SCADA Systems: Architecture, Protocols, and What You Actually Have to Specify

I and C Services

October 09, 2024

24 minutes read

scada monitoring system

A SCADA specification is a short list of decisions you will live with for fifteen years, and most of them are made by the integrator because the owner never wrote them down.

The protocol determines what can authenticate. Modbus, still the most widely deployed industrial protocol, has no data or command authentication at all. The scan rate determines what you can see, and a 50,000-tag system on pure polling can saturate a control LAN even at one-second scans. The alarm philosophy determines whether operators can act during an upset, and a system averaging more than one alarm per ten minutes has already failed its benchmark.

This guide covers the architecture, the protocol choice, the performance parameters and the security framework, in the form an owner needs to write a specification rather than read a definition.

What SCADA Is

SCADA stands for Supervisory Control and Data Acquisition. It is the system that collects data from geographically distributed field devices, presents it to operators, and allows them to issue control commands back.

The defining characteristic is distance and supervision. SCADA supervises; it does not usually close fast control loops itself. Those run locally in PLCs and controllers, which continue operating if the SCADA link drops.

In the ISA-95 and Purdue Reference Model, SCADA sits at Level 2, the supervisory control layer, above the field devices and controllers and below manufacturing operations and enterprise systems.

Architecture: The Purdue Model

Industrial control architecture is described using the Purdue Reference Model, which divides the system into levels by function and response time, and that division is also the basis for network segmentation.

Level

What sits there

Typical response

Level 0

Field devices: sensors, actuators, valves, instruments

Continuous

Level 1

Controllers: PLCs, RTUs, IEDs

Milliseconds

Level 2

SCADA, HMI, local supervisory control

Sub-second to seconds

Level 3

Site operations, historian, MES

Minutes to hours

Level 3.5

Industrial DMZ

Boundary

Level 4

Enterprise IT, ERP, business systems

Hours to days

The Level 3.5 DMZ is the most consequential element, because it is the boundary that prevents an enterprise network compromise from reaching control systems. A demilitarised zone holds the systems that must exchange data between OT and IT, such as the historian replica, so that neither network connects directly to the other.

On the highest-trust sites, a unidirectional gateway, also called a data diode, permits data out of the control network and physically prevents anything entering.

Why the model matters commercially

Every serious industrial cybersecurity requirement is expressed in terms of these levels. If your architecture drawing does not show them, you cannot demonstrate segmentation to an auditor, an insurer or a customer.

The Components

Four device classes and two software components make up a SCADA system, and the RTU versus PLC distinction is the one most often stated incorrectly.

A remote terminal unit (RTU) is a field device optimised for telemetry over distance. It samples analog inputs, digital inputs and pulse counts, timestamps events, buffers data when communications drop, and reports to a master station over a wide-area link. RTUs occupy Purdue Levels 0 to 1 and typically sample at configurable rates between 100 milliseconds and 10 seconds.

A programmable logic controller (PLC) is optimised for fast, deterministic local control. It executes a scan cycle of logic in a fixed, repeatable time, which is what makes it suitable for closing control loops and interlocks. IEC 61131-3 defines the programming languages.

The practical distinction: an RTU is built to survive poor communications over long distances and report reliably. A PLC is built to execute logic fast and repeatably in one place. Modern devices increasingly do both, but the specification should state which behaviour you are buying.

An intelligent electronic device (IED) is a protection or measurement device with embedded communications, common in electrical substations.

The SCADA server or master terminal unit polls field devices, maintains the real-time database and serves data to clients.

A historian is the time-series database that stores tag values with timestamps. It is where trend analysis, performance reporting and condition monitoring all draw from, and its retention period should be specified rather than defaulted.

Modern RTUs including the SEL RTAC, ABB RTU540 and Siemens SIMATIC RTU3000 support DNP3 and IEC 60870-5-104, and increasingly MQTT over cellular or satellite backhaul.

Protocols: The Decision That Lasts

The protocol choice determines what the system can authenticate, how fast events are timestamped, and how much bandwidth the system consumes, and changing it later means touching every device.

