<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Eziwan — All-in-One Industrial IoT Infrastructure Blog</title>
        <link>https://eziwan.com/en/blog</link>
        <description>Eziwan — All-in-One Industrial IoT Infrastructure Blog</description>
        <lastBuildDate>Fri, 25 Sep 2026 00:00:00 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <item>
            <title><![CDATA[Industrial IoT M2M SIM Cards in France: Comparison of Orange, SFR, and Bouygues in 2026]]></title>
            <link>https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison</link>
            <guid>https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison</guid>
            <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Comprehensive Comparison of Industrial IoT M2M SIM Cards in France 2026: Orange Business, SFR Business, Bouygues Entreprises, MVNOs (1NCE, Tele2). ARCEP coverage, rates, SLAs, roaming, private APNs, eSIMs, and the end of 2G/3G.]]></description>
            <content:encoded><![CDATA[<p>Choosing the right <strong>M2M SIM</strong> for your fleet of industrial IoT devices is a critical decision: network coverage, pay-as-you-go rates, SLAs, international roaming, APN security, LTE-M/NB-IoT compatibility, and—an often-overlooked factor—the <strong>planned phase-out of 2G and 3G</strong>, which will render thousands of already-deployed modems obsolete. This 2026 comparison, based on the most recent ARCEP data, analyzes the offerings of major French carriers, specialized MVNOs (1NCE, Tele2 IoT), and <strong>multi-carrier SIMs</strong>, to help you make a choice that will stand the test of time over the next 10 years.</p>
<div class="tableOfContentsInline_prmo"><ul class="table-of-contents"><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#in-a-nutshell-what-to-take-away-from-this-comparison">In a Nutshell: What to Take Away from This Comparison</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#what-is-an-m2m-sim-card-and-how-does-it-differ-from-a-consumer-sim-card">What is an M2M SIM card, and how does it differ from a consumer SIM card?</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#mobile-coverage-in-france-in-2026-what-the-arcep-data-shows">Mobile Coverage in France in 2026: What the ARCEP Data Shows</a><ul><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#4g-everyone-covers-more-than-99-of-the-population">4G: Everyone Covers More Than 99% of the Population</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#resource-sharing-the-sfrbouygues-crozon-agreement">Resource Sharing: The SFR/Bouygues “Crozon” Agreement</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#key-frequency-bands-for-the-iot">Key Frequency Bands for the IoT</a></li></ul></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#%EF%B8%8F-end-of-2g-and-3g-the-deadline-that-makes-networks-obsolete">⚠️ End of 2G and 3G: The Deadline That Makes Networks Obsolete</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#m2m-operators-in-france-an-overview-for-2026">M2M Operators in France: An Overview for 2026</a><ul><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#orange-business-m2m-data--orange-iot">Orange Business (M2M Data / Orange IoT)</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#sfr-business-sfr-iot">SFR Business (SFR IoT)</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#bouygues-telecom-for-business-iot">Bouygues Telecom for Business (IoT)</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#objenious--lorawan-bouygues">Objenious / LoRaWAN (Bouygues)</a></li></ul></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#mvnos-and-specialized-iot-operators">MVNOs and Specialized IoT Operators</a><ul><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#1nce--the-lifetime-sim-card-with-a-one-time-fee">1NCE — the “lifetime” SIM card with a one-time fee</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#tele2-iot--telenor-connexion">Tele2 IoT / Telenor Connexion</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#arkessa--zariot--transatel--onomondo">Arkessa / ZARIOT / Transatel / Onomondo</a></li></ul></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#multi-carrier-sims-the-solution-for-critical-industries">Multi-carrier SIMs: The Solution for Critical Industries</a><ul><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#how-it-works">How It Works</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#benefits-of-a-multi-carrier-sim-card">Benefits of a Multi-Carrier SIM Card</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#the-eziwan-sim-card">The Eziwan SIM Card</a></li></ul></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#private-apn-why-its-essential-in-industry">Private APN: Why It's Essential in Industry</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#typical-data-usage-by-use-case">Typical Data Usage by Use Case</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#international-roaming-things-to-watch-out-for">International Roaming: Things to Watch Out For</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#summary-comparison-table">Summary Comparison Table</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#how-to-choose-a-quick-decision-tree">How to Choose: A Quick Decision Tree</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#faq--industrial-iot-m2m-sim">FAQ — Industrial IoT M2M SIM</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#further-reading">Further Reading</a></li><li><a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#additional-resources">Additional Resources</a></li></ul></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="in-a-nutshell-what-to-take-away-from-this-comparison">In a Nutshell: What to Take Away from This Comparison<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#in-a-nutshell-what-to-take-away-from-this-comparison" class="hash-link" aria-label="Direct link to In a Nutshell: What to Take Away from This Comparison" title="Direct link to In a Nutshell: What to Take Away from This Comparison" translate="no">​</a></h2>
<p>Before getting into the details, here are the key takeaways for decision-makers who are pressed for time:</p>
<ul>
<li class=""><strong>Coverage</strong>: The four carriers (Orange, SFR, Bouygues, Free) now cover <strong>99% of the population with 4G</strong> thanks to the 2018 New Deal Mobile. The difference lies in rural areas and the size of the territory, where Orange maintains a slight lead.</li>
<li class=""><strong>Pricing</strong>: Bouygues and SFR are generally the most aggressive on volume plans; Orange charges a coverage premium.</li>
<li class=""><strong>Resilience</strong>: No single-carrier SIM card covers 100% of a multi-site network. The <strong>multi-carrier SIM</strong> (multi-IMSI / eUICC) automatically switches to the best network and eliminates single-carrier dead zones.</li>
<li class=""><strong>2026–2028 Deadline</strong>: <strong>2G will be shut down</strong> (Orange will shut down its network between September 22 and October 20, 2026), and <strong>3G will follow around 2028</strong>. Any new deployment must be <strong>LTE-M / NB-IoT / 4G</strong> at a minimum, or it will quickly become obsolete.</li>
<li class=""><strong>Security</strong>: For critical infrastructure (NIS2), a <strong>private APN</strong> + VPN is no longer an option but a prerequisite.</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-is-an-m2m-sim-card-and-how-does-it-differ-from-a-consumer-sim-card">What is an M2M SIM card, and how does it differ from a consumer SIM card?<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#what-is-an-m2m-sim-card-and-how-does-it-differ-from-a-consumer-sim-card" class="hash-link" aria-label="Direct link to What is an M2M SIM card, and how does it differ from a consumer SIM card?" title="Direct link to What is an M2M SIM card, and how does it differ from a consumer SIM card?" translate="no">​</a></h2>
<p>An <strong>M2M SIM</strong> (Machine-to-Machine), now more commonly referred to as an <strong>IoT SIM</strong>, is a SIM card designed specifically for industrial and connected devices. It differs from a smartphone SIM in almost every way:</p>
<table><thead><tr><th>Feature</th><th>Consumer SIM</th><th>M2M IoT SIM</th></tr></thead><tbody><tr><td>Operating Temperature</td><td>0 °C to +40 °C</td><td>−40 °C to +85 °C</td></tr><tr><td>Lifespan</td><td>2–3 years</td><td>10–15 years</td></tr><tr><td>Format</td><td>Nano SIM (4FF)</td><td>Industrial 2FF/3FF solderable (MFF2), eSIM</td></tr><tr><td>Resistance</td><td>Standard</td><td>Vibration, humidity, corrosion</td></tr><tr><td>Data allowance</td><td>Unlimited (shared)</td><td>Low (1 MB–5 GB/month)</td></tr><tr><td>Roaming</td><td>EU “Roam Like Home”</td><td>Dedicated M2M contracts (≠ RLH)</td></tr><tr><td>Private APN</td><td>No</td><td>Available</td></tr><tr><td>Static IP</td><td>No</td><td>Optional</td></tr><tr><td>Monitoring</td><td>No</td><td>Dashboard / Fleet API</td></tr><tr><td>eUICC (remote profile)</td><td>No</td><td>Available</td></tr><tr><td>Cancellation</td><td>Monthly</td><td>12–36-month contracts</td></tr></tbody></table>
<p><strong>Industrial SIM format:</strong> IoT gateways and routers most often include a SIM slot in the <strong>2FF (mini-SIM, 25×15 mm)</strong> or <strong>3FF (micro-SIM)</strong>, or even a <strong>soldered eSIM (MFF2)</strong> for high-vibration environments. This must be verified before placing any order—an incorrect format will halt the entire deployment.</p>
<blockquote>
<p><strong>Key Takeaway</strong>: An M2M SIM card isn't just a "cheap plan." It's an industrial component designed to last as long as the machine it's installed in.</p>
</blockquote>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="mobile-coverage-in-france-in-2026-what-the-arcep-data-shows">Mobile Coverage in France in 2026: What the ARCEP Data Shows<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#mobile-coverage-in-france-in-2026-what-the-arcep-data-shows" class="hash-link" aria-label="Direct link to Mobile Coverage in France in 2026: What the ARCEP Data Shows" title="Direct link to Mobile Coverage in France in 2026: What the ARCEP Data Shows" translate="no">​</a></h2>
<p>Coverage is the most important factor when choosing an M2M SIM card. Here is the actual state of the network, based on ARCEP data from Q4 2025 (published in March 2026), rather than on the operators’ marketing claims.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4g-everyone-covers-more-than-99-of-the-population">4G: Everyone Covers More Than 99% of the Population<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#4g-everyone-covers-more-than-99-of-the-population" class="hash-link" aria-label="Direct link to 4G: Everyone Covers More Than 99% of the Population" title="Direct link to 4G: Everyone Covers More Than 99% of the Population" translate="no">​</a></h3>
<p>Thanks to the mandatory requirements of the <strong>2018 New Deal Mobile</strong>, the four carriers now cover <strong>more than 99% of the French population with 4G</strong>. The battle is therefore no longer about population coverage, but rather about:</p>
<ul>
<li class=""><strong>Area coverage</strong> (rural areas, mountainous regions, secondary roads), where Orange maintains a lead.</li>
<li class=""><strong>Indoor coverage / signal quality</strong>, now rated by ARCEP on a three-tier scale: very good, good, limited.</li>
<li class=""><strong>Remaining dead zones</strong>, addressed by the targeted coverage program (several thousand shared cell towers).</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="resource-sharing-the-sfrbouygues-crozon-agreement">Resource Sharing: The SFR/Bouygues “Crozon” Agreement<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#resource-sharing-the-sfrbouygues-crozon-agreement" class="hash-link" aria-label="Direct link to Resource Sharing: The SFR/Bouygues “Crozon” Agreement" title="Direct link to Resource Sharing: The SFR/Bouygues “Crozon” Agreement" translate="no">​</a></h3>
<p>An important factor for network resilience: <strong>SFR and Bouygues Telecom share part of their network in less densely populated areas</strong> (a network-sharing agreement known as the “Crozon” agreement). In practice, in these areas, choosing SFR or Bouygues may amount to connecting to the <strong>same physical antenna</strong>—which reduces the value of a failover between these two providers and increases the value of a failover that includes <strong>Orange</strong> (an independent network). Free, for its part, benefits from roaming on the Orange network in areas it does not yet cover.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="key-frequency-bands-for-the-iot">Key Frequency Bands for the IoT<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#key-frequency-bands-for-the-iot" class="hash-link" aria-label="Direct link to Key Frequency Bands for the IoT" title="Direct link to Key Frequency Bands for the IoT" translate="no">​</a></h3>
<table><thead><tr><th>Band</th><th>Frequency</th><th>IoT Use</th></tr></thead><tbody><tr><td>B28</td><td>700 MHz</td><td>Long range, indoor penetration, rural</td></tr><tr><td>B20</td><td>800 MHz</td><td>Rural coverage, basements</td></tr><tr><td>B8</td><td>900 MHz</td><td>Extended coverage</td></tr><tr><td>B3</td><td>1800 MHz</td><td>Urban capacity, data rate</td></tr><tr><td>B1/B7</td><td>2100/2600 MHz</td><td>High urban density</td></tr><tr><td>n78</td><td>3.5 GHz (5G)</td><td>Very high data rates, dense areas</td></tr></tbody></table>
