---
title: "CAN Security Resources — White Papers, Standards, Glossary"
canonical_url: https://can-security.net/resources/
description: "Downloads, standards references, and a glossary for CAN and CAN FD security. Includes the five EmSA white papers, EU CRA and IEC 62443 links, and SPsec specs."
last_updated: 2026-08-27
---
# CAN Security Resources and Further Reading

A curated set of white papers, standards references, and a glossary supporting the rest of this reference. White paper PDFs are hosted on [esacademy.com](https://www.esacademy.com/en/library/security-white-papers.html).

## EmSA White Papers

### EmSA-WP-105: Secure Object Fieldbus Access (SOFA)

Hosted at [esacademy.com](https://www.esacademy.com/en/library/security-white-papers.html).

Specifies how compact secure protocols can be tunneled generically through fieldbus transports, the basis for the [SOFA](https://can-security.net/solutions/secure-object-fieldbus-access/) control described under Solutions. Covers authenticated access to selected object dictionary entries using AEAD.

[Download PDF →](https://www.esacademy.com/en/library/security-white-papers/emsa-wp-105-sofa-secure-object-fieldbus-access.html)

### EmSA-WP-104: Key Provisioning for Minimal Fieldbus Systems

Hosted at [esacademy.com](https://www.esacademy.com/en/library/security-white-papers.html).

Covers security key lifecycles and key handling for constrained fieldbus devices: how provisioning, update, and storage of keys are managed on nodes with very limited resources.

[Download PDF →](https://www.esacademy.com/en/library/security-white-papers/emsa-wp-104-key-provisioning-for-minimal-fieldbus-systems.html)

### EmSA-WP-103: CVSS for CAN

Hosted at [esacademy.com](https://www.esacademy.com/en/library/security-white-papers.html).

A practical method for scoring CAN vulnerabilities under [CVSS](https://can-security.net/resources/terms-and-definitions/#term-cvss) v4.0, with worked examples for an unprotected classical CAN node and the score reductions achieved by physical access limitation, system monitoring, and cryptographic measures. Establishes the 5.2 (Medium) baseline reused throughout this reference.

[Download PDF →](https://www.esacademy.com/en/library/security-white-papers/common-vulnerability-scoring-system-cvss-for-can.html)

### EmSA-WP-102: Interface Driven Security Evaluation for Sensors

Hosted at [esacademy.com](https://www.esacademy.com/en/library/security-white-papers.html).

An interface-driven method for evaluating the security of sensor interfaces, comparing the exposure of the memory bus, SPI, I2C, and CAN connections that bring sensor data into a system.

[Download PDF →](https://www.esacademy.com/en/library/security-white-papers/wp102.html)

### EmSA-WP-101: Security Justification for Classical CAN

Hosted at [esacademy.com](https://www.esacademy.com/en/library/security-white-papers.html).

Discusses when a documented security justification can serve in place of a full risk assessment for low-risk classical CAN systems with strong physical access controls, including the documentation auditors expect.

[Download PDF →](https://www.esacademy.com/en/library/security-white-papers/wp101.html)

## Regulations

- **EU Cyber Resilience Act** — official text on EUR-Lex: [Regulation (EU) 2024/2847](https://eur-lex.europa.eu/eli/reg/2024/2847/oj). See also the [CRA Annex I requirements matrix](https://can-security.net/resources/cra-requirements/) for a CAN-focused mapping of each requirement to the defensive measures on this site.

- **EU [NIS 2](https://can-security.net/resources/terms-and-definitions/#term-nis-2) Directive** — official text on EUR-Lex: [Directive (EU) 2022/2555](https://eur-lex.europa.eu/eli/dir/2022/2555/oj).

- **EU [Machinery Regulation](https://can-security.net/resources/terms-and-definitions/#term-machinery-regulation)** — official text on EUR-Lex: [Regulation (EU) 2023/1230](https://eur-lex.europa.eu/eli/reg/2023/1230/oj).

- **EU [Radio Equipment Directive (RED)](https://can-security.net/resources/terms-and-definitions/#term-red)** — official text on EUR-Lex: [Directive 2014/53/EU](https://eur-lex.europa.eu/eli/dir/2014/53/oj). Its delegated regulation activates cybersecurity requirements for radio-equipped products, addressed by the EN 18031 series.

## Standards and Guidelines

- **[IEC 62443](https://can-security.net/resources/terms-and-definitions/#term-iec-62443)** — series overview at [IEC Cyber Security](https://www.iec.ch/cyber-security).

- **ETSI [EN 303 645](https://can-security.net/resources/terms-and-definitions/#term-en-303-645)** — Cybersecurity for consumer IoT: [ETSI EN 303 645](https://www.etsi.org/deliver/etsi_en/303600_303699/303645/).

- **[NIST SP 800-82](https://can-security.net/resources/terms-and-definitions/#term-nist-sp-800-82)** — Guide to Operational Technology Security: [NIST SP 800-82 Rev. 3](https://csrc.nist.gov/pubs/sp/800/82/r3/final).

- **[BSI TR-02102](https://can-security.net/resources/terms-and-definitions/#term-bsi-tr-02102)** — Cryptographic recommendations: [BSI TR-02102](https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr02102/tr02102_node.html).

- **[NIST SP 800-57](https://can-security.net/resources/terms-and-definitions/#term-nist-sp-800-57)** — Recommendation for Key Management: [NIST SP 800-57 Part 1 Rev. 5](https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final).

- **[NIST SP 800-30](https://can-security.net/resources/terms-and-definitions/#term-nist-sp-800-30)** — Guide for Conducting Risk Assessments: [NIST SP 800-30 Rev. 1](https://csrc.nist.gov/pubs/sp/800/30/r1/final).

- **[FIPS 140-2 / 140-3](https://can-security.net/resources/terms-and-definitions/#term-fips-140-2)** — Security Requirements for Cryptographic Modules: [FIPS 140-3](https://csrc.nist.gov/pubs/fips/140-3/final).

## SPsec Specification Documents

The full [SPsec](https://can-security.net/resources/terms-and-definitions/#term-spsec) specification set (documents 101 through 302) is published on esacademy.com.

[SPsec specifications →](https://www.esacademy.com/en/library/spsec.html)

## Hardware Reference

Cryptographic CAN protection depends on the controller underneath it. The [Secure CAN MCUs](https://can-security.net/resources/secure-can-mcus/) table lists microcontroller families that pair a CAN FD interface with hardware security features, true random generation, secure key storage, and crypto accelerators, as a starting point when selecting silicon for a secured node.

Once the silicon is chosen, the [MCU Crypto Benchmarks](https://can-security.net/resources/crypto-benchmarks/) page reports measured code size, stack, and timing for the core primitives (SHA-256, HKDF, AES-128-GCM, Ed25519, and X25519) on three representative parts, so the flash, RAM, and CPU budget can be sized before committing to an approach.

## Frequently Asked Questions

### Where can I download the EmSA white papers?

All EmSA security white papers are listed at [esacademy.com/en/library/security-white-papers.html](https://www.esacademy.com/en/library/security-white-papers.html) with PDF download links. Direct deep links may change as new revisions are published; the library page is the stable entry point.

### Are the SPsec specifications publicly available?

Yes. The [SPsec project page](https://www.esacademy.com/en/library/spsec.html) on esacademy.com hosts the specification documents (SPsec 101 through 302). They are intended for public review and implementation.
