SIST EN IEC 63208:2025
(Main)Low-voltage switchgear and controlgear and their assemblies - Security requirements (IEC 63208:2025)
Low-voltage switchgear and controlgear and their assemblies - Security requirements (IEC 63208:2025)
IEC 63208:2025 This document applies to the main functions of switchgear and controlgear and their assemblies, called equipment, in the context of operational technology (OT 3.1.34). It is applicable to equipment with wired or wireless data communication means and their physical accessibility, within their limits of environmental conditions. It is intended to achieve the appropriate physical and cybersecurity mitigation against vulnerabilities to security threats.
This document provides requirements on the appropriate:
– security risk assessment to be developed including the attack levels, the typical threats, the impact assessment and the relationship with safety;
– levels of exposure of the communication interface and the determination of the equipment security level;
– assessment of the exposure level of the communication interfaces;
– assignment of the required security measures for the equipment;
– countermeasures for the physical access and the environment derived from ISO/IEC 27001;
– countermeasures referring to IEC 62443-4-2 with their criteria of applicability;
– user instructions for installation, operation and maintenance;
– conformance verification and testing, and – security protection profiles by family of equipment (Annex E to Annex I).
In particular, it focuses on potential vulnerabilities to threats resulting in:
– unintended operation, which can lead to hazardous situations;
– unavailability of the protective functions (overcurrent, earth fault, etc.);
– other degradation of main function.
It also provides guidance on the cybersecurity management with the:
– roles and responsibilities (Table 4);
– typical architectures (Annex A);
– use cases (Annex B);
– development methods (Annex C);
– recommendations to be provided to users and for integration into an assembly (Annex D);
– bridging references to cybersecurity management systems (Annex K).
This document does not cover security requirements for:
– information technology (IT);
– industrial automation and control systems (IACS), engineering workstations and their software applications;
– critical infrastructure or energy management systems;
– network device (communication network switch or virtual private network terminator), or
– data confidentiality other than for critical security parameters;
– design lifecycle management. For this aspect, see IEC 62443-4-1, ISO/IEC 27001 or other security lifecycle management standards.
Niederspannungsschaltgeräte und deren Niederspannungs-Schaltgerätekombinationen - Security Aspekte (IEC 63208:2025)
Appareillages et ensembles d'appareillages à basse tension - Exigences de sécurité (IEC 63208:2025)
IEC 63208:2025 Le présent document s'applique aux fonctions principales des appareillages et ensembles d'appareillages, appelés équipements, dans le contexte de la technologie d'exploitation (OT, 3.1.34). Il s'applique aux équipements équipés de moyens de communication de données filaires ou sans fil, ainsi qu'à leur accessibilité physique, dans les limites de leurs conditions d'environnement. Il a pour objet d'assurer l'atténuation appropriée de la sécurité physique et de la cybersécurité contre les vulnérabilités aux menaces à la sécurité.
Le présent document fournit des exigences sur les aspects appropriés suivants:
– l'appréciation du risque pour la sécurité à élaborer, y compris les niveaux d'attaque, les menaces types, l'appréciation de l'impact et la relation à la sécurité humaine;
– les niveaux d'exposition de l'interface de communication et la détermination du niveau de sécurité de l'équipement;
– l'évaluation du niveau d'exposition des interfaces de communication;
– l'attribution des mesures de sécurité exigées pour l'équipement;
– les contre-mesures pour l'accès physique et l'environnement selon l'ISO/IEC 27001;
– les contre-mesures en référence à l'IEC 62443-4-2, avec leurs critères d'applicabilité;
– les instructions pour l'utilisateur concernant l'installation, le fonctionnement et la maintenance;
– la vérification et les essais de conformité; et
– les profils de protection de la sécurité par famille d'équipements (de l'Annexe E à l'Annexe I).
En particulier, il met l'accent sur les vulnérabilités potentielles aux menaces entraînant:
– un fonctionnement non souhaitable, qui peut conduire à des situations dangereuses;
– une indisponibilité des fonctions de protection (surintensité, défaut de terre, etc.);
– toute autre dégradation de la fonction principale.