Protocol

Standard

Where it dominates

Key characteristic

Modbus / Modbus TCP

Modbus Organization

Process and factory automation, OEM skids

Simple, ubiquitous, no authentication. TCP port 502

DNP3

IEEE 1815

North American electric, water and gas utilities

Data priority classes, 1 ms SOE resolution, Secure Authentication available

IEC 60870-5-104

IEC 60870-5 series

European and international utility telemetry

Spontaneous event delivery, 10 ms SOE resolution, TCP port 2404

IEC 61850

IEC 61850

Substation automation

Over 100 logical nodes and 2,000+ data objects. High capability, high complexity

OPC UA

IEC 62541

Greenfield, vendor-neutral, IT and OT boundary

Platform-independent, five security classes, encryption and authentication built in

ICCP / TASE.2

IEC 60870-6

Inter-control-centre

Utility-to-utility data exchange

MQTT with Sparkplug B

OASIS

IIoT and cloud telemetry

Lightweight publish-subscribe over TLS

Modbus has no authentication, and that is not a detail

Modbus was developed in 1979 as a protocol between PLCs. It has no data or command authentication, which makes systems using it vulnerable to man-in-the-middle and spoofing attacks.

Modbus/TLS on port 802 is the only encrypted variant ratified by the Modbus Organization, in 2018, and it is not widely deployed. Where Modbus TCP is used on port 502, it should be firewalled to specific master IP addresses as a minimum.

DNP3 versus IEC 60870-5-104

Both derive from the IEC 60870-5 series and both use a reduced three-layer model, data link, pseudo-transport and application, rather than the full seven-layer OSI stack.

DNP3 dominates North American utility SCADA. IEC 60870-5-104 dominates European and international markets. That geographic split is the strongest single predictor of which you will encounter.

The technical difference that matters is data priority classes. DNP3 defines Class 1, 2 and 3 events, allowing the master to poll each at a different frequency: protection alarms every few seconds, trend data far less often. IEC 104 polls at a single frequency. On bandwidth-limited WAN or satellite links, DNP3's differential polling is materially more efficient, and DNP3 sends fewer, larger packets where IEC 104 sends many small ones.

Sequence of events resolution differs too: 1 millisecond in DNP3 against 10 milliseconds in IEC 60870-5-101 and 104. If post-event sequence reconstruction matters, specify it.

What to choose

Greenfield industrial site: OPC UA for vendor neutrality and built-in security, translating legacy protocols at the server boundary.
 Electric, water or gas utility: DNP3 in North America, IEC 60870-5-104 elsewhere, for timestamped events and select-before-operate.
 Substation automation: IEC 61850.
 OEM skids and simple in-plant integration: Modbus TCP, with the security limitation understood and mitigated.
 Single-vendor controller fleet: the ecosystem protocol, EtherNet/IP for Allen-Bradley, Profinet for Siemens.

The firmware trap

Always confirm the receiving SCADA platform's driver supports the specific firmware version of the field device, not just the protocol. A driver that supports DNP3 does not necessarily support your RTU's implementation of it.

Scan Rates, Tag Count and Network Load

A SCADA system's performance is set by scan rate and tag count together, and the combination is what saturates networks.

A tag is a single monitored or controlled data point: one pressure reading, one valve position, one motor status.

Scan rate is how often the master requests a value. Polling means the master asks every device for every point on a fixed cycle. Report by exception (RBE) means the field device pushes only changes.

The number that decides your network design

With pure polling, a 50,000-tag SCADA system can saturate a control LAN even at one-second scan rates.

DNP3, IEC 60870-5-104 and OPC UA subscriptions all support report by exception, which reduces LAN traffic by 90 percent or more because unchanged points are not transmitted.

If your specification requires a tag count in the tens of thousands, it must also require report by exception. Those two requirements are not independent.

Scan class tuning

Do not specify one rate for everything. Use scan classes: 250 milliseconds to 1 second for critical loops, 5 to 30 seconds for non-critical points, with deadbands applied throughout so that insignificant fluctuations do not generate traffic.

A deadband is the minimum change required before a value is reported, and setting it correctly is the difference between a system that reports meaningfully and one that reports noise.

Edge processing

Processing data at or near the source reduces the volume transmitted and the latency of local decisions. It matters most where bandwidth is constrained or where a control response must be faster than the round trip to the master.

For how condition data from these systems feeds maintenance strategy, see our comparison of predictive versus preventive maintenance.

Alarm Management

An alarm system averaging more than one alarm per ten minutes in steady operation has already failed its benchmark, and alarm floods are a documented cause of operator failure in major incidents.

