Building Secure Foundations and Strengthening Your Business Relationships through ISA/IEC 62443 Certifications
The security of industrial automation and control system (IACS) components is under greater scrutiny than ever before. Asset owners, regulators and insurers now expect independent, verifiable evidence — beyond marketing claims — that products meet ISA/IEC 62443 standards.
ISASecure® certifications can simply and powerfully demonstrate that your products:
- Meet legislative and regulatory policy requirements
- Meet requirements mandated by insurance companies
- Meet asset owner procurement requirements
ISASecure offers five certifications schemes that certify to ISA/IEC 62443 and are certified by independent ISO/IEC 16065 Certification Bodies (CBs). The first four schemes below are for suppliers and the last scheme is for asset owners.
Currently ISASecure maintains five certification schemes:
• ISASecure Security Development Lifecycle Assurance (SDLA)
• ISASecure Component Security Assurance (CSA)
• ISASecure IIoT Component Security Assurance (ICSA)
• ISASecure System Security Assurance (SSA)
• And, in 2026, ISASecure Automation and Control System Security Assurance (ACSSA)
ISASecure certification schemes are developed and maintained by ISASecure members, a balanced group of industry stakeholders including suppliers, end users, government agencies, consultants, CBs and more.
We will not focus on ACSSA as much in this blog post, as it is a certification scheme for asset owners.
Laying the Groundwork: Security Development Lifecycle Assurance (SDLA)
Before any product can achieve an ISASecure certification, its development process must first be proven secure. This is where the ISASecure Security Development Lifecycle Assurance (SDLA) certification begins.
An SDLA certification validates that a supplier has implemented robust cybersecurity practices across every stage of product development from initial concept through release and maintenance. The evaluation process measures the organization’s adherence to ISA/IEC 62443-4-1, focusing on secure design principles, risk management and long-term vulnerability handling.
This step is a valuable milestone for suppliers and establishes the foundation for certifying the components they manufacture under the CSA program.
What Is SDLA’s Primary Focus?
- Security management policies that embed cybersecurity accountability into the organization’s culture
- Threat modeling and risk assessment procedures that proactively identify potential vulnerabilities
- Secure coding and testing practices that prevent exploitable weaknesses from entering production
- Configuration and change management controls that ensure ongoing system integrity
- Patch and vulnerability management processes that enable rapid and responsible mitigation
Suppliers that meet these criteria are granted ISASecure SDLA certification, referenced by a version number such as ISASecure SDLA 3.0.0. Certification is valid for a defined term and can be renewed through demonstrated maintenance of compliant practices.
This certification serves as a visible symbol of trust. ISASecure publicly lists organizations that hold valid SDLA certifications (with permission) at isasecure.org, underscoring the transparency and rigor behind the process. It is also something suppliers can share with asset owners who include cybersecurity verification requirements in their procurement specifications.
To receive SDLA certification, suppliers work with a Certification Body (CB). ISASecure-licensed CBs are independently accredited by ISO/IEC 17011 Accreditation Bodies (AB) to the ISO/IEC 17065 international standard for CBs and the ISO/IEC 17025 international standard for test laboratories. ISASecure collaborates with CBs worldwide to evaluate and certify conformance with ISA/IEC 62443. Once suppliers complete this important task, they can move onto ISASecure Component Security Assurance (CSA) certification.
“ISASecure certification bridges technology and trust. More than a compliance mark, it connects standards to implementation through independent certification, ensuring that the principles of ISA/IEC 62443 are translated into measurable and verifiable practices. In Asia, we see growing interest from governments and critical infrastructure sectors to adopt ISA/IEC 62443 as a baseline for resilience and security assurance. This growing alignment between policy frameworks, industry adoption and certification mechanisms reflects a shared commitment to building a more secure and trustworthy automation ecosystem.”
– SZ Lin (林上智), chief cybersecurity advisor at Sun Square Co., Ltd. and president of ISA Taiwan Section
From Process to Product: ISASecure Component Security Assurance (CSA)
Once a supplier’s development process is certified through SDLA, the next step is to validate the security of their products through ISASecure’s Component Security Assurance (CSA) program.
The CSA certification, built upon ISA/IEC 62443-4-1 and 62443-4-2, provides a concrete, technically rigorous validation of a component’s security capabilities. It assures asset owners that a supplier’s products have been tested, verified and trusted against the industry’s most demanding benchmarks.
Why Certify? It’s About Trust
The benefits of certification extend far beyond compliance. Through ISASecure CSA certification, suppliers demonstrate:
- Commitment to Cybersecurity: Security is embedded into the Secure Development Lifecycle (SDL), not bolted on afterward.
- Instant Market Recognition: ISASecure is end-user driven and globally recognized, simplifying procurement and supplier approval.
