---
title: "Resources — Specifications and Downloads — CANcrypt"
canonical_url: "https://cancrypt.net/resources/"
description: "Download the SPsec specification documents for CANcrypt in current revisions: Concept, Glossary, Generic Specification, Generic Mapping and CAN FD Mapping."
last_updated: "2026-07-13"
---
# Specifications and Downloads

The SPsec document family in five PDFs: concept, glossary, generic specification and the two mapping documents. These specifications are the basis for CANcrypt V2.

## The Document Family

SPsec is published as a small set of documents that build on each other. Read 101 first for the why, 102 for vocabulary, 201 for the network-independent definitions and then whichever mapping document applies to the network you are deploying on.

### SPsec101 — Concept

Sets out the scope of SPsec: where small-packet networks are used, the threats they face, the regulatory backdrop and the security principles SPsec is built on.

[Download PDF](https://cancrypt.net/download/SPsec101-Concept.pdf) · v1.06 · 12 November 2025

### SPsec102 — Glossary

Defines the terminology used across the SPsec documents, grouped by topic: basics, attack vectors, cryptographic methods, roles, states, keys, data objects and timeouts.

[Download PDF](https://cancrypt.net/download/SPsec102-Glossary.pdf) · v1.26 · 11 December 2025

### SPsec201 — Generic Specification

The network-independent specification of SPsec: data types, parameter registers, cryptographic primitives, key derivations, control-plane services and event handling.

[Download PDF](https://cancrypt.net/download/SPsec201-Generic-Specification.pdf) · v1.35 · 11 December 2025

### SPsec301 — Generic Mapping

Maps SPsec onto generic serial point-to-point communication, with implementation notes for Modbus and CANopen.

[Download PDF](https://cancrypt.net/download/SPsec301-Generic-Mapping.pdf) · v1.01 · 12 November 2025

### SPsec302 — CAN FD Mapping

The CAN FD mapping that powers CANcrypt V2, covering security stamp layout, control-plane CAN ID assignment, timestamp synchronization and AEAD parameters. Compatible with CANopen FD.

[Download PDF](https://cancrypt.net/download/SPsec302-CAN-FD-Mapping.pdf) · v1.40 · 8 January 2026

## Further Reading and Tools

SPsec and CANcrypt sit within a wider set of CAN security material, tools and training from Embedded Systems Academy.

> ### CAN Security Reference
>
> Our companion site answers a wide range of CAN and CAN FD security questions, from threat models to IEC 62443 mapping.
>
> [Visit cansecurity.net →](https://www.cansecurity.net)

> ### EmSA Library
>
> Security white papers, application notes and technical articles from Embedded Systems Academy.
>
> [Open the library →](https://www.esacademy.com/en/library.html)

> ### Video Library
>
> Recorded talks and screencasts on CAN, CANopen and embedded security topics.
>
> [Watch the videos →](https://www.esacademy.com/en/library/video.html)

> ### EmSA Courses
>
> Online courses on CAN and CAN FD security, the EU Cyber Resilience Act and mapping a real device onto SPsec.
>
> [Browse courses →](https://emsa.courses/)

> ### Downloads
>
> Free tools, demos and reference utilities from the Embedded Systems Academy download area.
>
> [Open downloads →](https://www.esacademy.com/en/downloads.html)

> ### The CANopen Book
>
> Embedded Networking with CAN and CANopen, the reference book on CANopen fundamentals and implementation.
>
> [Visit canopenbook.com →](https://canopenbook.com)

## Frequently Asked Questions

### Which SPsec document should I read first?

Read SPsec101 (Concept) first, then SPsec102 (Glossary) for vocabulary, then SPsec201 (Generic Specification) for the network-independent definitions, then the mapping document for your network.

### Which document covers CANcrypt V2?

SPsec302 (CAN FD Mapping) defines the CAN FD mapping that CANcrypt V2 implements.
