Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

PKI in OT

Also known as: OT PKI, Industrial PKI

German: PKI (Public-Key-Infrastruktur) in der OT

In OT cybersecurity, PKI in OT is the use of a public key infrastructure to issue, distribute, renew and revoke certificates for industrial devices, controllers, servers and engineering tools, adapted to long device lifecycles, limited connectivity and the need for uninterrupted operation.

  • OT security

In one sentence

PKI in OT manages certificates for controllers, devices and servers, adapted to long lifecycles, limited connectivity and continuous operation.

Example

A plant's OT PKI issues device certificates to OPC UA servers on the lines, renews them automatically before expiry and keeps an offline root CA in a safe.

How it applies

  • Engineering: Certificates are used for OPC UA, secure industrial Ethernet variants, HTTPS on device web servers, VPNs for remote access and signed firmware. The design decides who operates the CA (operator, integrator, vendor), which trust lists devices hold and how devices without internet access get certificates.
  • Operation: Expiring certificates can stop communication in the middle of production. Monitoring expiry dates and automating renewal, where devices support standardized enrollment protocols, prevents outages.
  • Maintenance: When a device is replaced, its certificate must be revoked and a new one issued. Devices returned for repair should have their private keys removed or invalidated.
  • Documentation: Product documentation should describe certificate handling step by step: generating keys, installing certificates and trust lists, renewal, and the device's behavior on expiry or revocation. Commissioning checklists should include certificate setup.

PKI in OT vs. enterprise PKI

An enterprise PKI serves users and IT servers with frequent connectivity. OT PKI must cope with devices that run for decades, stay offline and cannot be restarted at will, so certificate lifetimes and renewal processes differ.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Knowledge editorial definition, based on IEC 62443 and OPC UA security practice

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!