Il fournit également des recommandations concernant le management de la cybersécurité, avec:
– les rôles et responsabilités (Tableau 4);
– les architectures types (Annexe A);
– les cas d'utilisation (Annexe B);
– les méthodes de développement (Annexe C);
– les recommandations à fournir aux utilisateurs et à intégrer à un ensemble (Annexe D);
– l'établissement de références aux systèmes de management de la cybersécurité (Annexe K).
Le présent document ne fournit aucune exigence de sécurité en ce qui concerne:
– les technologies de l'information (TI);
– les systèmes d'automatisation et de commande industrielles (IACS, Industrial Automation And Control Systems), les postes de travail d'ingénierie
et leurs applications logicielles;
– les systèmes de management des infrastructures essentielles ou de l'énergie;
– les dispositifs de réseau (commutateur de réseau de communication ou terminaison de réseau privé virtuel); ou
– la confidentialité des données autre que pour les paramètres de sécurité critiques;
– la gestion du cycle de vie de la conception. Pour cet aspect, voir l'IEC 62443-4-1, l'ISO/IEC 27001 ou d'autres normes de gestion du cycle de vie de la sécurité.
Nizkonapetostne stikalne in krmilne naprave ter njihovi sestavi - Varnostne zahteve (IEC 63208:2025)
General Information
Standards Content (Sample)
SLOVENSKI STANDARD
01-november-2025
Nizkonapetostne stikalne in krmilne naprave ter njihovi sestavi - Varnostne
zahteve (IEC 63208:2025)
Low-voltage switchgear and controlgear and their assemblies - Security requirements
(IEC 63208:2025)
Niederspannungsschaltgeräte und deren Niederspannungs-Schaltgerätekombinationen -
Security Aspekte (IEC 63208:2025)
Appareillages et ensembles d'appareillages à basse tension - Exigences de sécurité
(IEC 63208:2025)
Ta slovenski standard je istoveten z: EN IEC 63208:2025
ICS:
29.130.20 Nizkonapetostne stikalne in Low voltage switchgear and
krmilne naprave controlgear
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
EUROPEAN STANDARD EN IEC 63208
NORME EUROPÉENNE
EUROPÄISCHE NORM October 2025
ICS 29.130.20
English Version
Low-voltage switchgear and controlgear and their assemblies -
Security requirements
(IEC 63208:2025)
Appareillages et ensembles d'appareillages à basse tension Niederspannungsschaltgeräte und deren Niederspannungs-
- Exigences de sécurité Schaltgerätekombinationen - Security Aspekte
(IEC 63208:2025) (IEC 63208:2025)
This European Standard was approved by CENELEC on 2025-09-26. CENELEC members are bound to comply with the CEN/CENELEC
Internal Regulations which stipulate the conditions for giving this European Standard the status of a national standard without any alteration.
Up-to-date lists and bibliographical references concerning such national standards may be obtained on application to the CEN-CENELEC
Management Centre or to any CENELEC member.
This European Standard exists in three official versions (English, French, German). A version in any other language made by translation
under the responsibility of a CENELEC member into its own language and notified to the CEN-CENELEC Management Centre has the
same status as the official versions.
CENELEC members are the national electrotechnical committees of Austria, Belgium, Bulgaria, Croatia, Cyprus, the Czech Republic,
Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the
Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland,
Türkiye and the United Kingdom.
European Committee for Electrotechnical Standardization
Comité Européen de Normalisation Electrotechnique
Europäisches Komitee für Elektrotechnische Normung
CEN-CENELEC Management Centre: Rue de la Science 23, B-1040 Brussels
© 2025 CENELEC All rights of exploitation in any form and by any means reserved worldwide for CENELEC Members.
Ref. No. EN IEC 63208:2025 E
European foreword
The text of document 121/221/FDIS, future edition 1 of IEC 63208, prepared by TC 121 "Switchgear
and controlgear and their assemblies for low voltage" was submitted to the IEC-CENELEC parallel
vote and approved by CENELEC as EN IEC 63208:2025.
