Protocols About 2 min read

BACnet Secure Connect

BACnet Secure Connect protects BACnet communication using its own connection and certificate model. Plan device identity, certificate management and application permissions together.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Normative message, certificate, and failover requirements remain in the licensed standard; product interoperability is implementation specific.

Verification and testing

Overview#

BACnet Secure Connect (BACnet/SC) is a BACnet data link that uses WebSockets over TLS and supports IPv4 and IPv6. It replaces broadcast distribution at this data link with logical hub and node communication while preserving BACnet network and application services.1 The design entered the standard through Addendum bj to ANSI/ASHRAE 135-2016 and is incorporated into later consolidated editions.2

Topology#

text
SC node ── mutually authenticated TLS/WebSocket ── primary hub
   │                                                   │
   └──────── optional direct connection ───────────────┤
                                                       └── failover hub / routed BACnet networks

Every deployment needs explicit hub ownership, node enrolment, connection initiation rules, failover behaviour, supported direct connections, BACnet network numbering, and capacity limits. A reachable WebSocket endpoint isn't automatically an approved BACnet/SC peer.

Certificate lifecycle#

  • Issue unique node/hub certificates from project controlled trust anchors; protect private keys against export.
  • Bind the certificate identity to an approved BACnet device and role. Discovery, DNS, and IP address aren't identity proof.
  • Define validity, time source, chain building, revocation, renewal, emergency replacement, trust anchor rollover, and decommissioning procedures.
  • Validate the exact identity rules required by the standard and product; don't disable hostname/identity checks to “make TLS work.”
  • Audit enrolment, certificate and trust store changes, failed handshakes, unexpected issuers, reconnect storms, hub failover, and topology changes.

Use current TLS policy and protect the certificate management plane separately. Review TLS and PKI without replacing BACnet/SC specific certificate rules with generic HTTPS defaults.

Migration and residual risk#

A BACnet/SC router connected to BACnet/IP or MS/TP terminates the secure data link; downstream traffic may again be unauthenticated and cleartext. Document each boundary and constrain which networks, services, objects, and writes may cross it. Avoid transparent “secure overlay” claims.

BACnet/SC provides secure transport and peer authentication. It doesn't by itself decide whether a peer may command a particular property, guarantee correct priority array use, secure a device's web/SSH interface, or make bad control logic safe. Retain application authorisation and safety gates from BACnet family.

Validate TLS policy, hub failover, certificate rotation, revocation, clock faults, and vendor interoperability in the controlled target environment.

Primary sources#

Section overview · Wiki home

  1. BACnet International, BACnet Secure Connect ↩

  2. ASHRAE, published addenda to Standard 135-2016 ↩