ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
9 articles match your filters
The ACSSA assessment process: four phases and the report you receive
How an ISASecure ACSSA evaluation runs: the plan you approve, the four ACSSA-304 phases from risk assessment to report, and how to read the ACSSA-303 report.
An asset owner's installed IACS: IEC 62443 asset owner certification scope under ISASecure ACSSA, and the six documents that define it
ISASecure ACSSA certifies an asset owner's installed IACS, bounded by six change-controlled documents: who may apply, what is in scope and what is carved out.
What ISASecure ACSSA certification actually evaluates
ISASecure ACSSA certifies an asset owner's installed control system against IEC 62443-2-1, 3-2, 3-3 and 2-4 at maturity level 3. Here is the map.
SDA-C, FSA-C and VIT-C: what each ISASecure CSA assessment stream proves
The ISASecure CSA assessment process, stream by stream: what SDA-C, FSA-C and VIT-C each prove, the five result outcomes, the pass rule and the certificate.
What ISASecure CSA certification actually evaluates
ISASecure CSA certifies a component against IEC 62443-4-2: 166 functional requirements, four component types, three assessment streams and one security level.
What ISASecure ICSA certification actually evaluates
ISASecure ICSA certifies IIoT devices and gateways against IEC 62443-4-2: 182 requirements, two device types, a Core or Advanced tier and a maintenance audit.
The SDLA prerequisite for CSA, ICSA and SSA: one process audit, three product schemes
ISASecure CSA, ICSA and SSA each require a valid SDLA certificate. What the process audit settles once, what every product scheme re-checks, and how to plan.
How to read an ISASecure SSA certificate and report: zones, levels and user-enforced mitigations
How to read an ISASecure SSA certificate and its SSA-303 report: capability levels per zone, the ten report sections, and the mitigations the user must apply.
What ISASecure SSA certification actually evaluates
ISASecure SSA certifies a control system as sold against IEC 62443-3-3, with a capability security level per zone. Four elements, 116 functional rows: the map.
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.