Insights
ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
Topic
Security levels10Tiers (Core / Advanced)5Device & component types9Assessment streams6Testing & verification11Evidence & artifacts16Independent testing5Maturity levels4Sampling1Scope & boundaries16Surveillance & maintenance4Certification process20Common component constraints (CCSC)1Cost & effort3Comparisons4Roadmaps & readiness1
2 articles match your filters
SDLADeep dive
Fuzz, load, penetration and abuse-case testing: what the IEC 62443-4-1 SVV practice asks of a supplier
The SVV practice is where ISASecure SDLA is strictest: five IEC 62443-4-1 requirements, 20 assessable rows and a named test type behind most of them.
Sep 8, 20269 min readRead
SDLADeep dive
IEC 62443-4-1 process audit: the 23 SDLA rows no product evaluation examines
23 ISASecure SDLA-312 rows are checked only in the SDLA process audit, on Perseus's reading of its activity columns: defect handling, coding rules, pen testing.
Sep 8, 20269 min readRead
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.