Insights
ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
Topic
Security levels10Tiers (Core / Advanced)5Device & component types9Assessment streams6Testing & verification11Evidence & artifacts16Independent testing5Maturity levels4Sampling1Scope & boundaries16Surveillance & maintenance4Certification process20Common component constraints (CCSC)1Cost & effort3Comparisons4Roadmaps & readiness1
2 articles match your filters
SDLAIntermediate
The SDLA prerequisite for CSA, ICSA and SSA: one process audit, three product schemes
ISASecure CSA, ICSA and SSA each require a valid SDLA certificate. What the process audit settles once, what every product scheme re-checks, and how to plan.
Sep 8, 20269 min readRead
SSAIntermediate
How to read an ISASecure SSA certificate and report: zones, levels and user-enforced mitigations
How to read an ISASecure SSA certificate and its SSA-303 report: capability levels per zone, the ten report sections, and the mitigations the user must apply.
Sep 8, 20269 min readRead
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.