<p>For a sensor located underground or in a rural area, it’s the <strong>low bands (700/800 MHz)</strong> that matter—not the urban 5G highlighted in advertisements.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="️-end-of-2g-and-3g-the-deadline-that-makes-networks-obsolete">⚠️ End of 2G and 3G: The Deadline That Makes Networks Obsolete<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#%EF%B8%8F-end-of-2g-and-3g-the-deadline-that-makes-networks-obsolete" class="hash-link" aria-label="Direct link to ⚠️ End of 2G and 3G: The Deadline That Makes Networks Obsolete" title="Direct link to ⚠️ End of 2G and 3G: The Deadline That Makes Networks Obsolete" translate="no">​</a></h2>
<p>This is the most underestimated aspect of an IoT deployment in 2026, and it deserves its own section.</p>
<ul>
<li class=""><strong>2G</strong>: Orange will shut down its 2G network <strong>between September 22 and October 20, 2026</strong>. Other carriers are following a similar schedule. ARCEP even plans to <strong>eliminate the requirement to map 2G coverage</strong>, a sign that the technology is reaching the end of its life cycle.</li>
<li class=""><strong>3G</strong>: scheduled shutdown <strong>around 2028</strong>.</li>
</ul>
<p><strong>Direct consequence</strong>: Any <strong>2G-only</strong> modem or IoT module (still very common in older meters and alarms) will stop working as of fall 2026. A <strong>2G/3G</strong> module without 4G fallback will stop working around 2028.</p>
<p><strong>What should I do?</strong></p>
<ul>
<li class="">For any <strong>new deployment</strong>: require <strong>4G (LTE Cat-1 / Cat-1 bis)</strong> or low-power IoT <strong>LTE-M / NB-IoT</strong> modules, which will continue to be supported well beyond 2030.</li>
<li class="">For <strong>existing 2G/3G infrastructure</strong>: plan for hardware replacement before the deadline. An LTE-M/NB-IoT-compatible SIM card is not sufficient if the <strong>modem</strong> is not compatible.</li>
<li class="">Prioritize SIM cards for which the carrier explicitly guarantees long-term support for <strong>LTE-M and NB-IoT</strong>.</li>
</ul>
<blockquote>
<p><strong>Eziwan Tip</strong>: Eziwan gateways and SIM cards support 4G/LTE-M with fallback, designed to withstand these outages without requiring on-site intervention.</p>
</blockquote>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="m2m-operators-in-france-an-overview-for-2026">M2M Operators in France: An Overview for 2026<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#m2m-operators-in-france-an-overview-for-2026" class="hash-link" aria-label="Direct link to M2M Operators in France: An Overview for 2026" title="Direct link to M2M Operators in France: An Overview for 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="orange-business-m2m-data--orange-iot">Orange Business (M2M Data / Orange IoT)<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#orange-business-m2m-data--orange-iot" class="hash-link" aria-label="Direct link to Orange Business (M2M Data / Orange IoT)" title="Direct link to Orange Business (M2M Data / Orange IoT)" translate="no">​</a></h3>
<p><strong>Orange</strong> is the incumbent carrier with the most extensive coverage, particularly in rural areas and overseas territories.</p>
<p><strong>M2M Plans:</strong></p>
<ul>
<li class=""><strong>Flux M2M Lite</strong>: data only, plans ranging from 1 MB to 2 GB/month</li>
<li class=""><strong>Flux M2M Pro</strong>: data + SMS + voice, private APN available</li>
<li class=""><strong>Orange IoT Suite</strong>: SIM fleet management + connectivity + API</li>
</ul>
<p><strong>Key Strengths:</strong></p>
<ul>
<li class="">Most extensive 4G coverage, with a lead in rural and outlying areas</li>
<li class="">Nationwide <strong>LTE-M</strong> network deployed for low-power IoT</li>
<li class=""><strong>DOM/COM</strong> coverage (Réunion, Martinique, Guadeloupe, the Antilles, etc.)</li>
<li class="">Enterprise SLA with up to 99.9% availability</li>
<li class="">GSMA member for <strong>industrial eSIM</strong> profiles</li>
<li class="">Independent network (not shared): suitable as a “second carrier” in a failover scenario</li>
</ul>
<p><strong>Weaknesses:</strong></p>
<ul>
<li class="">Premium rates: often 20–40% higher than SFR and Bouygues</li>
<li class="">M2M contracts typically last 24–36 months</li>
<li class="">Minimum order quantities can be high (≈100 SIM cards)</li>
</ul>
<p><strong>Estimated rates (data only, excluding add-ons):</strong></p>
<table><thead><tr><th>Data Allowance / Month</th><th>Estimated Price / SIM / Month</th></tr></thead><tbody><tr><td>1–5 MB</td><td>2–4 €</td></tr><tr><td>50–100 MB</td><td>4–8 €</td></tr><tr><td>500 MB – 1 GB</td><td>8–15 €</td></tr></tbody></table>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="sfr-business-sfr-iot">SFR Business (SFR IoT)<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#sfr-business-sfr-iot" class="hash-link" aria-label="Direct link to SFR Business (SFR IoT)" title="Direct link to SFR Business (SFR IoT)" translate="no">​</a></h3>
<p><strong>SFR</strong> offers competitive M2M plans, providing good value for money on large-scale deployments and a popular <strong>pooling</strong> system.</p>
<p><strong>M2M Plans:</strong></p>
<ul>
<li class=""><strong>SFR IoT Connect</strong>: M2M data connectivity</li>
<li class=""><strong>SFR IoT Platform</strong>: fleet management + APIs + alerts</li>
<li class=""><strong>Pooled Plans</strong>: a shared total data allowance across all SIM cards under the contract</li>
</ul>
<p><strong>Key strengths:</strong></p>
<ul>
<li class="">Competitive rates (often 15% to 25% lower than Orange for average volumes)</li>
<li class=""><strong>Pooling</strong>: ideal when usage varies from one SIM to another</li>
<li class="">4G network comparable to Orange’s, with high-performance 5G in urban areas</li>
<li class="">Well-documented fleet management API</li>
</ul>
<p><strong>Weaknesses:</strong></p>
<ul>
<li class="">Coverage slightly behind Orange in very rural areas</li>
<li class="">Network <strong>shared with Bouygues</strong> (“Crozon”) in sparsely populated areas: SFR↔Bouygues failover is not very effective in these areas</li>
<li class="">M2M support is sometimes less responsive than in the Enterprise segment</li>
</ul>
<p><strong>Estimated rates:</strong></p>
<table><thead><tr><th>Data Allowance / Month</th><th>Estimated Price / SIM / Month</th></tr></thead><tbody><tr><td>10 MB</td><td>€1.50–3</td></tr><tr><td>100 MB</td><td>€3–6</td></tr><tr><td>1 GB</td><td>€6–12</td></tr></tbody></table>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="bouygues-telecom-for-business-iot">Bouygues Telecom for Business (IoT)<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#bouygues-telecom-for-business-iot" class="hash-link" aria-label="Direct link to Bouygues Telecom for Business (IoT)" title="Direct link to Bouygues Telecom for Business (IoT)" translate="no">​</a></h3>
<p><strong>Bouygues</strong> has significantly improved its coverage and often offers the <strong>lowest rates</strong> on the market for large data plans.</p>
<p><strong>M2M Offerings:</strong></p>
<ul>
<li class=""><strong>Bouygues Telecom IoT</strong>: Data SIM, SMS, voice</li>
<li class=""><strong>FleetMap</strong>: SIM fleet management tool</li>
<li class="">Partnerships with integrators for major IoT platforms</li>
</ul>
<p><strong>Strengths:</strong></p>
<ul>
<li class="">Very competitive prices, often the lowest for large volumes</li>
<li class="">Full 4G coverage, “Crozon” network sharing with SFR in sparsely populated areas</li>
<li class="">Volume-based pricing starting at ~50 SIM cards</li>
<li class="">Good level of service for small and medium-sized businesses</li>
</ul>
<p><strong>Weaknesses:</strong></p>
<ul>
<li class="">More limited presence in the French overseas departments and communities</li>
<li class="">Network shared with SFR in sparsely populated areas (same concern regarding failover)</li>
</ul>
<p><strong>Estimated rates:</strong></p>
<table><thead><tr><th>Data Allowance / Month</th><th>Estimated Price / SIM / Month</th></tr></thead><tbody><tr><td>10 MB</td><td>€1.20–2.50</td></tr><tr><td>100 MB</td><td>€2.50–5</td></tr><tr><td>1 GB</td><td>€5–10</td></tr></tbody></table>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="objenious--lorawan-bouygues">Objenious / LoRaWAN (Bouygues)<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#objenious--lorawan-bouygues" class="hash-link" aria-label="Direct link to Objenious / LoRaWAN (Bouygues)" title="Direct link to Objenious / LoRaWAN (Bouygues)" translate="no">​</a></h3>
<p>For <strong>low-power, low-data-rate</strong> applications (remote water/gas meter reading, asset tracking, environmental sensors), <strong>LoRaWAN</strong> is an alternative to cellular networks:</p>
<ul>
<li class="">National LoRaWAN network covering most of the population</li>
<li class="">Extremely low power consumption: several years on a single battery</li>
<li class=""><strong>Limitation</strong>: not suitable for video, high data rates, or frequent OTA updates</li>
</ul>
<blockquote>
<p>Note: The LoRaWAN ecosystem is evolving (acquisitions, strategic repositioning of players). Verify the long-term viability of the network and the commercial offering before making a long-term commitment.</p>
</blockquote>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="mvnos-and-specialized-iot-operators">MVNOs and Specialized IoT Operators<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#mvnos-and-specialized-iot-operators" class="hash-link" aria-label="Direct link to MVNOs and Specialized IoT Operators" title="Direct link to MVNOs and Specialized IoT Operators" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1nce--the-lifetime-sim-card-with-a-one-time-fee">1NCE — the “lifetime” SIM card with a one-time fee<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#1nce--the-lifetime-sim-card-with-a-one-time-fee" class="hash-link" aria-label="Direct link to 1NCE — the “lifetime” SIM card with a one-time fee" title="Direct link to 1NCE — the “lifetime” SIM card with a one-time fee" translate="no">​</a></h3>
<p><strong>1NCE</strong> offers a radical model: a <strong>one-time payment of about $10/$12</strong> for <strong>500 MB of data + 250 text messages valid for 10 years</strong>, on the Deutsche Telekom network and its partners (including Orange in France), with coverage in <strong>170+ countries</strong>. The SIM supports 2G, 3G, <strong>4G/LTE-M, NB-IoT</strong>, and is advertised as “5G-ready.”</p>
<p><strong>For:</strong></p>
<ul>
<li class="">Very low-power deployments (sensors, remote meter reading, asset tracking)</li>
<li class="">Virtually zero OPEX after purchase; predictable costs over 10 years</li>
<li class=""><strong>OpenVPN</strong> tunnel included, along with a management portal and API</li>
<li class=""><strong>Industrial</strong> (ruggedized) and <strong>eSIM/eUICC</strong> versions available (for a small additional fee)</li>
</ul>
<p><strong>Cons:</strong></p>
<ul>
<li class=""><strong>500 MB lifetime limit</strong>: insufficient for video or frequent OTA updates (top-up: ~€12 for 500 MB)</li>
<li class="">Limited data speed (up to 1 Mbit/s)</li>
<li class="">No dedicated private APN, unlike with enterprise carriers</li>
<li class="">Support is primarily text-based, except for the premium plan</li>
</ul>
<blockquote>
<p>1NCE is excellent for <strong>simple, straightforward applications</strong>. For industrial monitoring, regular VPN remote access, or video, you'll need a single-carrier or multi-carrier solution.</p>
</blockquote>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="tele2-iot--telenor-connexion">Tele2 IoT / Telenor Connexion<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#tele2-iot--telenor-connexion" class="hash-link" aria-label="Direct link to Tele2 IoT / Telenor Connexion" title="Direct link to Tele2 IoT / Telenor Connexion" translate="no">​</a></h3>
<p>European operators specializing in IoT, with attractive <strong>multi-country</strong> offerings for international deployments and mature fleet management.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="arkessa--zariot--transatel--onomondo">Arkessa / ZARIOT / Transatel / Onomondo<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#arkessa--zariot--transatel--onomondo" class="hash-link" aria-label="Direct link to Arkessa / ZARIOT / Transatel / Onomondo" title="Direct link to Arkessa / ZARIOT / Transatel / Onomondo" translate="no">​</a></h3>
<p><strong>eUICC / multi-IMSI</strong> solutions that allow switching between carriers based on coverage, with a unified core network—ideal for deployments <strong>across multiple countries</strong> and for avoiding vendor lock-in.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="multi-carrier-sims-the-solution-for-critical-industries">Multi-carrier SIMs: The Solution for Critical Industries<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#multi-carrier-sims-the-solution-for-critical-industries" class="hash-link" aria-label="Direct link to Multi-carrier SIMs: The Solution for Critical Industries" title="Direct link to Multi-carrier SIMs: The Solution for Critical Industries" translate="no">​</a></h2>
<p>A <strong>multi-carrier SIM</strong> (multi-IMSI / eUICC) is a card capable of automatically connecting to the carrier with the best signal at each location and <strong>switching back</strong> in the event of a network outage.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-it-works">How It Works<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#how-it-works" class="hash-link" aria-label="Direct link to How It Works" title="Direct link to How It Works" translate="no">​</a></h3>
<!-- -->
<small><em>Typical bands: Orange B20 (800 MHz) in rural areas, SFR B3 (1800 MHz) in urban areas, and Bouygues B28 (700 MHz) as a supplement. Selection is based on the RSRP/RSRQ measured on-site.</em></small>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="benefits-of-a-multi-carrier-sim-card">Benefits of a Multi-Carrier SIM Card<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#benefits-of-a-multi-carrier-sim-card" class="hash-link" aria-label="Direct link to Benefits of a Multi-Carrier SIM Card" title="Direct link to Benefits of a Multi-Carrier SIM Card" translate="no">​</a></h3>
<table><thead><tr><th>Criterion</th><th>Single-carrier SIM</th><th>Multi-carrier SIM</th></tr></thead><tbody><tr><td>National coverage</td><td>Operator-dependent</td><td>Best of the 3 networks</td></tr><tr><td>Operator dead zone</td><td>Outage</td><td>Automatic failover</td></tr><tr><td>Operator network outage</td><td>Total outage</td><td>Fallback to another network</td></tr><tr><td>Overall resilience</td><td>Low</td><td>High</td></tr><tr><td>Cost</td><td>Low</td><td>Slightly higher (+10–20%)</td></tr><tr><td>Management</td><td>1 contract</td><td>1 multi-operator contract</td></tr><tr><td>EU Roaming</td><td>Variable / optional</td><td>Often included</td></tr><tr><td>“Blind” deployment</td><td>Risky (coverage must be verified site by site)</td><td>Secure (the best network is selected on-site)</td></tr></tbody></table>
<p><strong>Ideal use cases:</strong> pumping stations, wind and solar farms, agricultural sites, multi-site remote meter reading, moving vehicles, multi-country deployments, and <strong>any site where checking carrier coverage on a carrier-by-carrier basis before installation would be too costly</strong>.</p>
<blockquote>
<p>“Crozon” Reminder: For true redundancy, the failover must include <strong>Orange</strong> (an independent network) and not just SFR and Bouygues, which share their network in sparsely populated areas.</p>
</blockquote>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-eziwan-sim-card">The Eziwan SIM Card<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#the-eziwan-sim-card" class="hash-link" aria-label="Direct link to The Eziwan SIM Card" title="Direct link to The Eziwan SIM Card" translate="no">​</a></h3>
<p>The <strong>Eziwan SIM</strong> is a multi-carrier M2M SIM included in our plans:</p>
<ul>
<li class="">Automatic switching between <strong>Orange / SFR / Bouygues</strong> based on the best coverage</li>
<li class="">Secure <strong>private APN</strong> (encrypted traffic between the gateway and the Eziwan cloud, data center in France)</li>
<li class="">Monitoring dashboard: <strong>RSRP, RSRQ, data usage</strong> in real time</li>
<li class="">Unified billing: a single contract for the entire fleet</li>
<li class=""><strong>No minimum volume commitment</strong>: order from 1 to 1,000 SIM cards</li>
<li class=""><strong>LTE-M</strong> and 4G compatible: designed to transition through the phase-out of 2G/3G without disruption</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="private-apn-why-its-essential-in-industry">Private APN: Why It's Essential in Industry<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#private-apn-why-its-essential-in-industry" class="hash-link" aria-label="Direct link to Private APN: Why It's Essential in Industry" title="Direct link to Private APN: Why It's Essential in Industry" translate="no">​</a></h2>
<p>The <strong>private APN</strong> (Access Point Name) creates a dedicated virtual network between your SIM cards and your cloud infrastructure, without going through the public internet.</p>
<!-- -->
<small><em>Traffic never passes through the public internet: a dedicated tunnel between the SIM and the data center; a static IP address is available per SIM.</em></small>
<p><strong>Advantages of a private VPN:</strong></p>
<ul>
<li class="">Traffic is never exposed to the public Internet (reduced attack surface)</li>
<li class=""><strong>Fixed IP addressing</strong> possible (same IP per SIM, simplifies remote access)</li>
<li class="">Complete network isolation from the operator’s other customers</li>
<li class="">A key component for <strong>NIS2</strong> compliance for critical and important entities</li>
</ul>
<p><strong>Public APN vs. Private APN:</strong></p>
<table><thead><tr><th></th><th>Public APN</th><th>Private APN</th></tr></thead><tbody><tr><td>Internet exposure</td><td>Yes</td><td>No (dedicated tunnel)</td></tr><tr><td>Fixed IP</td><td>Rare</td><td>Possible</td></tr><tr><td>Client Isolation</td><td>No</td><td>Yes</td></tr><tr><td>NIS2 Compliance</td><td>Insufficient on its own</td><td>Recommended</td></tr><tr><td>Additional Cost</td><td>—</td><td>~+1–3 €/SIM/month</td></tr></tbody></table>
<p><strong>Availability:</strong> Orange, SFR, and Bouygues all offer private APNs; the Eziwan SIM includes one by default.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="typical-data-usage-by-use-case">Typical Data Usage by Use Case<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#typical-data-usage-by-use-case" class="hash-link" aria-label="Direct link to Typical Data Usage by Use Case" title="Direct link to Typical Data Usage by Use Case" translate="no">​</a></h2>
<p>Choosing a plan that’s just the right size helps you avoid overpaying (or running out of data). Observed ranges:</p>
<table><thead><tr><th>Use Case</th><th>Variables</th><th>Polling</th><th>Monthly Usage</th></tr></thead><tbody><tr><td>Remote meter reading</td><td>3–5</td><td>15 min</td><td>1–5 MB</td></tr><tr><td>Pumping station (M340 PLC)</td><td>10–20</td><td>30 s</td><td>10–50 MB</td></tr><tr><td>Energy monitoring</td><td>20–50</td><td>10 s</td><td>50–200 MB</td></tr><tr><td>Multi-device SCADA</td><td>100–500</td><td>1 s</td><td>200–500 MB</td></tr><tr><td>720p video surveillance</td><td>—</td><td>Continuous</td><td>3–10 GB</td></tr><tr><td>VPN remote access (idle)</td><td>—</td><td>—</td><td>5–20 MB (keepalive)</td></tr><tr><td>VPN remote access (30-min session)</td><td>—</td><td>—</td><td>50–500 MB depending on activity</td></tr></tbody></table>
<p><strong>Optimization through edge computing:</strong> A gateway that filters data locally (dead band, aggregation, compression) before transmission reduces 4G data usage by <strong>70 to 95%</strong>. An M340 site with 30 variables can go from ~150 MB/month to <strong>15–25 MB/month</strong> — which, across 500 sites, means switching from a “200 MB” plan to a “50 MB” plan and achieving substantial savings across the entire fleet.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="international-roaming-things-to-watch-out-for">International Roaming: Things to Watch Out For<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#international-roaming-things-to-watch-out-for" class="hash-link" aria-label="Direct link to International Roaming: Things to Watch Out For" title="Direct link to International Roaming: Things to Watch Out For" translate="no">​</a></h2>
<p>For equipment deployed outside of France:</p>
<p><strong>European Union:</strong> Please note that M2M plans <strong>do not automatically</strong> qualify for the “Roam Like Home” benefit, which is reserved for consumer plans. M2M roaming is subject to specific contractual terms: always check your carrier’s M2M terms and conditions (data allowances, permitted duration of permanent roaming, and restrictions on “permanent roaming”).</p>
<p><strong>Outside the EU:</strong> Charges per MB can be very high (in the range of +0.5 to 2 €/MB). For international deployment, opt for a <strong>local SIM</strong> or a <strong>global multi-IMSI SIM</strong> (Eziwan, Tele2 IoT, Onomondo) that negotiates network access on a country-by-country basis.</p>
<p><strong>Permanent roaming:</strong> Some countries (and some host operators) restrict or prohibit permanent roaming for fixed devices. A sustainable deployment abroad must rely on a <strong>multi-IMSI</strong> plan or a local SIM card, not on “tolerated” roaming.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="summary-comparison-table">Summary Comparison Table<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#summary-comparison-table" class="hash-link" aria-label="Direct link to Summary Comparison Table" title="Direct link to Summary Comparison Table" translate="no">​</a></h2>
<table><thead><tr><th>Criterion</th><th>Orange</th><th>SFR</th><th>Bouygues</th><th>1NCE</th><th>SIM Eziwan</th></tr></thead><tbody><tr><td>Coverage in France</td><td>★★★★★</td><td>★★★★</td><td>★★★★</td><td>★★★★ (via partners)</td><td>★★★★★</td></tr><tr><td>Price</td><td>★★★</td><td>★★★★</td><td>★★★★★</td><td>★★★★★ (low data usage)</td><td>★★★★</td></tr><tr><td>Private APN</td><td>✅</td><td>✅</td><td>✅</td><td>❌</td><td>✅ included</td></tr><tr><td>Multi-carrier</td><td>❌</td><td>❌</td><td>❌</td><td>❌ (single carrier via partner)</td><td>✅</td></tr><tr><td>LTE-M / NB-IoT</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td></tr><tr><td>eSIM / eUICC</td><td>✅</td><td>✅</td><td>Partial</td><td>✅</td><td>✅</td></tr><tr><td>Fleet dashboard</td><td>✅</td><td>✅</td><td>✅</td><td>✅</td><td>✅ integrated</td></tr><tr><td>Fixed IP</td><td>✅ optional</td><td>✅ optional</td><td>✅ optional</td><td>❌</td><td>✅ optional</td></tr><tr><td>EU M2M roaming</td><td>✅ optional</td><td>✅ optional</td><td>✅ optional</td><td>✅ 170+ countries</td><td>✅ included</td></tr><tr><td>Min. order</td><td>≈100 SIMs</td><td>≈50 SIMs</td><td>≈50 SIMs</td><td>1 SIM</td><td>1 SIM</td></tr><tr><td>Contract term</td><td>24–36 months</td><td>12–24 months</td><td>12–24 months</td><td>None (one-time purchase)</td><td>No contract</td></tr><tr><td>Dedicated IoT support in French</td><td>✅</td><td>✅</td><td>✅</td><td>Premium</td><td>✅</td></tr></tbody></table>
<p>★ = Eziwan's estimated rating; adjust based on your geographic location and volume.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-to-choose-a-quick-decision-tree">How to Choose: A Quick Decision Tree<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#how-to-choose-a-quick-decision-tree" class="hash-link" aria-label="Direct link to How to Choose: A Quick Decision Tree" title="Direct link to How to Choose: A Quick Decision Tree" translate="no">​</a></h2>
<ul>
<li class=""><strong>Simple sensors, very low power consumption, fixed budget over 10 years</strong> → 1NCE or an operator’s LTE-M offering.</li>
<li class=""><strong>Multi-site national park, rural areas, high criticality</strong> → <strong>Multi-carrier SIM</strong> (Eziwan) with private APN.</li>
<li class=""><strong>Large urban volumes, cost optimization</strong> → Bouygues or SFR (pooling).</li>
<li class=""><strong>Overseas territories, maximum coverage required</strong> → Orange.</li>
<li class=""><strong>International/multi-country deployment</strong> → Global multi-IMSI SIM (Eziwan, Tele2 IoT, Onomondo).</li>
<li class=""><strong>Video / frequent remote access</strong> → Generous data plan from a single operator or multi-operator provider; definitely not a capped “lifetime” SIM.</li>
</ul>
<p>In any case: <strong>at least 4G/LTE-M modules</strong> (never 2G/3G alone) and <strong>a private APN</strong> whenever the data is sensitive.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq--industrial-iot-m2m-sim">FAQ — Industrial IoT M2M SIM<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#faq--industrial-iot-m2m-sim" class="hash-link" aria-label="Direct link to FAQ — Industrial IoT M2M SIM" title="Direct link to FAQ — Industrial IoT M2M SIM" translate="no">​</a></h2>
<p><strong>Can I use a consumer SIM card in an IoT gateway?</strong>
Technically, yes, but it’s not recommended. Consumer SIM cards support a limited temperature range (0–40 °C), have a shorter lifespan, and do not offer a private APN, fleet monitoring, or an industrial SLA. For a fleet deployed in the field, the additional cost of an M2M SIM is more than offset by the reliability and centralized management it provides.</p>
<p><strong>Will my 2G or 3G devices continue to work?</strong>
No, eventually. Orange is shutting down its 2G network between September 22 and October 20, 2026; other carriers will follow suit, and 3G will be phased out around 2028. Any <strong>2G-only</strong> module will be out of service as of fall 2026; a 2G/3G module without 4G fallback will be out of service around 2028. For any new project, insist on <strong>4G / LTE-M / NB-IoT</strong> hardware.</p>
<p><strong>What is the minimum data usage of an M2M SIM in standby mode?</strong>
Without business traffic, an M2M SIM only consumes data for network maintenance signals (keep-alive, heartbeat): depending on the carrier and configuration, 1–10 MB/month. With a private APN and a VPN tunnel (OpenVPN/IPSec) maintained continuously, expect 5–15 MB/month in keep-alive traffic, excluding application data.</p>
