# CAN Security Reference > A free, vendor-neutral reference site on Controller Area Network (CAN) and CAN FD security for industrial and IACS (Industrial Automation and Control Systems) applications, published by Embedded Systems Academy GmbH (EmSA / ESAcademy). Scope is deliberately limited to non-automotive contexts: industrial machinery, energy, building automation, medical, and other IACS deployments where CAN is used as a control bus. The site explains the regulatory drivers (EU Cyber Resilience Act, NIS 2 Directive, Machinery Regulation), the threat model specific to CAN, risk-assessment methodology (IEC 62443-3-2, CVSS v4.0), seven defensive controls (the "shells" plus zoning and the secure bootloader), and where each EmSA product fits. **Canonical domain:** https://cansecurity.net (primary). The site is also reachable at https://can-security.net (secondary mirror serving the same content). All `` and sitemap URLs point at cansecurity.net. ## What this site is for - Embedded engineers and integrators designing CAN-based industrial products who need to understand what cybersecurity requirements apply to them and how to meet those requirements at the bus level. - Compliance and product managers building the CRA / IEC 62443 documentation for a CAN product family. - Buyers and assessors comparing CAN security approaches across vendors. ## What this site is not - Not an automotive reference. ISO/SAE 21434, UNECE WP.29/R155, OBD-II, ECU-in-vehicle vocabulary, and telematics-as-vehicle-component are deliberately out of scope. - Not a substitute for the underlying standards. Where IEC 62443, NIST SP 800-82, or ETSI EN 303 645 cover a topic, this site summarizes and links out rather than restating. - Not a sales site. EmSA products are referenced where they implement a control discussed on the page; the surrounding content is vendor-neutral. ## Section index ### Why Now - https://cansecurity.net/why-now/ — Regulatory drivers: EU CRA, NIS 2, Machinery Regulation, EN 303 645, NIST SP 800-82, BSI TR-02102. ### Threats - https://cansecurity.net/threats/ — Three categories of CAN threats: physical access, protocol weaknesses, remote attack. Software updates treated as a combination example, not its own category. - https://cansecurity.net/threats/physical-access/ — Local physical access to wiring, connectors, or diagnostic ports. - https://cansecurity.net/threats/protocol-weaknesses/ — Inherent CAN protocol weaknesses: no authentication, ID spoofing, broadcast nature. - https://cansecurity.net/threats/remote-attack/ — Remote-service gateways, diagnostic ports, wireless maintenance. - https://cansecurity.net/threats/software-updates/ — Firmware-update channels as an attack surface; combination of bus access and remote entry. ### Risk Assessment - https://cansecurity.net/risk-assessment/ — IEC 62443-3-2 and CVSS v4.0 as complementary methodologies the CRA accepts. - https://cansecurity.net/risk-assessment/cvss-for-can/ — CVSS v4.0 walkthrough with CAN-specific scoring (based on EmSA white paper WP-103). - https://cansecurity.net/risk-assessment/iec-62443/ — IEC 62443-3-2 eight-step methodology with a CANopen worked example. - https://cansecurity.net/risk-assessment/defense-in-depth/ — Strategy and composition layer: how to combine the per-node shells, zoning, and the bootloader into layered protection. - https://cansecurity.net/risk-assessment/access-limitation/ — Perimeter area (out of scope), pointer to IEC 62443-3-3 SR 1.x and ISO/IEC 27001. - https://cansecurity.net/risk-assessment/secure-gateways/ — Perimeter area (out of scope), pointer to IEC 62443-3-3 SR 5.x and NIST SP 800-82. ### Solutions - https://cansecurity.net/solutions/ — Catalog of seven in-scope defensive controls plus the threats × shells coverage matrix at IEC 62443 Security Levels. - https://cansecurity.net/solutions/bus-load-monitoring/ — Physical-layer detective shell; surfaces flooding and error-frame storms to the security event log. - https://cansecurity.net/solutions/local-injection-detection/ — Data-link / network detective shell; per-node impersonation alarm. - https://cansecurity.net/solutions/frame-security/ — Cryptographic preventive shell; CANcrypt or SPsec frame authentication and encryption. - https://cansecurity.net/solutions/anomaly-event-monitoring/ — Cross-cutting detective shell with an auditable event log. - https://cansecurity.net/solutions/secure-object-fieldbus-access/ — Application-layer cryptographic shell for selected CANopen Object Dictionary entries (SOFA, currently under definition at CiA). - https://cansecurity.net/solutions/zoning-segmentation/ — System-level architectural measure: IEC 62443-3-2 zone-and-conduit pattern for CAN. - https://cansecurity.net/solutions/secure-bootloader/ — Composite control: authenticated firmware update under PSK_UP with AES-128-GCM, plus secure boot at startup. ### Resources - https://cansecurity.net/resources/ — White papers, standards, glossary. - https://cansecurity.net/resources/cra-requirements/ — Quick-reference matrix mapping CRA Annex I requirements (I-1, I-2a through