
What is IEC 62351? Cybersecurity for control-system protocols
IEC 62351 is the cybersecurity standard series for grid control technology. We explain how it secures IEC 61850, ICCP/TASE.2 and IEC 60870 with TLS, authentication, RBAC and key management.
In this article
IEC 62351 is the international cybersecurity standard series for power system automation. It protects exactly those communication protocols that control centres, substations and grid control systems use to exchange data – including IEC 61850, ICCP/TASE.2 and IEC 60870. It is published by IEC committee TC 57, which is also responsible for those protocols themselves.
Why is IEC 62351 needed?
The classic control-system protocols were designed for closed, physically isolated networks – security was not a design goal. With connectivity over TCP/IP, the integration of renewable generation and the classification of power supply as critical infrastructure, that has fundamentally changed. IEC 62351 retrofits the existing protocols with targeted protection mechanisms instead of having to reinvent them.
Which protocols does IEC 62351 secure?
The standard series covers the common protocols of grid control technology:
- IEC 61850: substation automation, including the real-time services GOOSE and Sampled Values
- ICCP / TASE.2 (IEC 60870-6): data exchange between control centres
- IEC 60870-5 and DNP3: telecontrol communication between control centre and station
- MMS: the client-server protocol behind IEC 61850 and ICCP
We cover two of them in detail in their own articles: What is IEC 61850? and What is ICCP / TASE.2?.
How is IEC 62351 structured?
The series is divided into several parts, each covering a protocol or security layer. The most important are:
- Part 3: securing TCP/IP-based connections with TLS and mutual authentication via X.509 certificates.
- Part 4: security for MMS-based protocols (ICCP/TASE.2 and IEC 61850) – transport protection plus authentication at the application layer.
- Part 5: authentication for IEC 60870-5 and derived protocols such as DNP3.
- Part 6: protection of the time-critical IEC 61850 services GOOSE and Sampled Values via digital signatures.
- Part 8: role-based access control (RBAC) following the subject–role–right principle.
- Part 9: key and certificate management – generation, distribution and revocation of cryptographic keys.
What protection does IEC 62351 provide?
- Authentication: communication partners prove their identity via X.509 certificates.
- Encryption: TLS protects the confidentiality of TCP/IP-based connections.
- Integrity: digital signatures ensure that messages have not been altered unnoticed.
- Access control: RBAC restricts who may perform which actions.
- Key management: governed handling of certificates and keys across their entire lifecycle.
Special case: GOOSE and Sampled Values
A special case are the real-time services GOOSE and Sampled Values from IEC 61850. They do not run over TCP/IP but directly at the Ethernet layer and must be delivered extremely fast – GOOSE messages within milliseconds. Classic encryption would be too slow for that. Part 6 therefore relies not on confidentiality but on authenticity and integrity: the telegrams are signed so that receivers detect tampering without delaying transmission.
IEC 62351 in practice – how IESOFT supports you
As a specialist in communication protocols for the energy sector, we help you operate IEC 61850, ICCP/TASE.2 and IEC 60870 securely – from consulting, development and training through suitable products to securing your communication in line with IEC 62351. Get in touch.
Published on:





