ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
20 articles match your filters
How ACSSA assesses IEC 62443-2-1 requirements: 89 composite verdicts from four standards
How ISASecure ACSSA folds IEC 62443-2-4, 3-2 and 3-3 results into one composite verdict per IEC 62443-2-1 requirement, and what makes a verdict fail.
After the certificate: ACSSA surveillance in years one and two, recertification in year three
How an ISASecure ACSSA certificate stays valid: 36 months, surveillance in years one and two, recertification in year three, nonconformities and suspension.
IEC 62443-2-1 audit evidence in an ACSSA evaluation: documents, interviews and inspection, never testing
How an ISASecure ACSSA evaluator gathers evidence on an installed IACS: documents, interviews and configuration inspection, never testing or device access.
The ACSSA assessment process: four phases and the report you receive
How an ISASecure ACSSA evaluation runs: the plan you approve, the four ACSSA-304 phases from risk assessment to report, and how to read the ACSSA-303 report.
An asset owner's installed IACS: IEC 62443 asset owner certification scope under ISASecure ACSSA, and the six documents that define it
ISASecure ACSSA certifies an asset owner's installed IACS, bounded by six change-controlled documents: who may apply, what is in scope and what is carved out.
IEC 62443-2-1 maturity level 2 vs 3: why ISASecure ACSSA certification needs level 3 on every requirement
In ISASecure ACSSA, maturity level 2 means a requirement is documented and level 3 means it is practised. Certification needs level 3 on every requirement.
IEC 62443 zone sampling in an ACSSA assessment: how zones, conduits and systems are sampled at maturity level 3
Where ISASecure ACSSA samples zones, device-bearing conduits and systems at maturity level 3, how the evaluator chooses the sample, and what to have ready.
IEC 62443 target security levels in ACSSA: the asset owner's level decides what is checked, and nothing is awarded
How ACSSA uses each zone's target security level from the asset owner's IEC 62443-3-2 risk assessment to decide what is checked, and why no level is awarded.
Service providers in ACSSA: IEC 62443-2-4, delegated tasks and the VIC shortcut
How ISASecure ACSSA evaluates an asset owner's service providers against IEC 62443-2-4: who counts, delegated tasks, the agreed list, NR-A and the VIC result.
ACSSA evaluation results: ten result types, and the one that fails
ACSSA records ten result types across four IEC 62443 parts. Only Not met fails; three others pass only with approved documentation; unsampled zones get none.
What ISASecure ACSSA certification actually evaluates
ISASecure ACSSA certifies an asset owner's installed control system against IEC 62443-2-1, 3-2, 3-3 and 2-4 at maturity level 3. Here is the map.
The Security Maintenance Audit: how an ISASecure ICSA certificate stays valid
How the ISASecure ICSA Security Maintenance Audit works: four IEC 62443-4-1 requirements, four topics, when audits fall, findings, suspension, withdrawal.
SDLA certificate validity and recertification: how an ISASecure SDLA certificate is kept
How long an ISASecure SDLA certificate lasts, 36 or 12 months, how a recertification audit renews it, and why the scheme has no surveillance or suspension.
IEC 62443-4-1 defect and update management: the SDLA practices product certifications come back to
How ISASecure SDLA evaluates IEC 62443-4-1 defect and update management: 15 rows, most seen only in the process audit, and the four requirements ICSA revisits.
IEC 62443-4-1 security guidelines and hardening: the SDLA practice with the most minimum requirements
ISASecure SDLA and the IEC 62443-4-1 security guidelines practice: 7 requirements, 17 rows, 10 minimum requirements, no mandatory artifacts, examined twice.
What is ISASecure SDLA, and what does the certificate actually certify?
ISASecure SDLA certifies a development organisation and a versioned development process against IEC 62443-4-1: eight practices, 47 requirements, no levels.
One certificate, several levels: how ISASecure SSA assigns a capability security level per zone
How ISASecure SSA assigns an IEC 62443 capability security level to each zone of a system, why one certificate can carry several levels, and how to specify it.
How to read an ISASecure SSA certificate and report: zones, levels and user-enforced mitigations
How to read an ISASecure SSA certificate and its SSA-303 report: capability levels per zone, the ten report sections, and the mitigations the user must apply.
A system as sold: IEC 62443-3-3 system certification scope under ISASecure SSA, and what falls outside it
ISASecure SSA certifies a control-system product as sold, at a version, in a fixed or scalable layout: the four eligibility criteria and what falls outside.
What ISASecure SSA certification actually evaluates
ISASecure SSA certifies a control system as sold against IEC 62443-3-3, with a capability security level per zone. Four elements, 116 functional rows: the map.
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.