<p><strong>Can you switch carriers without having to reconfigure everything?</strong>
With an <strong>eUICC</strong> (eSIM), yes: the carrier profile is reconfigured remotely, without any on-site intervention. With a standard physical single-carrier SIM, you have to physically replace the card. Eziwan’s <strong>multi-carrier SIM</strong> eliminates this problem: a single SIM automatically manages all three French networks.</p>
<p><strong>What is the difference between LTE-M and NB-IoT?</strong>
LTE-M offers higher data rates, low latency, and supports <strong>mobility</strong> (moving objects, voice capable)—making it suitable for asset tracking and real-time telemetry. NB-IoT is designed for <strong>very low-power, stationary</strong> devices (such as underground meters), offering excellent signal penetration but lower data rates and higher latency. Both technologies will survive the phase-out of 2G/3G.</p>
<p><strong>Do M2M SIM cards comply with French regulations?</strong>
Yes. M2M plans offered by French carriers are regulated by ARCEP. IoT data SIM cards do not require end-user identification (no ID required), except for plans that include voice calls or outgoing text messages to consumer numbers.</p>
<p><strong>How do you manage 500 SIM cards spread across 500 locations?</strong>
Through a <strong>fleet management portal</strong>: real-time data usage per SIM, detection of inactive or over-consuming SIMs, remote activation/deactivation, signal monitoring (RSRP/RSRQ), and threshold alerts. The Eziwan portal integrates this management <strong>into the same dashboard</strong> as your equipment monitoring, eliminating the need to switch between multiple interfaces.</p>
<p><strong>Is a multi-carrier SIM much more expensive?</strong>
Generally 10% to 20% more than an equivalent single-carrier SIM. For a critical site, this additional cost is negligible compared to the cost of an outage or a technical visit caused by a coverage gap that wasn’t properly anticipated.</p>
<hr>
<p><em>For a personalized recommendation based on your network and geographic areas, <a class="" href="https://eziwan.com/en/contact">contact our team</a> — we’ll perform a <strong>free coverage analysis</strong> of your sites, operator by operator.</em></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/failover-critical-connectivity">Blog: Dual-SIM LTE Failover — Securing Critical Connectivity</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/monitoring-rsrp-rsrq-industrial-4g-signal">Blog: Industrial 4G RSRP/RSRQ Monitoring — Interpreting LTE Metrics</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/industrial-lte-router">Blog: Industrial 4G LTE Router — Migrating from ADSL Before the End of Copper</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/5g-private-network-factory">Blog: 5G private network — use cases and ROI for the factory</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/dual-sim-industrial-4g-carrier-comparison">Blog: Industrial dual-SIM operator comparison</a></li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/industrial-connectivity">Industrial Connectivity</a> — 4G LTE and M2M connectivity solutions for industry</li>
<li class=""><a class="" href="https://eziwan.com/en/connectivite">Eziwan Connectivity</a> — M2M SIM plans and managed connectivity for industrial IoT</li>
<li class=""><a class="" href="https://eziwan.com/en/internet-connection-remote-industrial-site">Internet Connection for Remote Industrial Sites</a> — Connect a site without fixed infrastructure via 4G/LTE</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-solutions">Eziwan Industrial Solutions</a> — comprehensive range of industrial monitoring and connectivity solutions</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-iot-gateway">Industrial IoT Gateways</a> — multi-carrier IoT gateways with integrated SIM management</li>
</ul>]]></content:encoded>
            <category>connectivity</category>
            <category>industrial-iot</category>
            <category>sim-m2m</category>
            <category>4g</category>
            <category>operators</category>
            <category>iiot</category>
        </item>
        <item>
            <title><![CDATA[Grafana for Industrial IoT Monitoring: Modbus Dashboard, Alerts, History]]></title>
            <link>https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus</link>
            <guid>https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus</guid>
            <pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Comprehensive Grafana Guide for Industrial Monitoring: Connect Modbus/IoT Data, Create Production Dashboards, Configure SMS/Email Alerts, and Store 5 Years of Historical Data. Dashboard Examples.]]></description>
            <content:encoded><![CDATA[<p><strong>Grafana</strong> has become the go-to tool for industrial data visualization. Free, open-source, and extensible, it transforms your Modbus, OPC-UA, or MQTT data into operational dashboards. This guide shows you how to design a comprehensive industrial monitoring system with Grafana—or how Eziwan can provide it to you as a turnkey solution.</p>
<div class="tableOfContentsInline_prmo"><ul class="table-of-contents"><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#why-use-grafana-for-industrial-monitoring">Why Use Grafana for Industrial Monitoring?</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#architecture-from-modbus-to-grafana">Architecture: From Modbus to Grafana</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#install-grafana--influxdb-with-docker">Install Grafana + InfluxDB with Docker</a><ul><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#configuring-telegraf-for-mqtt">Configuring Telegraf for MQTT</a></li></ul></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#create-your-first-industrial-dashboard">Create Your First Industrial Dashboard</a><ul><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#panel-1-trend-chart-time-series">Panel 1: Trend Chart (Time Series)</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#panel-2-gauge-instantaneous-value">Panel 2: Gauge (Instantaneous Value)</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#panel-3-metrics-kpis">Panel 3: Metrics (KPIs)</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#panel-4-multi-site-table">Panel 4: Multi-site Table</a></li></ul></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#configure-grafana-alerts">Configure Grafana Alerts</a><ul><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#threshold-exceeded-alert">Threshold Exceeded Alert</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#alert-grouping-for-multi-site-environments">Alert Grouping for Multi-Site Environments</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#event-annotation">Event Annotation</a></li></ul></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#grafana-templates-and-variables-for-multi-site-setups">Grafana Templates and Variables for Multi-Site Setups</a><ul><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#create-a-site-variable">Create a "site" variable</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#using-the-variable-in-panels">Using the variable in panels</a></li></ul></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#preconfigured-grafana-dashboards-for-industry">Preconfigured Grafana Dashboards for Industry</a><ul><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#pumping-station-monitoring-dashboard">Pumping Station Monitoring Dashboard</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#multi-site-production-dashboard">Multi-Site Production Dashboard</a></li></ul></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#eziwan--grafana-integration">Eziwan → Grafana Integration</a><ul><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#mode-1-grafana-hosted-on-eziwan-recommended">Mode 1: Grafana hosted on Eziwan (recommended)</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#mode-2-export-to-your-existing-grafana-instance">Mode 2: Export to Your Existing Grafana Instance</a></li></ul></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#faq--grafana-for-industrial-monitoring">FAQ — Grafana for Industrial Monitoring</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#further-reading">Further Reading</a></li><li><a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#additional-resources">Additional Resources</a></li></ul></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="why-use-grafana-for-industrial-monitoring">Why Use Grafana for Industrial Monitoring?<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#why-use-grafana-for-industrial-monitoring" class="hash-link" aria-label="Direct link to Why Use Grafana for Industrial Monitoring?" title="Direct link to Why Use Grafana for Industrial Monitoring?" translate="no">​</a></h2>
<p>Grafana has established itself in the industry for several reasons:</p>
<ul>
<li class=""><strong>Universal connectors</strong>: InfluxDB, TimescaleDB, PostgreSQL, Prometheus, MQTT, REST API — a data source for every stack</li>
<li class=""><strong>Rich dashboards</strong>: time series, gauge, stat, table, heatmap, flow chart (with plugins)</li>
<li class=""><strong>Built-in alerts</strong>: SMS, email, Slack, PagerDuty, and webhook notifications</li>
<li class=""><strong>Access management</strong>: teams, folders, and permissions per dashboard</li>
<li class=""><strong>Industry-specific plugins</strong>: P&amp;ID (flowcharting), piping diagrams, and schematic diagrams</li>
</ul>
<p><strong>Compared to a traditional SCADA system:</strong></p>
<table><thead><tr><th></th><th>Grafana (+ IoT stack)</th><th>Wonderware/Ignition SCADA</th></tr></thead><tbody><tr><td>License cost</td><td>0 (open source)</td><td>5,000–50,000€</td></tr><tr><td>Hosting cost</td><td>50–200€/month (cloud)</td><td>Dedicated server + maintenance</td></tr><tr><td>Unlimited variables</td><td>✅</td><td>❌ (billed per tag)</td></tr><tr><td>Native web interface</td><td>✅</td><td>✅ (Ignition) / ❌ (Wonderware)</td></tr><tr><td>Mobile-ready</td><td>✅</td><td>Partially</td></tr><tr><td>Cloud integration</td><td>Native</td><td>Complex</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="architecture-from-modbus-to-grafana">Architecture: From Modbus to Grafana<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#architecture-from-modbus-to-grafana" class="hash-link" aria-label="Direct link to Architecture: From Modbus to Grafana" title="Direct link to Architecture: From Modbus to Grafana" translate="no">​</a></h2>
<p>The complete stack for monitoring Modbus PLCs in Grafana:</p>
<!-- -->
<p><strong>Alternative for large volumes:</strong></p>
<!-- -->
<p><strong>Eziwan Solution (all-in-one):</strong></p>
<p>Eziwan includes the complete stack (Modbus/OPC-UA data collection, cloud time series, preconfigured Grafana dashboards, SMS/email alerts) without requiring you to install and maintain the components individually.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="install-grafana--influxdb-with-docker">Install Grafana + InfluxDB with Docker<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#install-grafana--influxdb-with-docker" class="hash-link" aria-label="Direct link to Install Grafana + InfluxDB with Docker" title="Direct link to Install Grafana + InfluxDB with Docker" translate="no">​</a></h2>
