IEC 63208:2025
Low-voltage switchgear and controlgear and their assemblies - Security requirements
Low-voltage switchgear and controlgear and their assemblies - Security requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 126
- Дата публикации:
- 22 августа 2025 г.
- Издание:
- IEC IS 63208 edition 1 version 1
- ICS:
- 29.130.20
IEC 63208:2025 This document applies to the main functions of switchgear and controlgear and their assemblies, called equipment, in the context of operational technology (OT 3.1.34). It is applicable to equipment with wired or wireless data communication means and their physical accessibility, within their limits of environmental conditions. It is intended to achieve the appropriate physical and cybersecurity mitigation against vulnerabilities to security threats. This document provides requirements on the appropriate: – security risk assessment to be developed including the attack levels, the typical threats, the impact assessment and the relationship with safety; – levels of exposure of the communication interface and the determination of the equipment security level; – assessment of the exposure level of the communication interfaces; – assignment of the required security measures for the equipment; – countermeasures for the physical access and the environment derived from ISO/IEC 27001; – countermeasures referring to IEC 62443-4-2 with their criteria of applicability; – user instructions for installation, operation and maintenance; – conformance verification and testing, and – security protection profiles by family of equipment (Annex E to Annex I). In particular, it focuses on potential vulnerabilities to threats resulting in: – unintended operation, which can lead to hazardous situations; – unavailability of the protective functions (overcurrent, earth fault, etc.); – other degradation of main function. It also provides guidance on the cybersecurity management with the: – roles and responsibilities (Table 4); – typical architectures (Annex A); – use cases (Annex B); – development methods (Annex C); – recommendations to be provided to users and for integration into an assembly (Annex D); – bridging references to cybersecurity management systems (Annex K). This document does not cover security requirements for: – information technology (IT); – industrial automation and control systems (IACS), engineering workstations and their software applications; – critical infrastructure or energy management systems; – network device (communication network switch or virtual private network terminator), or – data confidentiality other than for critical security parameters; – design lifecycle management. For this aspect, see IEC 62443-4-1, ISO/IEC 27001 or other security lifecycle management standards.
Abstract
Overview
IEC 63208:2025 sets out comprehensive security requirements for low-voltage switchgear and controlgear, as well as their assemblies, with a particular focus on operational technology (OT) environments. This standard addresses equipment that leverages wired or wireless data communications and ensures that such equipment is protected against physical and cybersecurity threats and vulnerabilities. By applying robust risk assessment methodologies and specifying essential mitigation measures, IEC 63208:2025 enhances the resilience and safety of electrical installations in modern, connected infrastructures.
Key Topics
IEC 63208:2025 covers a range of essential topics for securing low-voltage switchgear and controlgear:
- Security Risk Assessment: Implements risk assessment approaches, including attack level identification, threat and impact analysis, and links to safety considerations.
- Communication Interface Exposure: Defines levels of exposure for equipment interfaces and establishes criteria for determining the necessary security levels.
- Physical and Cyber Countermeasures: Specifies measures for safeguarding physical access, including environmental controls in line with ISO/IEC 27001, and cybersecurity requirements referencing IEC 62443-4-2.
- User Instructions: Provides requirements for clear user documentation on installation, operation, and maintenance to support secure practices.
- Conformance and Testing: Outlines verification and testing procedures to ensure compliance with security requirements.
- Roles and Responsibilities: Addresses organizational roles and responsibilities concerning equipment security.
- Security Profiles: Develops protection profiles tailored to equipment families, such as soft-starters, motor starters, circuit-breakers, transfer switches, and wireless devices.
Applications
The requirements of IEC 63208:2025 are highly relevant across industries that depend on safe, reliable, and secure electrical distribution:
- Building Automation: Protects building management and control systems where low-voltage switchgear often features connected interfaces.
- Industrial Facilities: Safeguards controlgear assemblies within manufacturing, processing, and automation environments, where equipment is vulnerable to cyber and physical threats.
- Energy Distribution: Ensures security in electrical substations, power distribution panels, and utility installations by preventing unauthorized operation, service disruption, and other risks.
- Critical Infrastructure: Provides baseline security measures for operational technology in sectors such as transportation, healthcare, and water utilities.
By addressing threats ranging from denial of service and unauthorized control to integrity and availability of protective functions, this standard increases organizational confidence in the operational continuity and safety of electrical systems.
Related Standards
IEC 63208:2025 builds upon and complements several key security and safety frameworks, including:
- ISO/IEC 27001 - Refers to requirements for physical and environmental controls as part of information security management.
- IEC 62443-4-2 - Relates to technical security requirements for components used in industrial automation and control systems.
- IEC 62443-4-1 - Addresses secure product development lifecycle practices (referenced for lifecycle management outside this document's scope).
- European Cyber Resilient Act (CRA) - The standard maps requirements to the essential cybersecurity requirements of the European CRA where appropriate.
Practical Value
Implementing IEC 63208:2025:
- Reduces vulnerability to physical and cyber threats, mitigating risks such as equipment tampering, denial of service, and data breaches.
- Supports regulatory and contractual compliance by aligning with widely recognized international standards.
- Enhances the safe integration of smart and connected switchgear solutions in both new and legacy installations.
- Guides manufacturers, integrators, and end-users in establishing a clear, systematic approach to equipment security, from risk assessment to conformance testing.
For organizations aiming to strengthen the integrity and resilience of their electrical systems, IEC 63208:2025 provides a robust foundation for secure, sustainable operations.
Технические детали
- Технический комитет
- TC 121 - Switchgear and controlgear and their assemblies for low voltage
- SKU
- IEC 63208:2025
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
IEC TS 62443-6-2:2025
ДействующийSecurity for industrial automation and control systems - Part 6-2: Security evaluation methodology for IEC 62…
Overview IEC TS 62443-6-2:2025, published by the International Electrotechnical Commission (IEC), provides a dedicated security evaluation methodology for Industrial Automation and Control Systems (I…
IEC 62443-4-1:2018
ДействующийSecurity for industrial automation and control systems - Part 4-1: Secure product development lifecycle requi…
Overview IEC 62443-4-1:2018, published by the International Electrotechnical Commission (IEC), establishes process requirements for the secure development of products used in industrial automation an…