Automation Glossary • PROFINET Security Class

PROFINET Security Classes 1, 2, and 3

Merobix Engineering • • 7 min read

PROFINET began as an availability-first protocol, and its security model has been layered on in defined stages so plants can adopt protection incrementally. The three security classes describe how much of that protection is in force, from hardening the network around devices to cryptographically protecting the traffic itself. This page explains what each class adds, at a conceptual level.

Back to Blog

PROFINET Security Class in one line: The PROFINET security classes define escalating levels of protection. Class 1 relies on hardening and network measures - segmentation, access control, and device robustness - around otherwise standard PROFINET. Class 2 adds authentication and integrity so a device can verify who it is talking to and that messages were not altered. Class 3 adds encryption so the communication content is confidential as well as authenticated.

Why Security Is Layered Into Classes

PROFINET was designed for determinism and availability, not originally for a hostile network, so bolting on strong cryptography everywhere at once would be disruptive and, for many isolated cells, unnecessary. The class model lets a plant match protection to its exposure and its ability to adopt new firmware. A well-segmented line inside a controlled facility may sit safely at the network-hardening level, while a system with broader connectivity needs the cryptographic classes. This mirrors defense-in-depth thinking familiar from OT security generally, including sound VLAN segmentation for OT networks.

The classes are cumulative in intent: each higher class assumes the measures of the one below remain good practice. Cryptography does not replace segmentation and access control; it is added on top of them. Treating the classes as a ladder rather than alternatives keeps the mental model correct - you do not skip network hygiene because you enabled authentication.

What Each Class Adds

Security Class 1 is about robustness and the network around the devices: hardening device behavior against malformed or excessive traffic, and applying segmentation, firewalling, and access control so only intended systems can reach the PROFINET cell. The PROFINET communication itself is essentially standard here; the protection is architectural. For many existing installations this is the practical starting point because it can be applied without waiting for new device firmware.

Security Class 2 introduces authentication and integrity into the communication so a device can confirm the identity of its partner and detect that a message was tampered with, closing off spoofing and injection that Class 1 relies on the network to prevent. Security Class 3 adds confidentiality through encryption, so an eavesdropper on the wire cannot read the content, not just cannot forge it. Class 2 and Class 3 require devices and controllers that implement the cryptographic capabilities, so adopting them is tied to your equipment's support. As with any OT security program, decisions here should align with recognized industrial-security guidance and site policy rather than being improvised.

The Three Classes at a Glance

It helps to see the classes side by side before deciding what to ask of a given cell. Each row is cumulative: the measures in the row above are assumed to stay in place.

ClassWhat it addsWhat it depends on
Security Class 1Device robustness plus network hardening: segmentation, firewalling, and access control around otherwise standard PROFINET trafficNetwork architecture and switch configuration, largely independent of device firmware
Security Class 2Authentication and integrity, so devices verify who they talk to and detect tamperingDevices and controllers with cryptographic support, plus managed credentials
Security Class 3Confidentiality: the communication content is encrypted as well as authenticatedEverything Class 2 needs, with encryption supported end to end

Two things are worth reading out of that table. The class is a property of a cell or a connection, not a grade for the whole plant, so different parts of one site can legitimately sit at different classes. And the right-hand column is where projects actually stall: Class 1 is network engineering you can begin at the next maintenance window, while Classes 2 and 3 wait on what your installed device fleet can support, which for older hardware may mean waiting on replacement cycles rather than firmware updates.

Matching a Class to a Cell's Exposure

The practical question is never which class is best - higher is stronger - but which class a specific cell justifies. Think in terms of who can reach the cell and what a forged or altered frame could do there. An isolated machine cell behind its own firewall, with no route from the office network and no remote access, gets most of its risk reduction from Class 1 measures done well. A line that shares infrastructure with other systems, accepts remote engineering connections, or crosses areas you do not physically control has a credible spoofing and injection exposure, which is what Class 2 addresses. Confidentiality, the Class 3 addition, matters where the content of the traffic is itself sensitive or where the medium could be tapped without detection.

This is the same reasoning used when assigning target protection to zones and conduits under IEC 62443: partition the system, judge each zone's exposure and consequence, and set the ambition per zone rather than plant-wide. Sites already running that process can treat the PROFINET class decision as one output of it, alongside the IEC 62443 security levels assigned during risk assessment. The final call belongs with the site's security program and qualified personnel, not with whoever happens to be commissioning the cell that week.

Planning the Rollout

Adoption is an inventory problem before it is a configuration problem. A workable sequence:

  1. Inventory every device and controller in the cell and record which security class each supports, per the manufacturer's documentation - not from memory.
  2. Finish Class 1 first: segmentation, access control, unused ports disabled, and robustness settings applied. This is prerequisite work, not an alternative.
  3. Pilot Class 2 on one cell where every station supports it, and use the pilot to work out how credentials and certificates will be issued, stored, and renewed.
  4. Extend Class 3 only where the exposure argument for confidentiality actually holds.
  5. Write the operating procedures for certificate renewal and device replacement before scaling beyond the pilot.

The last step is the one that bites later. Once communication is authenticated, a replacement device is not just a spare with the right article number: it must be provisioned with valid credentials before it can rejoin, and an expired certificate can stop a cell as effectively as a broken cable. Whoever handles night-shift device swaps needs a written, tested procedure for that. Performance is the other thing to verify during the pilot rather than assume - cryptographic processing load varies with device hardware, so check the effect on your cycle times against the manufacturer's documentation for your actual equipment rather than trusting examples from other installations.

Frequently Asked Questions

What does PROFINET Security Class 1 provide?

Class 1 focuses on device robustness and the network around the devices: hardening against malformed or excessive traffic, plus segmentation, firewalling, and access control so only intended systems can reach the PROFINET cell. The PROFINET communication itself remains essentially standard; the protection is architectural, which is why it can often be applied without new device firmware.

What is the difference between Security Class 2 and Class 3?

Class 2 adds authentication and integrity, so a device can verify its partner's identity and detect tampering, blocking spoofing and message injection. Class 3 adds encryption on top, so the communication content is also confidential and cannot be read by an eavesdropper. Both require devices and controllers that implement the cryptographic capabilities.

Do the security classes replace network segmentation?

No. The classes are cumulative in intent: higher classes assume the network hardening and access control of Class 1 remain in place. Cryptography is added on top of good architecture, not instead of it. You do not drop segmentation because authentication or encryption is enabled - defense in depth still applies across all classes.

Can different cells on one site run different PROFINET security classes?

Yes, and this is the normal case during adoption. The class is decided per cell or connection based on its exposure, so an isolated cell can remain at Class 1 while a more exposed line runs Class 2 or 3. What should be uniform is the reasoning: each cell's class should trace back to the site's zone-based risk assessment, and Class 1 network hygiene stays in place everywhere regardless of what runs above it.

Does enabling Class 2 or Class 3 change PROFINET performance?

Authentication and encryption add processing work on every station, and how much that costs depends on the device hardware - the class definitions do not fix a performance figure. Verify cycle time behavior during a pilot against the manufacturer's documentation for your specific devices, and treat any headroom question as site-specific rather than assuming numbers from other systems carry over.

Sources and verification

This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.

Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.

More in Industrial Protocols
Profinet conformance class  •  Diagnose PROFINET Jitter  •  PROFINET LLDP Diagnosis  •  PROFINET device name mismatch  •  PROFINET Alarm Frame  •  All Industrial Protocols →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →