IEC 62443 certification cost has four parts: the standards you must buy, the scheme registration fee, the assessment fee a certification body charges, and the internal work of reaching the maturity level an assessor will accept. This guide prices each part from the sources that actually publish numbers, says which figures are estimates, and explains why two suppliers with similar products can receive quotes that differ by a factor of three.
IEC 62443 certification cost: the short answer
There is no single IEC 62443 certificate. The series certifies different things for different roles, so the first cost decision is which certificate you are actually buying. The table below sets out the typical ranges that accredited certification bodies and specialist consultancies publish in 2026; the figures are estimates, not a price list, and the scheme fees in the second column are the only numbers that are fixed and published.
| What is certified | Standard | Who buys it | Published scheme fee (ISASecure) | Typical assessment fee (estimate) |
|---|---|---|---|---|
| Secure development lifecycle (SDLA) | IEC 62443-4-1 | Product supplier | $1,500 per year | €15,000–€35,000 at Maturity Level 2 |
| Component (CSA / ICSA) | IEC 62443-4-2 | Product supplier | $1,200 per component or $1,500 per product family, per year | €25,000–€50,000 on top of a certified 4-1 process |
| System (SSA) | IEC 62443-3-3 | Supplier or integrator | $1,200 per year | €30,000–€50,000 |
| Service provider program | IEC 62443-2-4 | Integrator or maintenance provider | Body-specific | €15,000–€35,000 at Maturity Level 2 |
| Deployed site (ACSSA) | IEC 62443-2-1, 2-4, 3-2, 3-3 | Asset owner | Not yet published | Quoted per site; no public range yet |
Two notes on that table. The scheme fees are taken from the ISASecure certification pages as of September 2026 and are billed annually to keep a certificate listed. The assessment ranges are the figures a European IEC 62443 consultancy publishes for its clients, and they sit comfortably with the statement in ISASecure’s own FAQ that a first device certification “may range in cost from $50,000–$75,000”. Treat them as the order of magnitude, then read on for what moves your quote inside or outside them.
Why IEC 62443 certification cost has no fixed price
Certification bodies price an IEC 62443 assessment the way they price any conformity assessment: assessor days multiplied by a day rate, plus test-lab time for anything that involves a physical product. What varies is the number of days, and four things drive it.
Role. A supplier certifying a development process under Part 4-1 is audited on 47 requirements across eight practices. A supplier certifying a component under Part 4-2 is tested on the technical capabilities of the product itself. Under the ISASecure scheme the supplier’s development organization must already hold SDLA certification before a component can be certified, so the component fee is always in addition to the process fee. An asset owner certifying a plant under the new ACSSA scheme is assessed on four standards at once.
Target level. Component and system certificates carry a Capability Security Level from SL 1 to SL 4, and the functional assessment “incorporates more requirements at higher levels”, in the words of the CSA scheme document. Process certificates carry a maturity level on the four-step scale that Part 2-1 and Part 4-1 share. Every step up adds evidence, and evidence adds assessor days. Our guide to IEC 62443 security levels explains how SL-T, SL-C and SL-A relate, which matters because you pay to certify SL-C, the capability, not the level your customer’s risk assessment targets.
Scope and complexity. A single embedded sensor is cheaper than a distributed control system with a dozen component types. A development process run from one site is cheaper than one spread across three engineering centers in three countries. Test-lab time for vulnerability identification testing scales with the number of interfaces and protocols the product exposes.
Scheme. There are two mainstream routes. ISASecure, run by the ISA Security Compliance Institute, publishes its scheme documents and registration fees and accredits bodies such as exida, TÜV Rheinland and TÜV SÜD under ISO/IEC 17065. The IECEE CB Scheme issues “Certificates of Conformity – Industrial Cyber Security Capability” under operational document OD-2061 through national certification bodies, and those certificates report a three-number result for each practice: requirements passed, requirements not applicable, and total assessed.
The two routes assess against the same standard text, but the deliverable, the listing and the annual fees differ, so ask the customer who is demanding the certificate which one they will accept before you request quotes.
