Sep 1, 2026 | BAS, News

Why BACnet SC Is Becoming the Standard for Secure Building Automation

Building automation security used to be an afterthought. For years, Operational Technology (OT) networks stayed separate from IT infrastructure, and the assumption was that if your building access control systems weren’t visible to the outside world, they were safe. That assumption doesn’t hold anymore.

OT and IT networks are converging. Between edge controllers, IP devices, and remote access, the boundary that kept building systems isolated is largely gone. BACnet SC exists to address exactly that shift, and based on what we’re seeing in specs and on project sites, it’s on track to become the industry default for automated security.

What Is BACnet SC?

BACnet is the open protocol established by ASHRAE for building automation systems. It’s been the preferred standard for automated building controls for decades, but the original BACnet protocol (including BACnet IP) was built for interoperability rather than security. Devices could communicate freely, but nothing was managing the security of those connections. BACnet IP doesn’t require authentication and runs on UDP, which generates significant network traffic and creates real exposure on shared infrastructure.

BACnet SC is the Secure Connect addendum to the protocol. The easiest way to think about it is to view it as the same shift that moved websites from HTTP to HTTPS formats. TLS encryption, certificate-based authentication, and verified connections allow BACnet SC to bring that framework to building automation software and the devices running on it.

Every connection is authenticated. Every data transfer is encrypted. Your OT network stays protected even as it moves to IP.

Why Federal Specs Are Requiring BACnet SC

Federal facilities have historically relied on older protocols like LON and BACnet MSTP, 2-wire systems that stayed off the IP network and kept building controls out of reach from a building automation cybersecurity standpoint. That approach is being phased out as facilities move to faster IP-based infrastructure.

BACnet SC gives federal customers a path to use modern building automation systems without creating network vulnerabilities they’ll be held accountable for. We’re seeing it appear in Department of Defense project specs, Air Force installation requirements, and design documents from engineering firms doing federal work.

For spec engineers, the requirement is straightforward to include, typically in sections 23 09 00, 23 09 13, or the dedicated BAS cybersecurity section 23 09 14. At minimum, all IP-based BACnet communications shall utilize BACnet/SC per ANSI/ASHRAE Standard 135, and all internet-connected supervisory BAS devices shall comply with IEC 62443-4-2 Security Level 2 (SL2).

Security Validation Matters More Than Protocol Support

BACnet SC has been on every major manufacturer’s roadmap, and multiple OEMs now support it in various forms. However, BACnet SC support and independently validated cybersecurity are not the same thing.

Several building automation manufacturers have pursued IEC 62443 certifications across portions of their product portfolios, with Siemens prominently documenting IEC 62443-4-2 Security Level 2 (SL2) certified offerings for building automation applications. Certification adoption and scope continue to vary across the market.

IEC 62443-4-2 SL2 goes well beyond encryption. The standard evaluates technical security capabilities such as account management, system integrity, audit logging, secure update mechanisms, role-based access control, and other foundational cybersecurity requirements. These are the types of controls IT and cybersecurity teams increasingly review when determining whether a building automation system can be connected to enterprise networks.

We are in the process of designing a BACnet SC deployment for research campuses and an engineering firm performing extensive federal design work, including projects with DoD, USACE, VA, and DOE specifications. The driving requirement is the same: demonstrating that OT network security is verifiable and defensible rather than simply assumed.

Why Research Facilities Are Leading Adoption

Research environments have specific reasons to take building automation security seriously.

Many operate under contractual obligations tied to their funding sources. Between defense contracts, federal research grants, and proprietary IP, the organizations issuing those contracts expect environments to meet documented security standards, including the building systems.

There’s also the data itself. Research facilities track precise environmental conditions (temperature, humidity, pressure, etc.) tied directly to the validity of ongoing work. Healthcare research adds HIPAA considerations. Unsecured access to clinical space conditions is a compliance risk, not just an IT concern.

A breach in these environments can mean financial impact, loss of intellectual property, halted operations, and serious reputation damage. BACnet SC keeps the OT network genuinely isolated so that exposure doesn’t happen.

Addressing the IT and Facilities Tension

IT departments want locked-down networks. Facilities teams want remote access. BACnet SC helps resolve that tension to find a path forward.

When we deploy it, we bring IT in early to set encryption standards, authentication requirements, hardening guides, and port access. BACnet SC also eliminates the need for BBMDs, which have long been a vulnerability concern for IT. Certificate-based authentication works cleanly with NAT, something IT teams already know how to manage.

Integrated certificate management is a critical piece of this. Without it, BACnet SC becomes difficult to maintain, prone to outages, and expensive to support. With it built in, facilities managers can trust that their systems stay online and IT managers can check certificate status, monitor connections, and pull audit logs for compliance without relying on outside support.

A Sign of Where the Industry Is Going

Moving to BACnet SC doesn’t require replacing everything. Older BACnet controllers can be segmented from new IP infrastructure, so existing equipment stays in place while new portions run under the secure protocol. Hybrid sites are practical and cost-effective.

Cybersecurity breakouts in BAS specs were rare a few years ago. Now they’re common. Even when BACnet SC isn’t named explicitly, it’s one of the most effective methods for satisfying the security requirements appearing across project types. The manufacturers that are certified today have a meaningful head start. For project teams specifying smart building automation for federal, research, or healthcare environments, there’s no reason to wait. BACnet SC is the future of secure building automation.

Secure Your Building Automation System

Cybersecurity in building automation is no longer a secondary concern. It’s a specification requirement, a compliance obligation, and an operational priority for the facilities and IT teams responsible for keeping critical environments running. Albireo Energy works with organizations across federal, research, and healthcare sectors to design and implement building automation solutions that meet those demands from day one.

Contact our team to discuss your project and how BACnet SC fits into your facility’s security strategy!

News You May Like

Hand holding a lightbulb with coins inside.

10 Mind-Blowing Energy Efficiency Actions for Data Centers

Hand with energy icons appearing from fingers

Turn Energy Usage and Building Data into Actionable Items