The Relationship Between Certification and Cybersecurity: Product Legitimacy

  • Post category:PI NEWS
  • Reading time:2 mins read

Industrial network cybersecurity is fundamentally about (1) establishing trusted identities and (2) controlling what those trusted entities are permitted to do. Plenty has been written on the mechanisms involved in the latter (2): access control, defense-in-depth, authentication, roles, encryption, etc. But not enough has been written on the former. I.e. how can end-users ensure (trust) that the products they’re installing in their factories are legitimate and not compromised? PI is working hard to address these concerns by making it as easy as possible for end-users.

Establishing Trusted Identities

Regarding compromised devices, the proposed solution is the well-establised IDevID. Based on IEEE 802.1AR, and agreed upon in the Industrial Security Harmonization Group (IHSG), each IDevID is unique, manufacturer-installed, cryptographically bound to device hardware, tamper-resistant, and provides verifiable device identity. All based on X.509 certificates, it helps establish trust and enables secure device authentication. The issue of compromised devices is addressed as such.

Regarding legitimacy, and how cybersecurity relates to certification, the proposed solution is the signed GSDX container. The issue of illegitimate devices is addressed as such.

GSDX Containers

GSDX containers use the Open Package Convention (à la .docx or .pptx) to hold a device’s description (GSD) file and its Machine-Readable Conformance Declaration (MRCD) file. It is cryptographically signed to enable end-users to securely attribute the file to its declared vendor (GSD) and PI (MRCD). The MRCD proves the device was tested in a certified PI Test Lab.

MRCDs allow users to swiftly identify PI-technology-enabled products lacking a valid PI certificate.

Machine-Readable Conformance Declarations (MRCDs)

In June 2026, the first version (V1.0) of the specification for machine readable device certificates was published. The document “Machine Readable Conformance Declaration” (MRCD) contains the definition of the file format. The MRCD describes the tested and certified functions of a device and makes them available to engineering systems for validity verification. This will enable certification information to be evaluated in a machine-readable format (automatically) by engineering systems.

An MRCD contains the declaration of conformity for a PROFINET device represented by a Device Access Point (DAP), as well as multiple declarations of conformity for profiles, provided they are supported by that PROFINET device.

The MRCD specification is available for members to download here: https://www.profibus.com/download/mrcd-specification-machine-readable-conformance-declaration.