Disclaimer: All views presented here, in this newsletter, are my own, or are either sourced from internet or using AI (using LLMs) search and referenced accordingly.
Author or the newsletter are not liable for any actions taken by any individual or any organization / business / entity. The information provided is for information, education and awareness purposes only and is not specific to any business and or situation.
This publication does not constitute legal, regulatory, or professional security advice.
Hi Securing Things family, Hope you are doing well.
In the last newsletter edition (EU AI Act is about Trust, Not AI), I mentioned that we’ll be covering 3 awareness campaigns on 3 different topics on my socials. The Securing Things for EU AI Act Awareness Series was covered in previous edition.
↪️ This edition focuses on starting the 2nd of the 3rd campaigns as the main theme: Prove it - for Asset Owners - ISA Secure ACSSA awareness series. – What every stakeholder at an asset owner organization needs to know about ACSSA Conformity Assessment scheme.
The 3rd one on HKPCICSO; to start sometime soon as well.
Part 1 - ISASecure ACSSA Awareness Series
Remember to bookmark this, as I’ll be updating this as I continue the Prove it - ACSSA awareness series.
For fifteen years, IEC 62443 certification has been something your suppliers did. That just changed in 2026 for the first time.
Two words are quietly becoming the hardest question in industrial cyber security.
A regulator asks them. An insurer asks them. Your board asks them, usually after reading something alarming.
Prove it.
Not, are you compliant?
Not do you follow 62443?
Prove it — with evidence, about your operation, that a third party will stand behind.
ISASecure's new ACSSA (Automation Control System Security Assurance) certification conformity scheme is the first credible way to answer.
Early in 2026, I was lucky to be part of the 1st badge of participants to attend the ACSSA Evaluators Training and passed the exam a couple of months later and become ISASecure ACSSA for Evaluators Specialist. See the announcement post → here.
In this edition, we’ll walk through a brief introductory overview on ACSSA certification program, the ACSSA awareness series on my social and also highlight the upcoming free webinar on 3rd September 2026.
Don’t miss out on these informative resources to get you started!
But before we begin, do me a favor and make sure you “Subscribe” to let me know that you care and keep me motivated to publish more. Thanks!
Ready? let’s dig in.
Yours truly.
— Yousuf.
♻️if you know someone in your professional circle who will benefit from these resources and interested in learning. Thanks 🌟
Together with (Sponsor):
2 Free AI Courses. No Credit Card Needed.
5,000+ professionals use Skill Leap to get ahead with AI. Right now, two of their best courses are completely free - Claude 101 and the 14-Day AI Boot Camp.
Claude 101 covers prompting frameworks, Artifacts, file analysis, and real-world workflows in 19 lessons.
The Boot Camp covers ChatGPT, Gemini, Midjourney, and prompt engineering in 16 lessons. Downloadable workbooks. LinkedIn certificate.
Zero cost, no credit card, no catch.
Prove It - ACSSA for Asset Owners - An Awareness Series!
Here’s a free awareness series on ACSSA:

Part 1 → Securing Things for Asset Owners via ACSSA Certification - by M. Yousuf Faisal - an Awareness Series
<several additional parts will be added here over the next 30 days>
Be sure to bookmark this and come back to this for reference.
♻️Do let me know + reshare if you like & find this helpful in your roles♻️
If you’d like a video explainer to this series, do hit the reply button to let me know. If I get even 25 replies, I’ll turn this into free video series as well.
PROVE It - ACSSA for Asset Owner - Webinar:
Understanding ACSSA Certification — Site-level evidence layer for industrial cybersecurity.
Introduction to ISASecure's latest release of "Automation and Control System Security Assurance (ACSSA) certification schemes 1.0.0 – a certification that evaluates a deployed control system and related asset owner policies and procedures meets the requirements of ISA/IEC-62443-2-1, ISA/IEC-62443-3-2, ISA/IEC-62443-3-3, ISA/IEC-62443-2-4.

Registration Link → Free Webinar - Prove it - ACSSA Certification for Asset Owners
Agenda:
1 - The Evidence Gap
2 - What ACSSA actually is?
3 - The four Pillars
4 - Inspection vs. Certification
5 - Is ML3 Realistic?
6 - Fit with your obligations?
7 - Your Readiness Path?
No prior knowledge of ACSSA is needed - this is designed to help you get aware on the ISASecure ACSSA Certification scheme and its journey as building blocks.
