Grid control systems and plants under IEC 62443
Zone model with risk assessment and security level per zone
More on thisIndustries / Energy
Protect grid control systems and securely integrate smart meter gateways.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We protect grid control systems, generation assets and intelligent metering systems with security architecture based on IEC 62443, hardware security modules and PKI for smart meter gateways, and controlled interfaces between control room and corporate IT.
Zone model with risk assessment and security level per zone
More on thisISMS documentation with risk analysis and action plan
More on thisData platform connected to control system, metering systems and weather data
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
Control systems and telecontrol were built for isolated networks and today connect to office IT, service providers and distributed plants. We record plants and connections, divide control center, substations and corporate IT into zones under IEC 62443-3-2 and define a security level and the permitted conduits for each zone. We implement hardening, segmentation and protocol security under IEC 62351 in maintenance windows without touching the approved configuration of the plant. Intrusion detection reads IEC 60870-5-104 and IEC 61850 so that it can tell operator error from attack in the control systems.
A distribution system operator separates control center, substations and office IT into zones under IEC 62443; telecontrol connections run through secured conduits, and intrusion detection reads the control system protocols.
Our approach
Intelligent metering systems communicate only over TLS with certificates from the smart metering PKI, whose structure the technical guideline BSI TR-03109 defines. We plan sub-CAs for gateway administration and market participants, choose vendor-neutrally between Utimaco u.trust GP HSM, Thales Luna 7 and Entrust nShield 5c and conduct key ceremonies with roles, quorums and records. Certificates for gateways, control boxes and the CLS channel under section 14a EnWG receive a lifecycle with renewal, revocation and monitoring. The evidence for the ISMS certification of the gateway administrator is produced in the same project.
A metering point operator brings its sub-CA for smart meter gateways in-house from a service provider; the keys are generated in a recorded ceremony inside the HSM, and gateway administration and market participants receive certificates from its own PKI.
Our approach
Grid operators need a certified ISMS under the IT security catalog pursuant to section 11 EnWG, and KRITIS operators additionally need intrusion detection systems and regular evidence to the BSI. NIS2 extends registration, risk management and reporting obligations to further energy companies. We build the ISMS under ISO 27001 with the ISO 27019 extensions for process control or extend its scope to grid control. We set up intrusion detection along the BSI guidance, with logging, detection and response for IT and control systems. Reporting processes to the BSI and the Federal Network Agency are rehearsed with templates and deadlines before the audit takes place.
A municipal utility merges IT and control systems into one ISMS under ISO 27019 and evidences the implementation level of its intrusion detection before the next KRITIS audit date.
Our approach
Photovoltaics, wind farms, storage and combined heat and power plants deliver measurements and accept control commands, often over public networks and components from many vendors. We connect these plants to control system, direct marketers and Redispatch 2.0 via IEC 60870-5-104, IEC 61850, Modbus TCP and OPC UA, with data diodes and protocol gateways at the transitions. Remote maintenance by vendors and service providers runs through a central access point with jump server, multi-factor authentication, time-limited approval and session recording. Edge devices in substations and parks receive hardened operating systems, certificates and remote updates with signed firmware.
A wind farm operator replaces vendor modem access with a central remote maintenance access point and jump server; every session is assigned to a service provider, time-limited and recorded.
Our approach
Feed-in from photovoltaics and wind, heat pumps and charging infrastructure make load and generation harder to plan, and deviations cost balancing energy and redispatch. We build data platforms that combine control system history, smart meter gateway readings, weather data from the German Meteorological Service and market data, and train forecasting models on them with uncertainty bands per grid area and local substation. The models run outside the control systems, and their forecasts reach grid operations, balancing group management and trading as a proposal. Versioning, monitoring of forecast quality, retraining and classification under the EU AI Act are part of operations.
A distribution system operator forecasts photovoltaic feed-in per local substation from weather and metering data; grid operations sees congestion the day before instead of during the fault.
Our approach
Capable quantum computers will break RSA and elliptic curves, on which telecontrol connections, firmware signatures and the smart metering PKI rely today, and telecontrol devices, gateways and substation equipment stay in the field far longer than office IT. We inventory cryptographic algorithms, keys and certificates across control systems, PKI and plants, rate them by device lifetime and plan the migration to ML-KEM and ML-DSA in stages. Firmware signatures move first to hash-based schemes such as LMS and XMSS, while HSM firmware and PKI follow with hybrid certificates in line with BSI TR-02102. The roadmap ties every step to rollout and renewal cycles in the grid.
A gas network operator inventories the cryptography in its telecontrol systems and PKI; firmware signatures move first to hash-based schemes, and the sub-CA follows with hybrid certificates at the next device replacement.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Energy
Control center, substations and office IT on one network, firewall rules from commissioning, KRITIS audit date announced.
