ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
4 articles match your filters
IEC 62443-2-1 audit evidence in an ACSSA evaluation: documents, interviews and inspection, never testing
How an ISASecure ACSSA evaluator gathers evidence on an installed IACS: documents, interviews and configuration inspection, never testing or device access.
IEC 62443-2-1 maturity level 2 vs 3: why ISASecure ACSSA certification needs level 3 on every requirement
In ISASecure ACSSA, maturity level 2 means a requirement is documented and level 3 means it is practised. Certification needs level 3 on every requirement.
Service providers in ACSSA: IEC 62443-2-4, delegated tasks and the VIC shortcut
How ISASecure ACSSA evaluates an asset owner's service providers against IEC 62443-2-4: who counts, delegated tasks, the agreed list, NR-A and the VIC result.
ACSSA evaluation results: ten result types, and the one that fails
ACSSA records ten result types across four IEC 62443 parts. Only Not met fails; three others pass only with approved documentation; unsampled zones get none.
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.