ACSSA Is More Than an Assessment; It Is a Framework Asset Owners Have Been Missing
By Deniz Kaya
For as long as ISA/IEC 62443 has been called the gold standard for industrial cybersecurity, a quiet truth has sat alongside it: almost no asset owner has implemented it in full, and almost no two organizations have implemented it the same way.
That is not criticism of the teams doing the work — it's a consequence of how the industry got here. Before ACSSA, if you owned and operated an industrial automation and control system (IACS), you had to translate ISA/IEC 62443 into your own program. Some built it internally. Many leaned on an integrator, a consulting firm or an assessment and auditing provider. Each of those brought a different reading of the standard, a different scope, a different depth. The result was a landscape of custom programs that all cited the same standard and yet were rarely comparable to one another — or even repeatable within the same organization over time.
ACSSA gives that landscape a common reference point.
ACSSA (Automation and Control System Security Assurance) is the ISASecure® program for an operating IACS. It evaluates a deployed system against the relevant parts of the ISA/IEC 62443 series together — the asset owner's security program (ISA/IEC 62443 2‑1), the service providers who support it (ISA/IEC 62443 2‑4), the risk assessment and zone/conduit design (ISA/IEC 62443 3‑2), and the technical system capabilities in use (ISA/IEC 62443 3‑3) at two maturity levels: documented practice (ML 2) and evidence of implementation (ML 3).
But the part asset owners tend to underestimate is this: you do not have to treat ACSSA only as a pass/fail exam. You can adopt it as your framework.
- A target you set for yourself. ACSSA gives you a defined, credible level of compliance to aim for a bar to which you can hold your own environment, your integrators and your service providers, well before any formal evaluation. Instead of "align with ISA/IEC 62443" as an aspiration, you have a concrete specification of what "good" looks like for your system.
- An adaptable structure, not a one‑time event. The same framework that certifies your system can guide how you build and maintain it: how you scope zones and conduits, what you expect from service providers and what evidence you keep. It scales from a self‑directed improvement program up to full independent certification, on your timeline.
- Consistency you can rely on and prove. Because ACSSA is assessed the same way by accredited certification bodies, the result means the same thing across sites, across vendors and across years. That is something a bespoke internal program, however good, can never quite offer: a benchmark that is both yours and externally, repeatably verifiable.
The certificate at the end is real value. But for many asset owners, the bigger win arrives earlier — the moment ACSSA stops being "an assessment we might do someday" and becomes the shared target the whole program is built around.
Perseus Information Security Consulting works with asset owners and integrators on ISASecure and ISA/IEC 62443 programs. To hear how asset owners are adopting ACSSA, join the ISASecure webinar, What Asset Owners Should Know About ACSSA on Wednesday, 26 August 2026 at 10:00 a.m. ET to learn more.
Deniz Kaya, CEO of Perseus Information Security Consulting, has a strong background in cybersecurity, having worked in various roles. Deniz holds a Master of Science in Cybersecurity and Information Assurance from Western Governors University.
Deniz has a deep commitment to advancing cybersecurity across critical sectors. His skills include being a TISAX Lead Auditor, an ISA/IEC 62443 Cybersecurity Expert, ISO 27701 Lead Auditor and SWIFT CSP Accessor. Deniz has also completed the ISA IC49 ACSSA for Evaluators certification class and been heavily involved in the technical review and development of ACSSA as an ISASecure member.