SIST EN IEC 62541-2:2026
OPC unified architecture - Part 2: Security Model (IEC 62541-2:2026)
OPC unified architecture - Part 2: Security Model (IEC 62541-2:2026)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 64
- Дата публикации:
- 12 мая 2026 г.
- Издание:
- IEC 62541-2:2026
- ICS:
- 25.040
IEC 62541-2:2026 describes the OPC Unified Architecture (OPC UA) security model. It describes the security threats of the physical, hardware, and software environments in which OPC UA is expected to run. It describes how OPC UA relies upon other standards for security. It provides definition of common security terms that are used in this and other parts of the IEC 62541 series. It gives an overview and concept of the security features that are specified in other parts of the series. It references services, mappings, and Profiles that are specified normatively in other parts of the 62541 series. It provides suggestions or best practice guidelines on implementing security. Any seeming ambiguity between this document and one of the other normative parts does not remove or reduce the requirement specified in the other normative part. There are many different aspects of security that are addressed when developing applications. However, since OPC UA specifies a communication protocol, the focus is on securing the data exchanged between applications. This does not mean that an application developer can ignore the other aspects of security like protecting persistent data against tampering. It is important that the developers look into all aspects of security and decide how they can be addressed in the application. Common security features for industrial Controls are defined in IEC 62443-4-2 and OPC UA defined a relationship to them in Annex A. This document is directed to readers who will develop OPC UA applications. It is also for end Users that wish to understand the various security features and functionality provided by OPC UA. It also offers some recommendations that can be applied when deploying systems. These recommendations are generic in nature since the details would depend on the actual implementation of the OPC UA applications and the choices made for the site security. This edition cancels and replaces the third edition of IEC TR 62541-2, published in 2020.This edition constitutes a technical revision.
Abstract
Overview
SIST EN IEC 62541-2:2026, published by CLC, defines the security model for OPC Unified Architecture (OPC UA). This international standard outlines how OPC UA assesses and mitigates security threats in physical, hardware, and software environments. It explains the key security objectives relevant to OPC UA, describes common security terminology, and establishes OPC UA’s reliance on other security standards. The document is essential for OPC UA application developers and end users who want to understand, implement, and maintain robust security within industrial and IT systems that use OPC UA.
This latest edition replaces the previous IEC TR 62541-2:2020 and constitutes a technical revision, reflecting evolving best practices and aligning with security standards such as IEC 62443-4-2.
Key Topics
- Security Architecture
- Describes the OPC UA security environment and outlines the architecture, including client/server and publish/subscribe models.
- Security Objectives
- Authentication: Ensures identity verification for users and applications.
- Authorization: Controls access based on roles and permissions.
- Confidentiality: Protects sensitive data from unauthorized disclosure.
- Integrity: Ensures information is not tampered with during transmission.
- Non-Repudiation, Auditability, Availability: Covers proof of actions, audit trails, and system uptime.
- Security Threats
- Identifies common risks such as denial of service, eavesdropping, spoofing, message replay/alteration, session hijacking, and credential compromise.
- Profiling and Best Practices
- References to security services, mappings, security profiles, and configuration guidelines.
- Suggests best practices for secure deployment, such as certificate management, cryptographic key handling, and timeout settings.
- Implementation and Deployment Guidance
- Recommendations on using cryptography, managing user roles, using OAuth2, JWT, HTTPS, TLS, Websockets, and rate limiting.
Applications
SIST EN IEC 62541-2:2026 is designed for practical use in a range of industrial and IT scenarios:
- Industrial Automation: Ensures secure communications and data exchange in SCADA, DCS, and PLC environments.
- Enterprise Integration: Provides secure integration between shop-floor and business IT systems.
- Product Development: Assists developers in designing secure OPC UA applications with attention to data-in-transit security and persistent data protection.