I-2m) to defensive measures on this site. ### Legal / Contact - https://cansecurity.net/contact/ — Contact information for EmSA. - https://cansecurity.net/imprint/ + https://cansecurity.net/imprint/de/ — §5 TMG legal pages (English and German). - https://cansecurity.net/privacy/ + https://cansecurity.net/privacy/de/ — GDPR privacy notice (English and German). ## Machine-readable artifacts - https://cansecurity.net/sitemap.xml — XML sitemap of all canonical URLs. - https://cansecurity.net/robots.txt — crawl policy (maximum AI visibility: all major training crawlers explicitly allowed). ## Publisher Embedded Systems Academy GmbH (EmSA), registered in Hannover, Germany. Trading names: EmSA, ESAcademy. The site is published as a free reference and funnels to existing EmSA properties: - https://www.esacademy.com — EmSA consulting and security white papers - https://www.cancrypt.net — CANcrypt / SPsec source-code offering for CAN and CAN FD frame security - https://emsa.courses — EmSA training catalogue (CRA, IEC 62443, CAN-specific courses) - https://can-dragon.com — CAN Dragon family (Router FD, AEM Library) hardware products - https://canopenmagic.com — CANopen Magic analysis and diagnostic tool - https://www.cangineberry.com — CANgineBerry embedded controller ## License and citation The reference content is published for educational use. Verbatim text reuse, redistribution, or inclusion in for-profit products, courses, or publications requires prior written permission. Brand names (CANcrypt, SPsec, CAN Dragon, CANopenIA) are trademarks of Embedded Systems Academy GmbH. Citations welcome — please cite the page URL together with the publisher (Embedded Systems Academy GmbH). ## Section index ### Contact EmSA - https://cansecurity.net/contact/ — Reach Embedded Systems Academy about CAN and CAN FD security, EU CRA and IEC 62443 obligations, customizing a Solutions shell, or reviewing a risk assessment. ### Imprint - https://cansecurity.net/imprint/ — Legal information for the CAN Security Reference website, operated by Embedded Systems Academy GmbH (Barsinghausen, Germany), as required under §5 TMG. - https://cansecurity.net/imprint/de/ — Anbieterkennzeichnung gemäß §5 TMG für die Website CAN Security Reference, betrieben von der Embedded Systems Academy GmbH in Barsinghausen, Deutschland. ### Key Management - https://cansecurity.net/key-management/ — A getting-started orientation to key management for CAN and CAN FD devices: CRA and IEC 62443 expectations, symmetric versus asymmetric, and handover. - https://cansecurity.net/key-management/asymmetric-key-management/ — What a full public-key infrastructure for CAN devices involves and where it is documented, plus a minimal PKI a smaller company can realistically run. - https://cansecurity.net/key-management/fieldbus-device/ — What a fieldbus device must protect at each lifecycle stage: firmware, identity at handover, software updates, configuration, and end-of-life key destruction. - https://cansecurity.net/key-management/handover/ — Security steps when a manufacturer hands a CAN device to an integrator, and an integrator passes a system to an operator: ownership, keys, and scoped authority. - https://cansecurity.net/key-management/regulations-standards/ — What the EU Cyber Resilience Act and IEC 62443 require about cryptographic keys for CAN devices: risk-based, mechanism-neutral, met by symmetric keys. - https://cansecurity.net/key-management/symmetric-key-management/ — Per-device key diversification for CAN fleets: storing keys, deriving them from a root, the asymmetric governance hybrid, and rotation and revocation cycles. - https://cansecurity.net/key-management/symmetric-vs-asymmetric/ — The core key-management choice for CAN devices: shared secrets versus key pairs, what each costs to provision and verify, and the algorithms on each side. ### Privacy Notice - https://cansecurity.net/privacy/ — Privacy notice for the CAN Security Reference website: no cookies, no tracking, no analytics, no forms. Information about server logs and your GDPR rights. - https://cansecurity.net/privacy/de/ — Datenschutzerklärung der Website CAN Security Reference: keine Cookies, kein Tracking, keine Analyse. Hinweise zu Server-Logs und Ihren Rechten nach DSGVO. ### CAN Security Resources and Further Reading - https://cansecurity.net/resources/ — Downloads, standards references, and a glossary for CAN and CAN FD security. Includes the five EmSA white papers, EU CRA and IEC 62443 links, and SPsec specs. - https://cansecurity.net/resources/cra-requirements/ — Quick-reference matrix mapping each EU CRA Annex I cybersecurity requirement (I-1 through I-2m) to the defensive shells available for CAN-based products. - https://cansecurity.net/resources/crypto-benchmarks/ — Measured code size, stack, and timing for SHA-256, HKDF, AES-128-GCM, Ed25519, and X25519 on three CAN FD microcontrollers, from the EmSA CryptoEval harness. - https://cansecurity.net/resources/iec-62443-sl2-requirements/ — Quick-reference matrix mapping the CAN-relevant IEC 62443-3-3 system requirements at Security