Modbus Security
Modbus Security adds protected transport and peer identity to Modbus. Apply it alongside the device register map and permissions for each read or write.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Inherited check dated 10 September 2026. Supporting evidence for this inherited check has not been independently confirmed.
Recorded scope: The Modbus Organization describes TLS, X.509 certificates and port 802 for Modbus Security. This does not establish that a particular endpoint implements that protocol.
Public Modbus Organization material was reviewed; implementers must use the current downloadable security specification and product certificate profile.
On this page
Overview#
The Modbus Security protocol wraps Modbus in TLS and uses X.509 v3 certificates for client and server authentication and role based authorisation. The Modbus Organization assigns TCP port 802 to this protected form; classic Modbus TCP commonly uses 502.1
Security is more than enabling a TLS listener. Interoperability depends on the supported Modbus Security specification edition, TLS versions and cipher suites, certificate profile, trust anchor model, identity to role mapping, revocation/time policy, and whether both products implement the same authorisation behaviour.
Connection decision sequence#
- Resolve an approved endpoint from configuration, not unauthenticated discovery alone.
- Establish TLS with current policy and validate the full server certificate path and expected identity.
- Present the client certificate and prove possession of its private key.
- Map the authenticated certificate identity to an explicit least privilege Modbus role.
- Authorise each requested function and address range; don't infer rights from network location.
- Audit identity, decision, function, range, result, and correlation metadata without logging secrets.
PKI operations#
- Give devices unique identities. Don't clone one certificate/private key into a fleet image.
- Protect private keys with hardware backed storage where supported; make export and replacement auditable.
- Stage trust anchor and leaf rotation with overlap, verify clock quality, and define behaviour when revocation infrastructure is unavailable.
- Separate commissioning/bootstrap trust from steady state trust. An installation default can't remain an operational root of trust.
- Monitor certificate expiry, unexpected issuers, identity/role changes, failed handshakes, downgrade attempts, and authorisation denials.
Migration#
Inventory both endpoints and intervening gateways. A gateway that terminates Security and emits classic RTU/TCP creates a new cleartext trust boundary; document where authentication ends and physically protect the downstream segment. Run 502 and 802 concurrently only under a time bounded migration plan. Ensure firewall and monitoring policy distinguishes them.
TLS authenticates the endpoint and protects transport; it doesn't validate register semantics, make a write safe, prove physical completion, or repair a compromised authorised controller. Preserve the point contract and change control gates in Modbus family.
Validate certificate exchange, authorisation, error handling, downgrade rejection, and conformance against the selected product versions in an isolated authorised environment.