# Energy SCADA Systems and PQC

**Source**: https://quantumsequrity.com/blog/energy-scada-pqc
**Category**: Industry & Use Cases

---

[← Back to Blog](../../blog.html) Industry & Use Cases

# Energy SCADA Systems and PQC

10 min read

The North American electric grid runs on Supervisory Control and Data Acquisition (SCADA) systems that were designed when cryptography was an afterthought and rebuilt over decades into networks that now span continents. Generation, transmission, and distribution are coordinated through control center applications that talk to substation gateways that talk to remote terminal units and intelligent electronic devices, all over a mix of dedicated fiber, microwave links, leased circuits, and increasingly internet-based connectivity. The North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) standards govern security, and the Federal Energy Regulatory Commission (FERC) enforces NERC standards as legally binding requirements. When quantum computers eventually break the RSA, ECDSA, and Diffie-Hellman cryptography that current grid security depends on, the migration cost will be enormous, and the constraints unique to grid operations make this one of the hardest sectors to migrate.

This article walks through the NERC CIP framework, the IEC 62351 standards for power system communications security, ICS-CERT advisories that shape grid cybersecurity practice, and the constraints that make PQC migration in the energy sector different from enterprise IT.

## Why the Grid Is Uniquely Hard to Migrate

Energy infrastructure has long lifecycles, performance constraints that enterprise IT does not face, and regulatory requirements that span every change. A protective relay installed in a substation today is expected to operate for 20 to 30 years. A SCADA RTU may run for 15 years or more. The communications protocols those devices use, including DNP3, IEC 60870-5-101 / 104, IEC 61850 GOOSE/SV, and Modbus, were designed for reliability and determinism, not cryptographic agility. Adding cryptography after the fact, as IEC 62351 does, runs into bandwidth, latency, and processing constraints that vary by application.

Grid operations also have a regulatory sequence that does not allow for casual experimentation. Every change to a Bulk Electric System Cyber Asset (BES Cyber Asset) needs to be tracked under NERC CIP-010 (Configuration Change Management). Every cryptographic configuration is subject to documentation under CIP-005 (Electronic Security Perimeters), CIP-007 (System Security Management), and CIP-011 (Information Protection). Failure to comply produces penalties up to $1.4 million per violation per day. The compliance burden is real, and it shapes how PQC migration must be planned.

For broader background see [What Is Post-Quantum Cryptography](what-is-post-quantum-cryptography.html) and [Why RSA-2048 Will Break](why-rsa-2048-will-break.html).

## NERC CIP Standards and Cryptographic Controls

NERC CIP comprises a family of standards covering cybersecurity for the bulk electric system. CIP-002 categorizes BES Cyber Systems by impact (low, medium, high). CIP-005 establishes Electronic Security Perimeters around medium and high impact assets. CIP-007 specifies system security management including patching and ports and services. CIP-011 covers information protection, including handling of BES Cyber System Information.

Cryptographic controls run through these standards as enforcement mechanisms. CIP-005 requires that electronic access through the security perimeter is protected, which in practice means VPNs and TLS with strong cryptography. CIP-007 requires authentication of users and processes. CIP-012 specifies that real-time assessment data and real-time monitoring data exchanged between control centers be protected by cryptography. None of these standards specifically name post-quantum algorithms today, but they all require cryptography appropriate to the risk, and the risk envelope is changing.

For broader regulatory context see [PQC for Critical Infrastructure Grid](pqc-critical-infrastructure-grid.html) and [PQC for Government and Defense](pqc-government-defense.html).

## IEC 62351 and Power System Communications

IEC 62351 is the international standard suite for security in power system management and information exchange. The publication addresses authentication and integrity for IEC 61850 (substation automation), IEC 60870-5 series (telecontrol), IEC 60870-6 (TASE.2 / ICCP for inter-control center), DNP3, and related protocols. IEC 62351-3 covers TLS profiles. IEC 62351-5 covers application-layer authentication for telecontrol. IEC 62351-6 covers IEC 61850 GOOSE and SV authentication.

