Ask what level an ISASecure SSA certificate is "at" and the accurate answer is another question: which zone? An SSA certificate lists the security zones the supplier defined inside the system and states a capability security level for each, and those levels need not match. Here is why, how each zone's level is set, and how to specify it.
The zone is the unit of the level
SSA certifies a control-system product as one supplier sells it: a stated version, with a stated layout or family of layouts. Inside that boundary the supplier partitions the system into security zones, each a group of components the supplier intends to protect to one level. The zone breakdown arrives with the application, on the architecture diagram alongside the system boundary, every component and every connection.
Each zone then carries its own capability security level, written SL-C, from 1 to 4. The functional assessment runs zone by zone, each against its own level's requirement set, and the certificate names every zone with its certified level. In a scalable system, where a zone type may be replicated, every instance of that type shares one level. That is the structural difference from CSA, where one level covers the whole component.
Capability, not target
IEC 62443 attaches "security level" to more than one thing, among them a target level and a capability level, and an SSA certificate states exactly one of them.
An asset owner assigns a target level to each zone of a facility: the protection that zone needs, as the owner's risk assessment sees it. A product has a capability level: what its own security functions support when configured as the supplier documents, without counting compensating measures the owner adds. SSA certifies capability: a zone certified at SL-C 2 is one for which every FSA-S row in scope at level 2 was assessed for that zone and none came back not supported, with the lifecycle review and the vulnerability scan also passing at that level.
A supplier's certificate cannot state a target level, because a target belongs to a zone in the owner's plant, not to the product. It supplies the other half of the comparison: a stated capability to hold up against the target. Whether that suffices, and what compensating measures close any gap, is the owner's decision; the evaluation does not assess them. One owner-side dependency is recorded: the SSA-303 report lists the user-enforced risk mitigations the supplier relies on and conditions its conformity statement on them.
You name a maximum; the zone earns its level
The level printed for a zone is not simply the level the supplier asked for. Under the scheme's certification requirements (ISASecure_SY.R4), the applicant states, for each zone, the maximum capability level it wants certified, and the certifier awards each zone the highest level it qualifies for, up to that maximum.
First, a zone can land below what was asked. A zone put forward at SL-C 3 that misses a criterion applicable only at level 3 can still be certified at level 2 if it meets everything applicable there and the rest of the evaluation passes at that level. The application names a ceiling; the evaluation finds the level.
Second, the levels on one certificate need not match. ISCI's own illustration is a system with two zones at SL-C 1 and a safety zone at SL-C 2. That is the point: the supplier need not lift every zone to the most sensitive zone's level, and the buyer sees which part of the product carries the higher assurance.
What a zone's level changes in the evaluation
Of the four elements of an SSA evaluation, three barely move with the level. The SDLA prerequisite (SDLPA-S) has no level. The review of development-lifecycle artifacts (SDA-S) is the same at every level except one row, SDLA-DM-4, whose check follows the zone's level. The vulnerability identification scan (VIT-S) runs the same way at every level, but its pass threshold is set per component by its zone's level: critical findings must be addressed at SL-C 1, high findings join at SL-C 2, medium at SL-C 3 and every finding at SL-C 4, addressed meaning either fixed, or dismissed with a written reason why the finding does not apply to the product. A safety zone at 2 beside zones at 1 means two scan thresholds in force at once, and a pass never means zero findings.
The element that grows is FSA-S, the functional assessment against IEC 62443-3-3 through the SSA-311 workbook, and its applicability is cumulative: every row in scope at SL 1 stays in scope at SL 2 and above.
Applicability is cumulative: a zone certified at SL 3 is assessed against every row applicable at SL 1, 2 and 3. No requirement enhancement applies at SL 1; SL 4 is the full set. Source: ISASecure SSA-311 v2.2.
A zone at SL-C 1 is assessed against 48 of the 116 rows; SL-C 2 brings 76 into scope, SL-C 3 brings 106, and SL-C 4 the full 116. No requirement enhancement applies at SL 1: that level is 37 of the 51 base system requirements plus 11 of the enumerated items into which the workbook splits four base requirements. Twelve more base requirements enter at SL 2 and the last two at SL 3; above SL 2 the growth is almost entirely enhancements of requirements already in scope. The steps are 28, 30 and 10 rows.
Spread across the seven foundational requirements, the growth is uneven.
| Foundational requirement | SL 1 | SL 2 | SL 3 | SL 4 |
|---|---|---|---|---|
| FR 1 Identification & authentication control | 14 | 25 | 31 | 33 |
| FR 2 Use control | 15 | 19 | 28 | 31 |
| FR 3 System integrity | 5 | 10 | 16 | 19 |
| FR 4 Data confidentiality | 2 | 4 | 5 | 6 |
| FR 5 Restricted data flow | 4 | 6 | 10 | 11 |
| FR 6 Timely response to event | 1 | 2 | 3 | 3 |
| FR 7 Resource availability | 7 | 10 | 13 | 13 |
Cumulative row counts a zone is assessed against at each capability security level. Source: ISASecure SSA-311 v2.2.
Identification and authentication control and use control together hold more than half the rows at every level; data confidentiality and timely response to event stay small throughout. Timely response to event and resource availability stop growing at SL 3, so the ten rows that enter only at SL 4 fall in the other five families. For a supplier setting a ceiling, this grid is the first effort estimate.
Each row is recorded per zone as S (supported), N/S (not supported) or N/E (not evaluated, because the row does not apply at that zone's level), so the same requirement can be S in one zone and N/E in the next.
Conduits: modelled, not certified
The SSA documents use the zone and conduit model of IEC 62443, and the SSA-303 sample report's context drawing marks the conduits between zones. But the scheme scores and certifies zones only. No SSA requirement addresses conduits and no conduit receives a result. What a conduit would carry is captured on the zone side: each zone's specification lists the protocols used inside it, exchanged with other zones and leaving the system. A specification asking for a "conduit certified at SL 2" asks for something the scheme does not issue.
What this means for procurement language
Ask for the zone list, not "the level". The certificate is a list of zones with a level against each. "The system is SSA certified at SL 2" is at best a summary and at worst wrong, because another zone on the same certificate may be at 1. Name the zones and the level required of each.
Compare zone to zone. Your risk assessment sets a target for each zone of the plant; the certificate gives a capability for each zone of the product. Decide which certified zone hosts which function in your architecture, then check its level against the target there. Any gap is closed by measures outside the product, which the evaluation does not assess; the report's list of required user-enforced risk mitigations shows which owner-side measures the supplier already counts on.
Do not read the certificate as covering the site. It certifies the product as sold, at a version, in the layouts the supplier defined: not an installation, and not the conduits or network design between zones.
Suppliers: set each zone's ceiling on purpose. The maximum you name sets where the evaluation starts: which rows are assessed and which severity threshold the scan findings are judged against. If a zone lands lower, the lower level's row set and threshold are what the certificate rests on. Name the level you intend to evidence in each zone, not one figure for the whole system. As an ISASecure certification body, the first thing we confirm at application is the zone breakdown with its maximum per zone.
Where to go next
The rest of this series, including the article on the 30 rows a zone gains between SL 2 and SL 3, sits under the SSA filter on the Insights index. For the scan threshold's ladder in the component scheme, read the CSA VIT pass threshold by security level; SSA applies the same ladder, per zone.
Frequently asked questions
No. The certificate lists the security zones the supplier defined inside the system and states a capability security level, SL-C 1 to 4, for each zone. The levels can differ: ISCI's own example is a system with two zones at SL-C 1 and a safety zone at SL-C 2. A statement that a system is certified at SL 2 may be true of only one zone on the certificate; check the zone list.