PROFINET has quietly powered millions of industrial Ethernet nodes for over two decades, and it just received its most significant overhaul yet.
PI (PROFIBUS & PROFINET International) has released PROFINET Version 2.5, and this isn’t a routine maintenance update.
It’s a structural response to three pressures every plant floor is feeling right now: converging IT and OT networks, mounting cybersecurity requirements, and the shift toward virtualized, container-based automation.
If you’re specifying new equipment, planning a network upgrade, or just trying to keep your PROFINET knowledge current, here’s what actually changed in 2.5 and why it matters.
What Is New in PROFINET 2.5?
PROFINET 2.5 is built around four core themes.
- Deep integration with the IEC/IEEE 60802 standard for time-sensitive networking (TSN) and IT/OT convergence.
- A completely reworked security architecture, centered on a new protocol called SXP.
- A new transport channel for parameterization, tool access, and firmware updates that works with or without security enabled.
- Native support for Single Pair Ethernet (SPE) and Ethernet-APL, extending PROFINET into process automation and field-level devices that were previously out of reach.
Underneath all of it, backward compatibility remains a priority. Existing PROFINET investments aren’t stranded by this release.
Why PI Made This Update Now
For years, PROFINET’s real-time performance depended on tight control over network timing that didn’t always play well with ordinary TCP/IP traffic sharing the same wire. Meanwhile, industrial cybersecurity stopped being optional: insurers, customers, and regulators increasingly expect verifiable security at the device level, not just at the network perimeter.
PROFINET 2.5 is the first official specification to come out of PI’s cooperation with IEC and IEEE on the 60802 standard, with PI contributing domain knowledge in areas like practicable real-time communication alongside parallel TCP/IP traffic.
In plain terms: PROFINET can now sit natively inside a converged IT/OT network built on standard Ethernet switches, without the special handling it used to require.
IT/OT Convergence and IEC/IEEE 60802 Alignment
The headline architectural change is that PROFINET now aligns with 60802-based networks rather than needing a parallel, purpose-built infrastructure. This means.
- Real-time traffic and standard TCP/IP traffic can share the same network without one starving the other.
- Off-the-shelf (COTS) switches and NICs become viable in more places, instead of requiring PROFINET-certified components everywhere.
- Virtualized and container-based automation environments, think soft PLCs, edge compute nodes, and cloud-adjacent control functions, get a cleaner path into the PROFINET world.
For engineers, this is the difference between designing a bolted-on OT island and designing a network that IT can actually help you manage.
A New Security Architecture: SXP
Security is arguably the biggest story in 2.5. PROFINET has offered layered “Security Classes” (SecCl1–3) for a while, but earlier versions left gaps around certificate handling that made large-scale rollout awkward.
PROFINET Security Class 1 devices are already in use, and Class 2 and Class 3 functions are currently being tested; with v2.5, outstanding issues, including certificate distribution, have now been resolved.
The mechanism behind this is the Service eXchange Protocol (SXP), a new foundation for PROFINET security that’s been under active cross-vendor testing throughout 2026.
PROFINET Security Plugfests, bringing together companies across the ecosystem, have been testing SXP and the latest PROFINET security features to validate interoperability, with the insights feeding directly back into the finalization of the 2.5 specification.
Key security additions in 2.5 include the following.
| Feature | What It Does |
|---|---|
| SXP (Service eXchange Protocol) | Foundation protocol for secure device-to-device and controller-to-device communication |
| Secure provisioning (IDevID, certificates) | Introduces secure device identity and certificate-based provisioning |
| Secure SXP over TCP | Enables secure communication using SXP carried over TCP |
| New Conformance Class CC-E | A new conformance class introduced specifically to reflect these security-related changes, complementing the existing conformance classes |
| Layer 2 and Layer 3 operations | Secure communication and device access work even without IP-based connectivity, which is useful for devices that sit below the IP layer |
The practical takeaway
PROFINET’s security model now maps onto a structured, three-tier approach. Secure Cell, Secure Access, and Secure Realtime, letting you apply protection proportional to the risk of a given segment instead of an all-or-nothing posture.
The New Transport Channel
PROFINET 2.5 introduces a dedicated transport channel purpose-built for tasks like parameterization, tool access, and firmware updates with security switched on or off depending on the use case.
