Public key infrastructure for secure energy networks
Trusted communications for distributed energy resources, built to Australian standards and ready to scale.
Why it mattersSecurity is the foundation everything else stands on
As more distributed energy resources connect to the grid, trust becomes essential. Public key infrastructure, or PKI, lets devices, networks and operators trust each other. It confirms that every device is who it claims to be, and that every message is genuine. SwitchDin builds utility-grade PKI for high-DER networks. We deliver secure communication, identity management and compliance for the operators managing Australia's energy transition.
10M+
customer served by our partners
We provide control, data management and ancillary services to some of Australia's largest network operators, inverter OEMs, VPP operators and electricity retailers. Our PKI expertise is backed by our partnership with DigiCert. Together we deliver secure server and client certificate solutions for operators such as AusNet and Endeavour Energy, building on the DER security framework we established with SAPN.
What PKI delivers
Device and Server Integrity
Mitigating risks of invalid certificates through robust repositories and processes.
Secure Certificate Management
Safeguarding device identities and communication channels.
Compliance Testing & Validation
Ensuring that only certified devices integrate with energy networks.
Scalable Identity Management
Tracking identities of organisations, individuals, and devices securely.
Key components of PKI for DER
Certification Authority (CA)
Responsible for issuing and managing digital certificates.
Enables secure management of keys, safeguarding the system’s trust.
Supports compliance with IEEE 2030.5 CSIP-AUS standards.
Certificate Repository
A centralised list of valid certificates to validate device trustworthiness.
Facilitates blacklisting invalid or compromised devices.
Supports seamless migration through different certification phases.
Registration Authority (RA)
Vendor-agnostic device connectivity
Ensures certificates are issued only to compliant devices and systems.
Tracks compliance across deployment scenarios.
Certificate Policy (CP) & Certificate Practice Statement (CPS)
Defines the rules and practices for certificate issuance and management.
Ensures national alignment and traceability across DER networks.
SwitchDin’s PKI framework supports the transition to a secure, compliant, and future-ready DER network. By working collaboratively with DNSPs, OEMs, and industry stakeholders, we enable a trusted and scalable foundation for Australia’s energy transformation.
Contact us to learn more about our solutions for PKI-based DER security.
Frequently Asked Questions
-
The PKI service, developed by SwitchDin in collaboration with DigiCert, provides Public Key Infrastructure for Australian Distribution Network Service Providers (DNSPs). It supports Emergency Backstop mechanisms for Consumer Energy Resources (CER) in line with CSIP-AUS and IEEE 2030.5:2018.
The solution provides a shared Smart Energy Root CA (SERCA) and related PKI processes, aligning with National Energy PKI (NEPKI) concepts and supporting a smooth transition until NEPKI is fully operational. Its design and processes are also informed by the Australian Government’s Gatekeeper Public Key Infrastructure Framework.
-
SwitchDin acts as the primary Service Operator, overseeing the overall operation of the PKI. It provides first- and second-line technical support, maintains the CA hierarchy aligned with IEEE 2030.5, manages the information repository, conducts OEM identity checks and chairs the Policy Steering Committee. DigiCert operates the underlying PKI platform, providing third-line technical support and ensuring a reliable and secure platform in accordance with industry best practices.
DNSPs (Distribution Network Service Providers) manage registered CER within their networks. Their responsibilities include approving certificate requests related to their network, such as DNSP MICA and Utility Server Device certificates, and authorising OEMs, including Aggregators and Direct Connect, to request PKI services.
-
The Registration Authority (RA) is responsible for verifying the organisation and the identity of the "Authoriser" of a business entity.
This identity verification process adheres to Level of Assurance 2 of the Gatekeeper PKI Framework, published by the Digital Transformation Office of the Australian Government.
-
The PKI service is governed by a framework that ensures its secure and coordinated implementation. The service operates in strict adherence to the practices outlined in the Detailed Design Document and any processes it references.The Policy Steering Committee plays a vital role in guiding the development of the policy framework, with a strong emphasis on alignment with the National Energy Public Key Infrastructure (NEPKI). It includes representatives from SwitchDin, DigiCert, participating DNSPs, OEMs and other stakeholders to ensure interoperability, security and consistency across the broader energy ecosystem. Significant security issues, such as a compromised OEM MICA, are reported immediately, while other issues are discussed during regular steering committee meetings.
-
All pertinent information related to the PKI service is available through the SwitchDin support portal repository. This centralised resource includes reports on valid and invalid certificates, a certified list of OEMs for each DNSP through the Production PKI Certified List, and comprehensive process documentation, including the Detailed Design Document itself.
Common SERCA, MCA and DC MICAs are provided as a bundle to certificate requestors when needed, rather than being stored directly in the repository.
Build on foundation you can trust
SwitchDin's PKI framework supports the shift to a secure, compliant and future-ready DER network. We work alongside DNSPs, OEMs and industry partners to build a trusted, scalable foundation for Australia's energy transition.