Learn what it means for you as an asset owner and how this'll help your business.
Preference will be given to people from asset owners organizations - on first cum first serve basis - until the limited seats last.
Thu, Sep 3, 2026 6:00 PM - 7:00 PM (UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi
We look forward to having you attend the event!
📖 Register and ensure you secure your attendance here today. 📌
ACSSA for Asset Owners - 60-second version
ACSSA — Automation and Control System Security Assurance — is the first ISASecure scheme where the asset owner is the one being certified, not the vendor.
It assesses a real IACS (industrial automation control systems), in your plant, as you actually run it. Not a product on a bench. Not a brochure.
Your zones, your conduits, your patching reality, your contractors.
Who it's for: asset owners and operators of an IACS — energy, water, pharma, manufacturing, transport, buildings.
What's assessed: your security programme, your risk assessment, your system's technical controls, and the service providers you rely on.
Two ways in: a formal inspection (private report, no certificate) or full certification (certificate + optional public listing).
The kicker: certified products and certified service providers you already use can count as evidence. Your procurement discipline finally pays a dividend.
The Evidence Gap
The ISASecure family used to have a hole in the middle of it.
SDLA certified how a vendor develops.
CSA certified components.
SSA certified systems as shipped.
62443-2-4 certified service providers.
Every one of them answered the question
"Is this thing capable of being secure?"
Nobody was answering the harder question:
"Is the system you are actually operating, right now, actually secure?"
That gap is where every incident lives.
A perfectly certified PLC, integrated by a certified integrator, can still sit in a flat network with five-year-old firmware and a shared engineering password.
Every certificate in that sentence is real. The system is still indefensible.
ACSSA is the scheme that walks into that room.
And the timing is not accidental.
Regulators, insurers and boards have all arrived at the same demand within about eighteen months:
stop showing me supplier certificates, show me evidence about your own operation.
The Four Pillars
Four parts of the standard, each answering a different question.
This is the whole scheme in one table. ACSSA relies on following four:
Standard | Question it Answers | What is asked to be prove |
|---|---|---|
62443-2-1 | Do you run a real security programme? | Policies, governance, roles, patching, access control, incident response — and evidence they operate |
62443-2-4 | Do you know what you're protecting and from what? | Zone and conduit model, risk assessment, target security levels with justification |
62443-3-2 | Does the system technically deliver those levels? | System capabilities mapped to the SL-T you set per zone, and how you use them |
62443-3-3 | Are the people you outsource to up to standard? | Integration and maintenance provider processes, and evidence they were followed |
Read that again and notice what it means:
you cannot pass ACSSA on paperwork alone,
and you cannot pass it on technology alone.
2-1 without 3-3 is a binder. 3-3 without 2-1 is a shopping list.
The scheme deliberately requires both, plus the supply chain that touches them.
The majority questions nobody enjoys
Here is where most first assessments get uncomfortable.
62443 doesn't only ask whether you have a process.
It asks how maturely you operate it — broadly:
from ML1 (ad hoc, done by good people improvising)
through ML2 (a documented, managed process)
to ML3 (that process demonstrably practiced across the organisation, with records) and
ML4 (measured and continuously improved).
ML3 is the wall.
Most organisations sincerely believe they're there.
Under an evidence-based assessment, many discover they are at ML2 — a genuinely good process, applied inconsistently, evidenced partially.
Try it on your own programme. Your patching policy is excellent: reviewed, approved, no notes.
Now produce twelve months of evidence it was executed on the systems in scope.
Not the policy. The execution. Dated, attributable, complete.
If that would take a fortnight to assemble, that's the distinction the assessment draws — and it's the single most common reason a first attempt stalls.
Two things worth saying plainly.
First, this is not a criticism of the sector; it's where most of it honestly sits, including some very sophisticated operators.
Second, maturity is not a hardware problem.
A 1998 DCS with a disciplined, recorded change process can evidence higher maturity than a brand-new system nobody documents.
Legacy kit is a security-level question and a compensating-controls question.
It is not, by itself, a maturity question — and conflating the two wastes an enormous amount of effort.
The scope decision is yours — and it's the most important one you'll make
You define the boundary of the IACS being evaluated. One production line. One site. One process unit.
A certificate reads like "ABC Company IACS at City Y" — it is tied to a specific system, not stamped across the enterprise.
This is a feature, not a limitation. Start narrow, on a system you understand well, and prove the model works before you scale it.