ANSI/ISA-18.2, Management of Alarm Systems for the Process Industries, and its European counterpart EEMUA 191 set the benchmarks: approximately one alarm per operator per ten minutes in normal operation, and no more than ten alarms per ten minutes during an upset. Above that threshold the system is in an alarm flood, and operators cannot process the information.

IEC 62682 is the international equivalent of ISA-18.2.

Alarm rationalisation

Rationalisation is the structured review that determines, for every alarm, whether it is necessary, what the operator is expected to do about it, how urgent it is and what priority it carries. An alarm with no defined operator response is not an alarm; it is an event, and it belongs in the historian rather than on the alarm banner.

This belongs in the SCADA scope and is almost always excluded from it. Integrators configure the alarms the P&ID implies. Nobody asks whether an operator can act on all of them simultaneously.

What to specify

An alarm philosophy document as a deliverable. A rationalisation workshop in the project scope. Measured alarm rates as an acceptance criterion, not just functional alarm operation. And alarm performance reporting built into the system so the rate can be monitored after handover.

For how alarm management sits within a wider operations scope, see our guide to plant operations and maintenance.

HMI and Operator Interface

HMI design is a discipline with its own standard, and a screen that shows everything shows nothing during an upset.

ISA-101, Human Machine Interfaces for Process Automation Systems, governs HMI design, lifecycle and style guide development.

High-performance HMI principles invert conventional practice: muted greys as the default, colour reserved exclusively for abnormal conditions, analogue indicators showing value against normal range rather than bare numbers, and hierarchical navigation from overview to detail.

The purpose is that an operator glancing at a screen sees abnormality immediately, rather than scanning a colourful mimic for the one value that has changed.

What to specify

A style guide as a deliverable, produced before screen development rather than after. Navigation hierarchy defined. Colour used only for abnormal state. And operator involvement in screen review, because the people who will use it at 3am should see it before handover.

If operators cannot see the state

That is a design failure rather than a training problem, and retrofitting it after commissioning costs several times what specifying it would have. Screens are the part of the system operators touch every shift for fifteen years.

Cybersecurity

Connecting a control system creates an attack surface on equipment whose failure mode is physical, and there is an international standard that governs it.

ISA/IEC 62443 is the series of standards for Industrial Automation and Control Systems security, developed jointly by the International Society of Automation and the IEC. Its core architectural concepts are zones, groups of assets with similar security requirements, and conduits, the controlled pathways between them. IEC 62443-3-3 defines system security requirements and security levels SL1 to SL4, where SL4 addresses nation-state-capable attackers.

IEC 62351 provides security for power system communications specifically, and IEC 62351-3 mandates TLS 1.2 or higher for IEC 60870-5-104 and IEC 61850 MMS.

NERC CIP applies to the North American bulk electric system.

Why this is not an IT problem

OT prioritises the safe and continuous operation of a physical process. IT prioritises data confidentiality. In OT, control actions must occur within defined timing windows, which means a security measure that introduces latency can cause a physical incident rather than a data loss.

The precedent is TRITON, 2017 malware built specifically to defeat the safety instrumented system of a petrochemical plant. It was the first known malware targeting the layer designed to prevent explosions and toxic releases, and the attackers reached the safety controller through the plant network.

Practical hardening

Segment by Purdue level, with Levels 0 and 1 inside Level 2 cells, a Level 3 SCADA and DMZ tier, and Level 4 enterprise separated.

Disable every unused protocol service. If you use DNP3 only, close Modbus TCP port 502. Disable SNMP v1 and v2c, Telnet, FTP and HTTP.

Force TLS on OPC UA, with a security policy of Basic256Sha256. A policy of None is acceptable only on a trusted control-network backbone, and arguably not even there.

Apply role-based access on the HMI and log every setpoint write to an append-only audit store, so that a command can be attributed after the fact.

Insurance and compliance

Insurers increasingly assess OT security posture, segmentation and incident response when pricing industrial risk. Regulated operators face specific obligations, and a documented architecture mapped to Purdue levels is the evidence both require.

SCADA, DCS and SIS

Three system types are routinely confused, and buying the wrong one is expensive because the architectures are not interchangeable.

System

Optimised for

Typical application

SCADA

Supervision over distance, telemetry, event collection

Pipelines, water networks, utility grids, dispersed assets

DCS

Continuous closed-loop process control

Refineries, chemical plants, power stations, single large sites

SIS

Bringing a process to a safe state independently

Any process with a hazard requiring an independent protection layer

A distributed control system (DCS) is designed for tightly integrated continuous control across a single large process, with control and supervision built as one system. SCADA is designed for supervision across distance, where controllers act locally and report centrally.

