ISASecure Certification
System Security Assurance (SSA)
Certify your integrated automation system against IEC 62443-3-3 with ISASecure SSA. Evaluation runs three parallel assurance streams and is performed per security zone, so the certificate binds the Security Level achieved in each zone rather than a single system-wide grade.
System-Level Security Assessment
Overview
ISASecure SSA (System Security Assurance) certifies an integrated automation system against IEC 62443-3-3. Rather than grading the system as a single whole, evaluation is performed per security zone: the certificate binds the Security Level (SL) achieved in each zone, so a deploying asset owner can match their own zone targets directly to the certificate's per-zone table.
Planning defines the system's zone breakdown first — the zones with their capability Security Levels, the conduits between them and to external endpoints, and the components mapped to each zone. A current SDLA certification (IEC 62443-4-1) is a prerequisite. Evaluation then runs three assurance streams in parallel: Secure Development Artifacts (SDA), the Functional Security Assessment (FSA) against IEC 62443-3-3, and Vulnerability Identification Testing (VIT).
The Functional Security Assessment is the heart of SSA — the seven Foundational Requirements of IEC 62443-3-3 are evaluated zone by zone, and a requirement may achieve different results in different zones. The report declares the SL reached in each zone, and an independent certification decision follows under ISO/IEC 17065. A zone that falls short of its claimed SL can be bound at a lower level rather than failing the whole certificate.
Per-Zone Evaluation
Assessment by security zone, with the certificate binding the SL achieved in each zone
Three Assurance Streams
Development artifacts (SDA), functional assessment (FSA) and vulnerability testing (VIT) in parallel
IEC 62443-3-3
Seven Foundational Requirements evaluated against the standard, zone by zone
SDLA Prerequisite
A current SDLA certification (IEC 62443-4-1) is required before SSA evaluation begins
IEC 62443-3-3
The Seven Foundational Requirements
The Functional Security Assessment evaluates these seven Foundational Requirements zone by zone. The same requirement may achieve a different result in different zones, and each zone's capability Security Level is determined from the outcome.
FR1 — Identification & Authentication Control
Reliable identification and authentication of users, devices and software processes before access is granted within a zone.
FR2 — Use Control
Enforcement of assigned privileges so that authenticated entities perform only the actions permitted for their role within a zone.
FR3 — System Integrity
Protection of the integrity of the system, its communications and its information against unauthorized modification.
FR4 — Data Confidentiality
Protection of the confidentiality of information at rest and in transit against unauthorized disclosure.
FR5 — Restricted Data Flow
Segmentation into zones and conduits so that data flow is restricted to what each zone boundary permits.
FR6 — Timely Response to Events
Detection of security events, collection of the evidence needed to respond, and timely notification of the appropriate parties.
FR7 — Resource Availability
Protection against denial of essential services and the availability of the system's resources under adverse conditions.
SSA Certification Process
Our Approach
Driving standards
- IEC 62443-3-3 — system security requirements
- IEC 62443-4-1 — secure development (SDLA prerequisite)
- ISO/IEC 17025 — accredited testing
- ISO/IEC 17065 — impartial certification decision
Planning
Define the system's zone breakdown — zones with their capability security levels, conduits between them, and the components mapped to each zone. A current SDLA certification is a prerequisite.
- Define zones with their capability security levels
- Define conduits between zones and to external endpoints
- Inventory components and map each to its zone(s)
- Confirm the SDLA prerequisite; asset owner signs off scope
Frequently Asked Questions
FAQ
ISASecure SSA (System Security Assurance) certifies an integrated industrial automation system against IEC 62443-3-3. Evaluation is performed per security zone and runs three parallel assurance streams: Secure Development Artifacts (SDA), the Functional Security Assessment (FSA) against IEC 62443-3-3, and Vulnerability Identification Testing (VIT). Rather than producing a single system-wide grade, the certificate binds the Security Level (SL) achieved in each zone.
Certify Your System Security
Demonstrate the integrated security of your industrial automation system with ISASecure SSA certification from Perseus, an accredited Chartered Laboratory.