Asset inventory, zones and conduits under IEC 62443-3-2, hardening in maintenance windows, intrusion detection with control system protocols in the SIEM.
Separated zones in operation, intrusion detection with proven implementation level, audit documents ready before the date.
02 / Energy
Smart meter rollout under way, certificates come from a service provider without transparency, the operator wants the keys of its own sub-CA in-house.
PKI concept under BSI TR-03109-4, HSM selection, recorded key ceremony, connection of gateway administration and market participants.
Own sub-CA with HSM-protected keys, certificate lifecycle in the operations manual, evidence for the ISMS certification.
03 / Energy
Photovoltaic feed-in exceeds spreadsheet forecasts, balancing energy and redispatch effort rise, measurements sit unused in the control system.
Data platform with control system history, measurements and weather data, forecasting models per local substation with uncertainty bands, model operations with quality report.
Forecasts with uncertainty bands for grid operations and balancing group, congestion visible the day before, models with version state and evidence.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
Plants, networks, interfaces and obligations under KRITIS, NIS2 and the IT security catalog
Zone model, PKI architecture, intrusion detection, operating model
Segmentation, PKI, remote access and data platform in maintenance windows
Monitoring, certificates, audits, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six fields of action from control systems under IEC 62443 to post-quantum cryptography for long-lived assets, planned, integrated and operated by OTOKO®. Every measure can be evidenced to the BSI, the Federal Network Agency and auditors. The entire solution runs in German data centers.
Cybersecurity for the energy sector protects control systems, generation plants and metering systems against outages and attacks and evidences every measure to the BSI and the Federal Network Agency. OTOKO® covers six fields of action: grid control systems and plants under IEC 62443, smart meter gateway PKI and HSMs under BSI TR-03109, KRITIS evidence with an ISMS under ISO 27019, remote maintenance and connection of distributed plants, forecasting of load and generation with data platforms, and post-quantum readiness for long-lived assets. Keys and certificates reside in hardware security modules, HSMs for short.
The difference from a pure consulting project lies in operations and evidence. Every zone, every telecontrol connection and every certificate comes with documentation, a version state and the records that the KRITIS audit and the IT security catalog of the Federal Network Agency require. Cryptography and hardware security modules are our core competence. Keys of the smart meter PKI and of telecontrol systems therefore reside in certified devices instead of software.
Cryptography and hardware security modules are our core competence. We plan and operate the smart meter PKI sub-CA, telecontrol certificates and firmware signatures in certified devices, as BSI TR-03109 requires.
The entire solution runs in German data centers. This applies to the PKI, intrusion detection and the data platform for forecasts.
We work with operators of critical infrastructure and regulated industries. We know what the BSI, the Federal Network Agency, auditors and information security expect in energy supply.
One team accompanies you from consulting to operations. OT security architects, cryptography specialists and data engineers stay on board without handover to third parties.
Most utilities do not fail for lack of technology but on legacy control systems, gaps in evidence and deadlines from KRITIS and NIS2.
01
Control system, telecontrol and office IT share one network, engineering workstations reach every controller and the firewall rules date from commissioning.
02
Certificates for gateways, telecontrol devices and control boxes live in spreadsheets, the sub-CA keys sit in software and an expiry only surfaces during an outage.
03
The SIEM collects events from office IT but not the control system protocols IEC 60870-5-104 and IEC 61850, and reporting to the BSI depends on a single person.
04
Vendors and service providers reach plants through their own modems and VPN access, without approval, time window or session recording.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Your control center, your data center, your HSMs and sub-CA | Data centers in Germany, operated under ISO 27001 | Azure, AWS or Google Cloud, region Germany selectable |
| Operation | Your team or OTOKO® as managed service | OTOKO®, with audit rights and evidence for the KRITIS audit | Shared, platform services by the provider |
| Tools | Control system, OT monitoring, HSMs and PKI on site, Kafka, Kubernetes | Hosted PKI, HSM as a service, data platform for forecasts | Cloud HSM services, managed data and ML services |
| Suited for | Grid operations, telecontrol, sub-CA of the smart meter PKI | KRITIS operators with a need for sovereignty and audit evidence | Forecasts, analytics, market communication, peak loads |
| Compliance | Full control, evidence from your ISMS under ISO 27019 | Processing agreement under GDPR, KRITIS contract, location Germany | Processing agreement, standard contractual clauses, no control commands from the cloud |
Collaboration
Project
Clearly scoped initiative such as a zone model under IEC 62443, the setup of a sub-CA or preparation for the KRITIS audit, with a defined result, milestones and acceptance.
Team reinforcement
OT security architects, cryptography specialists or data engineers work in your teams, tools and approval processes, directly in the control center if needed.
Managed service
OTOKO® operates intrusion detection, PKI and HSMs or the data platform with agreed service levels, regular reports and the evidence that KRITIS auditors and the Federal Network Agency require.
