An ACSSA certificate belongs to one asset owner and describes that owner's installed industrial automation and control system. Few owners run such a system alone; integrators, maintenance contractors and sometimes a corporate IT group work on it. ISASecure ACSSA reaches them through IEC 62443-2-4, the part of the series written for integration and maintenance service providers, and narrowly: each provider is examined only for the tasks the asset owner has handed to it for this system.
Who counts as a service provider
The service-provider list is one of the six change-controlled documents by which the asset owner defines the IACS under ACSSA-300's first numbered requirement. An organisation belongs on it when the owner expects it to carry out integration or maintenance work on the system's cyber or cyber-physical components within the three and a half years after the application: the three years to recertification plus a six-month margin.
Two kinds of organisation qualify. An external provider works under a contract with the owner, or a subcontract down the chain. An internal unit qualifies when it works under a documented agreement and outside the owner's direct management; designating it a service provider is the owner's decision.
No provider is ever the applicant. The owner applies, holds the certificate and answers for the system; a provider supplies evidence about the part of the IACS it works on. System integrators sit here too: a system offered and supported as a whole by one supplier is SSA's domain, as the article on the system as sold explains; one assembled and installed for a single owner is ACSSA's, and its integrator takes part as a service provider, not a certificate holder.
Delegated tasks: one result per provider, never sampled
ACSSA-300 Table 1 gives each qualifying service provider one result, at each maturity level, for every IEC 62443-2-4 requirement on its agreed applicable list, noting the part of the IACS each covers; NR-A is the result for a requirement whose task the asset owner has not delegated to that provider. Every qualifying provider is evaluated: ACSSA's level-3 sampling covers zones, device-bearing conduits and systems under consideration, never providers.
The pool is IEC 62443-2-4:2023 as the ACSSA-311 workbook (version 1.3, February 2026) carries it: 123 requirements, 72 base requirements and 51 requirement enhancements, one evaluation method each, in twelve functional areas, SP.01 to SP.12. Unlike security-program and capability requirements, a 62443-2-4 requirement carries no security level.
72 base requirements and 51 enhancements, evaluated per service provider only for the tasks delegated for the IACS under evaluation. Source: ISASecure ACSSA-311 v1.3.
A 62443-2-4 result is never a verdict in its own right: each of the 123 is associated with at least one asset-owner requirement from IEC 62443-2-1, and its result is folded into that requirement's composite verdict. The maturity level on it is not the provider's maturity as a 62443-2-4 certification would grade it; it is the level of support given to the owner's requirement: at level 2, whether the provider's process is documented; at level 3, whether it was carried out for this IACS. ACSSA-304 places the level-2 evaluation of providers in Phase 2, after each provider's task scope is mapped onto 62443-2-4, and the level-3 evaluation in Phase 3.
The agreed list, and the SP.01 set that applies to nearly every provider
Which of the 123 apply to a given provider is agreed between the evaluator and the asset owner; ACSSA-300's seventh numbered requirement sets out what the owner supplies for each provider.
| Item | What the asset owner provides for each provider |
|---|---|
| Identity | The provider's legal entity |
| Task | A name for the delegated task and a brief statement of what it involves |
| Basis | The parts of the contract or subcontract that describe the task; where the work lies ahead, a draft agreement will do, provided it is under change control |
| Internal agreement | The service agreement between the owner and an internal unit it has designated a provider |
| No contract available | An agreed task description, where an external provider's or subcontractor's contract cannot be produced |
| Applicable requirements | The list of 62443-2-4 requirements that apply to this provider, agreed with the evaluator |
| Certificates | Any relevant 62443-2-4 certificate at maturity level 3 or 4 that the provider holds |
One part of every list is fixed by ACSSA-300 Table 4, which names ten SP.01 requirements tied to three asset-owner requirements from the organisational family, ORG 1.2, ORG 1.3 and ORG 1.5, and says which kinds of provider each applies to. Most apply to every provider; the exceptions are reserved for providers with security-lead staff and for those whose tasks touch the automation equipment and its network links. Every list must include the ones Table 4 assigns to that kind of provider; the rest follows from the delegated tasks. As an ISASecure certification body, Perseus evaluates a provider against that agreed list and nothing wider.