<div class="language-yaml codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-yaml codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token comment" style="color:#999988;font-style:italic"># docker-compose.yml</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token key atrule" style="color:#00a4db">version</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">'3.8'</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token key atrule" style="color:#00a4db">services</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token key atrule" style="color:#00a4db">influxdb</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">image</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> influxdb</span><span class="token punctuation" style="color:#393A34">:</span><span class="token number" style="color:#36acaa">2.7</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">ports</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token punctuation" style="color:#393A34">-</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"8086:8086"</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">environment</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token key atrule" style="color:#00a4db">DOCKER_INFLUXDB_INIT_MODE</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> setup</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token key atrule" style="color:#00a4db">DOCKER_INFLUXDB_INIT_USERNAME</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> admin</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token key atrule" style="color:#00a4db">DOCKER_INFLUXDB_INIT_PASSWORD</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> mot_de_passe_securise</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token key atrule" style="color:#00a4db">DOCKER_INFLUXDB_INIT_ORG</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> eziwan</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token key atrule" style="color:#00a4db">DOCKER_INFLUXDB_INIT_BUCKET</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> industrie</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token key atrule" style="color:#00a4db">DOCKER_INFLUXDB_INIT_RETENTION</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> 1825d  </span><span class="token comment" style="color:#999988;font-style:italic"># 5 ans</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">volumes</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token punctuation" style="color:#393A34">-</span><span class="token plain"> influxdb_data</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain">/var/lib/influxdb2</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token key atrule" style="color:#00a4db">grafana</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">image</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> grafana/grafana</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain">10.4.0</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">ports</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token punctuation" style="color:#393A34">-</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"3000:3000"</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">environment</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token key atrule" style="color:#00a4db">GF_SECURITY_ADMIN_PASSWORD</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> grafana_securise</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">volumes</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token punctuation" style="color:#393A34">-</span><span class="token plain"> grafana_data</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain">/var/lib/grafana</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">depends_on</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token punctuation" style="color:#393A34">-</span><span class="token plain"> influxdb</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token key atrule" style="color:#00a4db">telegraf</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">image</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> telegraf</span><span class="token punctuation" style="color:#393A34">:</span><span class="token number" style="color:#36acaa">1.29</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">volumes</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token punctuation" style="color:#393A34">-</span><span class="token plain"> ./telegraf.conf</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain">/etc/telegraf/telegraf.conf</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain">ro</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">depends_on</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token punctuation" style="color:#393A34">-</span><span class="token plain"> influxdb</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token key atrule" style="color:#00a4db">volumes</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token key atrule" style="color:#00a4db">influxdb_data</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  grafana_data</span><span class="token punctuation" style="color:#393A34">:</span><br></div></code></pre></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="configuring-telegraf-for-mqtt">Configuring Telegraf for MQTT<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#configuring-telegraf-for-mqtt" class="hash-link" aria-label="Direct link to Configuring Telegraf for MQTT" title="Direct link to Configuring Telegraf for MQTT" translate="no">​</a></h3>
<div class="language-toml codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-toml codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain"># telegraf.conf</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">[[inputs.mqtt_consumer]]</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  servers = ["tcp://localhost:1883"]</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  topics = ["usine/#"]</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  qos = 1</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  data_format = "json"</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  # Parsing the MQTT topic: factory/site/station/variable</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  [[inputs.mqtt_consumer.topic_parsing]]</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    topic = "usine/+/+/+"</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    tags = "_/_/station/_"</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    fields = "_/_/_/value"</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">[[outputs.influxdb_v2]]</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  urls = ["http://influxdb:8086"]</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  token = "votre_token_influxdb"</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  organization = "eziwan"</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  bucket = "industrie"</span><br></div></code></pre></div></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="create-your-first-industrial-dashboard">Create Your First Industrial Dashboard<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#create-your-first-industrial-dashboard" class="hash-link" aria-label="Direct link to Create Your First Industrial Dashboard" title="Direct link to Create Your First Industrial Dashboard" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="panel-1-trend-chart-time-series">Panel 1: Trend Chart (Time Series)<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#panel-1-trend-chart-time-series" class="hash-link" aria-label="Direct link to Panel 1: Trend Chart (Time Series)" title="Direct link to Panel 1: Trend Chart (Time Series)" translate="no">​</a></h3>
<p>To view the pressure trends for a station over time:</p>
<p><strong>InfluxDB (Flux) Query:</strong></p>
<div class="language-flux codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-flux codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">from(bucket: "industrie")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; range(start: v.timeRangeStart, stop: v.timeRangeStop)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; filter(fn: (r) =&gt; r["_measurement"] == "mqtt_consumer")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; filter(fn: (r) =&gt; r["station"] == "station1")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; filter(fn: (r) =&gt; r["_field"] == "pression")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; aggregateWindow(every: v.windowPeriod, fn: mean, createEmpty: false)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; yield(name: "mean")</span><br></div></code></pre></div></div>
<p><strong>Panel settings:</strong></p>
<ul>
<li class="">Type: <code>Time series</code></li>
<li class="">Y-axis unit: <code>bar</code> (Pressure)</li>
<li class="">Line width: 2</li>
<li class="">Fill opacity: 10</li>
<li class="">Thresholds: green &lt; 8 bar, orange 8–10 bar, red &gt; 10 bar</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="panel-2-gauge-instantaneous-value">Panel 2: Gauge (Instantaneous Value)<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#panel-2-gauge-instantaneous-value" class="hash-link" aria-label="Direct link to Panel 2: Gauge (Instantaneous Value)" title="Direct link to Panel 2: Gauge (Instantaneous Value)" translate="no">​</a></h3>
<p>To display the current value of a variable:</p>
<p><strong>InfluxDB Query:</strong></p>
<div class="language-flux codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-flux codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">from(bucket: "industrie")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; range(start: -1m)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; filter(fn: (r) =&gt; r["station"] == "station1" and r["_field"] == "pression")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; last()</span><br></div></code></pre></div></div>
<p><strong>Panel settings:</strong></p>
<ul>
<li class="">Type: <code>Gauge</code></li>
<li class="">Min: 0, Max: 16</li>
<li class="">Unit: <code>bar</code></li>
<li class="">Thresholds: 0=green, 10=orange, 12=red</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="panel-3-metrics-kpis">Panel 3: Metrics (KPIs)<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#panel-3-metrics-kpis" class="hash-link" aria-label="Direct link to Panel 3: Metrics (KPIs)" title="Direct link to Panel 3: Metrics (KPIs)" translate="no">​</a></h3>
<p>To view the OEE or a production counter:</p>
<p><strong>InfluxDB Query:</strong></p>
<div class="language-flux codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-flux codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">from(bucket: "industrie")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; range(start: -24h)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; filter(fn: (r) =&gt; r["_field"] == "pieces_produites")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; sum()</span><br></div></code></pre></div></div>
<p><strong>Panel settings:</strong></p>
<ul>
<li class="">Type: <code>Stat</code></li>
<li class="">Unit: <code>pcs</code> (custom)</li>
<li class="">Color mode: <code>Background</code> (red if &lt; target)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="panel-4-multi-site-table">Panel 4: Multi-site Table<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#panel-4-multi-site-table" class="hash-link" aria-label="Direct link to Panel 4: Multi-site Table" title="Direct link to Panel 4: Multi-site Table" translate="no">​</a></h3>
<p>To view the status of all your sites in real time:</p>
<div class="language-flux codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-flux codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">from(bucket: "industrie")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; range(start: -5m)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; filter(fn: (r) =&gt; r["_field"] == "pression" or r["_field"] == "debit" or r["_field"] == "etat")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; last()</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; pivot(rowKey: ["_time", "station"], columnKey: ["_field"], valueColumn: "_value")</span><br></div></code></pre></div></div>
<p><strong>Result:</strong> a table with columns for Station, Pressure, Flow Rate, and Status, with one row per site.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="configure-grafana-alerts">Configure Grafana Alerts<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#configure-grafana-alerts" class="hash-link" aria-label="Direct link to Configure Grafana Alerts" title="Direct link to Configure Grafana Alerts" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="threshold-exceeded-alert">Threshold Exceeded Alert<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#threshold-exceeded-alert" class="hash-link" aria-label="Direct link to Threshold Exceeded Alert" title="Direct link to Threshold Exceeded Alert" translate="no">​</a></h3>
<p>In Grafana 10+ (Unified Alerting):</p>
<ol>
<li class="">Open the panel → <code>Edit → Alert</code></li>
<li class="">Create a rule:<!-- -->
<div class="language-text codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">Condition: WHEN last() OF query(A, 5m, now) IS ABOVE 10</span><br></div></code></pre></div></div>
</li>
<li class="">Configure the notification:<!-- -->
<ul>
<li class="">Contact Point: Email → <code>maintenance@usine.fr</code></li>
<li class="">Contact Point: Webhook → SMS via Twilio/OVH SMS</li>
</ul>
</li>
<li class="">Auto-mute: 15 minutes after acknowledgment</li>
</ol>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="alert-grouping-for-multi-site-environments">Alert Grouping for Multi-Site Environments<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#alert-grouping-for-multi-site-environments" class="hash-link" aria-label="Direct link to Alert Grouping for Multi-Site Environments" title="Direct link to Alert Grouping for Multi-Site Environments" translate="no">​</a></h3>
<p>To avoid "alert storms" when multiple sites go down at the same time:</p>
