IEC 62541-2:2026
OPC unified architecture - Part 2: Security Model
OPC unified architecture - Part 2: Security Model
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 60
- Дата публикации:
- 12 февраля 2026 г.
- Издание:
- IEC IS 62541 edition 1 version 1
- ICS:
- 25.040
IEC 62541-2:2026 describes the OPC Unified Architecture (OPC UA) security model. It describes the security threats of the physical, hardware, and software environments in which OPC UA is expected to run. It describes how OPC UA relies upon other standards for security. It provides definition of common security terms that are used in this and other parts of the IEC 62541 series. It gives an overview and concept of the security features that are specified in other parts of the series. It references services, mappings, and Profiles that are specified normatively in other parts of the 62541 series. It provides suggestions or best practice guidelines on implementing security. Any seeming ambiguity between this document and one of the other normative parts does not remove or reduce the requirement specified in the other normative part. There are many different aspects of security that are addressed when developing applications. However, since OPC UA specifies a communication protocol, the focus is on securing the data exchanged between applications. This does not mean that an application developer can ignore the other aspects of security like protecting persistent data against tampering. It is important that the developers look into all aspects of security and decide how they can be addressed in the application. Common security features for industrial Controls are defined in IEC 62443-4-2 and OPC UA defined a relationship to them in Annex A. This document is directed to readers who will develop OPC UA applications. It is also for end Users that wish to understand the various security features and functionality provided by OPC UA. It also offers some recommendations that can be applied when deploying systems. These recommendations are generic in nature since the details would depend on the actual implementation of the OPC UA applications and the choices made for the site security. This edition cancels and replaces the third edition of IEC TR 62541-2, published in 2020.This edition constitutes a technical revision.
Abstract
Overview
IEC 62541-2:2026 is the international standard that defines the security model for OPC Unified Architecture (OPC UA). Published by the International Electrotechnical Commission (IEC), this standard is a crucial part of the IEC 62541 series, which provides specifications for secure industrial communication. IEC 62541-2:2026 focuses on the security threats associated with the deployment of OPC UA in diverse environments, including physical, hardware, and software layers.
The document outlines security features, terminology, and best practice guidelines for implementing security in OPC UA applications. It also clarifies the relationship between OPC UA and related international standards, notably IEC 62443-4-2 for industrial control system security. This standard is essential for software developers, system integrators, and end users seeking to understand or implement security for OPC UA-based systems.
Key Topics
-
Security Objectives and Principles
- Authentication and authorization of users and applications
- Maintaining confidentiality and integrity of exchanged data
- Ensuring availability, non-repudiation, and auditability of operations
-
Threat Identification
- Examines various security threats such as denial of service, eavesdropping, message spoofing, session hijacking, and rogue server/publication attacks.
- Highlights risks of credential compromise, repudiation, and industrial espionage.
-
Security Mechanisms
- Describes the use of both asymmetric and symmetric cryptography for communication protection.
- Provides definitions for security-related concepts like certificates, trust lists, and secure channels.
- References use of TLS (Transport Layer Security), X.509 certificates, and cryptographic key management.
-
User and Application Security Management
- Details on access restriction, permissions, and roles to control access within industrial systems.
- Recommendations for identity management and the use of tokens for authenticated access.
-
Certificate Management
- Guidance for managing and revoking certificates and establishing trusted public key infrastructures (PKI).
- Differentiates between self-signed certificates and CA-signed certificates.
-
Security Profiles and Policies
- Outlines the different security policies and profiles that apply to OPC UA applications.
- Explains security mode settings for various topologies such as client/server and publish/subscribe models.
-
Deployment and Implementation Guidelines
- Offers best practices for secure implementation and deployment of OPC UA, including timeout settings, rate limiting, alarm management, and handling of unsecured services.
Applications
IEC 62541-2:2026 is applicable wherever OPC UA is deployed for industrial automation, process control, and data integration, particularly in the context of Industry 4.0, Industrial IoT, and secure enterprise interoperability. Typical use cases include:
- Industrial automation networks: Securing machine-to-machine (M2M) and device-to-cloud communications to mitigate cyber threats.
- Process control systems: Protecting critical infrastructure from unauthorized access or data manipulation.
- Integration with IT systems: Ensuring secure exchange of operational data between OT (Operational Technology) and IT environments.
- Remote monitoring and diagnostics: Safeguarding data transfer in cloud-based and multi-site architectures.
- Certification and compliance: Facilitating compliance with industry standards and regulations for cybersecurity.
By implementing this standard, organizations enhance cybersecurity resilience, protect intellectual property, and ensure safe and reliable industrial operations.
Related Standards
- IEC 62541-1: OPC Unified Architecture - Part 1: Overview and Concepts
- IEC 62443-4-2: Security for industrial automation and control systems - Technical security requirements for IACS components
- ISO/IEC 27001: Information technology - Security techniques - Information security management systems - Requirements
- TLS (Transport Layer Security): Industry-standard protocol for encrypted communications
- X.509: Standard for public key infrastructure (PKI) certificate formats
IEC 62541-2:2026 serves as the reference point for practitioners seeking an internationally harmonized approach to secure OPC UA deployments in modern industrial environments. By aligning with this standard and related frameworks, organizations can establish robust, scalable, and compliant security architectures for smart manufacturing and process industries.
Технические детали
- Технический комитет
- SC 65E - Devices and integration in enterprise systems
- SKU
- IEC 62541-2:2026
Похожие стандарты
Стандарты, упомянутые в описании
EN IEC 62541-9:2026
ДействующийOPC unified architecture - Part 9: Alarms and Conditions
Overview EN IEC 62541-9:2026 - OPC Unified Architecture Part 9: Alarms and Conditions - defines the standard approach to representing Alarms and Conditions within the OPC UA (Unified Architecture) ad…
IEC TS 62443-6-2:2025
ДействующийSecurity for industrial automation and control systems - Part 6-2: Security evaluation methodology for IEC 62…
Overview IEC TS 62443-6-2:2025, published by the International Electrotechnical Commission (IEC), provides a dedicated security evaluation methodology for Industrial Automation and Control Systems (I…
IEC 62541-13:2025
ДействующийOPC unified architecture - Part 13: Aggregates
Overview - IEC 62541-13:2025 (OPC UA - Aggregates) IEC 62541-13:2025 is the third edition of the OPC Unified Architecture (OPC UA) specification that defines the information model associated with Agg…