A safety instrumented system (SIS) is separate from both by design. It exists to bring the process to a safe state when defined conditions occur, and its independence from the control system is the point. IEC 61511, functional safety for the process industry sector, governs its lifecycle, with SIL, safety integrity level, expressing the required risk reduction.

An SIS must not share its logic solver with the control system. That independence is what makes it a protection layer rather than another control function.

For the SCADA and SIS service relationship in more detail, see our overview of SCADA and SIS services.

Oil and Gas Application

In oil and gas, SCADA monitors and controls pipeline operations, refineries and production facilities, and its highest-value function is leak detection.

Pipelines are the defining application because they are geographically dispersed, which is exactly what SCADA is built for. The system collects pressure, flow and temperature at intervals along the line and detects the signatures of a leak.

API RP 1130, Computational Pipeline Monitoring for Liquids, is the recommended practice governing software-based leak detection systems. It covers design, implementation, testing and operation of CPM systems, which infer leaks from the SCADA data rather than from dedicated leak sensors.

49 CFR Part 195 governs hazardous liquid pipeline safety in the United States, including requirements relating to leak detection capability.

Why the SCADA specification determines leak detection performance

A computational pipeline monitoring system infers leaks from mass balance and pressure transient analysis. Its sensitivity is bounded by the quality of the SCADA data feeding it: scan rate, instrument accuracy, timestamp resolution and communications reliability.

A leak detection system cannot be better than the telemetry beneath it, which means the leak detection requirement should drive the SCADA specification rather than being bolted on afterwards.

Alarm notification to mobile devices on malfunction is standard capability and it does not substitute for rationalisation. An operator receiving fifty notifications receives none.

For SCADA across the wider oil and gas value chain, see our guide to SCADA in the oil and gas supply chain.

What to Specify

A SCADA specification is reviewable only if it names numbers and standards, and most tenders name neither.

The specification checklist

Protocol, by name and version, for each interface: master to RTU, RTU to IED, and northbound to historian and enterprise.

Scan classes and rates, with critical points at 250 ms to 1 second and non-critical at 5 to 30 seconds, plus deadband requirements.

Tag count, current and design maximum, with report by exception required above a stated threshold.

Sequence of events resolution, 1 ms or 10 ms, stated explicitly if post-event reconstruction matters.

Redundancy configuration for server, network and communications paths, with failover time specified and tested.

Historian retention, in years, at full resolution and at compressed resolution.

Alarm philosophy and rationalisation as scoped deliverables, with measured alarm rate as an acceptance criterion against ANSI/ISA-18.2.

HMI style guide to ISA-101, delivered before screen development.

Security architecture mapped to Purdue levels, with an ISA/IEC 62443 security level target.

Documentation: register maps showing every readable and writable point, network diagrams, configuration backups, and as-built drawings.

Licence and configuration ownership, explicitly.

The ownership clause most owners miss

Establish that you own the configuration, the graphics, the database schema and the licences, in an exportable form, with no restriction on engaging a different integrator.

An integrator holding your configuration controls your next tender, your next expansion and every change request in between. This is the single most expensive term to omit and the cheapest to include.

Evaluating an integrator

Ask for a register map from a comparable project, redacted. Ask which protocol they propose and why. Ask what alarm rate their last system achieved after commissioning. Ask to see a network architecture drawing with Purdue levels marked. And ask what you receive at handover, in what format.

Commissioning

Factory acceptance testing, site acceptance testing, communication testing confirming the master reads at the specified scan rate, operator training and documentation handover all belong in the scope. For how these map onto project gates, see our guide to EPC engineering and the six gates.

Migration and Obsolescence

Most SCADA projects are migrations rather than new builds, and the trigger is usually vendor support ending rather than any functional shortcoming.

Control systems outlive the software generations they run on. A system installed fifteen years ago may run on an operating system no longer patched, on hardware no longer manufactured, with an integrator who has moved on and configuration files nobody can open.

The honest assessment

Functionality is rarely the reason to migrate. The reasons are security, because unpatched systems cannot be defended; spares, because failed hardware cannot be replaced; skills, because nobody remaining can modify the configuration; and integration, because the system cannot exchange data with anything modern.

