Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · Industrial communication

OPC UA security policy

Also known as: OPC UA security mode, Security policy (OPC UA)

German: OPC-UA-Sicherheitsrichtlinie

In OPC UA, a security policy is the named set of cryptographic algorithms and key lengths that an endpoint uses to sign and encrypt messages, and it is combined with a message security mode of None, Sign or SignAndEncrypt and with X.509 application instance certificates to protect the communication between client and server.

  • Industrial communication
  • OT security
  • Standards

In one sentence

An OPC UA security policy sets the algorithms an endpoint uses; with the mode None, Sign or SignAndEncrypt and certificates it protects messages.

Example

The OPC UA server of a case packer offers only the policy Basic256Sha256 with mode SignAndEncrypt; the MES client's certificate is added to the server's trust list during commissioning.

How it applies

  • Engineering: Each server endpoint names its security policy (for example None, Basic256Sha256, Aes128_Sha256_RsaOaep or Aes256_Sha256_RsaPss) and its mode. Older policies such as Basic128Rsa15 and Basic256 are deprecated by the OPC Foundation and should be disabled.
  • Security: Mode Sign protects integrity, SignAndEncrypt also confidentiality; None protects nothing. Application certificates authenticate the applications, while user authentication (user name, certificate or token) is a separate step. A strong policy doesn't make a system secure; certificate management, access rights and network segmentation per IEC 62443 still apply.
  • Commissioning: Certificates must be exchanged and trusted on both sides. Leaving the None endpoint enabled "for testing" or trusting every certificate automatically is a typical finding in audits.
  • Documentation: The documentation team documents the offered endpoints with policy and mode, how certificates are created, trusted, renewed and revoked (by hand or via a Public key infrastructure (PKI)), and which user roles exist.

Security policy vs. security mode

The mode says whether messages are signed, encrypted or neither; the policy says with which algorithms. An endpoint is defined by the combination, for example "Basic256Sha256 – SignAndEncrypt".

By knowledge.aitechdoc.world · Published September 28, 2026 · Last reviewed

Source: IEC 62541-2 / OPC 10000-2, OPC Unified Architecture — Part 2: Security Model; OPC 10000-7, Profiles

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!