New Security Requirements for Building Automation
Cybersecurity is increasingly becoming a fundamental requirement for the planning, operation, and devices used in building automation. The NIS2 Directive and the BSIG mandate operators of critical infrastructures to implement adequate risk management and effective security measures. At the same time, the Cyber Resilience Act (CRA) raises the requirements for manufacturers of devices and components.
For building automation, this means that communication must be protected, device identities must be reliably secured, and trust relationships must be established in a technically sound manner. Digital certificates from a Public Key Infrastructure (PKI) play a central role in this. A PKI issues and manages these certificates throughout their entire lifecycle. They enable secure communication and form the foundation for a robust trust chain between systems and devices.
Secure Management of Device Certificates Throughout Their Lifecycle
Digital certificates are not a one-time issue. To meet regulatory requirements and ensure a high level of security, they must be managed throughout the entire lifecycle of a device. Manufacturers typically equip their devices with initial certificates during production. However, before operational use in the building, these certificates must be replaced with certificates from a trusted corporate PKI of the building management. Additionally, certificates expire and must be monitored, renewed in time, and properly replaced.
With BACnet Secure Connect (BACnet/SC), building automation has created the necessary conditions to respond to increased security requirements. BACnet/SC-enabled devices use digital certificates to secure communication and establish trusted device identities.