ISASecure Certification

System Security Assurance (SSA)

Certify your integrated automation system against IEC 62443-3-3 with ISASecure SSA. Evaluation runs three parallel assurance streams and is performed per security zone, so the certificate binds the Security Level achieved in each zone rather than a single system-wide grade.

System-Level Security Assessment

Overview

ISASecure SSA (System Security Assurance) certifies an integrated automation system against IEC 62443-3-3. Rather than grading the system as a single whole, evaluation is performed per security zone: the certificate binds the Security Level (SL) achieved in each zone, so a deploying asset owner can match their own zone targets directly to the certificate's per-zone table.

Planning defines the system's zone breakdown first — the zones with their capability Security Levels, the conduits between them and to external endpoints, and the components mapped to each zone. A current SDLA certification (IEC 62443-4-1) is a prerequisite. Evaluation then runs three assurance streams in parallel: Secure Development Artifacts (SDA), the Functional Security Assessment (FSA) against IEC 62443-3-3, and Vulnerability Identification Testing (VIT).

The Functional Security Assessment is the heart of SSA — the seven Foundational Requirements of IEC 62443-3-3 are evaluated zone by zone, and a requirement may achieve different results in different zones. The report declares the SL reached in each zone, and an independent certification decision follows under ISO/IEC 17065. A zone that falls short of its claimed SL can be bound at a lower level rather than failing the whole certificate.

Per-Zone Evaluation

Assessment by security zone, with the certificate binding the SL achieved in each zone

Three Assurance Streams

Development artifacts (SDA), functional assessment (FSA) and vulnerability testing (VIT) in parallel

IEC 62443-3-3

Seven Foundational Requirements evaluated against the standard, zone by zone

SDLA Prerequisite

A current SDLA certification (IEC 62443-4-1) is required before SSA evaluation begins

IEC 62443-3-3

The Seven Foundational Requirements

The Functional Security Assessment evaluates these seven Foundational Requirements zone by zone. The same requirement may achieve a different result in different zones, and each zone's capability Security Level is determined from the outcome.

FR1 — Identification & Authentication Control

Reliable identification and authentication of users, devices and software processes before access is granted within a zone.

FR2 — Use Control

Enforcement of assigned privileges so that authenticated entities perform only the actions permitted for their role within a zone.

FR3 — System Integrity

Protection of the integrity of the system, its communications and its information against unauthorized modification.

FR4 — Data Confidentiality

Protection of the confidentiality of information at rest and in transit against unauthorized disclosure.

FR5 — Restricted Data Flow

Segmentation into zones and conduits so that data flow is restricted to what each zone boundary permits.

FR6 — Timely Response to Events

Detection of security events, collection of the evidence needed to respond, and timely notification of the appropriate parties.

FR7 — Resource Availability

Protection against denial of essential services and the availability of the system's resources under adverse conditions.

SSA Certification Process

Our Approach

Driving standards

  • IEC 62443-3-3 — system security requirements
  • IEC 62443-4-1 — secure development (SDLA prerequisite)
  • ISO/IEC 17025 — accredited testing
  • ISO/IEC 17065 — impartial certification decision
EdgesAdvanceAbandonClick any node for detail
IEC 62443-3-3

Planning

Define the system's zone breakdown — zones with their capability security levels, conduits between them, and the components mapped to each zone. A current SDLA certification is a prerequisite.

  • Define zones with their capability security levels
  • Define conduits between zones and to external endpoints
  • Inventory components and map each to its zone(s)
  • Confirm the SDLA prerequisite; asset owner signs off scope

Frequently Asked Questions

FAQ

ISASecure SSA (System Security Assurance) certifies an integrated industrial automation system against IEC 62443-3-3. Evaluation is performed per security zone and runs three parallel assurance streams: Secure Development Artifacts (SDA), the Functional Security Assessment (FSA) against IEC 62443-3-3, and Vulnerability Identification Testing (VIT). Rather than producing a single system-wide grade, the certificate binds the Security Level (SL) achieved in each zone.

Certify Your System Security

Demonstrate the integrated security of your industrial automation system with ISASecure SSA certification from Perseus, an accredited Chartered Laboratory.