ISASecure and IEC 62443, explained with the numbers
What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.
Filteractive
6 articles match your filters
The four IEC 62443-4-2 component types, and why the type determination decides your CSA scope
Software application, embedded device, host device or network device: which IEC 62443-4-2 component types apply to your product, and how they set CSA scope.
CSA vs ICSA: which ISASecure scheme fits your device
CSA certifies the four IEC 62443-4-2 component types by security level; ICSA certifies IIoT devices and gateways by Core or Advanced tier. How to choose.
Cloud links, wireless radios and the per-interface rule in ISASecure ICSA
In ISASecure ICSA, cloud and wireless links are ordinary accessible interfaces. How the per-interface rule and the untrusted-network declaration set the effort.
IIoT device or IIoT gateway: how the two ISASecure ICSA types decide your scope
Which of ISASecure ICSA's two IIoT types your product is, how the IEC 62443-4-2 families split between device and gateway, and why one product can carry both.
The 24 IIoT-specific requirements ISASecure ICSA adds to IEC 62443-4-2
ISASecure ICSA adds 24 IIoT-specific requirements to the IEC 62443-4-2 base: 18 at both tiers, 6 at Advanced only. What they cover and how to prepare.
A system as sold: IEC 62443-3-3 system certification scope under ISASecure SSA, and what falls outside it
ISASecure SSA certifies a control-system product as sold, at a version, in a fixed or scalable layout: the four eligibility criteria and what falls outside.
Have a product or system to certify?
Talk to the assessors who wrote these articles about what applies to you.