SSAIntermediateExplainer

A system as sold: IEC 62443-3-3 system certification scope under ISASecure SSA, and what falls outside it

ISASecure SSA certifies a control-system product as sold, at a version, in a fixed or scalable layout: the four eligibility criteria and what falls outside.

Perseus ISASecure Assessor TeamSeptember 8, 20268 min read

"System" is the most misread word in the name of the ISASecure System Security Assurance program. It does not mean a plant, a site, or the control system an integrator commissioned last year. It means a control-system product: something one supplier sells, at a version, in a layout or a defined family of layouts, and stands behind as a whole. Nothing installed anywhere is ever "SSA certified".

This article covers what qualifies as a system, how the supplier draws the boundary and its zones, what the certificate names, and what falls outside. The rest of the series is on the SSA filter of the Insights index.

What "system" means in the SSA documents

ISASecure SSA-100, the scheme description, and ISASecure SSA-300, the certification requirements, use "system" as shorthand for a control-system product offered by a single supplier. It is evaluated at a stated version and in a stated layout or family of layouts, against IEC 62443-3-3 for each zone's security capabilities and against IEC 62443-4-1 for the lifecycle artifacts produced for it. Control systems here include safety systems.

The client is the system supplier: SSA is a supplier's certification of a product, not an asset owner's certification of a deployment.

The four eligibility criteria

SSA-100 and SSA-300 set four conditions a product must meet before it can be submitted. In our own words:

#CriterionWhat it means in practiceWhat typically fails it
1More than one componentSeveral components engineered to operate as one product; two is the minimum.A single controller, switch or software package. That is a component, certified under CSA or ICSA.
2One supplier offers and supports the wholeA single supplier sells the product as a unit and takes responsibility for all of it. The parts may be made by several manufacturers.A collection of products from different vendors that nobody sells or supports as one thing.
3A fixed layout, or one that scales by ruleEither the arrangement of components is fixed, or the product grows by replicating components, zones or both under stated rules.A system whose shape is decided afresh for each customer, with no defined family.
4Configuration and version controlThe product is kept under configuration management and carries a version, so that what was evaluated can be identified later.A build that cannot be pinned to a version and a bill of materials.

Criterion 2 decides most borderline cases: a system built for one customer by an integrator, or by the asset owner's own engineers, fails it unless a single supplier then offers and supports the assembly as a product. As an ISASecure certification body, we apply these four criteria to every application before anything else is evaluated.

Components: four kinds, at least two

A system is made of components of the four IEC 62443 kinds: embedded device, host device, network device and software application, each defined in a line in the CSA hub article. A system needs at least two.

SSA does not require any component to hold a CSA or ICSA certificate, and a first SSA certification is initial either way. Nor does a component's own functional evaluation carry into the system's. The one reuse allowed is on the vulnerability scan, where a CSA-certified component's interfaces may be skipped while its own scan remains current under ISASecure SSA-420 §6.

The components may come from several manufacturers. Criterion 2 asks who offers and supports the whole, not who made the parts.

A single component is never a system. One device or one software package belongs in CSA, or in ICSA if it is an IIoT device or gateway.

The supplier draws the box

The supplier, not the certifier, states where the system ends, on the architecture diagram submitted with the application. Under SSA-300 requirement SY.R7 the diagram has to make the boundary explicit: where the product ends, where each security zone inside it begins and ends, which components sit in it and how they connect, and what traffic leaves the box.

The zone boundaries matter because the zone is the unit of the certified level. Each zone gets its own capability security level, SL-C 1 to 4: the applicant names the maximum wanted per zone and the certifier awards the highest level the zone qualifies for, up to that maximum (SSA-300 requirement SY.R4), so one certificate can carry different levels on different zones. The level is a capability level: what the product itself can deliver once set up as its documentation says, before anything in the surrounding installation adds protection. It is not the asset owner's target level for the zone the product will end up in, a different concept and not what SSA certifies.

