Insights

ISASecure and IEC 62443, explained with the numbers

What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.

Filteractive

10 articles match your filters

CSAIntermediate

CCSC explained: the four IEC 62443-4-2 constraints that apply to every component

IEC 62443-4-2 has a second axis beyond the seven foundational requirements: four common component security constraints. What each means for a CSA certificate.

Sep 8, 20268 min readRead
CSAIntermediate

The four IEC 62443-4-2 component types, and why the type determination decides your CSA scope

Software application, embedded device, host device or network device: which IEC 62443-4-2 component types apply to your product, and how they set CSA scope.

Sep 8, 20268 min readRead
CSAIntermediate

Independent testing in ISASecure CSA: what the lab must test itself

ISASecure CSA flags 34 of its 166 functional requirements for testing by the lab itself. What the flag means, what happens to the rest, and what to prepare.

Sep 8, 20268 min readRead
CSAIntermediate

SDA-C, FSA-C and VIT-C: what each ISASecure CSA assessment stream proves

The ISASecure CSA assessment process, stream by stream: what SDA-C, FSA-C and VIT-C each prove, the five result outcomes, the pass rule and the certificate.

Sep 8, 20268 min readRead
CSAIntermediate

The SDLA prerequisite: why ISASecure CSA needs it, and what the SDA-C artifact review adds

ISASecure CSA requires a valid SDLA certificate. What the process certificate covers, what the component-level SDA-C review adds, and what to prepare.

Sep 8, 20267 min readRead
CSAIntermediate

CSA security levels 1 to 4: what each level actually adds

IEC 62443 security levels explained through ISASecure CSA: what SL 1 to SL 4 are built to resist, how many requirements each adds, and how to pick a target.

Sep 8, 20268 min readRead
CSAIntermediate

ISASecure vulnerability identification testing: how the pass threshold scales with security level

ISASecure VIT pass criteria: one severity band is added per security level, the scan is identical at every level, and a pass never requires zero findings.

Sep 8, 20268 min readRead
CSAIntroductory

What ISASecure CSA certification actually evaluates

ISASecure CSA certifies a component against IEC 62443-4-2: 166 functional requirements, four component types, three assessment streams and one security level.

Sep 8, 20268 min readRead
CSADeep dive

What it takes to reach SL 3 in ISASecure CSA, by component type

Moving from SL 2 to SL 3 in ISASecure CSA adds 23 IEC 62443-4-2 requirements, 22 of them enhancements. What the step costs by component type and by FR.

Sep 8, 202610 min readRead
CSADeep dive

Where fuzzing, load testing and penetration testing actually live in ISASecure CSA

Suppliers often expect the certification lab to fuzz and pen-test their product. It does not. Who performs each kind of security test in a CSA evaluation, what the lab checks instead, and what to prepare.

Sep 8, 20268 min readRead

Have a product or system to certify?

Talk to the assessors who wrote these articles about what applies to you.