Cybersecurity built into every layer

DEIF combines secure product development, recognized cybersecurity standards and independent E27 approval to help customers protect critical energy control systems.

Cybersecurity backed by evidence

Independently certified products

All variants of the iE 250 and iE 350 controllers and the iE 650 PLC carry full IACS UR E27 certification, providing third-party evidence of assessed product cybersecurity capabilities.

Built on recognised requirements

The E27 assessment is based on cybersecurity requirements aligned with IEC 62443, including access control, secure communication, logging and vulnerability handling.

Relevant across applications

E27 originates in the marine classification framework, but the assessed product capabilities and supporting evidence are also relevant for land-based energy and industrial applications.

The threat landscape is changing - and the stakes are high

Critical infrastructure - power generation, maritime operations, industrial energy control – is increasingly connected, increasingly automated, and increasingly targeted. Cyberattacks on operational technology are no longer theoretical. Disrupted power systems, compromised vessel controls, and ransomware attacks on industrial networks are documented realities with real consequences: production stops, safety incidents, financial losses, and regulatory liability.

The challenge is not purely technical. It is organizational, regulatory, and commercial. Customers, classification societies, and legislators now demand demonstrable cybersecurity as a condition of doing business – and those demands are backed by enforceable law.

DEIF addresses this through standards-based product development, structured vulnerability management and independent third-party product certification.

Operational resilience

Built-in cybersecurity capabilities help protect availability, integrity and controlled access in critical energy applications.

Regulatory readiness

DEIF aligns product and organisational cybersecurity activities with relevant frameworks, including IEC 62443, IACS UR E27, the CRA and NIS2.

Independent product evidence

Full E27 certification for all variants of the iE 250, iE 350, and iE 650 PLC provides customers with third-party evidence that the defined product cybersecurity requirements have been assessed.

Cybersecurity at DEIF

DEIF designs, manufactures and supports control systems for energy and marine applications worldwide. As products become more connected and the regulatory environment becomes more demanding, cybersecurity is a core engineering and management discipline, not a compliance checkbox.

Product security

All variants of the iE 250 and iE 350 controllers and the iE 650 PLC carry full IACS UR E27 certification. This provides independent third-party evidence that defined cybersecurity requirements have been assessed at product level.

E27 originates from the maritime classification framework, but its technical cybersecurity requirements are aligned with recognised IEC 62443 principles. The certification therefore provides relevant product-security evidence not only for marine projects, but also for customers evaluating controllers for land-based energy and industrial applications.

The certification does not replace the customer’s assessment of the complete system, machine or installation. It gives customers a verified product-level starting point and documentation that can support the wider assessment.

IEC 62443 provides the technical foundation for DEIF’s product cybersecurity approach. Our controllers incorporate security capabilities designed in alignment with these requirements, while full IACS UR E27 certification provides independent evidence for all variants of the iE 250, iE 350 and iE 650 PLC.

Organisational security

DEIF operates under a formal information security management system aligned with ISO/IEC 27001. This provides a structured framework for governance, risk management, asset protection and continuous improvement, and supports how DEIF addresses its obligations under the EU NIS2 Directive.

As a manufacturer and supplier of critical infrastructure control systems, DEIF is classified as an important entity under NIS2. DEIF is implementing the Article 21 measures required by the Directive, including risk management policies, supply-chain security, incident handling, business continuity and security governance at management level.

One technical direction, different regulatory frameworks

IACS UR E27, IEC 62443 and the EU Cyber Resilience Act are not interchangeable. They have different scopes and legal functions. However, they address several common product cybersecurity themes, including secure design, access control, integrity, logging, vulnerability handling and security updates.

For DEIF, the work completed for full E27 certification provides a strong product-security foundation and independently assessed evidence that can support broader cybersecurity and CRA-readiness activities. E27 certification does not in itself demonstrate CRA conformity.

Framework

What it addresses

DEIF's position

IACS UR E27

Product-level cybersecurity requirements for on-board computer-based systems.

All variants of iE 250 and iE 350 controllers and the iE 650 PLC carry full certification. The certified capabilities and evidence are also relevant when these products are considered for land applications.

IEC 62443

International standards for cybersecurity in industrial automation and control systems.

Technical foundation for DEIF product cybersecurity. DEIF products include cybersecurity capabilities designed in alignment with relevant IEC 62443 requirements.

Cyber Resilience Act

EU product-cybersecurity regulation for products with digital elements.

DEIF is building the product-assurance capabilities required ahead of the relevant obligations. E27 supports readiness but does not equal CRA conformity.

ISO/IEC 27001

Information security management system framework.

Forms the organisational backbone of DEIF’s information security management.

NIS2 Directive

EU legislation on organisational cybersecurity and governance.

DEIF is subject to NIS2 and meets the applicable requirements through our ISO/IEC 27001-certified information security management system.

  • HJN

    Contact us to discuss your options

    - 90 years of energy pioneering
    - Manufactured at the highest standards
    - Superior quality
    - Unmatched service and support
    - Made in Denmark