Insights

ISASecure and IEC 62443, explained with the numbers

What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.

Filteractive

10 articles match your filters

CSAIntermediate

SDA-C, FSA-C and VIT-C: what each ISASecure CSA assessment stream proves

The ISASecure CSA assessment process, stream by stream: what SDA-C, FSA-C and VIT-C each prove, the five result outcomes, the pass rule and the certificate.

Sep 8, 20268 min readRead
CSAIntermediate

The SDLA prerequisite: why ISASecure CSA needs it, and what the SDA-C artifact review adds

ISASecure CSA requires a valid SDLA certificate. What the process certificate covers, what the component-level SDA-C review adds, and what to prepare.

Sep 8, 20267 min readRead
ICSAIntermediate

SDA-IC: the 93 lifecycle requirements checked per IIoT component, and the five ICSA-only practices

What ICSA's SDA-IC review checks per IIoT component: 93 of the 118 IEC 62443-4-1 lifecycle requirements, 16 IIoT-specific rows and five ICSA-only practices.

Sep 8, 20268 min readRead
ICSAIntermediate

The Security Maintenance Audit: how an ISASecure ICSA certificate stays valid

How the ISASecure ICSA Security Maintenance Audit works: four IEC 62443-4-1 requirements, four topics, when audits fall, findings, suspension, withdrawal.

Sep 8, 20268 min readRead
SDLAIntermediate

SDLA certificate validity and recertification: how an ISASecure SDLA certificate is kept

How long an ISASecure SDLA certificate lasts, 36 or 12 months, how a recertification audit renews it, and why the scheme has no surveillance or suspension.

Sep 8, 20268 min readRead
SDLAIntermediate

Full or readiness evaluation: the SDLA choice that sets your certificate at 36 or 12 months

ISASecure SDLA has two evaluation methods. One requirement passed by readiness evaluation sets the certificate at 12 months, not 36. The 21 rows that decide it.

Sep 8, 20269 min readRead
SDLAIntermediate

What counts as a major nonconformity in an IEC 62443-4-1 audit: the 31 SDLA minimum requirements

In an ISASecure SDLA audit a finding is major when no evidence exists, or when one of 31 minimum requirements is applied inconsistently. The full list.

Sep 8, 202610 min readRead
SDLAIntermediate

IEC 62443-4-1 certification levels: why ISASecure SDLA has none and every requirement must pass

ISASecure SDLA carried certification levels until 2018. Today it has none, and no maturity level either: every applicable IEC 62443-4-1 requirement must pass.

Sep 8, 20268 min readRead
SDLAIntermediate

The SDLA prerequisite for CSA, ICSA and SSA: one process audit, three product schemes

ISASecure CSA, ICSA and SSA each require a valid SDLA certificate. What the process audit settles once, what every product scheme re-checks, and how to plan.

Sep 8, 20269 min readRead
SSAIntermediate

How to read an ISASecure SSA certificate and report: zones, levels and user-enforced mitigations

How to read an ISASecure SSA certificate and its SSA-303 report: capability levels per zone, the ten report sections, and the mitigations the user must apply.

Sep 8, 20269 min readRead

Have a product or system to certify?

Talk to the assessors who wrote these articles about what applies to you.