
EtherCAT can meet the level 2 security requirements of the EU CRA (Cyber Resilience Act) without any modifications. Currently, extended functionalities are being developed for specific application scenarios. TÜV SÜD is collaborating with the EtherCAT Technology Group (ETG) to prepare the corresponding assessment report.
The importance of cybersecurity and cyber resilience is increasingly prominent: not only in Europe, but new regulations require companies to conduct appropriate risk assessments and demonstrate that adequate countermeasures have been taken. Manufacturers must provide reliable statements regarding the cyber resilience of their products.
As an Ethernet fieldbus technology, EtherCAT is based on Ethernet yet retains the simplicity of fieldbus systems, and it does not rely on IT technology. Therefore, conventional IT security measures have limited applicability or may not apply at all.
EtherCAT’s unique operating principle—real-time processing of Ethernet frames through dedicated EtherCAT chips—not only ensures ultra-high performance but also endows it with strong resistance to network attacks. This characteristic benefits from robust system architecture: EtherCAT segments are clearly isolated from upper-layer IT networks, significantly reducing the attack surface of the controller. Of course, the controller itself must implement appropriate protective measures; under this premise, EtherCAT cannot be attacked externally (i.e., from the internet or corporate networks); attacks must physically access the EtherCAT segment to be executed. Additionally, the EtherCAT device protocol is directly based on Ethernet frame transmission rather than through Internet Protocol (IP), while almost all malware is IP-based (requiring IP for routing).
EtherCAT chips will directly discard all non-EtherCAT Ethernet frames. Thanks to the characteristics of the chips, EtherCAT devices cannot process data that is not addressed to them locally—even corrupted firmware cannot change this. Unused EtherCAT ports on devices can be disabled by the controller, which can detect excess devices connected, even non-EtherCAT devices.
ETG Executive Director
Martin Rostan
We firmly believe that EtherCAT meets the requirements of the IEC 62443 standard and the CRA for almost all common applications without any changes or extensions to the protocol.

The IEC 62443 standard specifies the cybersecurity measures and processes for industrial control systems and serves as the basis for the EU CRA-related standards.
For applications with extremely high security requirements, ETG is developing protocol extensions that can be activated on demand without changing hardware. Furthermore, ETG is preparing a dedicated certification body so that ETG members can easily and uniformly sign and certify EtherCAT device description files and software.
Therefore, EtherCAT can meet the CRA requirements without any changes to the technology; and it can adapt to the needs of specific scenarios through backward-compatible extended functionalities.
TÜV SÜD is preparing an EtherCAT cyber resilience test report based on the IEC 62443 standard. Although the final assessment report has not yet been released, TÜV SÜD experts have already recognized ETG’s core conclusions.

