Insights

ISASecure and IEC 62443, explained with the numbers

What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.

Filteractive

8 articles match your filters

ACSSAIntermediate

After the certificate: ACSSA surveillance in years one and two, recertification in year three

How an ISASecure ACSSA certificate stays valid: 36 months, surveillance in years one and two, recertification in year three, nonconformities and suspension.

Sep 8, 20269 min readRead
ACSSAIntermediate

IEC 62443-2-1 audit evidence in an ACSSA evaluation: documents, interviews and inspection, never testing

How an ISASecure ACSSA evaluator gathers evidence on an installed IACS: documents, interviews and configuration inspection, never testing or device access.

Sep 8, 202610 min readRead
ACSSAIntermediate

The ACSSA assessment process: four phases and the report you receive

How an ISASecure ACSSA evaluation runs: the plan you approve, the four ACSSA-304 phases from risk assessment to report, and how to read the ACSSA-303 report.

Sep 8, 20269 min readRead
ACSSAIntermediate

An asset owner's installed IACS: IEC 62443 asset owner certification scope under ISASecure ACSSA, and the six documents that define it

ISASecure ACSSA certifies an asset owner's installed IACS, bounded by six change-controlled documents: who may apply, what is in scope and what is carved out.

Sep 8, 20269 min readRead
ACSSAIntermediate

IEC 62443-2-1 maturity level 2 vs 3: why ISASecure ACSSA certification needs level 3 on every requirement

In ISASecure ACSSA, maturity level 2 means a requirement is documented and level 3 means it is practised. Certification needs level 3 on every requirement.

Sep 8, 20268 min readRead
ACSSAIntermediate

IEC 62443 target security levels in ACSSA: the asset owner's level decides what is checked, and nothing is awarded

How ACSSA uses each zone's target security level from the asset owner's IEC 62443-3-2 risk assessment to decide what is checked, and why no level is awarded.

Sep 8, 20268 min readRead
ACSSAIntermediate

Service providers in ACSSA: IEC 62443-2-4, delegated tasks and the VIC shortcut

How ISASecure ACSSA evaluates an asset owner's service providers against IEC 62443-2-4: who counts, delegated tasks, the agreed list, NR-A and the VIC result.

Sep 8, 20269 min readRead
ACSSAIntermediate

ACSSA evaluation results: ten result types, and the one that fails

ACSSA records ten result types across four IEC 62443 parts. Only Not met fails; three others pass only with approved documentation; unsampled zones get none.

Sep 8, 20268 min readRead

Have a product or system to certify?

Talk to the assessors who wrote these articles about what applies to you.