Skip to content
NEW: ISASecure Site Assessment Program for OT Cybersecurity Learn More

Component Security Assurance (CSA) Certification

CSA focuses on the security of software applications, embedded devices, host devices, and network devices, as defined by the ISA/IEC 62443-4-2 standard.

CSA Certification Versions

Ordered most recent first.

CSA Version 1.0.0

EDSA Version 3.0.0

EDSA Version 2.1.0

EDSA Version 2.0.0

Component Security Assurance (CSA) - version 1.0.0

Effective 28 August 2019

*See ISASecure-117 for version transition details*

Scope

The ISASecure certification program Component Security Assurance (CSA) focuses on the security of software applications, embedded devices, host devices, and network devices. These are the component types used to build control systems, defined by the standard IEC 62443-4-2 Security for industrial automation and control systems Part 4-2: Technical security requirements for IACS components. CSA addresses component characteristics and supplier development practices for those components.  The CSA certification is designed to certify to international standards IEC 62443-4-2 and IEC 62443-4-1 Security for industrial automation and control systems Part 4-1: Secure product development requirements.

A component that meets the requirements of the ISASecure CSA specification earns the ISASecure CSA certification; a trademarked designation that provides instant recognition of product security characteristics and capabilities, and provides an independent industry stamp of approval similar to a ‘Safety Integrity Level’ Certification (ISO/IEC 61508). 

ISASecure CSA is a certification program for control system components, where a product is considered to be a component if it satisfies one or more of the definitions in IEC 62443-4-2:

Software application one or more software programs and their dependencies that are used to interface with the process or the control system itself (for example, configuration software and historian)

Embedded device special purpose device running embedded software designed to directly monitor, control or actuate an industrial process

Host device general purpose device running an operating system (for example Microsoft Windows OS or Linux) capable of hosting one or more software applications, data stores or functions from one or more suppliers

Network device device that facilitates data flow between devices, or restricts the flow of data, but may not directly interact with a control process

The release of ISASecure CSA 1.0.0 subsumes the former ISASecure EDSA certification program for embedded devices. CSA defines certification criteria for embedded devices as well as for the other three component types defined in IEC 62443-4-2.
  • The elements of a CSA certification are illustrated in Figure 1 below.
In order to obtain ISASecure CSA certification, a supplier must pass a security development lifecycle process assessment for component development (SDLPA-C).  Based upon this assessment, an ISASecure SDLA process certification is granted as described in SDLA-100. A supplier may already hold an SDLA process certification when they apply for an CSA certification, or may apply for CSA and SDLA certification in parallel. ISASecure certification of components has three additional elements:
  • Security Development Artifacts for components (SDA-C);
  • Functional Security Assessment for components (FSA-C); and
  • Vulnerability Identification testing for components (VIT-C).

SDLPA-C and SDA-C both assess development process. SDA-C examines the artifacts that are the outputs of the supplier’s development lifecycle processes as they apply to the component to be certified. FSA-C examines the security capabilities of the component, while recognizing in accordance with IEC 62443-4-2 that requirements for security functionality differ by component type. VIT scans the component for the presence of known vulnerabilities.

The CSA program defines four certification levels for a component, offering increasing levels of security assurance. Levels offered are capability security levels 1, 2, 3, and 4. A product that achieves certification to CSA capability security level n is certified to meet requirements for capability security level n as defined in IEC 62443-4-2, which includes a requirement for compliance to IEC 62443-4-1. A CSA certification earned by a particular product will indicate the applicable component type(s) and level, and thus be expressed for example, as ISASecure CSA Capability Level 3 (Software Application) or ISASecure CSA Capability Security Level 2 (Embedded Device, Network Device).

All levels of certification include the certification elements defined in Figure 1. SDLPA-C does not have an associated level. SDA-C and VIT-C assessments are the same for all certification levels with the exception of allowable residual risk for known security issues.  FSA-C incorporates more requirements at higher levels, aligned with the requirements assigned to each capability security level in IEC 62443-4-2. 


CSA-image (1)

Figure 1 - Evaluation Elements for  ISASecure CSA Certification

 

ISASecure® EDSA Conformance Scheme Fees

CSA Component Registration Fee (Annual Fee) $1,200
CSA Product Family Registration Fee (Annual Fee) $1,500

 

Component Security Assurance (CSA) Certification Scheme Description

CSA-100 ISASecure Certification Scheme View/Download Resource
CSA-102 Baseline Document Versions and Errata View/Download Resource

 

Transition Policy

ISASecure-117 Transition to CSA 1.0.0 and SSA 4.0.0  

View/Download Resource

Initial Certification and Maintenance of Certification Policies and Criteria

CSA-204 Use of Symbols and Certificates View/Download Resource
CSA-300 ISASecure Certification Requirements View/Download Resource
CSA-301 Maintenance of ISASecure Certification View/Download Resource
ISASecure-120 Relabeled Policy View/Download Resource
ISASecure-130  Product Family Policy View/Download Resource

 

Certification Requirements Specifications for CSA (Four Assessment Categories SDLPA, SDA, FSA, VIT)

CSA-311 Functional Security Assessment for Components View/Download Resource
CSA-312 Security Development Artifacts for Embedded Devices View/Download Resource
SSA-420 Vulnerability Identification Test (VIT) Specification View/Download Resource
SDLA-312 Security Development Lifecycle Assessment View/Download Resource
SDLA-100 ISASecure Certification Scheme View/Download Resource

 

Take the Next Step

Reduce your onsite risk, reduce your workload, and make your products stand out from the competition today.