ACSSA-304, the ISCI planning-and-execution document for conformity assessment bodies, gives an ACSSA evaluation its shape: a planning stage and four phases. ACSSA-303 gives the report its shape. This article follows them in order, from the plan you approve to the tables worth reading first.
Before Phase 1: a plan you approve
Nothing is evaluated until there is an agreed plan. ACSSA-304 describes a kick-off, a scope review, a draft plan, a review of the draft, and its issue. The scope review checks that the application is complete, not that the IACS conforms.
The draft weighs seven planning factors: the size of the asset-owner organisation; the number and complexity of its locations; where they are; regulated or critical-infrastructure status; how diverse the installed technology is; the extent of service-provider use; and the asset owner's demonstrated performance. Evaluation begins only once the asset owner has approved the plan.
One step can precede all of this: ACSSA-300 requires every conformity assessment body to offer an optional gap analysis before application, which ACSSA-100 describes as typical on the certification path. It is not part of the evaluation, and it is the cheapest point at which to find thin evidence or an unclear IACS boundary.
The four phases
ACSSA-304 names the phases by what they evaluate: the risk assessment, maturity level 2, maturity level 3, and the report. Each builds on the one before, but the plan may run parts of them in parallel.
| Phase | Maturity level 2 | Maturity level 3 |
|---|---|---|
| Phase 1 — risk-assessment evaluation | 33 | 36 |
| Phase 2 — maturity level 2 evaluation | 275 | — |
| Phase 3 — maturity level 3 evaluation | — | 383 |
| Phase 4 — prepare report | — | — |
Counts as Perseus's tooling assigns ACSSA-300 Table 1 rows to the four phases of ACSSA-304: Phase 1 the risk assessment, Phase 2 the documented-policy check, Phase 3 the practised check on site, Phase 4 the report. Sources: ISASecure ACSSA-300 v1.5 Table 1, ACSSA-304 v2.3, ACSSA-311 v1.3.
The counts (33 level 2 and 36 level 3 method evaluations in Phase 1, 275 in Phase 2, 383 in Phase 3) are as Perseus's tooling assigns ACSSA-300 Table 1 rows to ACSSA-304's phases; they sum to the 308 and 419 method evaluations derived from the ACSSA-311 workbook. Phase 4 grades nothing.
Phase 1: risk-assessment evaluation
Phase 1 evaluates the asset owner's IEC 62443-3-2 risk assessment: the 33 zone-and-conduit requirements, ZCR 1 to ZCR 7. At maturity level 2 they receive one result for the whole IACS; at level 3, one per system under consideration (sampled for some items) or, for the zone-level items, per sampled zone or device-bearing conduit. ACSSA-300 Table 1 also places here the level 3 process aspect of three IACS-wide IEC 62443-2-1 network requirements, NET 1.1 to NET 1.3. Three of the 33 items are recommendations: ACSSA records a result for them but does not score them.
The risk assessment also supplies each zone's target security level, which decides which IEC 62443-3-3 capabilities Phase 3 checks there, and fixes the zones and conduits from which the level 3 sample is drawn.
Phase 2: maturity level 2 evaluation
Phase 2 asks whether the security program is documented. The 87 IEC 62443-2-1 requirements (the count ACSSA-303 states) and the 2 policy-and-procedure-support items are evaluated at level 2 for each part of the IACS the asset owner runs under one set of policies; those parts must together cover the whole IACS. Each service provider is evaluated at level 2 against the IEC 62443-2-4 requirements agreed to apply to its tasks on this IACS. A provider's maturity level 3 IEC 62443-2-4 certificate from an IAF-MRA-accredited body can satisfy a requirement at this level only.
This is documentation work, which ACSSA-304 allows to be done remotely, and what the evaluator learns here informs which zones go into the Phase 3 sample.
Phase 3: maturity level 3 evaluation
Phase 3 asks whether the documented program is practised for this IACS, and it is the on-site phase because its evidence is physical: live configurations, the way access to rooms and cabinets is actually controlled, and how staff carry out procedures. Where a service provider does that work from its own premises, the evaluator goes there too.
ACSSA-304 sets an order. First the IACS-wide organisational requirements, ORG 1.1 to ORG 1.5 and ORG 2.4, each with a single IACS-wide result. Next, evaluated in full, the zone that combines the highest target security level with the most technical capabilities; ACSSA-300 makes it a mandatory member of the level 3 sample. Then a representative set of requirements across the other sampled zones and device-bearing conduits, and each service provider at level 3 for its delegated tasks. The IEC 62443-3-3 capability requirements enter only here, at level 3, zone by zone, for every capability at or below the zone's target level or called for by the owner's own requirements specification.
The evidence is records of execution, interviews with at least one representative of each relevant functional role within the sampled scope, and observation of the owner's or provider's staff performing a task or opening a configuration. The evaluator performs no testing and does not access devices, unlike a product certification, where the laboratory tests the product itself.
