Protocols About 2 min read

DNP3

DNP3 exchanges point values, events and commands. Check event classes, timestamps, quality flags and the security features supported by each device.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

IEEE 1815 is normative and licensed; implementation subsets, device profiles, and current DNP Users Group technical documents are required for interoperability.

Verification and testing

Overview#

DNP3 is a telecontrol protocol used between control centres, substations, outstations, gateways, and intelligent devices. It separates data link, pseudo transport, and application functions and supports static values, timestamped events, unsolicited responses, time synchronisation, file transfer, and controls.1

IEEE 1815-2012 remains the last published DNP3 edition, but IEEE now places it in the administratively inactive category because it passed the ten year lifecycle without a completed revision. The superseding P1815 project is an Active PAR/draft, not a published standard.2 This combination is why the page uses technology_status: mixed: the protocol remains deployed and a revision is active, while the published edition is administratively inactive. Don't present the draft or DNP Users Group next generation security work as an approved replacement.

Data contract#

DNP3 points are typed by object/variation and index, not by a universal name. Record group/variation, index, class assignment, flags/quality, engineering conversion, event/deadband behaviour, timestamp provenance, static variation, event variation, and control authority. Preserve device flags and online, restart, communication lost, remote forced, local forced, over range, and reference error semantics rather than flattening to a value.

Class 0 is an integrity/static poll convention; Classes 1 to 3 organize events. A master must define integrity polls, event polls, buffer overflow recovery, restart indication, duplicate event handling, unsolicited enable and confirmation, and stale data handling. Application confirmation is distinct from link acknowledgement and from physical operation.

For controls, model select before operate versus direct operate, control code, count/on/off timing, status, timeout, and subsequent authoritative state. Never retry a non idempotent control without knowing whether the outstation acted.

Time and transport#

DNP3 may run over serial or IP. Record link addresses independently from IP/serial addressing and enforce expected master/outstation roles. Time synchronisation and device event timestamps require explicit accuracy, clock quality, UTC/local handling, and correction policy; receipt time isn't event time.

Security#

DNP3 Secure Authentication version 5 is included in IEEE 1815-2012 and authenticates critical operations at the application layer.3 It isn't generic transport confidentiality. Confirm exact device support, user/key model, update key lifecycle, challenge mode, protected operations, failure behaviour, and conformance subset. Segment and allowlist paths, protect engineering interfaces, authenticate remote access, and monitor restarts, time changes, unsolicited enablement, control attempts, authentication failures, and point map/configuration changes.

The DNP Users Group describes ongoing work on DNP3 SA and a next generation DNP3 Security Layer/Authenticated Messaging Protocol.4 Track it as development work until a published applicable edition and product support exist.

Safety boundary#

DNP3 controls can switch real equipment and affect utilities or site resilience. Use read only, rate bounded observation first; controls, time changes, cold/warm restarts, file transfer, or unsolicited reconfiguration require a separately approved, non production acceptance process with independent safety observation.

Primary sources#

Section overview · Wiki home

  1. DNP Users Group, overview of DNP3 ↩

  2. IEEE Standards Association, IEEE 1815-2012 status ↩

  3. DNP Users Group, Secure Authentication version 5 overview ↩

  4. DNP Users Group, cybersecurity program ↩