Line item 1: the standards themselves
You cannot certify against a document you have not read, and the IEC sells each part separately. These are the IEC Webstore prices checked on 13 September 2026, in Swiss francs; at September 2026 rates a franc is worth roughly US$1.20–1.25.
| Part | Current edition | IEC Webstore price | Needed by |
|---|---|---|---|
| IEC 62443-2-1 | Ed 2.0, 2024 | CHF 405 | Asset owners |
| IEC 62443-2-4 | Ed 2.0, 2023 | CHF 405 | Service providers, integrators |
| IEC 62443-3-2 | Ed 1.0, 2020 | CHF 260 | Asset owners, integrators |
| IEC 62443-3-3 | Ed 1.0, 2013 | CHF 380 | Asset owners, integrators, system suppliers |
| IEC 62443-4-1 | Ed 1.0, 2018 | CHF 335 | Product suppliers |
| IEC 62443-4-2 | Ed 1.0, 2019 (+ Cor 1:2022) | CHF 405 | Product suppliers |
| IEC TS 62443-6-1 | Ed 1.0, 2024 | CHF 430 | Assessors (2-4 evaluation method) |
| IEC TS 62443-6-2 | Ed 1.0, 2025 | CHF 380 | Assessors (4-2 evaluation method) |
A product supplier’s minimum set, Parts 4-1 and 4-2, is CHF 740. An asset owner preparing for a site assessment needs Parts 2-1, 3-2 and 3-3, which is CHF 1,045 before adding 2-4 to understand what the plant’s service providers will be held to. Budget the full set at under CHF 3,000; it is the smallest line in the whole exercise and the one most often skipped, which is how teams end up certifying against a consultant’s summary rather than the standard.
One warning while you are buying. Several vendor sites claim that IEC 62443-4-2 was republished as a 2026 edition. The IEC Webstore on 13 September 2026 still lists Edition 1.0:2019 with the 2022 corrigendum as the current, valid document. The series is in revision, but no new edition of 4-2 has been published, and a certification body will assess you against the edition that exists.
Line item 2: scheme registration fees
This is the part of IEC 62443 certification cost that is genuinely published. ISASecure lists its conformance scheme fees on each certification page, and they are annual fees that keep the certificate registered and the product or organization listed on the ISASecure site.
| ISASecure scheme | Registration fee | Basis |
|---|---|---|
| SDLA (IEC 62443-4-1) | $1,500 | Annual, per certified development organization |
| CSA (IEC 62443-4-2) | $1,200 | Annual, per component |
| CSA product family | $1,500 | Annual, per registered product family |
| SSA (IEC 62443-3-3) | $1,200 | Annual, per certified system |
| ACSSA (asset owner site) | To be published | ISASecure lists the inspection-body and certification-body registration fees as “TBD” as of September 2026 |
Before 1 January 2020 the SDLA registration fee was $5,000 for members and $7,500 for non-members, with a separate maintenance fee; the flat $1,500 annual fee replaced that structure, and the old figures still circulate in older articles. Under the IECEE route there is no equivalent public fee table; the national certification body’s quote includes its own scheme costs.
The product family fee is the single most useful line in this table for a supplier with a range of similar devices. Registering a family at $1,500 a year instead of four components at $1,200 each is a small saving on paper, but the assessment logic behind it, where variants share the same development artifacts and most of the same functional evidence, is where the real reduction in assessment days comes from.
Line item 3: the assessment fee
The assessment fee is the largest external line in IEC 62443 certification cost, and ISASecure’s own guide says it is “negotiated with the ISASecure Certification Body”. No body publishes a rate card, so the ranges below come from published consultancy estimates and from suppliers who have disclosed their spend, and you should read them as 2026 estimates rather than quotes.
For a Part 4-1 process certification at Maturity Level 2, the published consultancy range is €15,000 to €35,000. That covers the document review of your secure development lifecycle, interviews with the people who run it, and evidence that the process has been executed on at least one product. Higher maturity levels cost more, but the same source notes the increment is smaller if an ML 2 certificate already exists, because the assessor is looking for evidence of consistent practice rather than re-reading the process.
For a Part 4-2 component certification on top of an already certified 4-1 process, the published range is €25,000 to €50,000, and the ISASecure FAQ’s $50,000–$75,000 for a first device certification is the upper end of the same picture. The spread is mostly Security Level and component type: a network device at SL 3 has far more capability requirements to demonstrate, and more interfaces to test, than a software application at SL 1. Under ISASecure, the component evaluation has three elements, a security development artifacts review, a functional security assessment and vulnerability identification testing, and only the functional assessment grows with the level.
