ISASecure Certification
ISASecure is a certification programme of the ISA Security Compliance Institute that independently certifies industrial automation products and supplier development processes against the ISA/IEC 62443 cybersecurity standards.
ISASecure is a certification programme operated by the ISA Security Compliance Institute (ISCI) that assesses industrial automation products and supplier development processes for conformance with the ISA/IEC 62443 standards. Assessments are carried out by accredited certification bodies, and certified products and organisations are listed publicly.
The main schemes are Security Development Lifecycle Assurance (SDLA), which certifies a supplier's development process against IEC 62443-4-1; Component Security Assurance (CSA), which certifies components such as controllers, devices and software applications against IEC 62443-4-2; and System Security Assurance (SSA), which certifies control systems against IEC 62443-3-3. Earlier embedded device certifications were issued under the Embedded Device Security Assurance (EDSA) scheme. Asset owners use certification as evidence during procurement, reducing the need to assess each supplier's claims independently.
A certificate states the security level capability for which a product was assessed and applies to specific versions, so buyers should check the certified version, level and scope. Certification demonstrates that capabilities exist and that development follows defined practices, but the security of an installation still depends on correct configuration, zoning and maintenance. Other IEC 62443 certification routes exist, including schemes run under the IECEE system.
Key points
- Operated by the ISA Security Compliance Institute (ISCI)
- SDLA certifies development processes against IEC 62443-4-1
- CSA certifies components against IEC 62443-4-2; SSA certifies systems against 62443-3-3
- Certificates apply to specific product versions, security levels and scopes
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- IEC 62443-4-1 Secure Product Development LifecycleOT & Industrial Cybersecurity
- IEC 62443-4-2 Component Security RequirementsOT & Industrial Cybersecurity
- IEC 62443-3-3 System Security RequirementsOT & Industrial Cybersecurity
- IEC 62443 Security Levels (SL)OT & Industrial Cybersecurity