Operational technology (OT) now sits at the center of public safety and economic stability. The same programmable controllers, network devices, and industrial systems that run power grids, water treatment plants, pipelines, and factory floors are increasingly connected, and increasingly targeted. As a result, asset owners and regulators no longer accept a vendor’s word that a product is “secure.” They want independent, internationally recognized proof.
That proof depends on two things working together: a rigorous technical standard, and credible accreditation behind the laboratory that applies it. This case study looks at how OT cybersecurity testing accreditation turns IEC 62443 into results the market can actually trust, and how a laboratory reaches that point through NAC.
The challenge: cybersecurity claims without accredited proof
The OT security market has a credibility problem. Dozens of products carry “cyber-secure” labels, but buyers often can’t distinguish a marketing claim from a rigorous, independently verified assessment. For a plant operator deciding which safety controller to install, that gap is not academic; it is a risk that propagates straight into critical infrastructure.
The IEC 62443 series was written to close exactly this gap. It defines security requirements for industrial automation and control systems (IACS) across products, systems, and the development processes behind them. But a standard only creates trust when a competent, impartial party tests against it, and when that party’s competence has itself been independently verified. Otherwise the market is back to trusting a self-declared claim, just with a standard number attached.
The framework: IEC 62443 and the ISASecure scheme
ISASecure, managed by the ISA Security Compliance Institute (ISCI), operationalizes IEC 62443 into concrete, certifiable conformance schemes. In practice, ISASecure certifications fall into three broad families:
- Development-lifecycle assurance: evaluating that a vendor’s security development process itself is disciplined and repeatable.
- Component security: technical security testing of embedded devices, host and network devices, and software applications.
- System security: assessment of integrated automation and control systems.
Certificates are issued by “chartered” laboratories and certification bodies. And here is the essential point that many vendors miss: a lab cannot simply declare itself an ISASecure lab. It must be independently accredited first.
Why accreditation is the missing link
Under the ISASecure scheme, the security testing behind a certificate must be performed by a laboratory whose technical competence has been independently accredited to ISO/IEC 17025 by an ISO/IEC 17011 accreditation body. And crucially, that accreditation body must itself be a signatory of the Global Accreditation Cooperation (Global ACI) Mutual Recognition Arrangement, the single global arrangement that replaced the former ILAC MRA and IAF MLA in January 2026.
This is what makes an ISASecure test result mean something across borders:
- ISO/IEC 17025 confirms the laboratory is technically competent to run the security tests and produce valid, reliable results.
- Global ACI MRA recognition confirms that those results are accepted internationally, not just locally.
Remove either layer and the result weakens. This is precisely where the accreditation body, NAC, enters the story.
The case: accrediting a laboratory for OT cybersecurity testing
Consider a representative applicant: an established product-testing laboratory with genuine OT security depth, staffed by engineers who understand industrial protocols, penetration testing, and the realities of a plant floor. Commercially, the opportunity is clear: asset owners and regulators are asking their suppliers for IEC 62443 conformance, and the lab wants to issue recognized ISASecure certificates rather than informal security reports.
The barrier is not technical skill. It is recognition. To have its ISASecure testing accepted, the applicant needs accreditation to ISO/IEC 17025 from an accreditation body that both understands the IEC 62443 technical domain and is a Global ACI MRA signatory.
This is where the NAC and ISASecure relationship does real work. Because NAC holds a Memorandum of Understanding with the ISA Security Compliance Institute and is a Global ACI MRA signatory, a laboratory can be accredited by NAC to ISO/IEC 17025 for the testing that underpins the ISASecure scheme. Rather than being routed through a default list and waiting for an agreement to be arranged, the applicant works with an accreditation body that has already established that pathway.
From there, the accreditation journey follows a clear arc:
- Scope definition: which ISASecure schemes and which parts of the IEC 62443 series the lab intends to cover.
- Documentation and management-system review: assessing the lab’s quality system against ISO/IEC 17025.
- Competence and method assessment: confirming that assessors, methods, and validation evidence match the declared cybersecurity testing scope.
- On-site assessment and witnessing: observing the lab actually perform security testing to verify competence in practice, not just on paper.
- Decision and accreditation: issuance of the ISO/IEC 17025 accreditation that lets the lab perform accredited testing within the ISASecure scheme.
The outcome is straightforward but valuable: the lab can now issue ISASecure certificates that carry Global ACI MRA recognition. A buyer in another country, or a regulator reviewing a supplier, can accept those certificates without re-testing, because the accreditation chain behind them is internationally recognized.
Why the NAC and ISASecure MoU matters
For laboratories entering the OT security market, the practical advantages of that MoU are concrete. It gives applicants a Global ACI MRA signatory accreditation body that already has a working relationship with ISASecure, an ISO/IEC 17025 accreditation process built for the testing that underpins ISASecure, and assessors who understand conformity assessment and the IEC 62443 domain rather than only one or the other. For a lab, that means less friction reaching the market, and for the market, it means one more credible source of trusted OT security certificates.
The bigger picture: trust for critical infrastructure
Cybersecurity for industrial systems is ultimately a trust problem. Asset owners must trust vendors; vendors must trust their test results; regulators must trust the certificates they rely on. IEC 62443 supplies the technical language, ISASecure turns it into a certification scheme, and accreditation, the layer that is easiest to overlook, is what makes the whole chain hold together across borders. As OT and IT continue to converge, that trust infrastructure only grows more important.
Frequently asked questions
What is ISASecure? ISASecure is a conformance certification program, managed by the ISA Security Compliance Institute, that certifies IACS products, systems, and development processes against the IEC 62443 series of standards.
What accreditation must an ISASecure test laboratory hold? A laboratory’s testing competence is accredited to ISO/IEC 17025 by an ISO/IEC 17011 accreditation body, whose recognition is what makes the resulting testing internationally trusted.
Does the accreditation body need to be recognized? Yes. The accreditation body must be a signatory of the Global ACI Mutual Recognition Arrangement, so that resulting results are recognized internationally.
Can NAC accredit our laboratory for ISASecure? NAC is a Global ACI MRA signatory and holds an MoU with the ISA Security Compliance Institute, so it can accredit laboratories to ISO/IEC 17025 for the testing that underpins the ISASecure scheme and IEC 62443 OT cybersecurity work.
How long does accreditation take? It depends on the lab’s readiness: the maturity of its management system, the breadth of scope, and the strength of its method-validation evidence. A well-prepared laboratory moves through the process considerably faster.
Take the next step
If your laboratory is building an OT cybersecurity practice and wants to issue internationally recognized ISASecure certificates, accreditation is the foundation. Contact NAC to discuss ISO/IEC 17025 accreditation for IEC 62443 and the ISASecure scheme.