The challenge is that IEC 62351 was written assuming RSA, ECDSA, and Diffie-Hellman as the underlying primitives. The standard supports cryptographic agility in principle, but the deployed base of devices implementing the standard is heterogeneous and slow to refresh. PQC migration in the IEC 62351 ecosystem will require updates to the standard itself, then implementation in firmware by device vendors, then field deployment over multi-year refresh cycles. The IEC technical committees have begun this work, but the timeline is years not months.

## ICS-CERT and the Operational Threat Landscape

The Industrial Control Systems Cyber Emergency Response Team, now part of CISA's Cybersecurity Division, publishes advisories and indicators of compromise for ICS environments. The advisory record over the past decade includes cases targeting ABB, Schneider Electric, Siemens, GE, Honeywell, and Rockwell devices. The 2015 and 2016 Ukraine grid attacks, the 2017 Industroyer/CrashOverride malware, and the 2021 Colonial Pipeline incident all demonstrated that adversaries are actively prepared to attack energy infrastructure.

For PQC migration, the ICS-CERT record matters because it establishes the threat realism. State-sponsored actors are actively positioned in energy networks. They are capturing traffic. They are storing it. The harvest-now-decrypt-later threat against grid traffic is not hypothetical. Anything captured today and decrypted in a future quantum era would expose grid operating data, vulnerability intelligence, and operational patterns that adversaries could weaponize for future intrusions or kinetic targeting.

## Constraints on PQC Deployment in Grid Environments

PQC algorithms have larger keys, ciphertexts, and signatures than classical algorithms. ML-KEM-768 ciphertexts are about 1,088 bytes. ML-DSA-65 signatures are 3,309 bytes. SLH-DSA signatures are 7,856 to 49,856 bytes depending on parameters. Classical RSA-2048 ciphertexts and signatures are 256 bytes. Classical ECDSA P-256 signatures are 64 to 72 bytes.

In enterprise IT the size differences are tolerable. In substation automation they can be operationally significant. IEC 61850 GOOSE messages are designed for sub-4-millisecond latency and are typically small frames carried on Layer 2 multicast. Adding a 3 KB signature to a GOOSE frame breaks the protocol assumptions. SLH-DSA at 8 KB to 50 KB signatures is even more difficult. The IEC technical committees and major vendors are working on profiles that fit PQC into time-critical messaging, but the work is not finished.

Slower protocols like DNP3 secure authentication and TASE.2 / ICCP have more room to absorb PQC overhead, but still face deployment challenges in field devices with limited memory and processing capability. Many deployed RTUs and IEDs use 32-bit microcontrollers with megabytes of flash, not the multi-gigabyte enterprise compute that PQC libraries assume.

## Migration Strategy for Generation, Transmission, Distribution

The three operational segments of the electric grid have different migration profiles. Generation is dominated by larger plants with modern control systems. The cryptographic footprint is concentrated in plant DCS, generator excitation, and the connection to the transmission system. Migration is feasible across a 5 to 10 year horizon assuming vendor support arrives.

Transmission is the heart of the NERC CIP regime. The bulk electric system at 100 kV and above is highly regulated and operationally critical. Transmission control centers, EMS/SCADA platforms, and substation automation systems all need PQC migration. The work is concentrated and the regulatory framework is established. A 7 to 10 year migration is realistic for transmission.

Distribution is the long tail. The deployed base of distribution automation, AMI head ends, smart meters, and DA controllers is enormous and heterogeneous. Many devices have no cryptographic agility and will need to be replaced. Migration in distribution will likely take 15 to 20 years and will overlap with the broader grid modernization investments around DER integration, microgrids, and grid-edge intelligence.

## Hybrid Cryptography for the Migration Window

NIST recommends hybrid post-quantum deployments during the migration window. Hybrid combines a classical algorithm with a PQC algorithm such that breaking the channel requires breaking both. For grid operations this is the right posture: it preserves backward compatibility with deployed devices while gaining quantum resistance for newly captured traffic.