For a system certification under Part 3-3 or a service-provider program under Part 2-4, expect €30,000 to €50,000. Systems are priced on zone and conduit count, component count and the number of integration services in scope, which is why an integrator’s quote depends heavily on how tightly the reference architecture is defined before the assessor arrives.
Day rates behind these figures are not published either. The bodies doing this work are the same ones that price functional safety assessments, and OT security assessors are scarcer than ISO 27001 auditors, so assume a specialist day rate above what you pay a management-system auditor. Assume too that the body will want a gap assessment or pre-audit first, which is usually a separate, smaller engagement.
Line item 4: the internal cost of reaching Maturity Level 2
Every quote above assumes you arrive at the assessment with a documented, executed process. For most first-time applicants, the gap between where they are and where the assessor needs them to be is the largest cost in the project, and it is invisible on the certification body’s invoice.
The standard is explicit about the threshold. Part 2-1 places documented policies, procedures and training at Maturity Level 2, and Part 4-1’s practices are written the same way: the assessor is checking that each of the 47 requirements is defined in writing, that people are trained on it, and that there is evidence it is followed. Level 3 adds a track record of the documented process being practiced consistently over time, which no template can provide, but Level 2 is largely a documentation exercise. Our explainer on IEC 62443 maturity levels walks through what evidence each level demands.
That is the gap the IEC 62443 Toolkit is built to close for asset owners and service providers. It contains 117 templates, 82 Word documents and 35 Excel workbooks, organized on the eight security program elements of IEC 62443-2-1 Edition 2.0, with the zone and conduit, risk assessment and applicability workbooks pre-seeded with every requirement in the standard, so the evidence pack an ACSSA or Part 2-4 assessor asks for exists before the gap assessment rather than after it.
The pack also ships mappings to ISO/IEC 27001:2022 and NIST CSF 2.0, which matters because the standard’s own annexes still map to the 2013 and 1.1 editions.
Realistic internal budgets run from a few weeks of one engineer’s time for a small supplier with mature processes to six to twelve months of a part-time program lead for an asset owner starting from an undocumented plant. The best single predictor is whether an asset inventory under change control and a risk assessment already exist, because those are the two submissions ACSSA requires before an evaluation can be scheduled.
IEC 62443 certification cost for asset owners: the ACSSA scheme
Until 2026 the honest answer for a plant owner was that there was nothing to certify; ISASecure’s own guide said there was “no additional cost” for asset owners because no asset owner scheme existed. That changed with Automation and Control System Security Assurance, announced in June 2025 and effective 17 February 2026, which evaluates “a deployed control system and related asset owner policies and procedures” against Parts 2-1, 2-4, 3-2 and 3-3 at a specific site.
ACSSA offers two products at the same evaluation depth. An inspection ends in a letter confirming the evaluation was completed, with no surveillance and no symbol; ISASecure positions it as a tool for internal assurance or for measuring progress between assessments. A certification attests to overall conformity, runs for three years, requires periodic surveillance, and allows the ISASecure ACSSA symbol to be displayed for that system. The full scheme is described on the ISASecure ACSSA certification page.
Pricing is the open question. As of September 2026 ISASecure lists the ACSSA body registration fees as not yet released, Perseus Information Security Consulting is the first accredited ACSSA certification body, and no public assessment range exists. What can be said with confidence is that the assessment is site-specific and multi-standard, so expect it to be quoted per site and to sit above a single-standard system certification.
Two factors will pull IEC 62443 certification cost down for a plant. A maintenance service provider that already holds a Part 2-4 certificate at ML 3 contributes evidence directly, and a site that already runs an ISO 27001-style security program has most of the Part 2-1 documentation in a different binder. Our comparison of NIS2 and IEC 62443 covers why European operators are looking at ACSSA now rather than later.
