Insights

ISASecure and IEC 62443, explained with the numbers

What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.

Filteractive

10 articles match your filters

ACSSAIntermediate

An asset owner's installed IACS: IEC 62443 asset owner certification scope under ISASecure ACSSA, and the six documents that define it

ISASecure ACSSA certifies an asset owner's installed IACS, bounded by six change-controlled documents: who may apply, what is in scope and what is carved out.

Sep 8, 20269 min readRead
ACSSAIntermediate

IEC 62443 target security levels in ACSSA: the asset owner's level decides what is checked, and nothing is awarded

How ACSSA uses each zone's target security level from the asset owner's IEC 62443-3-2 risk assessment to decide what is checked, and why no level is awarded.

Sep 8, 20268 min readRead
ACSSAIntermediate

Service providers in ACSSA: IEC 62443-2-4, delegated tasks and the VIC shortcut

How ISASecure ACSSA evaluates an asset owner's service providers against IEC 62443-2-4: who counts, delegated tasks, the agreed list, NR-A and the VIC result.

Sep 8, 20269 min readRead
ACSSAIntroductory

What ISASecure ACSSA certification actually evaluates

ISASecure ACSSA certifies an asset owner's installed control system against IEC 62443-2-1, 3-2, 3-3 and 2-4 at maturity level 3. Here is the map.

Sep 8, 20268 min readRead
CSAIntermediate

CCSC explained: the four IEC 62443-4-2 constraints that apply to every component

IEC 62443-4-2 has a second axis beyond the seven foundational requirements: four common component security constraints. What each means for a CSA certificate.

Sep 8, 20268 min readRead
ICSAIntermediate

Cloud links, wireless radios and the per-interface rule in ISASecure ICSA

In ISASecure ICSA, cloud and wireless links are ordinary accessible interfaces. How the per-interface rule and the untrusted-network declaration set the effort.

Sep 8, 20268 min readRead
SSAIntermediate

One certificate, several levels: how ISASecure SSA assigns a capability security level per zone

How ISASecure SSA assigns an IEC 62443 capability security level to each zone of a system, why one certificate can carry several levels, and how to specify it.

Sep 8, 20268 min readRead
SSADeep dive

Reference layouts and scalable systems: how one ISASecure SSA certificate covers a family of configurations

How ISASecure SSA certifies a scalable IEC 62443-3-3 system: zone specifications, layouts in scope, the reference layout the lab tests, and nine submissions.

Sep 8, 202610 min readRead
SSAIntermediate

A system as sold: IEC 62443-3-3 system certification scope under ISASecure SSA, and what falls outside it

ISASecure SSA certifies a control-system product as sold, at a version, in a fixed or scalable layout: the four eligibility criteria and what falls outside.

Sep 8, 20268 min readRead
SSAIntroductory

What ISASecure SSA certification actually evaluates

ISASecure SSA certifies a control system as sold against IEC 62443-3-3, with a capability security level per zone. Four elements, 116 functional rows: the map.

Sep 8, 20268 min readRead

Have a product or system to certify?

Talk to the assessors who wrote these articles about what applies to you.