6 Aug 2026 · 5 min read
Certified is not secure
security · iec-62443 · ot · procurement · architecture
A server on a bench answered the same question twice inside the same second. The question was the speed of a pump, and both times the answer was 42.0 hertz. One of those answers travelled in a form that anybody with a capture running would have read without effort. The other did not, and an observer sitting on that network would not have known the second question had been asked at all.
It was one server. Same firmware, same configuration file, same certificate on the same datasheet. What changed between the two answers was which door the client knocked on, and a datasheet has nothing to say about which door your integrator wired.
That gap is worth understanding before the next procurement cycle, because it is the kind you end up paying for twice.
Three letters that get collapsed into one
The standard is careful here in a way the market around it is not. It treats security level as three separate things, and the space between them is where the money goes missing.
Target is what you decided a given zone needs. It comes out of a risk assessment on your plant, with your consequences and your tolerance for them.
Capability is what a component could do if somebody set it up that way. It gets tested in isolation, on a bench, by a lab that has never seen your site.
Achieved is what is actually true of the running plant once the integrator has gone home. It is measurable, and hardly anybody measures it.
A datasheet certifies capability. Procurement reads it and books it as achieved. Everything in between, meaning the configuration, the network the component sits on, and the compensating measures somebody intended to add later, goes unbought and unbuilt.
It happens quietly, and it happens more than once
The pump on the bench was the first of three, and it is the cleanest of them because nothing about it was misconfigured. The server legitimately offered both an unprotected way in and a protected one. Both are supported, both are documented, and the certificate covers the machine either way. Which one gets used is a decision made during commissioning by whoever was holding the laptop.
The second was a message broker. Brokers of this kind support transport encryption and per-client permissions, and both are standard, documented and free. This one was running with neither. Every client that connected did so anonymously, and the connect packet says so plainly to anyone who looks, because the two bits that would carry a username and a password are simply not set. A host with no business being there published a single value to a valve command topic, and the broker did what brokers do. It accepted the message and passed it along to the legitimate subscriber, which had no way of telling that the instruction had arrived from somewhere new.
That host accounted for fourteen frames out of two thousand three hundred and sixty-four. Well under one percent of the traffic. Any rule watching for a volume anomaly would have watched it go straight past.
The third was a controller from a large and well-regarded vendor, whose devices ship with access protection available. It had not been switched on. A write landed on a data block, and there is no authentication step anywhere in the exchange before it, because nothing ever asked for one.
Three vendors, one shape. The capability was present and what was achieved was nothing.
The uncomfortable part is that nobody lied
The reflex reading is that vendors oversell. It is a satisfying conclusion and it is the wrong one.
Capability certification is doing exactly the job it was designed for. It is an honest statement about a component considered on its own, and it is scoped that narrowly on purpose, because a testing lab genuinely cannot know what you will plug the thing into. The defect sits on the buying side: a component-level claim gets used to answer a system-level question, because it is the only document in the room and it has a number on it.
Four of seven
The requirements in the standard fall into seven groups. In plain terms they cover proving who someone is, controlling what they are allowed to do, keeping messages from being altered, keeping them from being read, controlling which parts of the plant may talk to which, noticing when something happens and responding to it, and staying upright under stress.
Read that list again and watch where the boundary falls. The first four are properties a component can carry on its own, and a bench test can confirm them. The last three are not, and no bench can. They belong to a plant rather than a box: to a drawing, to somebody watching, to a system that has been tested under load.
No certificate on any device can move those three, and those three are the ones that would have stopped everything described above. Putting the control devices in their own zone keeps the unfamiliar host off the segment entirely. Somebody watching for commands from unfamiliar sources catches fourteen frames that no volume threshold ever will.
The companion lab arrives at the same split from the other direction. Sitting on the wire and reading traffic, you can only honestly answer four of the seven. The other three leave no trace there at all, which is a large part of why they are the ones nobody buys.
What to ask for instead
Four moves, cheapest first, none of them requiring a purchase order.
Ask for capability together with its configuration. "Certified to level 2" is an incomplete sentence. "Level 2 with these services disabled, this policy enforced and these ports closed" is a claim somebody on your side can check on a Tuesday afternoon.
Write your target for each zone before you go shopping. It comes out of a risk assessment on your own plant. Buying first and then reading a datasheet to find out what you were aiming at is the wrong way round, and it is remarkably common.
Measure what was achieved after commissioning rather than at factory acceptance. The broker was capable at factory acceptance and anonymous in production. The gap opened during integration, which is where these gaps almost always open.
Name your compensating measures out loud, in writing. The standard permits them, and brownfield work would be impossible without them. Left unnamed, they are not a control. They are an assumption.
None of this needs a new product, and most of it is a conversation rather than a project. The certificate is a real document and it is telling the truth about a box. Your plant is not a box.
Keep reading
Newsletter
New essays, by email.
SCADA, cloud, AI, and the plant floor — a short email when something new is published. No noise, unsubscribe anytime.