A tight, honest scope that passes is worth infinitely more than an ambitious one that stalls.
One more useful detail: an IACS can be evaluated whether or not it is already in operation.
Greenfield projects can build toward ACSSA and be assessed before handover — the cheapest moment in the entire lifecycle to fix a security design.
Inspection OR Certification? Pick your Door
Formal inspection — carried out by an accredited Inspection Body, which issues an inspection report.
You get a rigorous, independent read of where you stand.
No certificate, no public exposure.
Ideal as a first pass, a board briefing, or a gap analysis with teeth.
Certification — carried out by an accredited Certification Body, which issues a certificate plus a full certification report.
You may display the ISASecure symbol.
ISCI will publish your certificate on isasecure.org only if you ask — otherwise it can be released privately to a named third party.
That last point matters more than it looks. You control disclosure.
You can hold a genuine third-party certificate and show it to a regulator, a customer or an insurer without advertising your critical infrastructure to the internet.
Certificates carry an expiry date, require periodic surveillance to stay valid, and need recertification to extend.
It is a live commitment, not a plaque.
You may already be part-way there
This is the part most asset owners miss, and it's the strongest commercial argument in the scheme.
Where you have used ISASecure CSA certified components, SSA certified systems, vendors with SDLA certification, or maintenance and integration providers holding 62443-2-4 certification, those certifications contribute evidence toward the 3-3 and 2-4 elements of your ACSSA evaluation.
Every certified product you specified and every certified integrator you hired now reduces the evidence burden on your own assessment.
If you've been pushing 62443 into procurement for years and struggling to articulate the return — this is it, in writing.
It does not eliminate the work.
An ACSSA evaluation examines how you use those capabilities to meet each zone's target security level, not merely that you bought them.
But it materially shortens the road.
Who's in the room
Role | What they contribute |
|---|---|
Asset owner | Accountable. Defines the IACS boundary, applies, owns the outcome |
Integration service provider | Design and integration-phase documentation for the system under evaluation |
Maintenance service provider | Maintenance process documentation and evidence it was executed |
Product suppliers | Evidence of product technical capabilities within each zone |
IB (Inspection Body) / CB (Certification Body) | Perform the evaluation; issue inspection reports or grant certification |
ISCI | Owns the scheme, interprets the specifications, lists accredited bodies |
Practical read: Start collecting from your integrators and maintainers now.
The documentation ACSSA wants from them is easiest to obtain while the commercial relationship is warm — and painfully hard three years after project close.
Our honest take
What we like:
It closes the accountability gap.
It is evidence-based rather than questionnaire-based.
It rewards good procurement. And the inspection route gives you a low-risk way to find out where you really stand before committing to anything public.
What to think about:
Evidence collection is the real cost, not the assessment fee — most organisations underestimate this by a wide margin.
Scope discipline is everything. Surveillance is an ongoing obligation your budget needs to know about.
And as with any new scheme, the population of accredited bodies and the pool of practitioner experience will take time to mature.
Our recommendation:
Treat ACSSA as a structured improvement programme that happens to end in a certificate — not as a compliance sprint.
Organisations that approach it that way finish faster and get more from it.
Five things to do before you apply
Pick one IACS. One site, one line, one unit. The one you know best, not the one that worries you most.
Find your zone and conduit model. If it doesn't exist, or hasn't been touched since commissioning, that is your genuine starting point — 3-2 underpins everything else.
Audit your evidence, not your intentions. For each 2-1 requirement, ask: could I show a stranger proof this operated last quarter?
Inventory the certifications you already hold across products, systems and service providers. Map them to 3-3 and 2-4. You will be pleasantly surprised.
Talk to your integrator and maintenance provider now. Get the documentation while people still remember the project.
Join us live on free Webinar: Prove It — ACSSA Certification for Asset Owners
A live session hosted by Securing Things Limited on Microsoft Teams.
Agenda have seven items, then open Q&A.
The Evidence Gap.
What ACSSA actually is
The Four Pillars
Inspection vs. Certification
Is ML3 realistic?
Fit with your obligations
Your readiness path
Then live Q&A — the part most people come for. Bring the question you haven't been able to answer for your board.

When: 3rd September 2026. 6 - 7 pm GMT +8
Where: Microsoft Teams
Register: Registration Link (Please use official email to secure your spot)
Cost: Free
Places are limited so the Q&A stays genuinely useful.
