---
title: "Secure Gateways for CAN — Perimeter Shell (Out of Scope)"
canonical_url: https://can-security.net/risk-assessment/secure-gateways/
description: "Gateways, routers, bridges, and repeaters around a CAN network are perimeter coupling devices, not CAN-specific controls. IEC 62443 and NIST SP 800-82 apply."
last_updated: 2026-08-27
---
# Secure Gateways — Perimeter Shell (Out of Scope)

Gateways, routers, bridges, and repeaters that connect a CAN network to other networks are *perimeter coupling devices* rather than CAN-specific controls. They are out of scope for this reference because general industrial cybersecurity standards apply directly. The [Defense in Depth](https://can-security.net/risk-assessment/defense-in-depth/) page under [Risk Assessment](https://can-security.net/resources/terms-and-definitions/#term-risk-assessment) lists this as one of the perimeter areas acknowledged but not detailed here, with the framing that "every link leaving CAN is a conduit risk".

## Where to Look

Treat each coupling device as a conduit between zones with explicit trust levels. IEC 62443-3-3 SR 5.x (Restricted data flow / zone-and-conduit) governs the boundary; SR 7.6 (Network and security configuration settings) requires minimizing services, ports, and protocols. NIST SP 800-82 covers OT firewalling, remote-access design, and intrusion detection at the gateway. For external channels, [TLS-PSK](https://can-security.net/resources/terms-and-definitions/#term-tls-psk) (RFC 4279) and [cTLS](https://can-security.net/resources/terms-and-definitions/#term-ctls) are the practical choices on resource-constrained gateways. The CAN-specific shells covered elsewhere in this reference assume the gateway perimeter is in place; see [Defense in Depth](https://can-security.net/risk-assessment/defense-in-depth/) for the bus-side shells that pick up where the perimeter stops. [IEC 62443-3-3](https://can-security.net/resources/iec-62443-sl2-requirements/) [NIST SP 800-82](https://can-security.net/resources/terms-and-definitions/#term-nist-sp-800-82)

> ### EmSA Security Consulting

> EmSA consulting covers the CAN-bus portion only: reviewing the bus-side findings in your gateway risk assessment, or customizing a Frame Security shell to match the [IEC 62443](https://can-security.net/resources/terms-and-definitions/#term-iec-62443) conduit boundaries the gateway enforces. Gateway hardening itself remains in the hands of general IACS practice.

> [Talk to ESAcademy →](https://www.esacademy.com/en/security.html)

## Frequently Asked Questions

### Why are CAN gateways out of scope for this reference?

Gateways, routers, bridges, and repeaters that bridge between CAN and other networks are perimeter coupling devices rather than CAN-specific controls. The hardening they need (firewall rules, TLS-PSK or cTLS for external channels, zone-and-conduit boundaries) is general industrial cybersecurity practice and is well covered by IEC 62443-3-3 SR 5.x and NIST SP 800-82.

### Which standards should I consult for CAN gateway security?

IEC 62443-3-3 SR 5.x for zone-and-conduit and restricted data flow; SR 7.6 for minimizing services and ports; NIST SP 800-82 for OT firewalling and remote-access patterns. For the CAN-specific concern that "every link leaving CAN is a conduit risk", the [Defense in Depth](https://can-security.net/risk-assessment/defense-in-depth/) page under Risk Assessment covers how the bus-side shells assume the gateway perimeter is in place.
