IEC 62351 - Power Systems Communication Security
IEC 62351 is a series of standards addressing the cybersecurity of communication protocols used in power systems. It provides security specifications for protocols including IEC 61850 (substation automation), IEC 60870-5 (telecontrol), IEC 61968/61970 (CIM), and DNP3. Covers authentication, encryption, access control, and key management for operational technology (OT) communications in the energy sector.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (26)
Access Control
| Code | Title |
|---|---|
| IEC62351-8 | Role-Based Access Control |
Application Security
| Code | Title |
|---|---|
| IEC62351-4 | MMS and IEC 61850 Application Security |
Architecture
| Code | Title |
|---|---|
| IEC62351-10 | Security Architecture |
Communications Security
| Code | Title |
|---|---|
| IEC62351-3 | TLS for TCP/IP Profiles |
Conformance
| Code | Title |
|---|---|
| IEC62351-100 | Conformance Testing |
Cryptography
| Code | Title |
|---|---|
| IEC62351-9 | Cybersecurity Key Management |
Data Security
| Code | Title |
|---|---|
| IEC62351-11 | XML File Security |
Governance
| Code | Title |
|---|---|
| IEC62351-13 | Guidelines on Security Topics |
Incident Response
| Code | Title |
|---|---|
| IEC62351-IR | Incident Response for Substations |
Inter-Control Centre
| Code | Title |
|---|---|
| IEC62351-ICCP | ICCP/TASE.2 Secure Bilateral |
Logging
| Code | Title |
|---|---|
| IEC62351-14 | Cybersecurity Event Logging |
Monitoring
| Code | Title |
|---|---|
| IEC62351-MON | Security Monitoring of Substation Networks |
Network Security
| Code | Title |
|---|---|
| IEC62351-SEG | Segmentation of Process and Station Buses |
Operations
| Code | Title |
|---|---|
| IEC62351-7 | Network and System Management |
PKI
| Code | Title |
|---|---|
| IEC62351-CERT | Certificate Lifecycle for Substations |
Parts 1-2: Introduction and Glossary
| Code | Title |
|---|---|
| 62351-1 | Introduction |
| 62351-2 | Glossary of terms |
Parts 10-11: Architecture and XML Security
| Code | Title |
|---|---|
| 62351-10 | Security architecture guidelines |
| 62351-11 | Security for XML documents |
Parts 12-14: DER, Resilience, and Monitoring
| Code | Title |
|---|---|
| 62351-12 | Resilience and security recommendations for DER |
| 62351-13 | Cyber-physical generation and storage resilience |
| 62351-14 | Cyber security event logging |
Parts 3-4: TCP/IP and MMS Security Profiles
| Code | Title |
|---|---|
| 62351-3 | Profiles including TCP/IP |
| 62351-4 | Profiles including MMS and similar payloads |
Parts 5-6: Protocol-Specific Security
| Code | Title |
|---|---|
| 62351-5 | Security for IEC 60870-5 and derivatives |
| 62351-6 | Security for IEC 61850 profiles |
Parts 7-9: Network Management, Access Control, and Key Management
| Code | Title |
|---|---|
| 62351-7 | Network and system management (NSM) |
| 62351-8 | Role-based access control (RBAC) |
| 62351-9 | Cyber security key management |
Protocol Security
| Code | Title |
|---|---|
| IEC62351-5 | IEC 60870-5 and DNP3 Secure Authentication |
Resilience
| Code | Title |
|---|---|
| IEC62351-12 | Resilience for DER and Substation Automation |
Substation Security
| Code | Title |
|---|---|
| IEC62351-6 | IEC 61850 GOOSE and SV Security |
Supplier
| Code | Title |
|---|---|
| IEC62351-SUP | Supplier Security Requirements |
Vulnerability
| Code | Title |
|---|---|
| IEC62351-PATCH | Patch and Vulnerability Management for OT |
Your Compliance Coverage
If you comply with IEC 62351 - Power Systems Communication Security, you already cover:
O-RAN WG11 Security Specification
18%
6 controls mapped
Compare →NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
18%
6 controls mapped
Compare →MTCS (Singapore)
18%
6 controls mapped
Compare →+ 282 more: FTC GLBA Safeguards Rule (16 CFR Part 314) (18%), NIST Privacy Framework (15%)
See all 285 mapped frameworks ↓Maps to 285 other frameworks
Frequently Asked Questions
What is IEC 62351 - Power Systems Communication Security?
IEC 62351 - Power Systems Communication Security is a compliance framework from International (IEC) with 26 domains and 34 controls. IEC 62351 is a series of standards addressing the cybersecurity of communication protocols used in power systems. It provides security specifications for protocols including IEC 61850 (substation automation), IEC 60870-5 (telecontrol), IEC 61968/61970 (CIM), and DNP3. Covers authentication, encryption, access control, and key management for operational technology (OT) communications in the energy sector. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does IEC 62351 - Power Systems Communication Security have?
IEC 62351 - Power Systems Communication Security has 34 controls organised across 26 domains. The largest domains are Parts 12-14: DER, Resilience, and Monitoring (3 controls), Parts 7-9: Network Management, Access Control, and Key Management (3 controls), Parts 1-2: Introduction and Glossary (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does IEC 62351 - Power Systems Communication Security map to?
IEC 62351 - Power Systems Communication Security maps to 285 other compliance frameworks. The top mapping partners are O-RAN WG11 Security Specification (18% coverage), NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security (18% coverage), MTCS (Singapore) (18% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with IEC 62351 - Power Systems Communication Security compliance?
Start your IEC 62351 - Power Systems Communication Security compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IEC 62351 - Power Systems Communication Security requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required