If you own, operate, secure, audit or supply an industrial control system, this one is aimed squarely at you.
Forward this to one person
The colleague who has been asked "are we 62443 compliant?" and doesn't yet have a good answer. ACSSA is how that answer starts getting built.
Securing Things Limited — practical OT and industrial cyber security.
Follow us on LinkedIn for the webinar announcement and future editions.
Scheme details in this edition are drawn from ISASecure's published ACSSA programme documentation.
Always confirm current requirements, specification versions and accredited body details with ISCI or your chosen conformity assessment body before applying.
Together with (Sponsor):
Your Competitors Just Hired an Entire GTM Team. No Humans.
AI agents are doing the work of full GTM teams. Pipeline, content, customer service. The startups using them aren't waiting for headcount approvals.
Get the free Practical Guide to Agentic GTM for Startups and see exactly where to start.
My Recent Most Viewed Social Posts
In case you’ve missed - here are some of my recent most viewed social posts.
🗞️🗞️[ST # 87] EU AI Act Is about Trust, not AI! ✅– My EU AI Act Awareness Series + Easy Peasy Guide + What Every Manufacturing Leader Needs to Know Before AI Governance Becomes a Boardroom Conversation🚀[Securing Things by M. Yousuf Faisal] 🗞️🗞️
🗞️🗞️[ST # 86] Cybersecurity - Before & After Mythos ✅ Big Change AI Reveals for Cybersecurity, Mythos CISO briefing, What This Means for CISOs and So Where Do We Go From Here. 🚀 [Securing Things by M. Yousuf Faisal] 🗞️🗞️
🗞️🗞️[ST # 85] Cybersecurity Insights from Q1 2026 ✅ IT, OT, AI Cybersecurity Market (fundings, start-ups & M&As), Incidents, breaches, ransomware, cyber threat landscape, regulations and CISOs evolving role. Things are happening & changing very fast.🚀 [Securing Things by M. Yousuf Faisal] 🗞️🗞️
🗞️🗞️[ST # 84] Cybersecurity Insights from Q4 2025 ✅ IT, OT, AI Cybersecurity Market (fundings, start-ups & M&As), Incidents, breaches, ransomware, cyber threat landscape, regulations and CISOs evolving role. Things are happening & changing very fast.🚀 [Securing Things by M. Yousuf Faisal] 🗞️🗞️
🗞️🗞️[ST # 83] The Digital Factory - Industry Debates Part 4 ✅Most common Industry Debates (IT/OT Convergence, Purdue Model Dead or Alive, Digital transformation - a strategy or a project, MQTT vs. OPC UA and more) and other updates. [Securing Things by M. Yousuf Faisal] 🗞️🗞️
🗞️🗞️[ST # 82] AI Security & OT Cybersecurity ✅AI tools for research papers, Agentic AI security, AI in OT security guidance, AI benchmark task, Cybersecurity for Railway + Robotics, Li-Fi Tech and weekly inspiration🚀[Securing Things by M. Yousuf Faisal] 🗞️🗞️
Ways in which I can help?
Whenever you are ready - I can help you with:
A - IT & OT Cybersecurity Advisory / Consulting services - for securing your business and or its digital transformation journey.
B - Security Awareness Training & Phishing Awareness Portal - Train your staff and build a Security awareness program through our subscription based service.
C - Securing Things Academy (STA) - Security trainings for IT & OT practitioners.
Visit the newsletter website for Links to above services and or reach out at info[at]securingthings[dot]com or DM me via LinkedIn.
D - Securing Things Newsletter - Sponsor this newsletter to showcase your brand globally, or subscribe to simply Get Smarter at Securing Things.
Reach out at newsletter[at]securingthings[dot]com or DM me via LinkedIn.
✉️ Wrapping Up
Have questions, comments, or feedback? Just reply directly, I’d love to hear from you.
Also, if you find this or previous newsletter edition(s) useful and know other people who would too, I'd really appreciate if you'd forward it to them. Thanks a ton.
Thanks for reading - until the next edition!
It’s a Great Day to Start Securing Things for a Smart & Safer Society.
Take care and Best Regards,
Rate the newsletter content
If you are reading this online don’t forget to register; validate your email, and request a login link to submit the poll.
Your feedback and input is invaluable to me as we work together to strengthen our cybersecurity defenses and create a safer and smarter digital society. Thank you for your trust and continued support.





