UL LLC is a certification body that can conduct assessments and certifications on behalf of the ISASecure certification scheme. We are independently accredited by an ISO/IEC 17011 accreditation body to ISO/IEC 17065, the international standard for product and process certification bodies. We demonstrate the qualifications necessary to conduct assessments of industrial automation and control systems using the ISASecure certification specifications.
What is ISASecure?
ISASecure is a third-party conformity assessment scheme based on the ISA/IEC 62443 series of standards. A third-party conformity assessment scheme is also known as a certification scheme. ISASecure currently certifies industrial automation and control system (IACS) products and the security development lifecycle used by product suppliers.
What products can be certified under ISASecure?
Products include IACSs such as distributed control systems (DCS) and supervisory control and data acquisition (SCADA), and IACS components like embedded devices, host devices, network devices and software applications.
How is the ISA Security Compliance Institute related to ISASecure?
The ISA Security Compliance Institute (ISCI) is the owner and developer of the ISASecure certification scheme, which is the set of rules and procedures that identifies the types of products and processes being assessed, identifies the specified requirements, and provides the methodology to perform a certification. ISCI is a non-profit subsidiary of the International Society of Automation (ISA), and includes asset owners, product suppliers, certification bodies and other interested organizations as members.
While ISCI develops and maintains the ISASecure certification scheme, it does not perform the certification itself. This is done by ISASecure certification bodies (CB), which are organizations that specialize in third-party conformity assessments.
Why is ISASecure certification important?
In today's world, end users are increasingly conscious of the dangers associated with cyber-attacks. ISASecure certification offers your customers a reliable way to verify the security features of your products, giving you a unique edge in the market. Moreover, these certifications can effectively show that your products:
- Comply with regulatory requirements.
- Fulfill the needs set by insurance companies.
- Meet the procurement criteria of asset owners.
ISASecure certifications are playing a crucial role in helping to secure automation that impacts our daily routines.
What services does UL LLC provide under the ISASecure certification scheme?
UL LLC can provide the following services:
- Security Development Lifecycle Assurance (SDLA) – a certification that the product supplier’s security development lifecycle meets the requirements of ISA/IEC-62443-4-1, secure product security development lifecycle requirements.
- System Security Assurance (SSA) – a certification that the IACS system meets the requirements of ISA/IEC-62443-3-3, system security requirements and security levels and has been developed using certified SDLA processes
- Component Security Assurance (CSA) – a certification that the IACS component meets the requirements of ISA/IEC-62443-4- 2, technical security requirements for IACS components and has been developed using certified SDLA processes. IACS components include embedded devices, host devices, network devices and software applications.
- IIoT Component Security Assurance (ICSA) – a certification based on ISA/IEC62443-4-2-2018, security for industrial automation and control systems, part 4-2: technical security requirements for IACS components. It is very closely aligned with the CSA certification and includes a few exceptions and a few extensions to the Part 4-2 requirements to account for the unique characteristics of IIoT components. ISASecure also added a market surveillance requirement to the security lifecycle dimension of the certifications.
Get connected with our team
Contact us to learn how we can help you with your ISASecure certification needs.