ICSA LABS

Organization dossier Founded 1989 as NCSA Status: closed 2022

For thirty-odd years it was one of the oldest names in security-product certification — the third-party stamp firewalls and antivirus wore to market. The vendors it certified were also the customers who paid it, helped write the criteria, and got two-to-four weeks to fix a failing product before the grade was final. Then, in 2022, it closed without a press conference.

ICSA Labs, an independent Verizon test lab, has been providing credible, third-party product assurance for end-users since 1989.

ICSA Labs, describing itself in the Verizon ICSA Labs fact sheet (its own marketing)

ICSA Labs gains a contractual commitment from the product vendor… a significant part of the ICSA Labs Certification process involves self-checking by the organization whose product is certified.

ICSA Labs, describing its own certification process, icsalabs.com — Product Certification (archived Dec 2022)

ENTITY
ICSA Labs — began as NCSA (National Computer Security Association) in 1989; in its final years an "independent division of Verizon" FACT
ROLE
Third-party certifier of security products — anti-virus, firewall, IPsec & SSL VPN, network IPS, anti-spyware, IoT, later health-IT FACT
THE MODEL
Vendor-pays: the manufacturer contracts with and pays ICSA before testing; a "significant part" of the process is the vendor's own self-checking; a failing product gets "typically 2 to 4 weeks" to be fixed before certification is finalized or revoked FACT
THE ARGUMENT
A certifier funded by the firms it certifies has a structural conflict of interest — compliance theater by incentive, not by any proven bad act. This is a reading of the model, not an adjudicated finding
RECORD
No fraud allegation. No falsified-result finding. No regulator, court, or reporting says ICSA faked a test. The case here is the incentive structure, in ICSA's own published words — nothing more FACT
STATUS
CLOSED 2022 — ceased operation after ~33 years; the WildList virus-sample collection it managed ended with it

This one is a structure, not a scandal. No court, no heckled ballroom, no snake oil — just a business model that was legal, disclosed, and, its defenders will tell you, ordinary for the industry. Read it that way. The receipts are almost entirely ICSA's own words about how its certification worked; the argument is what those words add up to.

The case is milder than most files here, and the counter-case is genuinely strong. That is why both sides get the microphone. Weigh the incentives; decide whether a stamp you paid for means what a stamp is supposed to mean.

the drama timeline

ACT I — THE CREDENTIAL (1989–2000s)

A young industry needed someone to say which products were safe. A consortium of the vendors themselves volunteered to help decide. Note who is in the room when the criteria are written.

  1. 1989

    NCSA is founded

    The National Computer Security Association is founded. Per its history, it "worked together with anti-virus software vendors to develop one of the first anti-virus software certification schemes" — a consortia model in which the organization and the vendors it would grade built the testing criteria together.

    The people being tested helped write the test. This is stated as history, not as a crime — but it is the seed of everything below.

  2. 1990s–2000s

    The stamp everyone wanted

    The lab expands well beyond antivirus, certifying "firewall, IPsec VPN, cryptography, SSL VPN, network IPS, anti-spyware and PC firewall products," and later IoT and health-IT. Its certification became a marketing asset vendors displayed to buyers — the third-party assurance that a product had passed an independent test.

  3. Accreditation as the seal of neutrality

    ICSA marketed itself as a "credible, third-party" lab and pointed to formal accreditation — a NIST NVLAP-accredited testing laboratory and an ANSI-accredited certification body (for its health-IT work). NVLAP accreditation is granted against the ISO/IEC 17025 laboratory-competence standard: it attests that a lab runs its tests competently.

    What such accreditation does not attest — and never claimed to — is that the lab is financially independent of the customers it grades. That is our observation, not the accreditor's.

ACT II — THE MODEL (in its own words)

Here is the whole case, and it is quoted from the subject. Not an accusation about ICSA — a description BY ICSA of how a product earned and kept the stamp.

  1. the deal

    The vendor contracts, and pays, first

    By ICSA's own account, certification "begins" when "ICSA Labs gains a contractual commitment from the product vendor." The manufacturer is the counterparty and the customer: it contracts for, and pays for, the testing of the product it wants certified. ICSA further states that "a significant part of the ICSA Labs Certification process involves self-checking by the organization whose product is certified."

  2. the loophole?

    Fail the test, get a few weeks to fix it

    If a product fails, ICSA's process states, "the responsible party is given a short time (typically 2 to 4 weeks) to rectify the problem(s)." Only "if the shipping product still does not meet current certification criteria by the end of this grace period" is certification "explicitly and publicly revoked." And once certified, "all future versions of the product (as applicable) are inherently certified."

    The critic's reading: a test you can fail and then fix on a two-week clock measures a vendor's willingness to patch, not the security a customer actually bought. The defender's reading is in the next act, and it is not weak.

ACT III — THE QUIET CLOSE (2017–2022)

Institutions of this kind rarely end in scandal. They end in a line item. Watch it wind down.

  1. APR 2017

    A dry run for the ending

    Per its history, "ICSA Labs temporarily ceased operation in April 2017, restoring operations a year later." A first, reversible pause.