<div class="language-yaml codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-yaml codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token comment" style="color:#999988;font-style:italic"># alertmanager.yml</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token key atrule" style="color:#00a4db">route</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token key atrule" style="color:#00a4db">group_by</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">[</span><span class="token string" style="color:#e3116c">'alertname'</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">'site'</span><span class="token punctuation" style="color:#393A34">]</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token key atrule" style="color:#00a4db">group_wait</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> 30s</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token key atrule" style="color:#00a4db">group_interval</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> 5m</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token key atrule" style="color:#00a4db">repeat_interval</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> 3h</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token key atrule" style="color:#00a4db">receiver</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">'maintenance-team'</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token key atrule" style="color:#00a4db">receivers</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token punctuation" style="color:#393A34">-</span><span class="token plain"> </span><span class="token key atrule" style="color:#00a4db">name</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">'maintenance-team'</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">email_configs</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token punctuation" style="color:#393A34">-</span><span class="token plain"> </span><span class="token key atrule" style="color:#00a4db">to</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">'maintenance@usine.fr'</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token key atrule" style="color:#00a4db">send_resolved</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> </span><span class="token boolean important" style="color:#36acaa">true</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token key atrule" style="color:#00a4db">webhook_configs</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">      </span><span class="token punctuation" style="color:#393A34">-</span><span class="token plain"> </span><span class="token key atrule" style="color:#00a4db">url</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">'https://api.sms-provider.fr/send'</span><br></div></code></pre></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="event-annotation">Event Annotation<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#event-annotation" class="hash-link" aria-label="Direct link to Event Annotation" title="Direct link to Event Annotation" translate="no">​</a></h3>
<p>Add automatic annotations to graphs when alarms occur:</p>
<div class="language-flux codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-flux codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">// Create an InfluxDB annotation when a failure occurs</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">from(bucket: "industrie")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; range(start: v.timeRangeStart)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; filter(fn: (r) =&gt; r["_field"] == "defaut" and r["_value"] == 1)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; map(fn: (r) =&gt; ({r with _value: "Défaut détecté sur ${r.station}"}))</span><br></div></code></pre></div></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="grafana-templates-and-variables-for-multi-site-setups">Grafana Templates and Variables for Multi-Site Setups<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#grafana-templates-and-variables-for-multi-site-setups" class="hash-link" aria-label="Direct link to Grafana Templates and Variables for Multi-Site Setups" title="Direct link to Grafana Templates and Variables for Multi-Site Setups" translate="no">​</a></h2>
<p><strong>Template Variables</strong> let you create a generic dashboard that can be reused across all your sites.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="create-a-site-variable">Create a "site" variable<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#create-a-site-variable" class="hash-link" aria-label="Direct link to Create a &quot;site&quot; variable" title="Direct link to Create a &quot;site&quot; variable" translate="no">​</a></h3>
<p><code>Dashboard Settings → Variables → New Variable</code>:</p>
<ul>
<li class="">Name: <code>site</code></li>
<li class="">Type: <code>Query</code></li>
<li class="">Data Source: InfluxDB</li>
<li class="">Query:<!-- -->
<div class="language-flux codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-flux codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">import "influxdata/influxdb/schema"</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">schema.tagValues(bucket: "industrie", tag: "station")</span><br></div></code></pre></div></div>
</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="using-the-variable-in-panels">Using the variable in panels<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#using-the-variable-in-panels" class="hash-link" aria-label="Direct link to Using the variable in panels" title="Direct link to Using the variable in panels" translate="no">​</a></h3>
<div class="language-flux codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-flux codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">from(bucket: "industrie")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; range(start: v.timeRangeStart)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; filter(fn: (r) =&gt; r["station"] == "${site}")</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  |&gt; filter(fn: (r) =&gt; r["_field"] == "pression")</span><br></div></code></pre></div></div>
<p>The operator can now select the site from a drop-down menu at the top of the dashboard.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="preconfigured-grafana-dashboards-for-industry">Preconfigured Grafana Dashboards for Industry<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#preconfigured-grafana-dashboards-for-industry" class="hash-link" aria-label="Direct link to Preconfigured Grafana Dashboards for Industry" title="Direct link to Preconfigured Grafana Dashboards for Industry" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="pumping-station-monitoring-dashboard">Pumping Station Monitoring Dashboard<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#pumping-station-monitoring-dashboard" class="hash-link" aria-label="Direct link to Pumping Station Monitoring Dashboard" title="Direct link to Pumping Station Monitoring Dashboard" translate="no">​</a></h3>
<div class="language-text codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">┌─────────────────────────────────────────────────────────────────┐</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│  Station: [dropdown]  │  Period: [6h|24h|7d|30d] │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">├──────────────┬──────────────┬──────────────┬────────────────────┤</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│  Pressure    │   Flow Rate │  Level │  Pump Status │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│  [gauge]     │   [gauge]    │  [gauge]     │  [stat 🟢/🔴]      │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">├──────────────┴──────────────┴──────────────┴────────────────────┤</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│  24-Hour Trends: Pressure / Flow / Level │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│  [time series graph]                                             │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">├─────────────────────────────────────────────────────────────────┤</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│  Active Alarms    │  Latest Actions │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│  [table]            │  [table annotations]                       │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">└─────────────────────────────────────────────────────────────────┘</span><br></div></code></pre></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="multi-site-production-dashboard">Multi-Site Production Dashboard<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#multi-site-production-dashboard" class="hash-link" aria-label="Direct link to Multi-Site Production Dashboard" title="Direct link to Multi-Site Production Dashboard" translate="no">​</a></h3>
<div class="language-text codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">┌────────────────────────────────────────────────────────────────────┐</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│  Vue globale — 15 sites                                            │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">├──────────┬──────────┬──────────┬──────────┬──────────┬────────────┤</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│ Site 1   │ Site 2   │ Site 3   │ Site 4   │ Site 5   │ ...        │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│ TRS: 87% │ TRS: 91% │ TRS: 73% │ TRS: 94% │ TRS: 82% │            │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│ 🟢 OK    │ 🟢 OK    │ 🔴 Alrm  │ 🟢 OK    │ 🟡 Warn  │            │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">├──────────┴──────────┴──────────┴──────────┴──────────┴────────────┤</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│  24-Hour Cumulative Production: Target vs. Actual [bar chart] │</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">└────────────────────────────────────────────────────────────────────┘</span><br></div></code></pre></div></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="eziwan--grafana-integration">Eziwan → Grafana Integration<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#eziwan--grafana-integration" class="hash-link" aria-label="Direct link to Eziwan → Grafana Integration" title="Direct link to Eziwan → Grafana Integration" translate="no">​</a></h2>
<p>Eziwan offers two ways to integrate with Grafana:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="mode-1-grafana-hosted-on-eziwan-recommended">Mode 1: Grafana hosted on Eziwan (recommended)<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#mode-1-grafana-hosted-on-eziwan-recommended" class="hash-link" aria-label="Direct link to Mode 1: Grafana hosted on Eziwan (recommended)" title="Direct link to Mode 1: Grafana hosted on Eziwan (recommended)" translate="no">​</a></h3>
<p>The Eziwan platform <strong>natively integrates</strong> Grafana. Your Modbus/OPC-UA data is already stored in our time-series database hosted in France. You can access the dashboards directly from your browser, with:</p>
<ul>
<li class="">Preconfigured dashboards for common use cases (water, energy, production)</li>
<li class="">Managed SMS/email alerts</li>
<li class="">5 years of data archiving with no configuration required</li>
<li class="">Multi-site, multi-user, and access rights management</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="mode-2-export-to-your-existing-grafana-instance">Mode 2: Export to Your Existing Grafana Instance<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#mode-2-export-to-your-existing-grafana-instance" class="hash-link" aria-label="Direct link to Mode 2: Export to Your Existing Grafana Instance" title="Direct link to Mode 2: Export to Your Existing Grafana Instance" translate="no">​</a></h3>
<p>If you already have an internal Grafana instance:</p>
<ul>
<li class=""><strong>Eziwan REST API</strong>: Query your data via <code>GET /api/v1/variables/{id}/history</code></li>
<li class=""><strong>MQTT Webhook</strong>: Eziwan publishes your data to your existing MQTT broker</li>
<li class=""><strong>Eziwan Grafana Plugin</strong> (available upon request): plugin data source for direct connection</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq--grafana-for-industrial-monitoring">FAQ — Grafana for Industrial Monitoring<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#faq--grafana-for-industrial-monitoring" class="hash-link" aria-label="Direct link to FAQ — Grafana for Industrial Monitoring" title="Direct link to FAQ — Grafana for Industrial Monitoring" translate="no">​</a></h2>
<p><strong>Can Grafana replace a SCADA system in production?</strong>
For visualization and alerts, yes, in many cases. For real-time control (writing to a PLC, control sequences), a SCADA system or a dedicated HMI system is still recommended. Grafana excels at data archiving, trend analysis, and multi-site monitoring.</p>
<p><strong>Which database should you use to store industrial data in Grafana?</strong>
<strong>InfluxDB</strong> is the standard choice for industrial time series (high frequency, native compression, powerful Flux queries). <strong>TimescaleDB</strong> (a PostgreSQL extension) is a good fit if you already use PostgreSQL. <strong>Prometheus</strong> is well-suited for infrastructure metrics but less relevant for process data.</p>
<p><strong>How do I secure access to Grafana from the Internet?</strong>
Place Grafana behind a reverse proxy (Nginx/Traefik) with TLS, enable OIDC/LDAP authentication, disable anonymous access, and configure alerts for failed login attempts. Never expose InfluxDB directly to the Internet.</p>
<p><strong>Can Grafana handle 1,000 sites and 100,000 variables?</strong>
Yes, with the right architecture. InfluxDB 2.x supports billions of data points. Grafana Enterprise handles clustering. For very large volumes, consider using Apache Kafka upstream for streaming, along with differentiated retention policies (1-second data retained for 30 days, 1-minute data retained for 5 years).</p>
<p><strong>Can I display a P&amp;ID diagram in Grafana?</strong>