Hybrid TLS in control center to control center communication is already feasible today using OpenSSL profiles that support ML-KEM hybrid key exchange. Hybrid in IEC 62351-3 TLS profiles will follow as the IEC committees publish updated guidance. Hybrid in time-critical Layer 2 messaging like GOOSE remains an open research area with active work at IEEE Power and Energy Society and IEC Technical Committee 57. See [Hybrid Encryption](hybrid-encryption.html) for construction details.

## Vendor Roadmaps and the Procurement Lever

Energy utilities are large customers with concentrated procurement. The major SCADA vendors (GE, Schneider Electric, Siemens, ABB, Hitachi Energy, OSI Inc.) and the major protective relay vendors (SEL, ERLPhase, GE Multilin) all listen to utility procurement requirements. Adding PQC migration commitments to RFPs and contract renewals is the most effective lever utilities have.

Procurement language should require: a published PQC migration roadmap with dates, support for hybrid TLS in management interfaces, FIPS validation status of cryptographic modules, cryptographic agility (the ability to swap algorithms via configuration), and CBOM (Cryptographic Bill of Materials) deliverables. Utilities should be willing to ask for and pay for these capabilities rather than assuming vendors will deliver them on their own schedule.

## Reliability Coordination and Inter-Control-Center Communication

Reliability coordinators (RCs), balancing authorities (BAs), and transmission operators (TOs) coordinate grid operations through inter-control-center communication using the IEC 60870-6 (TASE.2) protocol commonly known as ICCP. ICCP carries real-time operating data, schedule information, and contingency analyses between control centers. NERC CIP-012 specifically addresses the protection of real-time data exchanged between control centers.

ICCP traditionally runs over dedicated networks with TLS or VPN protection at the network layer. PQC migration in ICCP is feasible through the perimeter VPN and TLS upgrades described above. The ICCP application layer itself does not include cryptographic operations and does not need direct PQC modification. The migration is therefore largely a network infrastructure upgrade for ICCP, which is one of the most tractable parts of the broader grid PQC program.

For broader sector context see [NIST FIPS Guide](nist-fips-guide.html) and [PQC for Critical Infrastructure Grid](pqc-critical-infrastructure-grid.html).

## Renewable Integration and DER Cybersecurity

The grid edge is changing rapidly. Distributed Energy Resources (DER), including rooftop solar, battery storage, electric vehicle chargers, and small wind, are connecting to the distribution system in increasing volumes. IEEE 1547 governs the technical interconnection requirements, and IEEE 1547.3 specifies cybersecurity requirements for DER communications. The cryptographic stack at the DER edge is even more constrained than traditional substation automation: residential solar inverters have limited compute and bandwidth, and the cumulative population is potentially in the millions for major utilities.

For PQC, DER cybersecurity is a fresh design opportunity. The IEEE 1547.3 cybersecurity profiles are still being refined, and the specifications can be written to include hybrid post-quantum cryptography from the outset for new equipment. SunSpec Alliance, the industry consortium that defines DER communication interfaces, has begun engaging with NIST PQC work. New DER deployments specified after 2026 increasingly include PQC-capable communications.

The retrofit problem for existing DER is harder. Residential solar inverters typically have 10-year operational lifetimes, and the installed base is large. The PQC retrofit will likely come through firmware updates where supported and through natural refresh as equipment ages out. Utility distribution operators are tracking the DER population in their territories and including DER cybersecurity, including the PQC trajectory, in their grid modernization plans.

The broader grid edge cybersecurity question intersects with the smart inverter functionality (frequency support, voltage regulation, ride-through behavior) that is increasingly required by interconnection standards. Cryptographic authentication of the commands sent to smart inverters is a critical safety property as the population grows: an adversary who can spoof commands to a million inverters can potentially destabilize the distribution grid. PQC-grade authentication is essential for this scale of deployment, and the migration timeline should be coordinated with the broader DER buildout schedule.

## Frequently Asked Questions

### Does NERC CIP require post-quantum cryptography?
Not by name as of 2026. NERC CIP standards require cryptography appropriate to the risk and consistent with FIPS-validated implementations where applicable. As the FIPS validation portfolio expands to include PQC, NERC CIP audit expectations will likely follow.