  2. 2022

    Closed by the parent, and the WildList with it

    "ICSA Labs ceased operation in 2022, following closure by its parent company Verizon." The shutdown also ended the WildList — the curated collection of in-the-wild virus samples ICSA had managed and distributed to the industry for testing. Roughly thirty-three years of security certifications, wound down with minimal industry commentary.

    No press conference. No scandal. The oldest stamp in the business simply stopped being printed.

both sides, on the record

The structural case (an argument about incentives, not a finding of wrongdoing): the certifier was paid by the vendors it certified, and said so — certification "begins" with "a contractual commitment from the product vendor." The consortia origin means vendors helped write the criteria their products would face. A "significant part" of the process was the vendor's own self-checking. A failing product got "typically 2 to 4 weeks" to be fixed before the grade was final. Whatever the intent of any individual tester, the money flowed from the graded to the grader.

Accreditation is not independence: lab accreditation (NVLAP, against ISO/IEC 17025) certifies that tests are run competently. It does not certify that a lab is financially independent of the firms whose products it grades — and marketing that leans on the accreditation can invite readers to hear "neutral" where the accreditation only says "competent."

The through-line: the auditor paid by the audited is the same shape that recurs across the compliance industry — the incentive to keep the customer certified sits on the same side of the ledger as the fee.

Pay-for-testing is the industry norm, not a tell. Independent test labs — ICSA, and its peers — have to be funded somehow, and the party that wants a product certified is the party that pays for the work. That is how UL tests appliances and how most conformance labs operate. A funding model shared by the entire sector is not, by itself, evidence of anything.

Retest windows are ordinary QA. Giving a vendor a short, defined period to correct a failing item before a result is finalized is standard practice in conformance and quality testing; the alternative — one shot, no fixes — is not how most certification schemes work. And ICSA's own process says certification is "explicitly and publicly revoked" if the product still fails at the end of the window.

The accreditation is real and the method was published. ICSA held genuine NIST NVLAP and ANSI accreditations and published its certification criteria and testing reports; certified products' reports were made public. There is no allegation, order, court finding, or reporting that ICSA fabricated a result, faked a test, or knowingly passed an insecure product. This file documents an incentive structure, in the subject's own words — and nothing more.

YOU DECIDE

Scoped to the claim, never the institution — and this is a claim about a structure, not a charge against anyone. The claim "a paid certifier can be a neutral one" is the one on trial, and it is genuinely contestable: the fee flowed from the graded to the grader, the vendors helped write the criteria, and a failing product could be patched on a two-to-four-week clock before the grade set. Read the other way, every one of those facts is ordinary for a conformance lab, the accreditation was real, the method was public, and no one has ever shown ICSA cooked a single result.

There is no fraud here to find, and this page alleges none. What there is, in ICSA's own words, is an incentive map — the money and the criteria and the retest clock all sitting on the vendor's side of the table. Whether that map produces a trustworthy stamp is the question the reader is left holding. The lab closed in 2022 without ever having to answer it out loud.

The archive does not judge. The archive merely keeps the receipts.

evidence locker

SUBJECT'S OWN WORDS — THE MODEL, UNEDITED

  1. Verizon — ICSA Labs fact sheet (PDF, live) SELF-PUBLISHED — "an independent Verizon test lab… providing credible, third-party product assurance… since 1989"; the product lines; the NVLAP / ANSI / ONC accreditations. verizon.com/business/resources/factsheets/icsa-fact-sheet.pdf
  2. ICSA Labs — "Product Certification" process page (archived Dec 5, 2022; live site unreachable) SELF-PUBLISHED — "a contractual commitment from the product vendor," the "self-checking" language, the "typically 2 to 4 weeks" grace period, revocation, and "future versions… inherently certified." web.archive.org/web/20221205003613/…/product-certification
  3. ICSA Labs — "Testing Services" page (archived Jun 30, 2022) SELF-PUBLISHED — the paid testing-and-certification service, in the lab's own words. web.archive.org/web/20220630200028/…/testing-services

RECORD & HISTORY

  1. Wikipedia — International Computer Security Association FACT — founding as NCSA (1989), the "consortia model" with anti-virus vendors, "independent division of Verizon," the scope of certifications, the temporary April 2017 cessation, the 2022 closure by Verizon, and the end of the WildList. en.wikipedia.org/wiki/International_Computer_Security_Association

THE ARGUMENT — STATED AS ARGUMENT, NOT AS FACT

  1. troll.fan research file — Institutional Failures: ICSA Labs ANALYSIS — the structural conflict-of-interest reading (vendor-pays, self-authored criteria, remediation window, accreditation-as-shield). Our argument, built from the primary sources above; not an adjudicated finding. troll.fan/institutional.html
The standard. Everything above is sourced to ICSA Labs' and Verizon's own published materials and to the documented history of the organization. The vendor-pays model, the self-checking step, the two-to-four-week remediation window, the accreditations, and the 2022 closure are quoted or stated from the subject's own pages and the record. The conflict-of-interest reading is presented as an argument about incentives, clearly flagged as such and answered at full strength by the defense — because pay-for-testing is the industry norm, retest windows are ordinary QA, the accreditation is genuine, the methodology was public, and no fraud, falsified result, or wrongdoing has ever been alleged or found. No motive is asserted, no individual is named, and no charge is implied beyond the structure the receipts show. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.