The following dates are fixed:
• latest date by which the document has to be implemented at national (dop) 2026-10-31
level by publication of an identical national standard or by endorsement
• latest date by which the national standards conflicting with the (dow) 2028-10-31
document have to be withdrawn
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CENELEC shall not be held responsible for identifying any or all such patent rights.
Any feedback and questions on this document should be directed to the users’ national committee. A
complete listing of these bodies can be found on the CENELEC website.
Endorsement notice
The text of the International Standard IEC 63208:2025 was approved by CENELEC as a European
Standard without any modification.
In the official version, for Bibliography, the following notes have to be added for the standard indicated:
IEC 60204-1:2016 NOTE Approved as EN 60204-1:2018
IEC 60364-1 NOTE Approved as HD 60364-1
IEC 60364-4-41 NOTE Approved as HD 60364-4-41
IEC 60364-4-43 NOTE Approved as HD 60364-4-43
IEC 60870-5 (series) NOTE Approved as EN 60870-5 (series)
IEC 60947-2 NOTE Approved as EN IEC 60947-2
IEC 60947-4-1 NOTE Approved as EN IEC 60947-4-1
IEC 60947-4-2 NOTE Approved as EN IEC 60947-4-2
IEC 60947-4-3 NOTE Approved as EN IEC 60947-4-3
IEC 60947-5-1 NOTE Approved as EN IEC 60947-5-1
IEC 60947-5-2 NOTE Approved as EN IEC 60947-5-2
IEC 60947-5-3 NOTE Approved as EN 60947-5-3
IEC 60947-5-5 NOTE Approved as EN 60947-5-5
IEC 60947-5-7 NOTE Approved as EN IEC 60947-5-7
IEC 60947-6-1 NOTE Approved as EN IEC 60947-6-1
IEC 60947-6-2 NOTE Approved as EN IEC 60947-6-2
IEC 61439-1:2020 NOTE Approved as EN IEC 61439-1:2021 (not modified)
IEC 61508-2 NOTE Approved as EN 61508-2
IEC 61439-2 NOTE Approved as EN IEC 61439-2
IEC 62061 NOTE Approved as EN IEC 62061
IEC 62264-1 NOTE Approved as EN 62264-1
IEC 62351 (series) NOTE Approved as EN IEC 62351 (series)
IEC 62351-5 NOTE Approved as EN IEC 62351-5
IEC 62351-6 NOTE Approved as EN IEC 62351-6
IEC 62351-8 NOTE Approved as EN IEC 62351-8
IEC 62351-9 NOTE Approved as EN IEC 62351-9
IEC 62443 (series) NOTE Approved as EN IEC 62443 (series)
IEC 62443-2-1 NOTE Approved as EN IEC 62443-2-1
IEC 62443-2-4 NOTE Approved as EN IEC 62443-2-4
IEC 62443-3-3:2013 NOTE Approved as EN IEC 62443-3-3:2019 (not modified)
IEC 62559-2:2015 NOTE Approved as EN 62559-2:2015 (not modified)
IEC/TR 63069 NOTE Approved as CLC IEC/TR 63069
IEC/TR 63201:2019 NOTE Approved as CLC IEC/TR 63201:2020 (not modified)
ISO/IEC 15408-1:2022 NOTE Approved as EN ISO/IEC 15408-1:2023 (not modified)
ISO/IEC 15408-2:2022 NOTE Approved as EN ISO/IEC 15408-2:2023 (not modified)
ISO/IEC 27000:2018 NOTE Approved as EN ISO/IEC 27000:2020 (not modified)
ISO/IEC 27002:2022 NOTE Approved as EN ISO/IEC 27002:2022 (not modified)
ISO/TS 14441:2013 NOTE Approved as CEN ISO/TS 14441:2013 (not modified)
Annex ZA
(normative)
Normative references to international publications
with their corresponding European publications
The following documents are referred to in the text in such a way that some or all of their content
constitutes requirements of this document. For dated references, only the edition cited applies. For
undated references, the latest edition of the referenced document (including any amendments)
applies.
NOTE 1 Where an International Publication has been modified by common modifications, indicated by (mod),
the relevant EN/HD applies.
