ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
9 articles match your filters
IEC 62443 target security levels in ACSSA: the asset owner's level decides what is checked, and nothing is awarded
How ACSSA uses each zone's target security level from the asset owner's IEC 62443-3-2 risk assessment to decide what is checked, and why no level is awarded.
CCSC explained: the four IEC 62443-4-2 constraints that apply to every component
IEC 62443-4-2 has a second axis beyond the seven foundational requirements: four common component security constraints. What each means for a CSA certificate.
The four IEC 62443-4-2 component types, and why the type determination decides your CSA scope
Software application, embedded device, host device or network device: which IEC 62443-4-2 component types apply to your product, and how they set CSA scope.
Cloud links, wireless radios and the per-interface rule in ISASecure ICSA
In ISASecure ICSA, cloud and wireless links are ordinary accessible interfaces. How the per-interface rule and the untrusted-network declaration set the effort.
IIoT device or IIoT gateway: how the two ISASecure ICSA types decide your scope
Which of ISASecure ICSA's two IIoT types your product is, how the IEC 62443-4-2 families split between device and gateway, and why one product can carry both.
The 24 IIoT-specific requirements ISASecure ICSA adds to IEC 62443-4-2
ISASecure ICSA adds 24 IIoT-specific requirements to the IEC 62443-4-2 base: 18 at both tiers, 6 at Advanced only. What they cover and how to prepare.
One certificate, several levels: how ISASecure SSA assigns a capability security level per zone
How ISASecure SSA assigns an IEC 62443 capability security level to each zone of a system, why one certificate can carry several levels, and how to specify it.
IEC 62443-3-3 requirements: how ISASecure SSA evaluates all 100 clauses in FSA-S
ISASecure SSA's FSA-S stream covers every clause of IEC 62443-3-3: 51 system requirements and 49 enhancements, laid out as 116 rows and scored zone by zone.
A system as sold: IEC 62443-3-3 system certification scope under ISASecure SSA, and what falls outside it
ISASecure SSA certifies a control-system product as sold, at a version, in a fixed or scalable layout: the four eligibility criteria and what falls outside.
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.