- Competitive Advantage: Certified components rise to the top of RFP lists; the ISASecure mark signals reliability and trustworthiness.
- Risk Reduction: Certification mitigates supply chain risk by verifying that components conform to internationally recognized security criteria.
For asset owners and integrators, ISASecure certification offers confidence that they are selecting components engineered for long-term resilience.
The CSA Certification Process
The CSA program evaluates IACS components — such as controllers, gateways, networking devices and field instruments — against the ISA/IEC 62443-4-1 (process) and 62443-4-2 (technical) standards. This ensures both secure development and secure functionality.
Core Evaluation Steps
- Pre-Assessment and Scope Definition:
Identify the component(s) to be certified, define their environment and align test plans with ISA/IEC 62443 requirements. - Security Development Lifecycle Assessment (per 62443-4-1):
Validate secure design principles, coding practices, threat modeling and vulnerability management. - Technical Security Requirements Testing (per 62443-4-2):
Verify authentication, encryption, role-based access control, secure communication and audit logging. - Vulnerability Analysis and Independent Penetration Testing:
Conduct static and dynamic analysis, exploiting known CVEs and OT-specific threat scenarios. - Documentation and Evidence Review:
Review security guidance, user documentation and configuration instructions for clarity and completeness. - Certification Decision by an Independent ISASecure-Accredited Body:
Conducted by an impartial Certification Body (CB); successful products are listed in the ISASecure Certified Product Register.
The ICSA Certification Process
The IIoT Component Security Assurance (ICSA) certification was inspired by recommendations published after a joint ISA Global Cybersecurity Alliance (ISAGCA) and ISASecure study, providing a certification specifically designed for IIoT products that certifies to the industry-leading ISA/IEC 62443 series of international standards.
The study results determined that the standards ISA/IEC 62443-4-1, ISA/IEC 62443-4-2 and the ISASecure certification Component Security Assurance (CSA) that assesses conformance to these standards were suitable for use in securing IIoT devices and gateways, covering 90% of the desired criteria for IIoT certification. For the additional 10% of criteria desired, the ICSA certification added several additional requirements and modifications, including a restructuring of the ISA/IEC 62443 capability security levels.
After restructuring, two certification tiers were created. The program defines two certification tiers for a component, offering a Core and Advanced level of security assurance. This structure is an adaptation of the ISA/IEC 62443 structure which has four security levels. Core tier is based on security level 2 requirements from ISA/IEC 62443-4-2 and the Advanced tier is based on security level 4.
It was also necessary to remove a small number of existing ISA/IEC 62443-4-2 requirements not applicable for IIoT components and refining methods for assessing conformance to ISA/IEC 62443-4-2 requirements by focusing on challenges specific to the IIoT environment (i.e., IIoT-specific use-cases).
To strengthen stakeholder confidence, ICSA incorporates Security Maintenance Audit (SMA). SMA requires a periodic surveillance evaluation of the supplier’s security maintenance practices as applied to an IIoT component holding ISCA certification.
The SSA Certification Process
The SSA program is a certification program for a particular subset of control systems. Requirements fall under ISA/IEC 62443-3-3 and ISA/IEC 62443-4-1. A control system product that meets all of the following criteria may be certified under SSA:
A system meeting the following criteria may be certified under SSA:
- The control system consists of an integrated set of components and includes more than one component.
- The control system is available from and supported as a whole by a single supplier, though it may include hardware and software components from several manufacturers.
- The control system may have a fixed component and zone layout.
- The system product is under configuration control and version management.
The SSA specifications define and use the notions of security zone, conduit and security level introduced in ANSI/ISA 62443-1-1. The process evaluation requirements for SDLA certification and SDA-S artifact assessment align with the requirements in the approved standard ANSI/ISA 62443-4-1, “Security for industrial automation and control systems Part 4-1: Secure product development lifecycle requirements.”
ISASecure’s Most Recent Certification: Automation and Control System Security Assurance (ACSSA)
The scope of an ACSSA evaluation includes the following:
- An IACS that is in-operation or operations-ready
- A security program (SP) that documents the security policies and procedures for the IACS
- The roles, responsibilities and training for the personnel who interact with the IACS
- Service providers responsible for IACS maintenance, integration or other services
“ACSSA is the holy grail of OT cybersecurity assurance. Until ACSSA, all we had was component and system certification (and vendor certification tied to these). The gap was always the lack of a means to independently assure that a facility was secure.”
