Insights

ISASecure and IEC 62443, explained with the numbers

What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.

Filteractive

11 articles match your filters

ACSSADeep dive

How ACSSA assesses IEC 62443-2-1 requirements: 89 composite verdicts from four standards

How ISASecure ACSSA folds IEC 62443-2-4, 3-2 and 3-3 results into one composite verdict per IEC 62443-2-1 requirement, and what makes a verdict fail.

Sep 8, 20269 min readRead
ACSSAIntermediate

After the certificate: ACSSA surveillance in years one and two, recertification in year three

How an ISASecure ACSSA certificate stays valid: 36 months, surveillance in years one and two, recertification in year three, nonconformities and suspension.

Sep 8, 20269 min readRead
ACSSAIntermediate

The ACSSA assessment process: four phases and the report you receive

How an ISASecure ACSSA evaluation runs: the plan you approve, the four ACSSA-304 phases from risk assessment to report, and how to read the ACSSA-303 report.

Sep 8, 20269 min readRead
ACSSAIntermediate

An asset owner's installed IACS: IEC 62443 asset owner certification scope under ISASecure ACSSA, and the six documents that define it

ISASecure ACSSA certifies an asset owner's installed IACS, bounded by six change-controlled documents: who may apply, what is in scope and what is carved out.

Sep 8, 20269 min readRead
ACSSAIntermediate

ACSSA evaluation results: ten result types, and the one that fails

ACSSA records ten result types across four IEC 62443 parts. Only Not met fails; three others pass only with approved documentation; unsampled zones get none.

Sep 8, 20268 min readRead
ACSSAIntroductory

What ISASecure ACSSA certification actually evaluates

ISASecure ACSSA certifies an asset owner's installed control system against IEC 62443-2-1, 3-2, 3-3 and 2-4 at maturity level 3. Here is the map.

Sep 8, 20268 min readRead
ICSAIntermediate

The Security Maintenance Audit: how an ISASecure ICSA certificate stays valid

How the ISASecure ICSA Security Maintenance Audit works: four IEC 62443-4-1 requirements, four topics, when audits fall, findings, suspension, withdrawal.

Sep 8, 20268 min readRead
SDLAIntermediate

SDLA certificate validity and recertification: how an ISASecure SDLA certificate is kept

How long an ISASecure SDLA certificate lasts, 36 or 12 months, how a recertification audit renews it, and why the scheme has no surveillance or suspension.

Sep 8, 20268 min readRead
SDLAIntroductory

What is ISASecure SDLA, and what does the certificate actually certify?

ISASecure SDLA certifies a development organisation and a versioned development process against IEC 62443-4-1: eight practices, 47 requirements, no levels.

Sep 8, 20268 min readRead
SSAIntermediate

How to read an ISASecure SSA certificate and report: zones, levels and user-enforced mitigations

How to read an ISASecure SSA certificate and its SSA-303 report: capability levels per zone, the ten report sections, and the mitigations the user must apply.

Sep 8, 20269 min readRead
SSAIntroductory

What ISASecure SSA certification actually evaluates

ISASecure SSA certifies a control system as sold against IEC 62443-3-3, with a capability security level per zone. Four elements, 116 functional rows: the map.

Sep 8, 20268 min readRead

Have a product or system to certify?

Talk to the assessors who wrote these articles about what applies to you.