Phase 4: prepare report
Phase 4 collates and decides. For results resting on one of the three special circumstances (risk-based not required, compensating security measure, not feasible), the documentation approved by the asset owner and every affected stakeholder is gathered and checked. The whole result set is then reviewed against the ten consistency conditions in ACSSA-300's annex: the results under the four standards must agree with one another, and the evaluator may not derive one part's result from another's except between the two maturity levels.
On the certification path the decision follows ACSSA-300: a certificate is granted when every requirement passes at maturity level 3, any nonconformity found on the way having a correction plan accepted within 30 days and closure within 90. Under ISO/IEC 17065 the decision-maker was not part of the evaluation. The report is written to ACSSA-303 and the certificate issued; like Phases 1 and 2, this phase may be conducted remotely.
The report you receive
ACSSA-303 is the template: sixteen sections, forty tables and three figures, arranged as four main blocks over a single result set. Sections 1 to 5 are overview and statistics; section 6 holds every evaluation result; sections 7 to 11 present the same results by area of responsibility; sections 12 to 15 are reference material; section 16 is a surveillance annex. One template serves the inspection and certification schemes; a passing certification report drops the nonconformity tables and adds three statements of conformity.
| Section | Title | Tables and figures |
|---|---|---|
| 1 | Management summary | Figure 1: composite status by category |
| 2 | Purpose and scope | Table 1: which sections matter to which reader |
| 3 | Target of evaluation | Tables 2–3: systems under consideration, zones and conduits with their target levels; Table 4: service providers; Figure 2: the IACS and its environment |
| 4 | Evaluation concepts | Table 5: the ten result types |
| 5 | Evaluation statistics | Tables 6–9: results per standard; Figure 3: applicable IEC 62443-2-4 requirements by functional area |
| 6 | All evaluation results | Tables 10–15, among them Table 10 nonconformity short list, Table 11 nonconformity detail, Table 12 composite results per security-program requirement, Table 13 zone properties (section 6.5 sampling strategy for systems under consideration, zones and conduits) |
| 7 | ORG 2.1 and the risk assessment | Tables 16–18 |
| 8 | Hardware and software systems | Table 19: every IEC 62443-3-3 requirement against every examined zone and conduit |
| 9 | Results by zone and conduit | Tables 20–27 |
| 10 | IACS-wide requirements | Table 28 |
| 11 | Results by service provider | Tables 29–31 |
| 12 | Project management | Table 32: references; Tables 33–34: documents |
| 13 | Status and signatures | — |
| 14 | Annex: result types | Table 35 |
| 15 | Annex: abbreviations | — |
| 16 | Annex: surveillance report | Tables 36–40 |
The three statements: the asset owner's risk assessment meets IEC 62443-3-2; within the security context that assessment sets, the IACS meets IEC 62443-2-1 and IEC 62443-3-3; and the integration and maintenance services performed on the IACS meet the IEC 62443-2-4 requirements that apply to them.
Three tables, by role
Beyond Table 1, the reading guide, three tables do most of the work.
Table 12 is the composite view and the asset owner's table: one line per IEC 62443-2-1 requirement and support item, 89 in all, each folding the owner's own process aspect with the results of its associated service-provider, risk-assessment and capability requirements. Only a "Not met" fails a line.
Table 13 anchors section 6.5, the sampling strategy. The table lists the risk properties of each zone; the section's text covers device-bearing conduits and systems under consideration as well and says which were selected for the level 3 sample, and why. A zone outside a requirement's sample receives no result for it, only a not-examined mark.
Table 19 is the integrator's table: every IEC 62443-3-3 requirement against every examined zone and conduit, with the security-program requirement each supports.
ISCI's sample report illustrates the structure on a small fuel-terminal loading facility (one system under consideration, three zones, three conduits, three service providers) that passes 75 of its 89 composites, figures that belong to the sample, not the program. Perseus evaluates against this same ACSSA document set as an ISASecure certification body.
Nonconformities in the report
Any result recorded as "Not met", at either maturity level, is a nonconformity. The report lists them in Table 10 and details each in Table 11 under an identifier of the form NC-YYYY-NNN: the maturity level and security level concerned, the finding and its evidence, the zones or conduits and service providers affected, the normative requirement and its associated IEC 62443-2-1 or support requirement, and the date, evaluator and asset-owner contact. ACSSA-300 states its major-and-minor classification for surveillance and recertification audits; the initial evaluation runs on the 30-day and 90-day clocks above.
Where to go next
The rest of the series is on the ACSSA filter of the Insights index; for the contrast with a system certified as sold rather than as installed, see the SSA article on that boundary.
Frequently asked questions
Three of them can. Phase 1 (risk-assessment evaluation), Phase 2 (maturity level 2) and Phase 4 (prepare report) review documents and artifacts and may be conducted remotely. Phase 3 (maturity level 3) may not: its evidence is the running system and the people operating it, at the asset owner's and, where relevant, the service providers' locations. A small asset owner with one location may simply have every phase happen on site.