Thanks to clear layer separation, this channel is suitable for both highly optimized embedded systems and virtualized, container-based environments, which is exactly the kind of flexibility needed as controllers increasingly run as software instances rather than dedicated hardware.
Why this matters day-to-day: firmware updates and engineering tool access have historically been one of the messier, less-standardized corners of industrial networking. Formalizing a channel for this reduces the number of vendor-specific workarounds engineers have had to live with.
Support for Single Pair Ethernet (SPE) and Ethernet-APL
This update also incorporates the latest enhancements for integrating Ethernet-APL and Single Pair Ethernet, with the changes reflected in the updated GSD/GSDX device description files. In practice, this extends PROFINET’s reach into the following.
- Process automation environments (tank farms, hazardous areas) via Ethernet-APL, which delivers Ethernet connectivity and power over long distances on two-wire cabling
- Space- and weight-constrained field devices via SPE, replacing bulkier standard Ethernet cabling at the sensor/actuator level
This is a meaningful expansion beyond PROFINET’s traditional stronghold in discrete manufacturing and building automation, pushing it further into process industries that have historically leaned on Fieldbus or HART.
Motion Control on Standard Hardware
PROFINET 2.5 also extends support for motion control applications running on standard, off-the-shelf hardware rather than requiring specialized motion-specific components while still supporting time-synchronized operation.
Combined with the TSN alignment from 60802, this opens the door to running high-precision motion control over the same converged network as everything else, rather than isolating it on a dedicated segment.
PROFINET 2.5 vs. Previous Versions: Quick Comparison
| Area | Before 2.5 | PROFINET 2.5 |
|---|---|---|
| Network architecture | PROFINET-optimized infrastructure, limited standard IT/OT convergence | Native alignment with IEC/IEEE 60802 networks |
| Security | SecCl1 in use; SecCl2/3 incomplete, certificate distribution unresolved | SXP protocol, resolved certificate distribution, new CC-E conformance class |
| Firmware/tool access | Vendor-specific, inconsistently standardized | Dedicated transport channel, security optional |
| Process automation reach | Limited native support | Ethernet-APL and SPE integration |
| Motion control hardware | Often required specialized components | Supported on standard COTS hardware |
| Backward compatibility | — | Maintained as a stated priority |
What This Means for Engineers and Integrators
- If you’re specifying new devices, start checking datasheets for 2.5 / SXP / CC-E support, especially for anything touching security-sensitive segments.
- If you manage IT/OT convergence projects, PROFINET 2.5 gives you a much stronger technical basis to argue for shared network infrastructure instead of parallel OT-only networks.
- If you work in process industries, the SPE/APL support is worth watching closely. It signals PROFINET actively competing for territory that used to belong to other protocols.
- If you’re not touching new hardware soon, there’s no urgency. Backward compatibility means existing PROFINET networks keep working as-is.
FAQ
Is PROFINET 2.5 backward compatible with older PROFINET devices?
Yes. Backward compatibility has been a stated priority throughout PROFINET’s development, and 2.5 is designed to protect existing investments rather than obsolete them.
What is SXP in PROFINET?
SXP (Service eXchange Protocol) is the new foundational protocol behind PROFINET Security in version 2.5, enabling secure and interoperable communication, including scenarios without IP-based connectivity, and forming the basis for the new CC-E conformance class.
Does PROFINET 2.5 replace the need for PROFIsafe?
No. PROFINET 2.5’s security enhancements address network and communication security (authentication, encryption, secure provisioning). PROFIsafe remains the separate, dedicated protocol for functional safety.
Can PROFINET 2.5 run over the same network as regular IT traffic?
Yes, that’s one of its central goals. Alignment with IEC/IEEE 60802 is specifically meant to let real-time PROFINET traffic and standard TCP/IP traffic share the same converged network without one degrading the other.
Does PROFINET 2.5 work with process automation instrumentation?
Yes, through added support for Ethernet-APL and Single Pair Ethernet (SPE), which extend PROFINET’s reach into process environments and field devices that previously relied on other communication methods.
PROFINET 2.5 is still rolling out across vendor product lines through 2026, with ongoing plugfests validating SXP interoperability.
If you’re planning a network refresh, it’s worth confirming with your automation vendor exactly which 2.5 features their current firmware and hardware actually support before you build it into a spec.