What is ISASecure?
ISASecure is an independent certification programme that demonstrates that industrial products, systems and development processes comply with the IEC 62443 standards. The programme is run by the ISA Security Compliance Institute (ISCI), a not-for-profit organisation within the International Society of Automation (ISA). Audits are carried out by accredited certification bodies. For asset owners, an ISASecure certificate provides objective evidence during procurement, rather than just a supplier’s promise that a product is “IEC 62443 compliant”.
🔧 What ISASecure certifications are there?
| Certification | Full name | Assessed against | For |
|---|---|---|---|
| SDLA | Security Development Lifecycle Assurance | IEC 62443-4-1 | A supplier’s development organisation |
| CSA | Component Security Assurance | IEC 62443-4-1 + IEC 62443-4-2 | Components: PLC, HMI, switch, software |
| ICSA | IIoT Component Security Assurance | IEC 62443-4-2 with IIoT extensions | IIoT devices and gateways |
| SSA | System Security Assurance | IEC 62443-3-3 + IEC 62443-4-1 | Complete control systems, such as a DCS |
| ACSSA | Automation and Control System Security Assurance | IEC 62443-2-1, IEC 62443-2-4, IEC 62443-3-2, 3-3 | An asset owner’s OT security programme |
ACSSA is the newest scheme and, unlike the others, targets the user of the installation rather than a supplier.
🧠 How does certification work?
- Preparation — the supplier defines the scope and target security level
- Process assessment — the auditor checks the development process against IEC 62443-4-1 (for CSA, SSA and SDLA)
- Functional assessment — the technical requirements per security level are verified
- Testing — including vulnerability scans and communication robustness tests
- Certificate and listing — the certified product is added to ISASecure’s public list
A certificate applies to a specific product version. New versions are reassessed, with the scope depending on the changes.
🔄 What is the difference between ISASecure and IEC 62443 itself?
| IEC 62443 | ISASecure | |
|---|---|---|
| What | Series of standards with requirements | Certification programme |
| Publisher | IEC and ISA | ISCI (part of ISA) |
| Mandatory | No, voluntary | No, voluntary |
| Outcome | Requirements you can meet | Independent proof that you meet them |
Besides ISASecure, products can also be certified against IEC 62443 through the IEC’s IECEE scheme.
🏭 Why is ISASecure relevant for IT/OT?
- Procurement — asset owners can require a CSA or SSA certificate at a specific SL in tenders, as part of supplier security
- Legislation — certification helps suppliers demonstrate compliance with the Cyber Resilience Act and the cybersecurity requirements of the Machinery Regulation
- Supply chain risk — a certified development process reduces the chance of vulnerabilities in third-party components
🛠️ How do you use ISASecure as an asset owner?
- Include certification in your requirements — ask for a CSA or SSA certificate at the required security level when buying new controllers
- Check the certificate details — do the product model, firmware version and security level match what you are buying?
- Look at the development process — an SDLA certificate says something about how the supplier also builds future versions and patches
- Combine with your own measures — a certified component still needs to be configured securely and placed in the right zone
- Consider ACSSA for your own OT security programme, if you want it assessed externally
| You are buying… | Ask for… |
|---|---|
| A PLC, switch or HMI | CSA (and therefore implicitly 4-1 + 4-2) |
| An IIoT sensor or gateway | ICSA |
| A complete DCS or SCADA system | SSA |
| Development work or a custom product | SDLA of the developer |
❓ Frequently asked questions
What is the difference between ISASecure CSA and SSA?
ISASecure CSA certifies an individual component, such as a PLC, switch or software application, against IEC 62443-4-2 and 4-1. ISASecure SSA certifies a complete control system, such as a DCS, against IEC 62443-3-3 and 4-1. An SSA system often consists of several components that may each also be CSA certified.
Who performs ISASecure certifications?
ISASecure certifications are carried out by certification bodies recognised by ISCI and accredited by an accreditation body. Examples include large testing and inspection companies such as TÜV, Bureau Veritas, exida and UL. The certificate is published on the ISASecure website.
How long is an ISASecure certificate valid?
An ISASecure certificate applies to the certified product version. New versions are reassessed, with the scope depending on the changes. For process certificates such as SDLA, periodic surveillance audits check that the development process is still being followed.
Is ISASecure the same as IEC 62443 certification?
ISASecure is one of the certification programmes for IEC 62443, but not the only one. Products can also be certified through the IEC’s IECEE scheme. Both programmes assess against the same standards; the difference lies in the organisation, the testing approach and recognition among customers.
How much does ISASecure certification cost?
The cost of ISASecure certification depends on the type of certificate, the complexity of the product and the maturity of the development process. Besides the audit and testing fees of the certification body, suppliers often spend the most on internal preparation, such as setting up processes and documentation. ISCI members get access to the scheme documentation.
📌 In summary
ISASecure is the independent certification programme for IEC 62443, with schemes for development processes (SDLA), components (CSA, ICSA), systems (SSA) and asset owners’ OT security programmes (ACSSA). It makes the claim “IEC 62443 compliant” verifiable.
