Insights

ISASecure and IEC 62443, explained with the numbers

What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.

Filteractive

11 articles match your filters

ACSSAIntermediate

IEC 62443-2-1 audit evidence in an ACSSA evaluation: documents, interviews and inspection, never testing

How an ISASecure ACSSA evaluator gathers evidence on an installed IACS: documents, interviews and configuration inspection, never testing or device access.

Sep 8, 202610 min readRead
ACSSAIntermediate

IEC 62443-2-1 maturity level 2 vs 3: why ISASecure ACSSA certification needs level 3 on every requirement

In ISASecure ACSSA, maturity level 2 means a requirement is documented and level 3 means it is practised. Certification needs level 3 on every requirement.

Sep 8, 20268 min readRead
ACSSAIntermediate

Service providers in ACSSA: IEC 62443-2-4, delegated tasks and the VIC shortcut

How ISASecure ACSSA evaluates an asset owner's service providers against IEC 62443-2-4: who counts, delegated tasks, the agreed list, NR-A and the VIC result.

Sep 8, 20269 min readRead
ACSSAIntermediate

ACSSA evaluation results: ten result types, and the one that fails

ACSSA records ten result types across four IEC 62443 parts. Only Not met fails; three others pass only with approved documentation; unsampled zones get none.

Sep 8, 20268 min readRead
CSAIntermediate

The SDLA prerequisite: why ISASecure CSA needs it, and what the SDA-C artifact review adds

ISASecure CSA requires a valid SDLA certificate. What the process certificate covers, what the component-level SDA-C review adds, and what to prepare.

Sep 8, 20267 min readRead
ICSAIntermediate

SDA-IC: the 93 lifecycle requirements checked per IIoT component, and the five ICSA-only practices

What ICSA's SDA-IC review checks per IIoT component: 93 of the 118 IEC 62443-4-1 lifecycle requirements, 16 IIoT-specific rows and five ICSA-only practices.

Sep 8, 20268 min readRead
SDLAIntermediate

IEC 62443-4-1 defect and update management: the SDLA practices product certifications come back to

How ISASecure SDLA evaluates IEC 62443-4-1 defect and update management: 15 rows, most seen only in the process audit, and the four requirements ICSA revisits.

Sep 8, 20269 min readRead
SDLAIntermediate

Full or readiness evaluation: the SDLA choice that sets your certificate at 36 or 12 months

ISASecure SDLA has two evaluation methods. One requirement passed by readiness evaluation sets the certificate at 12 months, not 36. The 21 rows that decide it.

Sep 8, 20269 min readRead
SDLAIntermediate

What counts as a major nonconformity in an IEC 62443-4-1 audit: the 31 SDLA minimum requirements

In an ISASecure SDLA audit a finding is major when no evidence exists, or when one of 31 minimum requirements is applied inconsistently. The full list.

Sep 8, 202610 min readRead
SDLAIntermediate

IEC 62443-4-1 security guidelines and hardening: the SDLA practice with the most minimum requirements

ISASecure SDLA and the IEC 62443-4-1 security guidelines practice: 7 requirements, 17 rows, 10 minimum requirements, no mandatory artifacts, examined twice.

Sep 8, 20269 min readRead
SSAIntermediate

SSA SDA-S artifacts: the 74 lifecycle rows ISASecure checks for a system, and why fuzz and load results are among them

ISASecure SSA's SDA-S stream re-checks 74 assessable rows of the SDLA-312 lifecycle catalogue for the system as sold, fuzz and load coverage included.

Sep 8, 20268 min readRead

Have a product or system to certify?

Talk to the assessors who wrote these articles about what applies to you.