Certification and Conformity

IEC 62443 certification and conformity claims are only useful when their scope is clear. A development-process certificate, component certificate, system certificate, service-provider process certificate, and operating IACS assessment answer different questions. None of them is automatically the same as CRA presumption of conformity.

Certificate scope controls the claim

A certificate should be read as a scoped conformity statement. The useful facts are the scheme, standard part, edition, version of the scheme, assessment object, capability or maturity level if stated, product or system version, certificate holder, issuing body, and any profile or limitation.

  • process scope for secure development or service-provider capability;
  • component scope for software applications, embedded devices, host devices, or network devices;
  • system scope for a control system product, reference layout, and security zones;
  • operating IACS scope for an asset-owner evaluation or site assessment;
  • legal scope for CRA, which depends on the Regulation and OJ-cited harmonised standards, common specifications, or eligible EU cybersecurity certification schemes.

ISASecure scheme boundaries

ISASecure is an ISA-owned certification scheme for IEC 62443-related automation and control system claims. Its public scheme pages separate product, system, development-process, and IACS assessment claims.

SDLA

Security Development Lifecycle Assurance applies to the supplier's documented development lifecycle process for control system products and maps to IEC 62443-4-1.

CSA and former EDSA

Component Security Assurance applies to component products and uses IEC 62443-4-2 with supplier development practice evidence from IEC 62443-4-1.

SSA

System Security Assurance applies to a control system product and its zones, layouts, and capability claims under IEC 62443-3-3.

ACSSA

Automation and Control System Security Assurance evaluates an operating or operations-ready IACS together with related asset-owner policies and procedures.

IECEE certificate boundaries

IEC describes IECEE industrial cyber security certification as a route for testing and certifying cyber security in the industrial automation sector. The public IECEE certificate database and standard pages are useful pointers, but the certificate report remains the controlling artefact for scope. The page should not infer the assessment object from the fact that IEC 62443 appears in the certificate family.

Scheme and standard

Read the certificate against the listed IEC 62443 part, edition, programme, test report, and certification body.

Assessment object

Confirm whether the certificate is about a product, component, system, process, service capability, or operating IACS.

CRA presumption is a legal mechanism

CRA presumption of conformity depends on Regulation (EU) 2024/2847. A product with digital elements or a manufacturer's process can benefit from presumption only for the essential cybersecurity requirements covered by an applicable harmonised standard whose reference has been published in the Official Journal, or by another CRA mechanism such as common specifications or an eligible European cybersecurity certification scheme.

That is a different legal mechanism from ordinary IEC 62443 use, ISASecure certification, or an IECEE certificate. CEN-CENELEC public CRA material describes work to adapt EN IEC 62443 material into CRA-facing harmonised standards, including A11 work for EN IEC 62443-4-1:2018 and EN IEC 62443-4-2:2019. Until the relevant reference is published and the product is within its scope, the existing IEC 62443 evidence is supporting evidence, not CRA presumption by itself.

Reading certificates without overclaiming

The safe reading is narrow. A certificate can be strong evidence for the thing it actually assessed. It should not be stretched into a broader claim about a different role, a different product version, a different deployment, or a different legal regime.

  • Do not treat SDLA as proof that a specific component meets IEC 62443-4-2 technical requirements.
  • Do not treat CSA as proof that a deployed system has the right zones, conduits, SL-T, or operating procedures.
  • Do not treat SSA as proof that the asset owner's operating IACS security programme meets IEC 62443-2-1.
  • Do not treat a 2-4 service-provider certificate as proof that the product supplied by that provider has a component capability level.
  • Do not treat any IEC 62443 certificate as CRA presumption unless the CRA legal mechanism, OJ reference, covered Annex I requirement, and product scope are all present.

Useful certificate wording

The claim should name the scheme, part, edition, assessment object, version, level, scope limits, and the role it supports.

Sources