Avoiding the PKI Pitfalls: Getting IEEE 2030.5 Certificate Strategies Right
IEEE 2030.5 is rapidly emerging as a leading protocol for DER management, driven by increasing utility adoption and regulatory momentum. However, a consistent and growing challenge has begun to surface across deployments: security certificate strategy. While IEEE 2030.5 requires the use of PKI, it leaves key implementation decisions (such as certificate sourcing, trust chain ownership, and lifecycle management) open to utilities, manufacturers, and third-party providers to make.
As a result, many organizations are encountering unexpected complexity mid-deployment. Unlike traditional enterprise PKI environments, IEEE 2030.5 certificate implementations introduce constraints that fundamentally change how utilities must approach security. Certificates are typically embedded and cannot be easily modified after deployment, common revocation mechanisms are limited or unsupported, and architectural choices around who manages the trust chain can have long-term implications for cybersecurity risk, operational flexibility, and compliance.
EPRI research and industry engagement have shown that many utilities remain unaware of these requirements until late in the project lifecycle; often after key design decisions have already been made. This has led to project delays, rework, and in some cases, misplaced concerns about the protocol itself rather than the underlying certificate strategy. As IEEE 2030.5 adoption continues to scale, this gap in understanding represents a systemic risk to successful, repeatable DER integration.
This panel brings together a uniquely comprehensive set of perspectives across the IEEE 2030.5 PKI ecosystem. It includes leadership from the team that developed and operates the SunSpec PKI (currently one of the most widely used certificate frameworks) alongside EPRI research into certificate strategy and a utility actively deploying IEEE 2030.5 at scale.
Together, panelists will unpack:
- Why PKI strategy is one of the most critical—and underestimated—components of IEEE 2030.5 deployments
- The key decisions utilities must make early, and the implications of getting them wrong
- How certificate sourcing models (utility-managed, vendor-managed, or third-party) impact risk, scalability, and policy alignment
- Real-world lessons learned from deployments, including where organizations have been caught off guard
- Practical approaches utilities can take today to avoid delays, reduce risk, and ensure long-term interoperability
This session is designed to move beyond theory and provide actionable, experience-based guidance. Attendees of any background will leave with a clear understanding of why PKI must be treated as a first-order design decision (not an implementation detail) and how to proactively structure their approach to support secure, scalable IEEE 2030.5 deployments.
Speaker's Relationship to Topic
Tom Tansy (DER Security Corp) – Formerly of SunSpec Alliance, led development of the SunSpec PKI, one of the most widely adopted certificate frameworks in the IEEE 2030.5 ecosystem.
Ben Ealey (EPRI) – Leads IEEE 1547 interoperability and cybersecurity efforts and has authored industry guidance on IEEE 2030.5 certificate strategies and key decisions utilities must make for successful deployments.
Ajit Renjit (PG&E) – Principal engineer supporting ADMS and DERMS implementations leveraging IEEE 2030.5, with firsthand experience navigating certificate strategy and deployment challenges at scale.
Matt Wallace (PPL) – Engineering leader supporting DER integration and IEEE 2030.5 adoption at PPL, bringing utility-side experience in evaluating and implementing PKI approaches within real-world grid operations.
Damon Kachur (SecureG, CEO) – Leads development of high-assurance PKI solutions for critical infrastructure, providing perspective on certificate lifecycle management, trust models, and secure deployment practices for utility-scale environments.