Level 2 to the defensive controls available for CAN products. - https://cansecurity.net/resources/secure-can-mcus/ — A maintained reference of microcontroller families that pair a CAN FD interface with on-chip security: TRNG, secure key storage, and crypto accelerators. - https://cansecurity.net/resources/terms-and-definitions/ — Glossary of CAN security terms: protocols (CAN, CAN FD, CANopen), regulations (CRA, NIS 2, IEC 62443), and the cryptographic primitives used on this site. ### Risk Assessment for CAN and CAN FD Systems - https://cansecurity.net/risk-assessment/ — IEC 62443-3-2 risk assessment for CAN systems, kept distinct from CVSS v4.0 vulnerability scoring. How the two activities fit together in a CRA-ready process. - https://cansecurity.net/risk-assessment/access-limitation/ — Physical and logical access limitation around a CAN network is a perimeter area, not a CAN-specific control. IEC 62443-3-3 and NIST SP 800-82 apply here. - https://cansecurity.net/risk-assessment/cvss-for-can/ — The EU Cyber Resilience Act requires CVSS vulnerability scoring, but CAN does not map cleanly to its categories. A consistent method based on EmSA-WP-103. - https://cansecurity.net/risk-assessment/defense-in-depth/ — How to combine CAN-specific shells, zoning, the secure bootloader, and perimeter controls into layered protection that meets IEC 62443 security levels. - https://cansecurity.net/risk-assessment/iec-62443/ — The IEC 62443-3-2 eight-step risk-assessment methodology applied to CAN-based products, with a CANopen worked example and CRA-aligned lifecycle records. - https://cansecurity.net/risk-assessment/secure-gateways/ — Gateways, routers, bridges, and repeaters around a CAN network are perimeter coupling devices, not CAN-specific controls. IEC 62443 and NIST SP 800-82 apply. ### CAN Security Solutions - https://cansecurity.net/solutions/ — Catalog of in-scope CAN security controls: per-node frame-level shells, zoning and segmentation, and the secure bootloader, mapped to threats and IEC 62443 SLs. - https://cansecurity.net/solutions/anomaly-event-monitoring/ — Anomaly Event Monitoring watches the CAN bus, applies anomaly rules, and emits an auditable security event log. Required by CRA Annex I and IEC 62443 SR 6.x. - https://cansecurity.net/solutions/bus-load-monitoring/ — Bus Load Monitoring tracks CAN bus load across time windows to surface availability loss from attack or sabotage. Non-cryptographic shell, IEC 62443 SR 7.x. - https://cansecurity.net/solutions/frame-security/ — Frame Security: cryptographic authentication and confidentiality on CAN. CANcrypt, SPsec, and CANopen AES-128-GCM. IEC 62443 SR 1.x / SR 3.x / SR 4.x. - https://cansecurity.net/solutions/local-injection-detection/ — Local Injection Detection: each legitimate CAN sender watches for impersonation of its own IDs. A non-cryptographic data-link-layer shell, IEC 62443 SR 3.x. - https://cansecurity.net/solutions/mitigation-flowchart/ — A six-step flowchart for choosing which CAN security mitigations to apply, from gateway protection and access limitation to frame encryption and authentication. - https://cansecurity.net/solutions/secure-bootloader/ — Secure bootloader for CAN: authenticated firmware update with the Update Key and AES-128-GCM, plus challenge/response gating and secure boot at startup. - https://cansecurity.net/solutions/secure-object-fieldbus-access/ — Secure Object Fieldbus Access (SOFA): authenticated read or write of selected CANopen Object Dictionary entries, using AEAD with AES-128-GCM, under CiA. - https://cansecurity.net/solutions/zoning-segmentation/ — Zoning per IEC 62443 divides a CAN system into segments by risk profile. Classical CAN stays in protected zones, CAN FD frame protection covers exposed ones. ### Threats and Attack Vectors on CAN and CAN FD Networks - https://cansecurity.net/threats/ — Physical bus access, frame injection, replay, ID spoofing, denial of service, and remote entry: CAN and CAN FD threat categories with CVSS v4.0 baselines. - https://cansecurity.net/threats/physical-access/ — Direct physical access to CAN wiring enables sniffing, frame injection, replay, and denial of service. How CVSS v4.0 scores these physical attacks on CAN. - https://cansecurity.net/threats/protocol-weaknesses/ — CAN and CAN FD have no built-in authentication, source verification, or confidentiality. Any node transmits any ID. Protocol weaknesses and CVSS scores. - https://cansecurity.net/threats/remote-attack/ — Gateways, diagnostic ports, remote-service interfaces, and wireless maintenance links open indirect remote attack paths into otherwise isolated CAN networks. - https://cansecurity.net/threats/software-updates/ — The firmware update channel is the most privileged path into a CAN node. CANopen and J1939 standardize firmware download for interoperability, not security. ### The Regulatory Case for CAN Security - https://cansecurity.net/why-now/ — The EU Cyber Resilience Act, NIS 2 Directive, and Machinery Regulation require systematic cybersecurity for CAN-based industrial products from 2027 onward.