Ask an asset owner preparing for ISASecure ACSSA which maturity level they are aiming for and the answer is often "level 2 first, then level 3". It is a natural reading of IEC 62443-2-1, and for certification it is the wrong plan. ACSSA distinguishes two levels that matter, documented and practised, and certifies only when every requirement reaches the second.
Documented or practised: the two levels in plain terms
IEC 62443-2-1 grades an asset owner's security program on a four-step maturity scale. ACSSA borrows the scale but uses two of its steps as the grades a requirement can earn.
Maturity level 2 means documented. For the requirement in question, the asset owner's policies and procedures are written down and cover the part of the IACS being examined. Whether anyone follows them is not yet the question. In the standard's vocabulary this is the managed level.
Maturity level 3 means practised. The same written procedures are demonstrably followed for this IACS: the records exist, the configurations match, and the people responsible can show what they do. The standard calls this the defined, or practised, level.
A procedure that sits in a document-management system and is not followed is level 2. A working habit nobody has written down is not even level 2, however sound; level 1 on the standard's scale is practice without documentation. Certification wants both the documented procedure and the evidence that it is lived.
Levels 1 and 4
ACSSA is two conformity-assessment schemes sharing one evaluation method: inspection under ISO/IEC 17020 and certification under ISO/IEC 17065. Maturity level 1 belongs to the inspection scheme only, as an optional, informational extra; it is never the basis for a public claim, and certification does not use it.
Level 4 is not specified in the ACSSA documents; an IACS operating at level 4 for a requirement is evaluated, and passes, as level 3. Level 3 is the ceiling as well as the threshold.
Three aspects, five sub-aspects
Every IEC 62443-2-1 requirement is looked at from three angles, which ACSSA-300 calls aspects: the asset owner's own policies and procedures; the support it receives from service providers under IEC 62443-2-4; and the use of IEC 62443-3-3 technical capabilities in the zones the requirement touches. ACSSA-300 refines these into five sub-aspects, numbered I to V. A level-2 evaluation covers sub-aspects I and II; a level-3 evaluation covers all five.
Level 2 stops at what is documented, by the asset owner and in the supporting service-provider and risk-assessment material; level 3 goes on to whether the procedures are followed, providers execute what was delegated, and the capabilities each zone's target security level calls for are configured and in use.
| Aspect | What the evaluator examines | Level 2 | Level 3 |
|---|---|---|---|
| Asset owner's policies and procedures (IEC 62443-2-1) | The written program; at level 3 also the records showing it is followed for this IACS | Yes | Yes |
| Service-provider support (IEC 62443-2-4) | The provider's processes for the tasks delegated for this IACS; at level 3 also evidence that they were carried out | Yes | Yes |
| Use of technical capabilities (IEC 62443-3-3) | Whether the capabilities the zone's target level requires are present, configured and used | Not evaluated | Yes |
The result of a 2-1 requirement at each level is a composite: the asset owner's own process aspect taken together with the results of its associated requirements — 2-4 and 3-2 at level 2; 2-4, 3-2 and 3-3 at level 3. There are 89 such composite verdicts: 87 for IEC 62443-2-1, as ACSSA-303 states, plus two for ACSSA's own policy-and-procedure-support items, which cover the two 3-3 requirements with no governing requirement in 2-1. Of the ten result types, only Not met fails.
The evaluator sets the level
The asset owner does not declare a maturity level. It chooses between inspection and certification and, for inspection, whether to include level 1. The level is determined by the evaluator, requirement by requirement, from the evidence.
For certification the threshold is the same on every requirement: ACSSA-300's decision rule grants the certificate when every requirement from all four IEC 62443 parts, and both support items, has passed at level 3. There is no level-2 certificate, no partial certificate and no percentage. A requirement found Not met needs a correction plan the certification body accepts within 30 days and closure within 90 days. ISASecure's process scheme for product suppliers takes the opposite route and has no levels at all; ACSSA has levels, and for certification collapses them to one.
As an ISASecure certification body, this is the rule we certify against: level 3, determined by the evaluator, on every requirement.