Five regulations that bind grid operators, generators and metering point operators, with their requirements and what OTOKO® delivers for them.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| IT Security Act 2.0 and KRITIS | Current technical safeguards for plants above the thresholds of the KRITIS Ordinance, intrusion detection systems, regular evidence to the BSI, reporting of significant incidents | Classification of plants, intrusion detection for IT and control systems along the BSI guidance, audit documents with implementation level, reporting process with templates |
| NIS2 | Registration, risk management measures for supply chain, cryptography and access, staged reporting with early warning, notification and final report, accountability of management | Gap analysis of the measures, cryptography and access concept, reporting process with deadlines and exercises, training evidence for management |
| ISO 27019 and IT security catalog | ISMS under ISO 27001 with the ISO 27019 extensions for process control, grid control in scope under section 11 EnWG, certification and a contact person for IT security | ISMS setup or extension with network structure plan, risk analysis and action plan, certification preparation and audit support |
| IEC 62443 | Zones and conduits with security levels, system requirements for control systems, hardening of components, patch and change processes for automation systems | Zone model with risk assessment, segmentation and hardening, test evidence per zone, operations manual for patches in maintenance windows |
| BSI TR-03109 | Certified smart meter gateways under protection profile, smart metering PKI with sub-CAs, TLS with certificates from the PKI, requirements for the gateway administrator and its ISMS | PKI concept and sub-CA with HSM, certificate profiles and lifecycle, connection of gateway administration and market participants, ISMS evidence |
FAQ
15 answers about your industry, the project and ongoing operations.
The portfolio covers zone model and hardening of control systems under IEC 62443, PKI and HSMs for smart meter gateways under BSI TR-03109, KRITIS evidence with an ISMS under ISO 27019 and intrusion detection, remote maintenance and connection of distributed plants, forecasts for load and generation, and post-quantum readiness. Each field of action can be commissioned individually or as a complete package, with operation in German data centers.
Whether a plant counts as critical depends on the thresholds of the KRITIS Ordinance per plant category, for example for power grids, generation, gas supply and district heating. NIS2 additionally covers energy companies by size and sector, also below these thresholds. We classify your plants, derive the obligations with deadlines and determine which evidence must be produced first.
Yes, that is the normal case. Older control systems and telecontrol devices rarely receive updates, so we protect them with zones, upstream industrial firewalls, data diodes, controlled remote access and passive monitoring of network traffic. These measures take effect without touching the approved configuration of the plant and are introduced in maintenance windows. We work with operators of critical infrastructure and regulated industries. There this approach is everyday practice.
The technical guideline specifies that gateways, gateway administration and market participants communicate only over TLS with certificates from the smart metering PKI. Operating a sub-CA requires registration under the BSI root, certificate profiles under TR-03109-4, an ISMS under ISO 27001 and keys that are generated and stored in an HSM. We deliver PKI concept, HSM integration, key ceremony and the evidence for certification.
The data platform reads from the process network through a data diode or protocol gateway but never writes back. Readings from smart meter gateways reach the platform via gateway administration, pseudonymized under GDPR and the Metering Point Operation Act. The models run outside the control systems, and their forecasts flow into grid operations as a proposal, not as a control command.
Now, with the inventory. Smart meter gateways, telecontrol devices and substation equipment stay in the field well beyond the expected arrival of capable quantum computers, and replacing devices in the grid takes years of lead time. The inventory shows which firmware signatures, certificates and connections migrate first, and the roadmap ties the migration to rollout and renewal cycles.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
OT security architect: Zone model, hardening, intrusion detection for control systems. Cryptography specialist: Smart meter PKI, HSM integration, PQC roadmap. Integration developer: Interfaces to plants, remote access, data diodes. Data engineer: Data platform, forecasting models, model operations. Compliance consultant: KRITIS, NIS2, IT security catalog, audit documents. Project lead: Milestones, maintenance windows, acceptance, reports.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
Plants, networks, interfaces and obligations under KRITIS, NIS2 and the IT security catalog Asset inventory, crypto inventory, gap analysis, prioritized list of measures by impact on supply
Project: Clearly scoped initiative such as a zone model under IEC 62443, the setup of a sub-CA or preparation for the KRITIS audit, with a defined result, milestones and acceptance. Team reinforcement: OT security architects, cryptography specialists or data engineers work in your teams, tools and approval processes, directly in the control center if needed. Managed service: OTOKO® operates intrusion detection, PKI and HSMs or the data platform with agreed service levels, regular reports and the evidence that KRITIS auditors and the Federal Network Agency require.
Monitoring, certificates, audits, knowledge transfer Intrusion detection in daily operations, certificate renewal, audit support, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Energy
Let us review together where your grids and plants are exposed today and which measures deliver the most benefit first.
Book a first consultation