Insights

ISASecure and IEC 62443, explained with the numbers

What each certification program actually evaluates, how the security levels and device types change the scope, and where the common points of confusion come from — written by the assessors who run these evaluations.

Filteractive

10 articles match your filters

ACSSAIntermediate

IEC 62443 target security levels in ACSSA: the asset owner's level decides what is checked, and nothing is awarded

How ACSSA uses each zone's target security level from the asset owner's IEC 62443-3-2 risk assessment to decide what is checked, and why no level is awarded.

Sep 8, 20268 min readRead
CSAIntermediate

CSA security levels 1 to 4: what each level actually adds

IEC 62443 security levels explained through ISASecure CSA: what SL 1 to SL 4 are built to resist, how many requirements each adds, and how to pick a target.

Sep 8, 20268 min readRead
CSAIntermediate

ISASecure vulnerability identification testing: how the pass threshold scales with security level

ISASecure VIT pass criteria: one severity band is added per security level, the scan is identical at every level, and a pass never requires zero findings.

Sep 8, 20268 min readRead
CSAIntroductory

What ISASecure CSA certification actually evaluates

ISASecure CSA certifies a component against IEC 62443-4-2: 166 functional requirements, four component types, three assessment streams and one security level.

Sep 8, 20268 min readRead
CSADeep dive

What it takes to reach SL 3 in ISASecure CSA, by component type

Moving from SL 2 to SL 3 in ISASecure CSA adds 23 IEC 62443-4-2 requirements, 22 of them enhancements. What the step costs by component type and by FR.

Sep 8, 202610 min readRead
ICSADeep dive

Advanced is SL 4, except when it is SL 3: the ISASecure ICSA tier-to-level trap

ICSA Advanced maps to SL 4 in the functional assessment but to SL 3 in vulnerability testing. Why the mappings diverge and how to read the certificate.

Sep 8, 20268 min readRead
SSAIntermediate

One certificate, several levels: how ISASecure SSA assigns a capability security level per zone

How ISASecure SSA assigns an IEC 62443 capability security level to each zone of a system, why one certificate can carry several levels, and how to specify it.

Sep 8, 20268 min readRead
SSAIntermediate

ISASecure SSA vulnerability testing: the scan where each zone sets its own pass threshold

How VIT-S works in ISASecure SSA: one known-vulnerability scan of every IP-addressed component, with the pass threshold set per component by its zone's level.

Sep 8, 20268 min readRead
SSAIntroductory

What ISASecure SSA certification actually evaluates

ISASecure SSA certifies a control system as sold against IEC 62443-3-3, with a capability security level per zone. Four elements, 116 functional rows: the map.

Sep 8, 20268 min readRead
SSADeep dive

What it takes to move a zone from SL 2 to SL 3 in ISASecure SSA

Raising a zone from SL 2 to SL 3 in ISASecure SSA adds 30 IEC 62443-3-3 rows: two base requirements and 28 enhancements, two of them lab-tested. All 30, by FR.

Sep 8, 202610 min readRead

Have a product or system to certify?

Talk to the assessors who wrote these articles about what applies to you.