IEC 62351 - Power Systems Communication Security
IEC 62351 is a series of standards addressing the cybersecurity of communication protocols used in power systems. It provides security specifications for protocols including IEC 61850 (substation automation), IEC 60870-5 (telecontrol), IEC 61968/61970 (CIM), and DNP3. Covers authentication, encryption, access control, and key management for operational technology (OT) communications in the energy sector.
IEC 62351 - Power Systems Communication Security is a compliance framework from International (IEC) with 26 domains and 34 controls that map to 288 other frameworks. The largest domains are Parts 12-14: DER, Resilience, and Monitoring (3 controls), Parts 7-9: Network Management, Access Control, and Key Management (3 controls), Parts 1-2: Introduction and Glossary (2 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (26)
Access Control
| Code | Title |
|---|---|
| IEC62351-8 | Role-Based Access Control |
Application Security
| Code | Title |
|---|---|
| IEC62351-4 | MMS and IEC 61850 Application Security |
Architecture
| Code | Title |
|---|---|
| IEC62351-10 | Security Architecture |
Communications Security
| Code | Title |
|---|---|
| IEC62351-3 | TLS for TCP/IP Profiles |
Conformance
| Code | Title |
|---|---|
| IEC62351-100 | Conformance Testing |
Cryptography
| Code | Title |
|---|---|
| IEC62351-9 | Cybersecurity Key Management |
Data Security
| Code | Title |
|---|---|
| IEC62351-11 | XML File Security |
Governance
| Code | Title |
|---|---|
| IEC62351-13 | Guidelines on Security Topics |
Incident Response
| Code | Title |
|---|---|
| IEC62351-IR | Incident Response for Substations |
Inter-Control Centre
| Code | Title |
|---|---|
| IEC62351-ICCP | ICCP/TASE.2 Secure Bilateral |
Logging
| Code | Title |
|---|---|
| IEC62351-14 | Cybersecurity Event Logging |
Monitoring
| Code | Title |
|---|---|
| IEC62351-MON | Security Monitoring of Substation Networks |
Network Security
| Code | Title |
|---|---|
| IEC62351-SEG | Segmentation of Process and Station Buses |
Operations
| Code | Title |
|---|---|
| IEC62351-7 | Network and System Management |
PKI
| Code | Title |
|---|---|
| IEC62351-CERT | Certificate Lifecycle for Substations |
Parts 1-2: Introduction and Glossary
| Code | Title |
|---|---|
| 62351-2 | Glossary of terms |
Parts 10-11: Architecture and XML Security
Parts 12-14: DER, Resilience, and Monitoring
Parts 3-4: TCP/IP and MMS Security Profiles
Parts 5-6: Protocol-Specific Security
Parts 7-9: Network Management, Access Control, and Key Management
Protocol Security
| Code | Title |
|---|---|
| IEC62351-5 | IEC 60870-5 and DNP3 Secure Authentication |
Resilience
| Code | Title |
|---|---|
| IEC62351-12 | Resilience for DER and Substation Automation |
Substation Security
| Code | Title |
|---|---|
| IEC62351-6 | IEC 61850 GOOSE and SV Security |
Supplier
| Code | Title |
|---|---|
| IEC62351-SUP | Supplier Security Requirements |
Vulnerability
| Code | Title |
|---|---|
| IEC62351-PATCH | Patch and Vulnerability Management for OT |
Your Compliance Coverage
If you comply with IEC 62351 - Power Systems Communication Security, you already cover:
O-RAN WG11 Security Specification
18%
6 controls mapped
Compare →NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
18%
6 controls mapped
Compare →MTCS (Singapore)
18%
6 controls mapped
Compare →+ 285 more: FTC GLBA Safeguards Rule (16 CFR Part 314) (18%), NIST Privacy Framework (15%)
See all 288 mapped frameworks ↓Maps to 288 other frameworks
What is IEC 62351 - Power Systems Communication Security and who does it apply to?
IEC 62351 - Power Systems Communication Security is a compliance framework from International (IEC) with 26 domains and 34 controls. IEC 62351 is a series of standards addressing the cybersecurity of communication protocols used in power systems. It provides security specifications for protocols including IEC 61850 (substation automation), IEC 60870-5 (telecontrol), IEC 61968/61970 (CIM), and DNP3. Covers authentication, encryption, access control, and key management for operational technology (OT) communications in the energy sector. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does IEC 62351 - Power Systems Communication Security actually require?
IEC 62351 - Power Systems Communication Security has 34 controls organised across 26 domains. The largest domains are Parts 12-14: DER, Resilience, and Monitoring (3 controls), Parts 7-9: Network Management, Access Control, and Key Management (3 controls), Parts 1-2: Introduction and Glossary (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of IEC 62351 - Power Systems Communication Security do I already cover?
IEC 62351 - Power Systems Communication Security maps to 288 other compliance frameworks. The top mapping partners are O-RAN WG11 Security Specification (18% coverage), NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security (18% coverage), MTCS (Singapore) (18% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement IEC 62351 - Power Systems Communication Security?
Start your IEC 62351 - Power Systems Communication Security compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IEC 62351 - Power Systems Communication Security requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required