Five result types, one of them a shortcut
Of ACSSA's ten result types, five can be recorded on a 62443-2-4 requirement.
| Abbreviation | Meaning, in plain terms | Effect |
|---|---|---|
| M | The evaluator confirmed that the provider satisfies the requirement at this maturity level for its delegated tasks | Pass |
| NM | The evaluator could not confirm it: the evidence is missing, or the process is not followed | The only failing result |
| NR-A | The work behind the requirement was never handed to this provider | Pass |
| VIC | The provider holds a qualifying third-party 62443-2-4 certificate covering the requirement | Pass, at maturity level 2 only |
| NF | The requirement is not feasible, or the law does not allow it, for this IACS | Pass, with documentation approved by the asset owner and every affected stakeholder |
NR-A is the routine result for work a provider does not do; the workbook offers it on all 123 methods at both levels. NF, one of ACSSA's three special circumstances, is offered on exactly two 62443-2-4 items, SP.01.04 and its enhancement, both on background checks. A Not met at either level is a nonconformity; its record names the provider, the 62443-2-4 requirement and the asset-owner requirement it supports. ACSSA-303 states that an asset-owner requirement passes only when its associated requirements pass, so the provider's Not met holds up that composite verdict and, under ACSSA-300's decision rule, the certificate, until the nonconformity is closed: a correction plan accepted within 30 days, closure within 90.
VIC: what a provider's own certificate buys
Many providers hold their own 62443-2-4 certificate, and ACSSA gives it a defined value through the result VIC, verified by independent certification. The conditions, in gist: issued at maturity level 3; relevant to the requirement and to the tasks performed on this IACS; issued by a certification body accredited by an IAF MRA signatory; and valid for the period in which the service was performed, or, for work still ahead, valid when the ACSSA report is issued.
When those hold, VIC passes the requirement for that provider at ACSSA maturity level 2, and only there. Level 2 asks whether the provider's process is documented, which a level-3 certificate attests well. Level 3 asks whether it was executed for this IACS, which no outside certificate can show; the ACSSA documents say a stand-alone level-3 62443-2-4 certification only partially implies ACSSA level 3. A level-2 62443-2-4 certificate is not accepted at all. The workbook offers VIC at level 2 on 122 of the 123 service-provider methods and at level 3 on none (the exception is SP.12.07; no reason is stated).
The certificate settles the documentation half; records of the work on this owner's system are still needed, and the evaluator, not the provider or the owner, determines the level reached.
Five consistency conditions
ACSSA-300 requires the finished result set to satisfy ten consistency conditions, five of which concern 62443-2-4. In gist:
- If every asset-owner requirement that a 62443-2-4 requirement supports is itself not required or not feasible, that requirement is NR-A for every provider.
- A provider to which the agreed list makes a requirement applicable cannot receive NR-A on it.
- Met at maturity level 3 needs Met or VIC at maturity level 2.
- NR-A appears at both maturity levels or at neither.
- NF appears at both maturity levels or at neither.
These are checks on a completed result set, not a way of filling it in: except between the two maturity levels, an evaluator may not derive one part's result from another's, so that later results test earlier ones.
Where providers appear in the report
Providers appear in the ACSSA-303 report at three points: the target-of-evaluation section lists them (the report's Table 4); the statistics section charts 62443-2-4 results by functional area (Figure 3); and section 11, results by service provider, holds Tables 29 to 31. The same results also feed the composites in Table 12. The third of a passing certification report's three statements of conformity is that the integration and maintenance services performed for the IACS conform to the applicable 62443-2-4 requirements.
What a provider should expect to be asked
Providers enter an ACSSA evaluation through the asset owner, whose requests follow from the rules above: contract extracts or a task description precise enough to map onto 62443-2-4; agreement on the applicable list, Table 4's SP.01 requirements included; at level 2, the documented processes behind each applicable requirement; at level 3, records showing that those processes ran on this IACS; any 62443-2-4 certificate with its scope, for VIC; and people to interview. ACSSA-101 lists provider contracts, agreements and execution artifacts among the documents gathered, and provider staff among the interviewees. Phase 3, the level-3 evaluation, is conducted on site, and that includes service-provider sites. The evaluator performs no testing and does not access devices; a provider answers from its own records and staff.
The relationship outlasts the initial evaluation: general surveillance in years one and two reviews new or changed provider tasks and personnel, and detailed surveillance can re-evaluate level 3 where IACS changes may have moved a 62443-2-4 result. That is why the list looks three and a half years ahead.
Where to go next
The rest of this series is on the ACSSA filter of the Insights index. For the boundary between an installed system and a system as sold, see what SSA certifies.
Frequently asked questions
It is if the asset owner expects it to carry out integration or maintenance work on the IACS at some point in the three and a half years after the application. It then goes on the service-provider list, one of the six documents that define the IACS, and is evaluated against IEC 62443-2-4 for those tasks only. An integrator whose work is finished, with nothing further planned in that window, is not evaluated as a provider, although for an integrated system ACSSA-300 still points to it as the first source of the system documentation the evaluation needs. In neither case is the integrator the applicant.