Phased or big bang

Phased migration runs old and new in parallel and cuts over by area, which costs more and risks less. Big bang cuts over in a single outage window, which is cheaper and only viable where an outage of sufficient length exists.

The choice is usually made by the process, not by preference. A pipeline or a continuous plant rarely has a window long enough for a full cutover.

Cloud and hosted SCADA

Hosted supervisory functions and remote access are increasingly viable and they change the security perimeter fundamentally. Real-time control stays on site regardless. Treat any cloud element as a Level 4 or DMZ component in the architecture, never as a substitute for local control.

Staffing

A modern SCADA system requires different skills from the one it replaces, including network and security competence that the previous generation did not. Plan the capability alongside the system.

How Requirements Vary by Sector

The architecture and the standards are constant. The protocol and the emphasis change.

Power utilities

DNP3 in North America, IEC 60870-5-104 internationally, IEC 61850 within substations. NERC CIP compliance is mandatory on the bulk electric system, and sequence of events resolution matters because post-fault analysis depends on it.

Oil and gas pipelines

Geographic dispersion, satellite and cellular backhaul, and leak detection under API RP 1130 driving the telemetry specification. Bandwidth constraints make DNP3's differential polling advantageous.

Water and wastewater

Highly dispersed, frequently unattended sites, with municipal budget constraints favouring simpler architectures. Often the largest tag counts relative to budget.

Manufacturing and process plants

Frequently DCS rather than SCADA for the core process, with SCADA supervising utilities and dispersed assets. Ecosystem protocols dominate where the controller fleet is single-vendor.

Renewables and storage

Plant controllers, inverters and battery management systems, with grid code compliance driving the response requirements. IEC 61850 increasingly used for interface to the grid operator.

Small sites

A full SCADA system is uneconomic below a certain scope. A packaged control panel with a permissive run input and an alarm contact is not SCADA; it is a control panel, and calling it SCADA in a tender produces quotations for something far larger.

Outside the United States

The protocol landscape differs, with IEC 60870-5-104 and IEC 61850 more prevalent than DNP3. The standards are international, but the regulatory layer is not: NERC CIP is North American, and other jurisdictions operate their own critical infrastructure regimes.

What Prismecs Does

Prismecs provides instrumentation and control services including SCADA and DCS support, installation and commissioning, and ongoing operations and maintenance on the systems it installs.

The relevant distinction on this topic is that the party configuring the system is the party that operates it afterwards. An integrator who hands over at commissioning never finds out whether the alarm rationalisation held, whether the scan classes were right, or whether operators could act during the first real upset.

Prismecs is OEM-agnostic, which on a control system matters because the platform recommendation is not tied to a licence the recommender sells.

Apply this article's criteria to any integrator, including us. Ask which protocol is proposed and why. Ask what alarm rate the last comparable system achieved after commissioning. Ask for a network architecture drawing with Purdue levels marked. Ask what you own at handover.

To discuss a SCADA specification, migration or control system assessment, send your current platform and version, protocol landscape, tag count, site topology and the driver for the project to sales@prismecs.com or call +1 (888) 774-7632.

Frequently Asked Questions

What does SCADA stand for?

SCADA stands for Supervisory Control and Data Acquisition. It is the system that collects data from geographically distributed field devices, presents it to operators, and allows control commands to be issued back. The defining characteristic is supervision over distance. SCADA does not usually close fast control loops itself; those run locally in PLCs and controllers, which continue operating if the SCADA link drops.

Where does SCADA sit in the Purdue model?

At Level 2, the supervisory control layer. Level 0 holds field devices such as sensors and actuators. Level 1 holds controllers including PLCs, RTUs and IEDs. Level 3 holds site operations, the historian and MES. Level 3.5 is the industrial DMZ, and Level 4 is enterprise IT. That level structure is also the basis for network segmentation and for demonstrating it to auditors and insurers.

What is the difference between an RTU and a PLC?

An RTU is optimised for telemetry over distance: it samples inputs, timestamps events, buffers data when communications drop, and reports to a master over a wide-area link, typically at scan rates between 100 milliseconds and 10 seconds. A PLC is optimised for fast deterministic local control, executing logic in a fixed repeatable scan cycle. Modern devices do both, so the specification should state which behaviour you are buying.

Which SCADA protocol should I specify?