### How long will grid PQC migration take?
For transmission and bulk electric system assets, 7 to 10 years from serious start to broad deployment is realistic. Distribution and AMI will take longer, often 15 to 20 years, due to the size and heterogeneity of the deployed device base.

### Can PQC fit inside time-critical IEC 61850 GOOSE?
Not yet without profile updates. GOOSE is designed for sub-4-millisecond latency and small frame sizes, and PQC signature sizes break those assumptions. The IEC technical committees and major vendors are working on profiles. Hybrid approaches and protocol-specific optimizations are active research.

### What about distribution-level smart meters?
AMI head ends and the meter population behind them are the longest tail of grid PQC migration. Many deployed meters have no cryptographic agility and will need replacement on natural refresh cycles. Migration will overlap with broader grid modernization investments.

### Is the grid harvest-now-decrypt-later threat real?
Yes. ICS-CERT advisories and incident reports document active state-sponsored adversary positioning in energy networks. Captured grid traffic that becomes decryptable later would expose operating data, vulnerability intelligence, and patterns that could enable future intrusions or kinetic targeting.

### How does the FERC Order 706 and broader regulatory framework address quantum?
FERC Order 706 directed NERC to develop the original CIP standards, and subsequent FERC orders have continued to shape the standard development. Quantum cryptography has not yet been the subject of a specific FERC order, but the underlying authority to require cybersecurity standards remains. As NERC and the industry develop quantum readiness practices, FERC is positioned to formalize them through its order authority.

### What is the role of the E-ISAC in grid PQC coordination?
The Electricity Information Sharing and Analysis Center (E-ISAC) coordinates cybersecurity threat intelligence and best practice sharing across the North American grid. As quantum readiness becomes a more prominent industry concern, E-ISAC is positioned to disseminate guidance, coordinate vendor roadmap discussions, and facilitate information sharing among utilities about migration approaches that are working in practice. Utilities active in E-ISAC engagement typically lead in cybersecurity maturity, including the PQC dimension.

### How does the European grid (ENTSO-E and the NIS2 directive) compare on PQC migration?
ENTSO-E coordinates the European transmission system, and the NIS2 Directive establishes cybersecurity requirements for essential services including electricity. The European framework is broadly parallel to NERC CIP but applies across multiple national jurisdictions. PQC migration in European utilities tracks both NIST PQC standards and the broader EU cryptographic guidance from ENISA. The European Commission's interest in cryptographic agility, including the recent CRA (Cyber Resilience Act) provisions, applies to grid equipment vendors and creates a regulatory pressure analogous to the FERC framework in North America.

## Sources

- NERC. "Critical Infrastructure Protection (CIP) Standards." nerc.com.
- FERC. "Cybersecurity Standards Approval Orders." ferc.gov.
- IEC. "IEC 62351: Power systems management and associated information exchange - Data and communications security." iec.ch.
- CISA. "ICS-CERT Advisories." cisa.gov.
- NIST. "NIST IR 8547: Transition to Post-Quantum Cryptography Standards." nist.gov.
- NIST. "SP 800-82 Rev 3: Guide to Operational Technology (OT) Security." nist.gov.
- IEEE. "IEEE 1815: Standard for Electric Power Systems Communications - Distributed Network Protocol (DNP3)." ieee.org.
- IEEE. "IEEE 1547.3: Guide for Cybersecurity of Distributed Energy Resources." ieee.org.

## Related Articles

- [What Is Post-Quantum Cryptography](what-is-post-quantum-cryptography.html)
- [Why RSA-2048 Will Break](why-rsa-2048-will-break.html)
- [Harvest Now, Decrypt Later](harvest-now-decrypt-later.html)
- [PQC for Critical Infrastructure Grid](pqc-critical-infrastructure-grid.html)
- [Hybrid Encryption](hybrid-encryption.html)

---

### Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

[Try QNSQY](../../pricing.html)