Yes, with the <strong>Flowcharting</strong> plugin (based on draw.io). You draw your P&amp;ID diagram, attach Grafana variables to each piece of equipment, and the values are displayed in real time on the diagram, with colors changing based on the status.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/predictive-maintenance-iot-field-sensors">Blog: IIoT Predictive Maintenance — From Sensor Data to Field Alerts</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide">Blog: Remote Industrial Monitoring — The Complete Guide 2026</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/modbus-tcp-vs-rtu">Blog: Modbus TCP vs. RTU — Which Protocol Should You Choose?</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/solar-farm-monitoring">Blog: Solar Farm — IoT Supervision and Monitoring</a></li>
<li class=""><a class="" href="https://eziwan.com/en/docs/integration/modbus">Docs: Modbus RTU Configuration on the Eziwan Gateway</a></li>
</ul>
<hr>
<p><em>Want Grafana dashboards without having to manage the infrastructure? <a class="" href="https://eziwan.com/en/contact">Try Eziwan free for 30 days</a> — get your Modbus data into Grafana in less than an hour.</em></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/modbus-rtu-cloud">Modbus RTU to the Cloud</a> — Connect your RS-485 Modbus RTU devices to the cloud</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-cloud-data-logger">Industrial Cloud Data Logger</a> — Archive your Modbus data in the cloud</li>
<li class=""><a class="" href="https://eziwan.com/en/scada-cloud">Cloud SCADA</a> — cloud-based SCADA platform with built-in dashboards</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-protocols">Industrial Protocols</a> — understanding Modbus, MQTT, OPC UA, and other protocols</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-remote-support">Industrial Monitoring and Remote Support</a> — multi-site monitoring of your Modbus devices</li>
</ul>]]></content:encoded>
            <category>grafana</category>
            <category>industrial-iot</category>
            <category>supervision</category>
            <category>modbus</category>
            <category>dashboard</category>
            <category>monitoring</category>
        </item>
        <item>
            <title><![CDATA[Comprehensive OPC-UA Guide for Industry: Architecture, Security, Implementation]]></title>
            <link>https://eziwan.com/en/blog/complete-opc-ua-guide-industry</link>
            <guid>https://eziwan.com/en/blog/complete-opc-ua-guide-industry</guid>
            <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[OPC-UA Expert Guide: information model, security (X.509 certificates, encryption), NodeId profiles, implementation with Python/Node.js, OPC-DA migration. For automation engineers.]]></description>
            <content:encoded><![CDATA[<p><strong>OPC-UA</strong> (OPC Unified Architecture) has become the standard protocol for interoperability in Industry 4.0. However, its apparent complexity still hinders many implementations. This practical guide demystifies OPC-UA: architecture, security, NodeId, Python/Node.js implementation, and cloud integration.</p>
<div class="tableOfContentsInline_prmo"><ul class="table-of-contents"><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#what-is-opc-ua-and-why-does-it-matter">What Is OPC-UA and Why Does It Matter?</a><ul><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#why-opc-ua-dominates-industry-40">Why OPC-UA Dominates Industry 4.0</a></li></ul></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-architecture-fundamental-concepts">OPC-UA Architecture: Fundamental Concepts</a><ul><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#client-server">Client-Server</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#address-space-and-nodeid">Address Space and NodeId</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#communication-methods">Communication Methods</a></li></ul></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-security-the-complete-guide">OPC-UA Security: The Complete Guide</a><ul><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#security-modes">Security Modes</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#x509-certificates">X.509 Certificates</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#user-authentication">User Authentication</a></li></ul></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#implementing-opc-ua-in-python">Implementing OPC-UA in Python</a><ul><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#installation">Installation</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#python-opc-ua-client--reading-data">Python OPC-UA Client — Reading Data</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-python-client--subscription">OPC-UA Python Client — Subscription</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#secure-connection-with-a-certificate">Secure connection with a certificate</a></li></ul></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#implementing-opc-ua-in-nodejs">Implementing OPC-UA in Node.js</a><ul><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#reading-data">Reading Data</a></li></ul></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-on-major-industrial-controllers">OPC-UA on Major Industrial Controllers</a><ul><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#siemens-s7-1500--s7-1200">Siemens S7-1500 / S7-1200</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#schneider-electric-m580--m340">Schneider Electric M580 / M340</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#allen-bradley--rockwell-ethernetip">Allen-Bradley / Rockwell (EtherNet/IP)</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#beckhoff-twincat-3">Beckhoff TwinCAT 3</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#wago--phoenix-contact--pilz">Wago / Phoenix Contact / Pilz</a></li></ul></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-pubsub-the-extension-for-the-cloud">OPC-UA PubSub: The Extension for the Cloud</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#migration-from-opc-da-to-opc-ua">Migration from OPC-DA to OPC-UA</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-with-the-eziwan-gateway">OPC-UA with the Eziwan Gateway</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#faq--opc-ua">FAQ — OPC-UA</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#further-reading">Further Reading</a></li><li><a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#additional-resources">Additional Resources</a></li></ul></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-is-opc-ua-and-why-does-it-matter">What Is OPC-UA and Why Does It Matter?<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#what-is-opc-ua-and-why-does-it-matter" class="hash-link" aria-label="Direct link to What Is OPC-UA and Why Does It Matter?" title="Direct link to What Is OPC-UA and Why Does It Matter?" translate="no">​</a></h2>
<p>OPC-UA (IEC 62541) is a <strong>platform-independent</strong> communication protocol designed for the secure exchange of industrial data. Unlike its predecessor, OPC-DA (Windows-only, DCOM), OPC-UA runs on any operating system (Linux, Windows, embedded RTOS) and over any network (Ethernet, 4G, Wi-Fi).</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="why-opc-ua-dominates-industry-40">Why OPC-UA Dominates Industry 4.0<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#why-opc-ua-dominates-industry-40" class="hash-link" aria-label="Direct link to Why OPC-UA Dominates Industry 4.0" title="Direct link to Why OPC-UA Dominates Industry 4.0" translate="no">​</a></h3>
<ul>
<li class=""><strong>Interoperability</strong>: A Siemens S7-1500 OPC-UA server can be read by any compliant client without a proprietary driver</li>
<li class=""><strong>Information model</strong>: Data has meaning (unit, description, history), not just a value</li>
<li class=""><strong>Native security</strong>: encryption, authentication, certificates—built into the protocol</li>
<li class=""><strong>Compliance profiles</strong>: a lightweight subset for small embedded devices</li>
<li class=""><strong>Pubsub &amp; MQTT</strong>: OPC-UA Pub/Sub extension for cloud architectures (IEC 62541-14)</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="opc-ua-architecture-fundamental-concepts">OPC-UA Architecture: Fundamental Concepts<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-architecture-fundamental-concepts" class="hash-link" aria-label="Direct link to OPC-UA Architecture: Fundamental Concepts" title="Direct link to OPC-UA Architecture: Fundamental Concepts" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="client-server">Client-Server<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#client-server" class="hash-link" aria-label="Direct link to Client-Server" title="Direct link to Client-Server" translate="no">​</a></h3>
<p>The basic OPC-UA model is <strong>client-server</strong>:</p>
<!-- -->
<ul>
<li class=""><strong>OPC-UA Server</strong>: exposed by the device (PLC, HMI, data server)</li>
<li class=""><strong>OPC-UA Client</strong>: consumes the data (SCADA, gateway, cloud application)</li>
</ul>
<p>A single device can act as both a <strong>server and a client at the same time</strong> (e.g., a gateway that aggregates data from multiple PLCs and exposes the consolidated data).</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="address-space-and-nodeid">Address Space and NodeId<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#address-space-and-nodeid" class="hash-link" aria-label="Direct link to Address Space and NodeId" title="Direct link to Address Space and NodeId" translate="no">​</a></h3>
<p>The <strong>Address Space</strong> is the information tree exposed by an OPC-UA server. Each node has a unique <strong>NodeId</strong>:</p>
<!-- -->
<p><strong>NodeId Format:</strong></p>
<ul>
<li class=""><code>ns=2;i=1234</code> — namespace 2, integer identifier 1234</li>
<li class=""><code>ns=2;s=Station_1.Pression</code> — namespace 2, string identifier</li>
<li class=""><code>ns=0;i=2258</code> — namespace 0 (standard), ServerStatus</li>
</ul>
<p><strong>Namespaces:</strong></p>
<ul>
<li class=""><code>ns=0</code>: standard OPC-UA namespace (types, methods)</li>
<li class=""><code>ns=1</code>: often the manufacturer's namespace</li>
<li class=""><code>ns=2+</code>: application namespaces (your data)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="communication-methods">Communication Methods<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#communication-methods" class="hash-link" aria-label="Direct link to Communication Methods" title="Direct link to Communication Methods" translate="no">​</a></h3>
<table><thead><tr><th>Mode</th><th>Description</th><th>Use Case</th></tr></thead><tbody><tr><td><strong>Read</strong></td><td>One-time read of a node</td><td>Polling every N seconds</td></tr><tr><td><strong>Subscription</strong></td><td>Subscription to changes (MonitoredItem)</td><td>Events, alarms</td></tr><tr><td><strong>Browse</strong></td><td>Browsing the Address Space</td><td>Configuration, discovery</td></tr><tr><td><strong>Write</strong></td><td>Writing a value</td><td>Setpoints, commands</td></tr><tr><td><strong>Method Call</strong></td><td>Method call</td><td>Complex actions</td></tr><tr><td><strong>Pubsub</strong></td><td>MQTT or UDP publish/subscribe</td><td>Large-scale cloud architectures</td></tr></tbody></table>
<p><strong>Subscriptions are the right approach</strong> for real-time monitoring: instead of polling every second, the client subscribes to a node and receives a notification only when the value changes beyond a configurable threshold (<strong>DeadbandValue</strong>).</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="opc-ua-security-the-complete-guide">OPC-UA Security: The Complete Guide<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-security-the-complete-guide" class="hash-link" aria-label="Direct link to OPC-UA Security: The Complete Guide" title="Direct link to OPC-UA Security: The Complete Guide" translate="no">​</a></h2>
<p>Security is one of OPC-UA's strengths—and also one of the sources of its complexity. Here are the key concepts.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="security-modes">Security Modes<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#security-modes" class="hash-link" aria-label="Direct link to Security Modes" title="Direct link to Security Modes" translate="no">​</a></h3>
<table><thead><tr><th>Mode</th><th>Confidentiality</th><th>Integrity</th><th>Authentication</th><th>Usage</th></tr></thead><tbody><tr><td><code>None</code></td><td>None</td><td>None</td><td>None</td><td>Testing, isolated network</td></tr><tr><td><code>Sign</code></td><td>No</td><td>Signature</td><td>Certificate</td><td>Secure network</td></tr><tr><td><code>SignAndEncrypt</code></td><td>AES-256</td><td>Signature</td><td>Certificate</td><td>Internet, cloud</td></tr></tbody></table>
<div class="theme-admonition theme-admonition-caution admonition_xJq3 alert alert--warning"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 16 16"><path fill-rule="evenodd" d="M8.893 1.5c-.183-.31-.52-.5-.887-.5s-.703.19-.886.5L.138 13.499a.98.98 0 0 0 0 1.001c.193.31.53.501.886.501h13.964c.367 0 .704-.19.877-.5a1.03 1.03 0 0 0 .01-1.002L8.893 1.5zm.133 11.497H6.987v-2.003h2.039v2.003zm0-3.004H6.987V5.987h2.039v4.006z"></path></svg></span>caution</div><div class="admonitionContent_BuS1"><p>Never use <code>SecurityMode: None</code> in a production environment on a network accessible from the outside.</p></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="x509-certificates">X.509 Certificates<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#x509-certificates" class="hash-link" aria-label="Direct link to X.509 Certificates" title="Direct link to X.509 Certificates" translate="no">​</a></h3>