NOTE 2 Up-to-date information on the latest versions of the European Standards listed in this annex is available
here: www.cencenelec.eu.
Publication Year Title EN/HD Year
IEC 60364-7-729 - Low-voltage electrical installations - Part 7- HD 60364-7-729 -
729: Requirements for special installations
or locations - Operating or maintenance
gangways
IEC 60947-1 2020 Low-voltage switchgear and controlgear - EN IEC 60947-1 2021
Part 1: General rules
IEC 61439-1 2020 Low-voltage switchgear and controlgear EN IEC 61439-1 2021
assemblies - Part 1: General rules
IEC 62443-3-2 2020 Security for industrial automation and EN IEC 62443-3-2 2020
control systems - Part 3-2: Security risk
assessment for system design
IEC 62443-4-1 2018 Security for industrial automation and EN IEC 62443-4-1 2018
control systems - Part 4-1: Secure product
development lifecycle requirements
IEC 62443-4-2 2019 Security for industrial automation and EN IEC 62443-4-2 2019
control systems - Part 4-2: Technical
security requirements for IACS components
IEC/TS 62443-6-2 2025 Security for industrial automation and - -
control systems - Part 6-2: Security
evaluation methodology for IEC 62443-4-2
ISO/IEC 27001 2022 Information security, cybersecurity and EN ISO/IEC 27001 2023
privacy protection - Information security
management systems - Requirements
+ A1 2024 + A1 2024
ISO/IEC 27005 2022 Information security, cybersecurity and EN ISO/IEC 27005 2024
privacy protection - Guidance on managing
information security risks
ISO/IEC 27402 2023 Cybersecurity - IoT security and privacy - - -
Device baseline requirements
IEC 63208 ®
Edition 1.0 2025-08
INTERNATIONAL
STANDARD
Low-voltage switchgear and controlgear and their assemblies - Security
requirements
ICS 29.130.20 ISBN 978-2-8327-0604-6
IEC 63208:2025-08(en)
IEC 63208:2025 © IEC 2025
CONTENTS
FOREWORD. 8
INTRODUCTION . 10
1 Scope . 12
2 Normative references . 13
3 Terms, definitions and abbreviated terms . 13
3.1 Terms and definitions . 13
3.2 Abbreviated terms . 19
4 General . 20
5 Security objectives . 20
6 Security lifecycle management . 20
6.1 General . 20
6.2 Security risk assessment . 22
6.2.1 General . 22
6.2.2 Relationship between safety and security . 23
6.2.3 Impact assessment . 24
6.2.4 Security risk assessment result . 24
6.3 Response to security risk . 24
6.4 Security requirement specification . 25
6.5 Roles and responsibilities . 25
6.6 Important data . 26
6.7 Control system architecture . 26
6.7.1 Control system . 26
6.7.2 Levels of communication functionalities . 26
6.7.3 Levels of connectivity . 28
6.7.4 Exposure levels of equipment . 30
6.7.5 Equipment security levels . 30
6.7.6 Security protection profile . 31
7 Security requirements . 32
7.1 General . 32
7.2 Physical access and environment . 32
7.2.1 PA – Physical access and environment requirement . 32
7.2.2 Physical access and environment rationale . 32
7.2.3 PA-e – Physical access and environment enhancement . 33
7.2.4 Physical access and environment typical implementation . 34
7.3 Equipment requirement . 34
7.3.1 General . 34
7.3.2 FR 1 – Identification and authentication control . 35
7.3.3 FR 2 – Use control . 39
7.3.4 FR 3 – System integrity . 44
7.3.5 FR 4 – Data confidentiality . 50
7.3.6 FR 5 – Restricted data flow . 51
7.3.7 FR 6 – Timely response to events . 51
7.3.8 FR 7 – Resource availability . 52
8 Instructions for installation, operation and maintenance . 55
8.1 User instruction requirement . 55
8.2 User instruction enhancement . 56
IEC 63208:2025 © IEC 2025
8.3 User instruction implementation . 56
9 Conformance verification and testing. 57
9.1 General . 57
9.2 Design doc
...








Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.