Conduits may be drawn between zones, as the SSA-303 sample report's context drawing does, because the scheme uses the IEC 62443 zone-and-conduit model; but it scores and certifies zones only: no SSA requirement addresses a conduit.

Why a safety zone alone can be a system

The scheme does not dictate which functions a supplier bundles into one product; that is the supplier's commercial choice, which the certifier takes as given. A safety instrumented system offered as a product in its own right, two or more components, sold and supported as a whole, with a defined layout and a version, meets the four criteria and can be certified as a system with one zone or several. The same safety zone may equally sit as one zone inside a larger certified system. Which the supplier submits depends on how the product is sold, not on any rule in the scheme.

Fixed layout or a family of layouts

Criterion 3 leads to what most distinguishes system from component certification: a certificate can cover one fixed arrangement or a whole family, defined by rule rather than by list.

Under SSA-300 requirements SY.R1 and SY.R2, each zone type is defined by what may live in it, how many, which protocols it speaks and which capability level is sought for it; the family is the set of zone-instance counts the supplier stands behind. The smallest layout in the family is held to the same zone requirements as the largest. A later article in the series covers the layout rules.

From the family the supplier derives one reference layout holding every zone, every permitted component type per zone, and every protocol, software item and interface present anywhere in the family, and builds a physical instance of it: the reference system. The certifier tests that reference system and analyses every layout in the family. Test the reference, analyse the family.

What falls outside SSA

Together, the criteria leave the following outside the program:

  • A single component. One device or one software package is a CSA or ICSA matter.
  • A system assembled for one site by an integrator or the asset owner, from one or several vendors' products. It enters SSA only if a single supplier then offers and supports the assembly as a whole; otherwise the site-specific system is the domain of ISASecure's asset-owner program, not of SSA.
  • Any installation. Neither the plant nor the installed instance is certified; "our site is SSA certified" is never a correct statement.
  • Configurations outside the declared family. A layout beyond the stated counts, or one adding a component type or protocol the reference layout did not contain, is not covered.

What the certificate names, and how to read it

An SSA certificate is issued for a system version and a layout or set of layouts, and names every zone with the capability level it was certified to and the ISASecure certification version applied. Any public statement of certification status, whether from ISCI, the certifier or the supplier, has to pin the exact system version, state which layouts it applies to and name the certification version (SSA-300 requirement SY.R5); ISCI lists certified systems with the supplier's permission. The supplier must also hold an ISASecure SDLA certificate when the SSA certificate is issued, with the system inside the certified process's scope (see the SDLA article). Changes after issue, a modified version or a zone taken to a higher level, are governed by a separate ISCI document, SSA-301.

For an asset owner the certificate is a procurement fact about a product, zone by zone: the capability level each zone provides when configured as the supplier documents, at a stated version and in stated layouts. It says nothing about the level your plant achieves; that depends on your zone design, your target levels and the countermeasures around the product, matters for your own IEC 62443 risk assessment. Check that the version and layout you buy are the ones on the certificate.

For an integrator the certificate is design input. You still draw the installation's zones and conduits and pick their levels; the certified SL-C per zone tells you what the product contributes to a zone you place it in. A deployment built from a certified system is not itself certified, and a system you assemble for a customer enters SSA only if a single supplier, which could be you, offers and supports it as a product.

For a supplier the lesson is to draw the box deliberately. Decide what you sell as one thing, how it scales, where its zones are and what level each zone should carry, and write it down as a version. That box, and only that box, is what the certificate attests.

Frequently asked questions

No. An SSA certificate belongs to a product: a control system as one supplier sells it, at a version, in the layout or family of layouts named on the certificate. An installation built from that product is not itself certified, and neither is the site. What the certificate gives an asset owner is a statement of the capability level the product provides in each of its zones when configured as documented.

IEC 62443-3-3 system certificationISASecure SSAsystem security assurancesecurity zonereference layoutsystem supplier
Share this article
Back to Insights

Ready to Get Started?

Let our team of experts help you achieve and maintain compliance with industry-leading cybersecurity standards.