Wireless Communications Blog
DMR Encryption and IEC 62443 SL2 – What Industrial Sites Need to Know | Yesway Communications
There is a widespread and dangerous misunderstanding about DMR radio in industrial environments. It goes like this: “We switched from analogue to DMR, so our radio communications are now secure.”
They are not. DMR is digital. Digital is not the same as encrypted. And under IEC 62443 Security Level 2 — the baseline target for most industrial sites — an unencrypted DMR system does not meet the standard’s requirements for radio conduit security.
This post explains what the distinction means in practice, what IEC 62443 SL2 actually requires for a radio conduit, and how to establish whether your DMR system is compliant — or whether you have a significant gap you may not know about.
DMR digital versus DMR encrypted — the distinction that matters
DMR — Digital Mobile Radio — is an ETSI standard for digital two-way radio that replaced analogue PMR in most industrial and professional radio applications over the last fifteen years. The move from analogue to DMR brought real improvements: better spectral efficiency, cleaner audio, longer battery life, and the ability to carry data alongside voice.
What DMR does not provide by default is encryption. The DMR standard includes encryption capability — specifically, Advanced Encryption Standard (AES) with 256-bit keys, referred to in the standard as Enhanced Privacy — but this is an optional feature that must be explicitly enabled, correctly keyed, and consistently managed. It does not come switched on out of the box.
In practice, the majority of DMR radio systems deployed in UK industrial environments are running without encryption enabled. There are several reasons for this. Encryption requires compatible radio firmware — not all DMR handsets support AES-256, and mixed fleets are common. Encryption requires key management — keys must be generated, distributed to all radios, and rotated periodically. Encryption adds complexity to programming and maintenance. And historically, most industrial radio purchasers and installers have not considered encryption a priority, because the security risk was not framed in terms they recognised.
IEC 62443 changes that framing entirely.
What IEC 62443 Security Level 2 requires for a radio conduit
IEC 62443 defines four Security Levels, from SL1 (protection against unintentional misuse) through to SL4 (protection against sophisticated state-level attacks). For most industrial radio systems, SL2 is the appropriate target — protection against intentional misuse by simple means with few resources, general skills, and low motivation.
That description — simple means, few resources, general skills — describes exactly the threat profile of intercepting an unencrypted DMR radio transmission. A software defined radio (SDR) dongle costs around £20. Free, open-source DMR decoder software is widely available. The barrier to intercepting an unencrypted DMR transmission is, objectively, low. A motivated person with basic technical interest can do it.
IEC 62443-3-3 defines the technical requirements for each Security Level through seven Foundational Requirements. For a radio conduit assessed at SL2, the relevant requirements include:
FR4 — Data Confidentiality: The conduit must protect the confidentiality of information transmitted across it from unauthorised disclosure. For a radio conduit, this means encryption. An unencrypted DMR system does not meet FR4 at SL2.
FR1 — Identification and Authentication Control: The conduit must authenticate devices and users attempting to use it. For a radio conduit, this means controlling which radios can access operational talkgroups. A talkgroup where any radio programmed to the correct channel can transmit — with no authentication of the transmitting device — does not meet FR1 at SL2.
FR5 — Restricted Data Flow: The conduit must restrict data flow to only that which is necessary. A radio system where all operational talkgroups are accessible from all handsets, regardless of the security zone the user is operating in, does not meet FR5 at SL2.
FR2 — Use Control: The conduit must enforce authorisation of all users and devices. Radio systems without talkgroup access management — where handsets can be programmed by users or third parties without oversight — do not meet FR2 at SL2.
How to check your DMR system against these requirements
Four questions establish whether a DMR system is meeting IEC 62443 SL2 requirements for a radio conduit:
1. Is AES-256 encryption enabled on all radios in the fleet?
This requires checking the codeplug — the programming file — of the radio fleet. Encryption must be enabled on every channel used for operational communications, and the encryption keys must be correctly distributed to all radios in the relevant talkgroups. Check also whether all handsets in the fleet are running firmware that supports AES-256. Older Tier II DMR handsets from some manufacturers do not.