– Steve Mustard, ISA fellow, past ISA president, ISASecure Technical Steering Committee lead, ISA instructor, author and president of Au2mation Consulting
The evaluation is performed against:
- ISA/IEC 62443-2-1: Security program requirements for IACS asset owners
- ISA/IEC 62443-3-2: Security risk assessment for system design
- ISA/IEC 62443-2-4: Security program requirements for IACS service providers
- ISA/IEC 62443-3-3: System security requirements and security levels
Two schemes are offered: inspection and certification. Both provide documented evaluation results at a point in time. However, a certification is valid for a specific period, requires periodic review and offers a recertification process to maintain the certification beyond that point.
The Importance of Proactive Certification
Global regulatory frameworks — including the EU Cyber Resilience Act (CRA) and NIS2 Directive — are reinforcing certification as a procurement prerequisite. Asset owners increasingly require proof of cybersecurity compliance in their supplier contracts.
ISASecure certifications give asset owners and customers confidence that security claims have been verified, not just promised.
“Chevron is committed to the adoption of ISA/IEC 62443 to achieve greatly enhanced, consistent and effective OT cybersecurity defenses. We feel strongly that ISASecure certified vendors and products can assist in streamlining our procurement processes, aid us in acquiring secure-by-design components and systems and provide the cybersecurity assurance we need to build ever more defensible and resilient OT architectures.”
– Kenny Mesker, Chevron, ICS cybersecurity engineer and ICS risk assessment subject-matter expert
Final Thought
ISASecure certification is a strategic investment in credibility, market access and industry trust. The ISASecure certifications establish measurable, independent assurance in how your products are developed, how securely they perform in the field and the overall cybersecurity of the asset owner’s facility. Development and certification standards using ISA/IEC 62443 are the gold standard.
In an industry where trust, reliability and safety are paramount, ISASecure certification demonstrates that your components have passed the most rigorous OT cybersecurity evaluation available. It’s a mark of assurance that builds confidence across the entire automation and critical infrastructure ecosystem.
To learn more about ISASecure certifications, visit https://isasecure.org/certification/certify-now. ISASecure’s independent certification bodies are worldwide.
Why ISASecure Certification Matters for Suppliers: A Conversation with Jim Lemanowicz, Cyber Security Product Manager from ABB Automation Technology
We recently had the opportunity to connect with Jim Lemanowicz, cyber security product manager from ABB Automation Technology, to learn about their experiences with ISASecure SDLA and CSA certifications.
1. As a global technology leader in electrification and automation, what can you share about ABB's commitment to OT cybersecurity and ISA/IEC 62443?
ABB treats product cybersecurity as a core business imperative, which is necessary as a "right to compete" for business, and not just a box to be checked. ABB has positioned ISA/IEC 62443 as a foundational standard for the entire automation portfolio. This is evident in how the ISA/IEC 62443-4-1 requirements are embedded into our product development lifecycle processes across multiple global sites.
This level of investment signals strong executive commitment and helps raise the bar for the entire sector.
2. ABB has achieved ISASecure Security Development Lifecycle Assurance (SDLA) certification. What does that certification demonstrate?
You cannot stay still in cybersecurity, and ISASecure SDLA (Security Development Lifecycle Assurance) certification for our development organizations demonstrates we have a structure in place to enable consistent product security and continuous improvement.
We develop our products via these policies and processes regardless of whether or not the end product will seek its own individual Component Security Assessment certification. However, many of our products do go on to obtain external certificates.
These achievements demonstrate that ABB is not just talking about security — we are subjecting our processes and products to independent, rigorous third-party assessment. In an industry where many suppliers still rely on self-attestation, ABB's certifications provide real, verifiable evidence of a structured, risk-based approach to IACS security.
3. Why certify components to CSA (ISA/IEC 62443-4-2)? Is it really important to have security requirements or checks in place for IACS devices?
Yes, absolutely. ISA/IEC 62443-4-2 defines many essential technical security requirements for IACS components (embedded devices, controllers, network devices, etc.). This means the devices are designed to provide the expected cybersecurity posture.
Some industries and critical infrastructure operators are looking for suppliers of components certified to CSA (Component Security Assurance). This means the component has been independently tested against a comprehensive set of security capabilities (authentication, authorization, encryption, secure boot, patch management, etc.). In our view, this provides clear, tangible value to all parties, such as:
- Reducing Risk: Minimizes the chance of incidents, downtime or regulatory penalties by building security into every device from the start.
- Building Customer Trust: Independent, third-party certification provides verifiable proof that our products meet internationally recognized security requirements.
- Meeting Market Expectations: Many asset owners and EPCs now require IEC 62443 compliance with tenders.
- Ensuring Global Consistency: The certification is recognized worldwide, simplifying procurement and compliance across regions and reducing redundant testing.
- Driving Continuous Improvement: It strengthens our development processes, resulting in higher-quality, more resilient products for our customers.
In today's threat landscape, strong product security is essential to protect plant environments. ABB's alignment to these requirements demonstrates our long-term commitment to delivering secure, reliable automation solutions.