Insights
ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
Topic
Security levels10Tiers (Core / Advanced)5Device & component types9Assessment streams6Testing & verification11Evidence & artifacts16Independent testing5Maturity levels4Sampling1Scope & boundaries16Surveillance & maintenance4Certification process20Common component constraints (CCSC)1Cost & effort3Comparisons4Roadmaps & readiness1
2 articles match your filters
CSAIntermediate
The SDLA prerequisite: why ISASecure CSA needs it, and what the SDA-C artifact review adds
ISASecure CSA requires a valid SDLA certificate. What the process certificate covers, what the component-level SDA-C review adds, and what to prepare.
Sep 8, 20267 min readRead
CSADeep dive
Where fuzzing, load testing and penetration testing actually live in ISASecure CSA
Suppliers often expect the certification lab to fuzz and pen-test their product. It does not. Who performs each kind of security test in a CSA evaluation, what the lab checks instead, and what to prepare.
Sep 8, 20268 min readRead
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.