ACSSAIntermediateExplainer

The ACSSA assessment process: four phases and the report you receive

How an ISASecure ACSSA evaluation runs: the plan you approve, the four ACSSA-304 phases from risk assessment to report, and how to read the ACSSA-303 report.

Perseus ISASecure Assessor TeamSeptember 8, 20269 min read

ACSSA-304, the ISCI planning-and-execution document for conformity assessment bodies, gives an ACSSA evaluation its shape: a planning stage and four phases. ACSSA-303 gives the report its shape. This article follows them in order, from the plan you approve to the tables worth reading first.

Before Phase 1: a plan you approve

Nothing is evaluated until there is an agreed plan. ACSSA-304 describes a kick-off, a scope review, a draft plan, a review of the draft, and its issue. The scope review checks that the application is complete, not that the IACS conforms.

The draft weighs seven planning factors: the size of the asset-owner organisation; the number and complexity of its locations; where they are; regulated or critical-infrastructure status; how diverse the installed technology is; the extent of service-provider use; and the asset owner's demonstrated performance. Evaluation begins only once the asset owner has approved the plan.

One step can precede all of this: ACSSA-300 requires every conformity assessment body to offer an optional gap analysis before application, which ACSSA-100 describes as typical on the certification path. It is not part of the evaluation, and it is the cheapest point at which to find thin evidence or an unclear IACS boundary.

The four phases

ACSSA-304 names the phases by what they evaluate: the risk assessment, maturity level 2, maturity level 3, and the report. Each builds on the one before, but the plan may run parts of them in parallel.

Where the method evaluations fall across the four ACSSA-304 phases
PhaseMaturity level 2Maturity level 3
Phase 1 — risk-assessment evaluation3336
Phase 2 — maturity level 2 evaluation275
Phase 3 — maturity level 3 evaluation383
Phase 4 — prepare report

Counts as Perseus's tooling assigns ACSSA-300 Table 1 rows to the four phases of ACSSA-304: Phase 1 the risk assessment, Phase 2 the documented-policy check, Phase 3 the practised check on site, Phase 4 the report. Sources: ISASecure ACSSA-300 v1.5 Table 1, ACSSA-304 v2.3, ACSSA-311 v1.3.

The counts (33 level 2 and 36 level 3 method evaluations in Phase 1, 275 in Phase 2, 383 in Phase 3) are as Perseus's tooling assigns ACSSA-300 Table 1 rows to ACSSA-304's phases; they sum to the 308 and 419 method evaluations derived from the ACSSA-311 workbook. Phase 4 grades nothing.

Phase 1: risk-assessment evaluation

Phase 1 evaluates the asset owner's IEC 62443-3-2 risk assessment: the 33 zone-and-conduit requirements, ZCR 1 to ZCR 7. At maturity level 2 they receive one result for the whole IACS; at level 3, one per system under consideration (sampled for some items) or, for the zone-level items, per sampled zone or device-bearing conduit. ACSSA-300 Table 1 also places here the level 3 process aspect of three IACS-wide IEC 62443-2-1 network requirements, NET 1.1 to NET 1.3. Three of the 33 items are recommendations: ACSSA records a result for them but does not score them.

The risk assessment also supplies each zone's target security level, which decides which IEC 62443-3-3 capabilities Phase 3 checks there, and fixes the zones and conduits from which the level 3 sample is drawn.

Phase 2: maturity level 2 evaluation

Phase 2 asks whether the security program is documented. The 87 IEC 62443-2-1 requirements (the count ACSSA-303 states) and the 2 policy-and-procedure-support items are evaluated at level 2 for each part of the IACS the asset owner runs under one set of policies; those parts must together cover the whole IACS. Each service provider is evaluated at level 2 against the IEC 62443-2-4 requirements agreed to apply to its tasks on this IACS. A provider's maturity level 3 IEC 62443-2-4 certificate from an IAF-MRA-accredited body can satisfy a requirement at this level only.

This is documentation work, which ACSSA-304 allows to be done remotely, and what the evaluator learns here informs which zones go into the Phase 3 sample.

Phase 3: maturity level 3 evaluation

Phase 3 asks whether the documented program is practised for this IACS, and it is the on-site phase because its evidence is physical: live configurations, the way access to rooms and cabinets is actually controlled, and how staff carry out procedures. Where a service provider does that work from its own premises, the evaluator goes there too.

ACSSA-304 sets an order. First the IACS-wide organisational requirements, ORG 1.1 to ORG 1.5 and ORG 2.4, each with a single IACS-wide result. Next, evaluated in full, the zone that combines the highest target security level with the most technical capabilities; ACSSA-300 makes it a mandatory member of the level 3 sample. Then a representative set of requirements across the other sampled zones and device-bearing conduits, and each service provider at level 3 for its delegated tasks. The IEC 62443-3-3 capability requirements enter only here, at level 3, zone by zone, for every capability at or below the zone's target level or called for by the owner's own requirements specification.

The evidence is records of execution, interviews with at least one representative of each relevant functional role within the sampled scope, and observation of the owner's or provider's staff performing a task or opening a configuration. The evaluator performs no testing and does not access devices, unlike a product certification, where the laboratory tests the product itself.

Phase 4: prepare report

Phase 4 collates and decides. For results resting on one of the three special circumstances (risk-based not required, compensating security measure, not feasible), the documentation approved by the asset owner and every affected stakeholder is gathered and checked. The whole result set is then reviewed against the ten consistency conditions in ACSSA-300's annex: the results under the four standards must agree with one another, and the evaluator may not derive one part's result from another's except between the two maturity levels.

On the certification path the decision follows ACSSA-300: a certificate is granted when every requirement passes at maturity level 3, any nonconformity found on the way having a correction plan accepted within 30 days and closure within 90. Under ISO/IEC 17065 the decision-maker was not part of the evaluation. The report is written to ACSSA-303 and the certificate issued; like Phases 1 and 2, this phase may be conducted remotely.

The report you receive

ACSSA-303 is the template: sixteen sections, forty tables and three figures, arranged as four main blocks over a single result set. Sections 1 to 5 are overview and statistics; section 6 holds every evaluation result; sections 7 to 11 present the same results by area of responsibility; sections 12 to 15 are reference material; section 16 is a surveillance annex. One template serves the inspection and certification schemes; a passing certification report drops the nonconformity tables and adds three statements of conformity.

SectionTitleTables and figures
1Management summaryFigure 1: composite status by category
2Purpose and scopeTable 1: which sections matter to which reader
3Target of evaluationTables 2–3: systems under consideration, zones and conduits with their target levels; Table 4: service providers; Figure 2: the IACS and its environment
4Evaluation conceptsTable 5: the ten result types
5Evaluation statisticsTables 6–9: results per standard; Figure 3: applicable IEC 62443-2-4 requirements by functional area
6All evaluation resultsTables 10–15, among them Table 10 nonconformity short list, Table 11 nonconformity detail, Table 12 composite results per security-program requirement, Table 13 zone properties (section 6.5 sampling strategy for systems under consideration, zones and conduits)
7ORG 2.1 and the risk assessmentTables 16–18
8Hardware and software systemsTable 19: every IEC 62443-3-3 requirement against every examined zone and conduit
9Results by zone and conduitTables 20–27
10IACS-wide requirementsTable 28
11Results by service providerTables 29–31
12Project managementTable 32: references; Tables 33–34: documents
13Status and signatures
14Annex: result typesTable 35
15Annex: abbreviations
16Annex: surveillance reportTables 36–40

The three statements: the asset owner's risk assessment meets IEC 62443-3-2; within the security context that assessment sets, the IACS meets IEC 62443-2-1 and IEC 62443-3-3; and the integration and maintenance services performed on the IACS meet the IEC 62443-2-4 requirements that apply to them.

Three tables, by role

Beyond Table 1, the reading guide, three tables do most of the work.

Table 12 is the composite view and the asset owner's table: one line per IEC 62443-2-1 requirement and support item, 89 in all, each folding the owner's own process aspect with the results of its associated service-provider, risk-assessment and capability requirements. Only a "Not met" fails a line.

Table 13 anchors section 6.5, the sampling strategy. The table lists the risk properties of each zone; the section's text covers device-bearing conduits and systems under consideration as well and says which were selected for the level 3 sample, and why. A zone outside a requirement's sample receives no result for it, only a not-examined mark.

Table 19 is the integrator's table: every IEC 62443-3-3 requirement against every examined zone and conduit, with the security-program requirement each supports.

ISCI's sample report illustrates the structure on a small fuel-terminal loading facility (one system under consideration, three zones, three conduits, three service providers) that passes 75 of its 89 composites, figures that belong to the sample, not the program. Perseus evaluates against this same ACSSA document set as an ISASecure certification body.

Nonconformities in the report

Any result recorded as "Not met", at either maturity level, is a nonconformity. The report lists them in Table 10 and details each in Table 11 under an identifier of the form NC-YYYY-NNN: the maturity level and security level concerned, the finding and its evidence, the zones or conduits and service providers affected, the normative requirement and its associated IEC 62443-2-1 or support requirement, and the date, evaluator and asset-owner contact. ACSSA-300 states its major-and-minor classification for surveillance and recertification audits; the initial evaluation runs on the 30-day and 90-day clocks above.

Where to go next

The rest of the series is on the ACSSA filter of the Insights index; for the contrast with a system certified as sold rather than as installed, see the SSA article on that boundary.

Frequently asked questions

Three of them can. Phase 1 (risk-assessment evaluation), Phase 2 (maturity level 2) and Phase 4 (prepare report) review documents and artifacts and may be conducted remotely. Phase 3 (maturity level 3) may not: its evidence is the running system and the people operating it, at the asset owner's and, where relevant, the service providers' locations. A small asset owner with one location may simply have every phase happen on site.

ISASecure ACSSAACSSA assessment processIEC 62443 asset owner certificationACSSA-304 evaluation phasesACSSA-303 reportIEC 62443-2-1 evaluation
Share this article
Back to Insights

Ready to Get Started?

Let our team of experts help you achieve and maintain compliance with industry-leading cybersecurity standards.