- System Deployment and Maintenance: Offers end users and system integrators actionable recommendations to safeguard OPC UA-based systems, including guidelines on certificate management and configuration of security profiles.
- Regulatory Compliance: Facilitates compliance with broader cybersecurity standards and requirements, including referencing IEC 62443-4-2 for industrial control system security.
Related Standards
For comprehensive OPC UA implementation and integration, SIST EN IEC 62541-2:2026 references several key standards:
- IEC 62541-1: OPC UA Overview and Concepts
- IEC 62541-3: Address Space Model
- IEC 62541-4: Services
- IEC 62541-5: Information Model
- IEC 62541-6: Mappings
- IEC 62541-7: Profiles
- IEC 62541-12: Discovery and Global Services
- IEC 62541-14: PubSub
- IEC 62541-18: Role-Based Security
- IEC 62443-4-2: Security for Industrial Automation and Control Systems - Technical security requirements for IACS components
Additional references include international security protocols such as TLS (RFC 2246), HTTPS (RFC 2818), OAuth2, JWT (RFC 7519), and guidelines from NIST.
SIST EN IEC 62541-2:2026 is the definitive reference for anyone seeking to implement, evaluate, or deploy OPC UA solutions with advanced and standardized security features for industrial and enterprise environments. For optimal OPC UA security, integration with referenced standards and adherence to suggested best practices are critical.
Технические детали
- Технический комитет
- MOV - Measuring equipment for electromagnetic quantities
- SKU
- SIST EN IEC 62541-2:2026
Похожие стандарты
Стандарты, упомянутые в описании
IEC 62541-2:2026
ДействующийOPC unified architecture - Part 2: Security Model
Overview IEC 62541-2:2026 is the international standard that defines the security model for OPC Unified Architecture (OPC UA). Published by the International Electrotechnical Commission (IEC), this s…
IEC TS 62443-6-2:2025
ДействующийSecurity for industrial automation and control systems - Part 6-2: Security evaluation methodology for IEC 62…
Overview IEC TS 62443-6-2:2025, published by the International Electrotechnical Commission (IEC), provides a dedicated security evaluation methodology for Industrial Automation and Control Systems (I…
IEC 62541-13:2025
ДействующийOPC unified architecture - Part 13: Aggregates
Overview - IEC 62541-13:2025 (OPC UA - Aggregates) IEC 62541-13:2025 is the third edition of the OPC Unified Architecture (OPC UA) specification that defines the information model associated with Agg…
IEC 62541-3:2020
ДействующийOPC Unified Architecture - Part 3: Address Space Model
Overview - IEC 62541-3:2020 (OPC UA Address Space Model) IEC 62541-3:2020 defines the OPC Unified Architecture (OPC UA) AddressSpace Model - the meta-model on which OPC UA information models are buil…
IEC 62541-4:2020
ДействующийOPC Unified Architecture - Part 4: Services
Overview IEC 62541-4:2020 (OPC Unified Architecture - Part 4: Services) defines the OPC UA Services: the abstract Remote Procedure Calls (RPCs) that OPC UA Clients invoke and OPC UA Servers implement…
IEC 62541-5:2020
ДействующийOPC Unified Architecture - Part 5: Information Model
Overview IEC 62541-5:2020 - OPC Unified Architecture, Part 5: Information Model defines the standardized Information Model for OPC UA servers. It describes the Nodes (types and instances) that make u…
IEC 62541-6:2020
ДействующийOPC Unified Architecture - Part 6: Mappings
Overview IEC 62541-6:2020 - "OPC Unified Architecture – Part 6: Mappings" defines how the OPC UA abstract services, information model and security model are mapped to concrete encodings and network t…
IEC 62541-7:2020
ДействующийOPC Unified Architecture - Part 7: Profiles
Overview IEC 62541-7:2020 - "OPC Unified Architecture – Part 7: Profiles" defines the Profiles used to group OPC UA features for conformance and testing. The standard separates feature sets into test…