2. Is there a key management process?
Encryption keys that never change are a significant vulnerability. IEC 62443 SL2 implies a security management programme — which includes periodic key rotation for radio encryption. If keys were set when the system was installed and have never been changed, the key management requirement is not met, even if encryption is technically enabled.
3. Is talkgroup access controlled?
Who can programme radios on the system? Is there a process for issuing, recovering, and decommissioning handsets? If radios can be added to operational talkgroups without oversight — whether by internal staff or contractors — the authentication and use control requirements are not met.
4. Are all radios on the system accounted for?
A radio asset register — listing every handset, repeater, and ancillary device on the system with its unique radio identifier — is a basic security management requirement under IEC 62443. If your organisation does not have an accurate, current register of radio assets, you cannot demonstrate that only authorised devices are operating on your network.
What about TETRA?
TETRA — Terrestrial Trunked Radio — is the trunked digital radio standard used by UK emergency services and increasingly by industrial operators in sectors including utilities, rail, and oil and gas. TETRA has significant security advantages over DMR by design: end-to-end encryption is a core feature of the standard rather than an optional add-on, and TETRA includes mutual authentication between handsets and infrastructure.
However, TETRA systems are not automatically IEC 62443 compliant simply because TETRA encryption is enabled. The zone-and-conduit assessment requirements still apply — the trunked radio network is a conduit that must be mapped against zone boundaries, assessed for risk, and assigned a Security Level target. The encryption status must be verified and documented. The key management process must be assessed. The access control to talkgroups must be reviewed.
TETRA makes SL2 compliance significantly more achievable than DMR in many configurations. It does not make the assessment requirement disappear.
The analogue legacy problem
It is worth addressing analogue radio directly, because a significant proportion of UK industrial sites are still running analogue PMR systems — either as their primary radio infrastructure or as a legacy layer alongside DMR.
Analogue radio cannot be encrypted in any meaningful sense. CTCSS and DCS tones — the “privacy codes” marketed by many radio suppliers — do not encrypt the transmission. They are squelch control mechanisms that prevent the receiving radio from opening its speaker unless the correct tone is present. The RF signal is still broadcast in the clear and can be received by any scanner set to the correct frequency, regardless of tone settings.
An analogue radio system operating as a conduit between IEC 62443 security zones cannot meet FR4 at SL2. The control for this finding in a gap analysis is migration to encrypted DMR or TETRA, or — where migration is not immediately feasible — compensating controls such as operational procedures restricting the information that may be transmitted over radio, combined with a documented remediation timeline.
Practical next steps
If your site runs DMR and you are implementing or reviewing an IEC 62443 programme, three immediate actions are worth taking:
First, pull the codeplugs from a sample of your fleet and verify encryption status. If you do not have access to the codeplugs — which is itself a governance finding — contact your radio supplier or a wireless communications specialist to obtain them.
Second, check whether your existing IEC 62443 zone-and-conduit diagram includes any wireless conduits. If it does not, your radio network has not been assessed regardless of its encryption status.
Third, consider whether the people who conducted your IEC 62443 assessment had the RF engineering background to assess your radio infrastructure. If they did not conduct an RF survey, they did not map your radio coverage against zone boundaries — and the conduit assessment for your radio network is incomplete.
Yesway Communications provides IEC 62443 radio conduit gap analysis for industrial sites — covering encryption status, talkgroup access controls, licence compliance, coverage mapping, and Security Level gap analysis, with a written report structured for integration with your existing IEC 62443 documentation. Contact us to arrange a free 30-minute scoping call.
Craig Miles is the founder of Yesway Communications and a wireless communications engineer with 30 years of experience across RF, industrial radio and satellite systems — including ILS engineering at Airbus Defence and Space on NATO satellite programmes. BSc · PGCE · QTS · Ofcom Licensed. IEC 62443 industrial radio security services ?
Need a standalone IEC 62443 wireless conduit assessment? Yesway is the only organisation offering a dedicated wireless conduit audit in the UK — covering SCADA telemetry, DMR, TETRA and unlicensed bands as a standalone service. Find out how the assessment works →