The three-year cost of ownership
IEC 62443 certification cost does not stop at the initial certificate. SDLA certification “expires in three years” and is extended only by passing a recertification audit; ACSSA certification is likewise three years with surveillance in between; component certificates are tied to a product version and must be maintained through defined update and upgrade procedures as the product changes. Add the annual registration fee every year the certificate is listed.
| Cost element | Year 1 | Year 2 | Year 3 | Notes |
|---|---|---|---|---|
| Standards | CHF 740–1,045 | — | — | One-off, unless an edition changes |
| Registration fee (SDLA + one CSA component) | $2,700 | $2,700 | $2,700 | ISASecure published fees |
| Initial assessment (4-1 + one 4-2 component) | €40,000–€85,000 | — | — | Consultancy estimate; SL and scope dependent |
| Surveillance and maintenance | — | Low thousands of euros upward | Low thousands of euros upward | Rises with product changes |
| Recertification | — | — | Up to close to the initial fee | Triggered at expiry or major change |
The consultancy source we cite puts ongoing costs “from a few thousand euros per year for simple surveillances up to nearly the full amount of the initial certification”, and that spread is real: a supplier whose product does not change pays little, while one that ships a major release every year is effectively re-certifying every year. For budgeting, the rule that holds up across schemes is to plan for roughly twice the initial assessment fee across the first three-year cycle, plus three years of registration fees.
How to reduce IEC 62443 certification cost without cutting corners
Certify the process once, then the products. Because a CSA certificate requires an SDLA certificate behind it, the 4-1 assessment is a fixed cost you pay once per development organization. Every subsequent component certification then reuses it, and the security development artifacts review for each component becomes a check that the certified process was followed, not a fresh process audit.
Certify the Security Level your customers actually specify. SL 2 is what most asset owner risk assessments land on for typical zones. Certifying at SL 3 because it looks better on the datasheet adds requirements, test time and assessment days that no tender may ever ask for. Read the target levels in your customers’ zone and conduit designs first.
Reach Maturity Level 2 before you ask for a quote. A body that finds an undocumented process at the gap assessment will price in a second visit. Arriving with the eight security program elements or eight development practices documented, trained and evidenced turns a two-stage engagement into one.
Choose the scheme your buyer names. An ISASecure listing and an IECEE Certificate of Conformity are both legitimate, but a customer’s supplier qualification process usually names one. Certifying under the wrong route and then buying the other is the most expensive mistake in this list. Our overview of IEC 62443 certification explains how the routes differ for each role.
Frequently asked questions
What is the IEC 62443 certification cost for a product supplier?
Plan for a Part 4-1 process assessment of roughly €15,000–€35,000 at Maturity Level 2, plus €25,000–€50,000 per component under Part 4-2 depending on Security Level, plus ISASecure registration fees of $1,500 for SDLA and $1,200 per component each year. ISASecure’s own FAQ places a first device certification at $50,000–$75,000. All of these are published estimates, not quotes.
Is there an IEC 62443 certification for asset owners?
Yes, since 17 February 2026. The ISASecure ACSSA scheme certifies a deployed control system at a specific site against Parts 2-1, 2-4, 3-2 and 3-3, with a three-year certificate and surveillance, or a one-time inspection that ends in a letter. Pricing has not been published and the first accredited certification body was only recently announced, so expect quotes rather than a rate card.
Do I have to buy the IEC 62443 standards to get certified?
You need the parts you are being assessed against. On the IEC Webstore in September 2026 the supplier pair 4-1 and 4-2 costs CHF 740 and the asset owner set 2-1, 3-2 and 3-3 costs CHF 1,045. The ISASecure technical specifications that assessors use are free to download.
How long is an IEC 62443 certificate valid?
SDLA and ACSSA certificates run three years and require recertification; component certificates are granted for a specific product version and maintained through the scheme’s update and upgrade procedures as the product changes. Registration fees are annual regardless.
Is IEC 62443 certification required by law?
No. IEC 62443 certification is voluntary and contractual; it is demanded by customers, insurers and, increasingly, by operators subject to NIS2 who want evidence from their suppliers. The EU Cyber Resilience Act will create legal obligations for product manufacturers, with reporting duties from 11 September 2026 and the remaining obligations from 11 December 2027, but it does not mandate an IEC 62443 certificate.
Whichever route you take, the cheapest assessment is the one you walk into prepared. If you are an asset owner or service provider building the Part 2-1 or Part 2-4 evidence base from a standing start, the IEC 62443 Toolkit gives you the 117 documents an assessor will ask for, already structured the way the standard is assessed, for $99.