OT key management gives PLCs, RTUs and field devices the cryptographic keys they need to verify who is connecting to them. Certificates never reached most of those devices. AKMSecure’s Autonomous Key Management™ (AKM) eliminates certificates: symmetric keys refresh continuously, with no certificate authority to reach, and the protocol is air-gapped capable.
OT devices stay in service for decades, sit on segmented or disconnected networks, and put availability ahead of patching. Many are constrained controllers built for a control function, not for cryptography. Key management that needs a reachable authority, frequent renewals or a technician on site fails in the field, or never gets deployed.
A controller commissioned today can still be running in 2050. Transportation field devices are 20-to-30-year assets, and industrial controllers commonly run on 15-to-20-year lifecycles. Certificate lifetimes are measured in months and keep getting shorter.
The protocols are the other half of the problem. CISA’s 2026 research on secure OT communication found that legacy industrial protocols leave OT networks “fully trusting anyone with access,” and that the long lifecycle of OT means the industry will be mitigating those insecure-by-design protocols for decades.
Timing is a hard requirement, not a preference. IEC 61850 allows a maximum end-to-end delay of 3 milliseconds for Type 1A protection messages, and CISA notes that slow signing and verification on the device creates an unacceptable delay. Uptime wins every argument: CISA even describes skipping certificate expiry checks as one interim approach, so that an expired certificate cannot drop a protection command.
PKI assumes a reachable certificate authority, scheduled renewals, revocation checks and staff to run them. OT offers none of those at the device. Secure versions of industrial protocols have existed since the early 2000s, yet many systems built in 2026 still rely on the insecure originals, and almost every operator CISA interviewed cited PKI challenges.
The secure variants exist, from DNP3 Secure Authentication to OPC UA. The barriers CISA’s interviewees described are structural:
CISA also notes that alternatives to PKI exist, such as pre-shared keys, and that the operators it interviewed did not mention them. We break down the findings in what CISA’s report confirms about OT authentication.
The result is not badly run PKI. When certificates cannot be deployed, the field falls back to shared static credentials, factory defaults, checksums or nothing at all. A better certificate manager does not change that. Eliminating certificates does, and Autonomous Key Management vs. PKI sets out the full comparison.
Valid credentials and devices that trust whoever connects. The campaigns federal agencies have documented rarely need zero-days. Attackers log in with stolen, default or static credentials, use operators’ own tools, and wait. A credential that stays valid for months turns a single intrusion into standing access to process control.
The Department of Energy now states that nation-state adversaries “continue to pre-position inside U.S. critical infrastructure networks” to hold energy infrastructure at risk. Pre-positioning is a bet that stolen access ages well. Perimeter controls, patching and detection all matter, and none of them makes a stolen credential worthless.
It has to protect the equipment already installed, for the full life of that equipment, with no certificate authority and no operator in the loop. In practice that means six properties: nothing that expires, air-gapped operation, continuous credential refresh, per-session verification, a small footprint, and recovery without a truck roll.
| OT condition | Certificate-based PKI | AKMSecure’s AKM |
|---|---|---|
| Decades-long asset life | Certificates expire and must be renewed on the device | No certificates; keys refresh perpetually |
| Segmented or disconnected networks | Needs a reachable certificate authority and revocation checks | No certificate authority; air-gapped capable |
| Thin staffing at remote sites | Provisioning and renewal often need an integrator | Provision once, with no human intervention afterwards |
| Stolen or default credentials | Valid until someone revokes them | Session-based keys; captured material has already expired |
Each device is provisioned once with a crypto seed. From that seed, AKM generates key material on the device, refreshes symmetric keys continuously and autonomously, and verifies every packet without a stored secret. A self-healing mechanism restores availability. There is no certificate authority anywhere in the design, so the protocol is air-gapped capable.
The cryptography is symmetric-only: AES-256 with SHA-384/512, with optional HSM integration. That makes AKM quantum-resilient by architecture and aligned to CNSA 2.0 symmetric-key guidance, which matters for a device that must stay secure against a cryptanalytically relevant quantum computer until the day it is retired.
AKM ships as a sub-1MB SDK. AKMSecure’s partners embed it in their existing hardware and software, so protection arrives inside the products operators already buy and maintain. The protocol is protected by seven patents (four granted, three pending). What is Autonomous Key Management? covers the protocol in full.
For an attacker, a credential taken from an engineering workstation has already expired, and traffic from an unverified source fails verification instead of blending in. That is Zero Trust at the protocol layer, with no standing privileges left to hold at risk.
AKM is aligned with IEC 62443 for industrial automation and control systems and CENELEC TS 50701 for railway, and aligned to CNSA 2.0 symmetric-key guidance. It supports electric utility programs working toward NERC CIP. AKMSecure’s leadership contributed to IEC 62443 and CENELEC TS 50701, and the company is an OT Cyber Coalition member.
ISA/IEC 62443 sets requirements for asset owners, product suppliers, integrators and service providers across the lifecycle of industrial automation and control systems. It partitions a system into zones and conduits, and its seven foundational requirements start with identification and authentication control. A conduit is only as strong as its ability to verify who is on the other end, and most field devices cannot do that. AKM gives them that verification at the protocol layer.
In electric power, NERC’s CIP-012 standard exists to protect the confidentiality and integrity of real-time assessment and monitoring data transmitted between control centers. Continuously refreshed symmetric keys serve that goal without adding certificate operations to a utility’s workload. Alignment does not replace an operator’s own assessment. What AKM removes is the certificate lifecycle that makes these requirements hard to meet in the field.
AKMSecure has also joined the Operational Technology Cybersecurity Coalition to bring certificate-free encryption for constrained OT endpoints to its policy work.
AKM ships as a sub-1MB SDK that AKMSecure’s partners embed in their existing hardware and software. Whether a given controller can host AKM depends on the device and the partner that builds or maintains it, and is a question to settle with AKMSecure.
No. AKM has no certificate authority to reach and no revocation list to check, so it is air-gapped capable. Key material is generated on the device from its provisioned crypto seed, which lets AKM run on segmented, intermittent or fully disconnected networks.
No. Segmentation limits what an attacker can reach. AKM makes reaching a device insufficient, because every session must verify. Used together, they stop a stolen or default credential from carrying an attacker from one zone to the next.
AKM reaches OT environments through AKMSecure’s partners, who embed the SDK in the hardware and software they deliver. Operators provision each device once. After that, no one has to schedule renewals or rotate keys.
Yes. AKM is symmetric-only, using AES-256 with SHA-384/512, and is aligned to CNSA 2.0 symmetric-key guidance. A device commissioned today does not face a post-quantum migration of its key management later in its service life.