It depends on sector and site. OPC UA, standardised as IEC 62541, is the strongest greenfield choice for vendor neutrality and built-in security. DNP3, standardised as IEEE 1815, dominates North American utility SCADA. IEC 60870-5-104 dominates European and international utility telemetry. IEC 61850 governs substation automation. Modbus suits OEM skids and simple integration where its security limitations are understood.

Is Modbus secure?

No. Modbus was developed in 1979 and has no data or command authentication, which leaves systems using it vulnerable to man-in-the-middle and spoofing attacks. Modbus/TLS on port 802 is the only encrypted variant ratified by the Modbus Organization, in 2018, and it is not widely deployed. Where Modbus TCP runs on port 502, firewall it to specific master IP addresses as a minimum.

What is the difference between DNP3 and IEC 60870-5-104?

Both derive from the IEC 60870-5 series and use a reduced three-layer model. DNP3 dominates North America, IEC 104 dominates Europe and international markets. DNP3 defines Class 1, 2 and 3 data priority, letting the master poll each at different frequencies, which is materially more efficient on bandwidth-limited WAN or satellite links. Sequence of events resolution is 1 millisecond in DNP3 against 10 milliseconds in IEC 104.

What scan rate should a SCADA system use?

Not one rate for everything. Use scan classes: 250 milliseconds to 1 second for critical control loops, and 5 to 30 seconds for non-critical points, with deadbands applied throughout so insignificant fluctuations generate no traffic. A deadband is the minimum change required before a value is reported, and setting it correctly separates meaningful reporting from noise.

How many tags can a SCADA system handle?

It depends on the reporting method rather than the platform. With pure polling, a 50,000-tag system can saturate a control LAN even at one-second scan rates. DNP3, IEC 60870-5-104 and OPC UA subscriptions all support report by exception, where devices push only changes, reducing LAN traffic by 90 percent or more. A specification requiring tens of thousands of tags must also require report by exception.

What alarm rate is acceptable?

ANSI/ISA-18.2 and EEMUA 191 set the benchmark at approximately one alarm per operator per ten minutes in normal operation, and no more than ten per ten minutes during an upset. Above that the system is in alarm flood and operators cannot process the information. IEC 62682 is the international equivalent. Measured alarm rate should be an acceptance criterion, not just functional alarm operation.

What is alarm rationalisation and does it belong in the SCADA scope?

Rationalisation is the structured review determining, for every alarm, whether it is necessary, what the operator should do about it, how urgent it is and what priority it carries. An alarm with no defined operator response belongs in the historian rather than on the alarm banner. It belongs in the SCADA scope and is almost always excluded, which is why so many systems flood.

What cybersecurity standard applies to SCADA?

ISA/IEC 62443, the series for Industrial Automation and Control Systems security developed jointly by ISA and the IEC. Its architecture uses zones, groups of assets with similar security requirements, and conduits, the controlled pathways between them. IEC 62443-3-3 defines security levels SL1 to SL4. IEC 62351 covers power system communications specifically, with IEC 62351-3 mandating TLS 1.2 or higher for IEC 60870-5-104 and IEC 61850 MMS.

What is the difference between SCADA, DCS and SIS?

SCADA supervises geographically distributed assets where controllers act locally and report centrally. A DCS provides tightly integrated continuous closed-loop control across a single large process such as a refinery or power station. An SIS is independent of both by design, existing to bring a process to a safe state, governed by IEC 61511 with SIL expressing required risk reduction. An SIS must not share its logic solver with the control system.

How does SCADA support pipeline leak detection?

Computational pipeline monitoring systems infer leaks from mass balance and pressure transient analysis using SCADA data, governed by API RP 1130, Computational Pipeline Monitoring for Liquids. In the United States, 49 CFR Part 195 governs hazardous liquid pipeline safety including leak detection requirements. A leak detection system cannot outperform the telemetry beneath it, so scan rate, instrument accuracy and timestamp resolution should be specified against the detection requirement.

Who should own the SCADA configuration and licences?

You should, explicitly and in writing. Establish that you own the configuration, graphics, database schema and licences in an exportable form, with no restriction on engaging a different integrator. An integrator holding your configuration controls your next tender, your next expansion and every change request between them. It is the most expensive term to omit and the cheapest to include.

Tags: SCADA Systems SCADA Protocols Industrial Control Systems Alarm Management OT Cybersecurity