigh.
ACSSA-300 names 13 occurrence types: eight that must be classed major, two that must be classed minor, and three left to the certification body's judgement. The classification applies to surveillance and recertification audits. Source: ISASecure ACSSA-300 v1.5 (R21).
| Class | Occurrence types, in gist |
|---|---|
| Always major | A pattern of security-program updates missing for IACS changes; a practice failure introduced by an IACS update; EVENT 1.1 no longer at level 3; the ORG 2.4 security-program reviews not performed; the risk-assessment updates ORG 2.1 calls for not made; a nonconformity still open from the previous audit; a requirement that passed on non-live evidence failing on live evidence; inaccurate public claims about the certification |
| Always minor | A deviation in practice with minor impact; an isolated deviation in practice |
| Certification body's judgement | Policies or procedures revised out of conformity; a single IACS change not carried into the security program; anything not on the list |
The consequences follow a fixed table:
| Finding | At a surveillance audit | At the recertification audit |
|---|---|---|
| No nonconformity | Good standing continues | Certificate extended 36 months from the prior expiry |
| Minor | Correction plan accepted within an agreed period, which should be about two months; the fix is verified at the next audit. Suspension if a minor from the previous audit is still open, or the plan is not accepted | A minor still open since the last surveillance lets the certificate expire; otherwise accepted plans allow extension |
| Major | Correction plan accepted within 30 days; closure inside an agreed grace period that should be 30 to 150 days, with level-3 re-validation. Suspension if not closed in time | Extension only if the major is corrected before expiry and no minors linger |
Suspension, restoration and withdrawal
ACSSA-300 uses three words for a certificate that stops being fully valid. A suspended certificate is paused, not cancelled, and can come back. A withdrawn certificate has been cancelled by the certification body that issued it. A terminated certificate is one the asset owner chose to give up.
Suspension has a defined exit. If every nonconformity that contributed to it is closed within six months, the certificate is restored and keeps its original expiry date. If not, it is withdrawn. A related allowance applies to a late recertification: if its requirements are met within six months after the expiry date, the certificate may still be extended from the original expiry.
The surveillance report
Each surveillance audit is documented against the annex ACSSA-303 reserves for it: five tables covering the baseline and current versions of the IACS-defining documents, what changed, risk-assessment and service-provider updates, earlier nonconformities, the ORG 2.4 review and the EVENT 1.1 and 1.8 re-check, then the detailed results and any new nonconformity, either added to the original certification report as an annex or issued on its own.
What the certificate says, and what you may say about it
The scheme description states one requirement for the certificate's content: it references the three-digit ISASecure version under which it was granted, ACSSA 1.0.0 being the program version named by the ACSSA documents held (February 2026). The certificate's full format is set by a separate ISASecure document, so this article makes no further claim about it.
Publication is the asset owner's call: ISCI posts the owner's name and certificate information only at the owner's request, or provides it directly to a third party the owner names. When the owner does make public claims, ACSSA-300 asks for three things: name the ISASecure version, name the asset owner, and do not mislead about scope. The certificate covers the IACS as bounded by its six defining documents, not the whole company and not every site the company runs. As an ISASecure certification body, Perseus can point only to those three tests; symbol-use rules sit in a separate ISASecure document.
What this means for asset owners
Keep the six documents and their change log current. Every year's first general-surveillance check starts from the logged changes and then looks for unlogged ones. A pattern of changes never carried into the security program is a mandatory major.
Follow your own risk-assessment update policy. The evaluator checks it against the schedule you set, and a missed update is on the mandatory-major list.
Keep practice evidence flowing all year. Twenty of the thirty detailed-surveillance requirements are random, so any requirement may come up.
Work the clocks. Thirty days to an accepted plan for a major, 30 to 150 days to close it, about two months to a plan for a minor, and six months to restore a suspended certificate before it is withdrawn.
Where to go next
The rest of this series is on the ACSSA filter of the Insights index. For the contrast with a certificate attached to a product version rather than an installed system, see the SSA article on the system as sold.
Frequently asked questions
To the end of the 36th month after the grant, as long as the asset owner remains in good standing: open major nonconformities are within their grace period, no minor nonconformity has been left open from one audit to the next, and correction plans have been accepted on time. Surveillance audits take place in years one and two. A recertification audit in year three, if passed, extends the certificate by 36 months counted from the previous expiry date, and the cycle repeats.