6 Aug 2026 · 5 min read

Certified is not secure

security · iec-62443 · ot · procurement · architecture

A server on a bench answered the same question twice inside the same second. The question was the speed of a pump, and both times the answer was 42.0 hertz. One of those answers travelled in a form that anybody with a capture running would have read without effort. The other did not, and an observer sitting on that network would not have known the second question had been asked at all.

It was one server. Same firmware, same configuration file, same certificate on the same datasheet. What changed between the two answers was which door the client knocked on, and a datasheet has nothing to say about which door your integrator wired.

one server, one certificatethe unprotected way inthe answer is on the wire, in the clearanyone on the segment reads itthe protected way inthe same answer, and nothing to readthe watcher learns nothingThe datasheet is identical either way.
The same value, asked for twice on the same machine a second apart. It shows up on the wire once, and which time depends on a choice made during commissioning.

That gap is worth understanding before the next procurement cycle, because it is the kind you end up paying for twice.

Three letters that get collapsed into one

The standard is careful here in a way the market around it is not. It treats security level as three separate things, and the space between them is where the money goes missing.

Target is what you decided a given zone needs. It comes out of a risk assessment on your plant, with your consequences and your tolerance for them.

Capability is what a component could do if somebody set it up that way. It gets tested in isolation, on a bench, by a lab that has never seen your site.

Achieved is what is actually true of the running plant once the integrator has gone home. It is measurable, and hardly anybody measures it.

A datasheet certifies capability. Procurement reads it and books it as achieved. Everything in between, meaning the configuration, the network the component sits on, and the compensating measures somebody intended to add later, goes unbought and unbuilt.

Targetwhat you decided this part of the plant needscomes from a risk assessment on your siteCapabilitywhat the box can do if set up that waythis is the one with a certificateAchievedwhat is actually true once it is runningmeasurable, and rarely measuredthe gapnobody sells thisConfiguration, the network it sits on, and the measures meant to cover the rest all live in that gap.
Three different things, routinely spoken of as one. Only the middle rung arrives with a document, and the bottom rung is the one you actually operate.

It happens quietly, and it happens more than once

The pump on the bench was the first of three, and it is the cleanest of them because nothing about it was misconfigured. The server legitimately offered both an unprotected way in and a protected one. Both are supported, both are documented, and the certificate covers the machine either way. Which one gets used is a decision made during commissioning by whoever was holding the laptop.

The second was a message broker. Brokers of this kind support transport encryption and per-client permissions, and both are standard, documented and free. This one was running with neither. Every client that connected did so anonymously, and the connect packet says so plainly to anyone who looks, because the two bits that would carry a username and a password are simply not set. A host with no business being there published a single value to a valve command topic, and the broker did what brokers do. It accepted the message and passed it along to the legitimate subscriber, which had no way of telling that the instruction had arrived from somewhere new.

That host accounted for fourteen frames out of two thousand three hundred and sixty-four. Well under one percent of the traffic. Any rule watching for a volume anomaly would have watched it go straight past.

The third was a controller from a large and well-regarded vendor, whose devices ship with access protection available. It had not been switched on. A write landed on a data block, and there is no authentication step anywhere in the exchange before it, because nothing ever asked for one.

the server on the benchprotected and unprotected ways in, both offeredcoulddidthe message brokerencryption and per-client permissions, both availablecoulddidthe controlleraccess protection available on the devicecoulddidThe first left both ways in open, so the weakest route decides. The other two shipped capable and ran with none of it on.
Three devices from three vendors. The taller bar is what each could enforce, the shorter one is what it did enforce on the day it was captured.

Three vendors, one shape. The capability was present and what was achieved was nothing.

The uncomfortable part is that nobody lied

The reflex reading is that vendors oversell. It is a satisfying conclusion and it is the wrong one.

Capability certification is doing exactly the job it was designed for. It is an honest statement about a component considered on its own, and it is scoped that narrowly on purpose, because a testing lab genuinely cannot know what you will plug the thing into. The defect sits on the buying side: a component-level claim gets used to answer a system-level question, because it is the only document in the room and it has a number on it.

your plantzones, conduits, the people watching, everything under loadthe boxcertifiedEverything outside this small rectangle is unaddressed by the document,and the document was never claiming otherwise.The failure is not the certificate. It is asking a component-level document a system-level question.
What a certificate actually speaks for, drawn inside the thing it gets used to speak for. The proportions are the argument.

Four of seven

The requirements in the standard fall into seven groups. In plain terms they cover proving who someone is, controlling what they are allowed to do, keeping messages from being altered, keeping them from being read, controlling which parts of the plant may talk to which, noticing when something happens and responding to it, and staying upright under stress.

Read that list again and watch where the boundary falls. The first four are properties a component can carry on its own, and a bench test can confirm them. The last three are not, and no bench can. They belong to a plant rather than a box: to a drawing, to somebody watching, to a system that has been tested under load.

No certificate on any device can move those three, and those three are the ones that would have stopped everything described above. Putting the control devices in their own zone keeps the unfamiliar host off the segment entirely. Somebody watching for commands from unfamiliar sources catches fourteen frames that no volume threshold ever will.

The companion lab arrives at the same split from the other direction. Sitting on the wire and reading traffic, you can only honestly answer four of the seven. The other three leave no trace there at all, which is a large part of why they are the ones nobody buys.

a box can settle theseonly a plant can settle theseproving who someone iscontrolling what they may dokeeping messages unalteredkeeping messages unreadwhich parts may talk to whichnoticing and respondingstaying up under stressno datasheet moves any of theseThe three on the right are the ones that would have stopped every finding in the companion lab.
The seven requirement groups, sorted by what can settle them. A box can carry the four on the left. Only a plant can carry the three on the right.

What to ask for instead

Four moves, cheapest first, none of them requiring a purchase order.

Ask for capability together with its configuration. "Certified to level 2" is an incomplete sentence. "Level 2 with these services disabled, this policy enforced and these ports closed" is a claim somebody on your side can check on a Tuesday afternoon.

Write your target for each zone before you go shopping. It comes out of a risk assessment on your own plant. Buying first and then reading a datasheet to find out what you were aiming at is the wrong way round, and it is remarkably common.

Measure what was achieved after commissioning rather than at factory acceptance. The broker was capable at factory acceptance and anonymous in production. The gap opened during integration, which is where these gaps almost always open.

Name your compensating measures out loud, in writing. The standard permits them, and brownfield work would be impossible without them. Left unnamed, they are not a control. They are an assumption.

factory acceptanceintegrationhandoverrunning plantonoffthe gap opens hereWhich is why the level worth measuring is the one you measure after commissioning, not before it.
Protection was on when the box was tested and off by the time the plant was running. It was switched off to get something working, and never switched back.

None of this needs a new product, and most of it is a conversation rather than a project. The certificate is a real document and it is telling the truth about a box. Your plant is not a box.

Keep reading

Newsletter

New essays, by email.

SCADA, cloud, AI, and the plant floor — a short email when something new is published. No noise, unsubscribe anytime.