The two levels in numbers
The ISASecure ACSSA-311 workbook lists 422 evaluation methods, one per requirement item and security level. Three are grouping headers whose child rows carry the activities; of the other 419, each carries a level-2 and a level-3 activity, except those drawn from IEC 62443-3-3, which have a level-3 activity only. Counted as evaluations, derived from the workbook, that gives 308 at level 2 and 419 at level 3.
| Part | Maturity level 2 | Maturity level 3 |
|---|---|---|
| IEC 62443-2-1 (+ 2 policy-and-procedure-support items) | 152 | 152 |
| IEC 62443-2-4 (service providers) | 123 | 123 |
| IEC 62443-3-2 (risk assessment) | 33 | 33 |
| IEC 62443-3-3 (system capabilities) | 0 | 111 |
Maturity level 2 asks whether policies and procedures are documented; maturity level 3 asks whether they are practised for this IACS. System capabilities (3-3) are evaluated at level 3 only. 308 method evaluations at level 2, 419 at level 3. Source: ISASecure ACSSA-311 v1.3.
The whole difference sits in the IEC 62443-3-3 row: whether a capability is configured and in use is a question of practice, so it belongs to level 3, and its documentation side is carried by the 2-1 requirement that governs it.
Where level 2 is recorded, and where it is not
Level-2 results are never sampled. The IEC 62443-3-2 risk-assessment requirements get one level-2 result for the IACS; service-provider requirements, one per provider; the 2-1 requirements and the two support items, one per policy partition, a part of the IACS the asset owner defines as governed by one set of policies and procedures — for example the whole IACS, one system under consideration, or all zones but one. The partitions must together cover the whole IACS.
Level 3 is where zones and device-bearing conduits enter, and with them sampling; how the certification body chooses them has its own article in this series.
Level-2 results also travel. Where a second IACS of the same asset owner shares policies and procedures with the first, ACSSA-300 allows the level-2 results for the shared policies to be reused while the first remains certified. ACSSA-300 provides no such reuse for level 3, whose results are recorded per zone, device-bearing conduit, system under consideration or service provider of the IACS being evaluated.
What practised evidence looks like
ACSSA-101 describes three ways an evaluator gathers evidence: reviewing documents and artifacts, interviewing personnel, and inspecting systems and networks. Level 2 is largely the first. ACSSA-304 names Phase 2 of its four phases the maturity-level-2 evaluation and Phase 3 the maturity-level-3 evaluation; Phases 1, 2 and 4 may be done remotely, but Phase 3 is on site, including service-provider sites.
The evaluator does not test. ACSSA-304 is explicit that the evaluator performs no testing and does not access devices: where a control must be exercised, an asset-owner representative exercises it while the evaluator observes, and configurations are provided by the asset owner or viewed as its staff access them. Interviews are mandatory and reach, for measures people carry out, at least one representative of each relevant functional role within the sampled scope, unless the report justifies otherwise.
Practised evidence is therefore whatever shows the procedure ran here, what ACSSA-101 calls execution artifacts. Typical examples are training, change, incident and review records, and configurations that match the procedure. An operations-ready IACS is evaluated to the same criteria; where live evidence cannot yet exist, other forms are accepted, and ACSSA-300's surveillance rules (R26) require a later re-check against live evidence.
Service-provider requirements are evaluated at both levels too, but the level is the asset owner's, not the provider's: ACSSA asks whether the provider's documented process (level 2) and its execution for this IACS (level 3) support the owner's level on the associated 2-1 requirement. A level-3 IEC 62443-2-4 certificate from a body accredited by an IAF MRA signatory, where it covers the tasks delegated for this IACS, passes the corresponding ACSSA requirement at level 2 without further evidence; at level 3 it does not, because level 3 needs evidence that the delegated task was executed for this IACS.
What this means for preparation
Do not plan level 2 as a stepping stone unless you are choosing inspection. Certification does not stop at level 2; a program documented but not yet followed everywhere is not ready. Inspection gives per-requirement results without an overall verdict.
For every requirement, ask where the record is. The documented procedure answers level 2. Level 3 is answered by what the procedure left behind the last time it ran, on this IACS, and by the people who ran it.
Treat capabilities as things to use, not to own. A capability present in a zone but switched off or unconfigured does not satisfy the level-3 aspect; product certificates show that a capability exists, not that it is in use.
Where to go next
The whole series is on the ACSSA filter of the Insights index. For a system certified as its supplier sells it, at a capability security level rather than a maturity level, see the system as sold, not the installed system.
Frequently asked questions
Level 2 means written policies and procedures for the requirement exist and cover the part of the IACS being examined. Level 3 means those procedures are demonstrably followed for this IACS: the evaluator finds execution records, matching configurations and personnel who can show what they do. ACSSA records a separate result at each level, and the level-3 result also takes in whether the technical capabilities associated with the requirement are configured and in use in the zones evaluated.