<p>OPC-UA uses <strong>X.509</strong> certificates for mutual client-server authentication:</p>
<!-- -->
<p><strong>Creating a self-signed certificate for testing:</strong></p>
<div class="language-bash codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-bash codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token comment" style="color:#999988;font-style:italic"># Avec OpenSSL</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">openssl req </span><span class="token parameter variable" style="color:#36acaa">-x509</span><span class="token plain"> </span><span class="token parameter variable" style="color:#36acaa">-nodes</span><span class="token plain"> </span><span class="token parameter variable" style="color:#36acaa">-days</span><span class="token plain"> </span><span class="token number" style="color:#36acaa">3650</span><span class="token plain"> </span><span class="token parameter variable" style="color:#36acaa">-newkey</span><span class="token plain"> rsa:2048 </span><span class="token punctuation" style="color:#393A34">\</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token parameter variable" style="color:#36acaa">-keyout</span><span class="token plain"> client_key.pem </span><span class="token parameter variable" style="color:#36acaa">-out</span><span class="token plain"> client_cert.pem </span><span class="token punctuation" style="color:#393A34">\</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token parameter variable" style="color:#36acaa">-subj</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"/CN=EziwanGateway/O=Eziwan/C=FR"</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">\</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token parameter variable" style="color:#36acaa">-extensions</span><span class="token plain"> v3_req </span><span class="token punctuation" style="color:#393A34">\</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token parameter variable" style="color:#36acaa">-config</span><span class="token plain"> </span><span class="token operator" style="color:#393A34">&lt;</span><span class="token punctuation" style="color:#393A34">(</span><span class="token function" style="color:#d73a49">cat</span><span class="token plain"> /etc/ssl/openssl.cnf</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"> </span><span class="token builtin class-name">echo</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"[v3_req]"</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"> </span><span class="token builtin class-name">echo</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"subjectAltName=URI:urn:eziwan:gateway:client"</span><span class="token punctuation" style="color:#393A34">)</span><br></div></code></pre></div></div>
<p><strong>In production</strong>: Use an internal PKI or a recognized CA. Certificates must be exchanged manually between the client and the server the first time.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="user-authentication">User Authentication<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#user-authentication" class="hash-link" aria-label="Direct link to User Authentication" title="Direct link to User Authentication" translate="no">​</a></h3>
<p>In addition to machine certificates, OPC-UA supports <strong>user authentication</strong>:</p>
<ul>
<li class=""><strong>Anonymous</strong>: no authentication (if allowed by the server)</li>
<li class=""><strong>Username/Password</strong>: application login</li>
<li class=""><strong>Certificate</strong>: X.509 user certificate</li>
<li class=""><strong>IssuedToken</strong>: JWT or Kerberos token</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="implementing-opc-ua-in-python">Implementing OPC-UA in Python<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#implementing-opc-ua-in-python" class="hash-link" aria-label="Direct link to Implementing OPC-UA in Python" title="Direct link to Implementing OPC-UA in Python" translate="no">​</a></h2>
<p>The <strong>python-opcua</strong> library (or its fork, <strong>asyncua</strong>) is the go-to choice in Python.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="installation">Installation<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#installation" class="hash-link" aria-label="Direct link to Installation" title="Direct link to Installation" translate="no">​</a></h3>
<div class="language-bash codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-bash codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">pip </span><span class="token function" style="color:#d73a49">install</span><span class="token plain"> asyncua</span><br></div></code></pre></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="python-opc-ua-client--reading-data">Python OPC-UA Client — Reading Data<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#python-opc-ua-client--reading-data" class="hash-link" aria-label="Direct link to Python OPC-UA Client — Reading Data" title="Direct link to Python OPC-UA Client — Reading Data" translate="no">​</a></h3>
<div class="language-python codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-python codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token keyword" style="color:#00009f">import</span><span class="token plain"> asyncio</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">from</span><span class="token plain"> asyncua </span><span class="token keyword" style="color:#00009f">import</span><span class="token plain"> Client</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">async</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">def</span><span class="token plain"> </span><span class="token function" style="color:#d73a49">main</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    url </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"opc.tcp://192.168.1.10:4840/freeopcua/server/"</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword" style="color:#00009f">async</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">with</span><span class="token plain"> Client</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">url</span><span class="token operator" style="color:#393A34">=</span><span class="token plain">url</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">as</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token comment" style="color:#999988;font-style:italic"># Read a node by NodeId</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        node </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">get_node</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string" style="color:#e3116c">"ns=2;s=Station_1.Pression"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        value </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">await</span><span class="token plain"> node</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">read_value</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token keyword" style="color:#00009f">print</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string-interpolation string" style="color:#e3116c">f"Pression: </span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">{</span><span class="token string-interpolation interpolation">value</span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">}</span><span class="token string-interpolation string" style="color:#e3116c"> bar"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token comment" style="color:#999988;font-style:italic"># Read Multiple Nodes in a Batch</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        nodes </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">[</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">            client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">get_node</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string" style="color:#e3116c">"ns=2;s=Station_1.Pression"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">            client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">get_node</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string" style="color:#e3116c">"ns=2;s=Station_1.Debit"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">            client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">get_node</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string" style="color:#e3116c">"ns=2;s=Station_1.Defaut"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token punctuation" style="color:#393A34">]</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        values </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">await</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">read_values</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">nodes</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token keyword" style="color:#00009f">for</span><span class="token plain"> node</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> val </span><span class="token keyword" style="color:#00009f">in</span><span class="token plain"> </span><span class="token builtin">zip</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">nodes</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> values</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">            </span><span class="token keyword" style="color:#00009f">print</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string-interpolation string" style="color:#e3116c">f"  </span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">{</span><span class="token string-interpolation interpolation">node</span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">}</span><span class="token string-interpolation string" style="color:#e3116c">: </span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">{</span><span class="token string-interpolation interpolation">val</span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">}</span><span class="token string-interpolation string" style="color:#e3116c">"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">asyncio</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">run</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">main</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">)</span><br></div></code></pre></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="opc-ua-python-client--subscription">OPC-UA Python Client — Subscription<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-python-client--subscription" class="hash-link" aria-label="Direct link to OPC-UA Python Client — Subscription" title="Direct link to OPC-UA Python Client — Subscription" translate="no">​</a></h3>
<div class="language-python codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-python codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token keyword" style="color:#00009f">import</span><span class="token plain"> asyncio</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">from</span><span class="token plain"> asyncua </span><span class="token keyword" style="color:#00009f">import</span><span class="token plain"> Client</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">from</span><span class="token plain"> asyncua</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">common</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">subscription </span><span class="token keyword" style="color:#00009f">import</span><span class="token plain"> SubHandler</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">class</span><span class="token plain"> </span><span class="token class-name">DataChangeHandler</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">SubHandler</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword" style="color:#00009f">def</span><span class="token plain"> </span><span class="token function" style="color:#d73a49">datachange_notification</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">self</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> node</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> val</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> data</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token keyword" style="color:#00009f">print</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string-interpolation string" style="color:#e3116c">f"[CHANGE] </span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">{</span><span class="token string-interpolation interpolation">node</span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">}</span><span class="token string-interpolation string" style="color:#e3116c"> = </span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">{</span><span class="token string-interpolation interpolation">val</span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">}</span><span class="token string-interpolation string" style="color:#e3116c">"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword" style="color:#00009f">def</span><span class="token plain"> </span><span class="token function" style="color:#d73a49">event_notification</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">self</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> event</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token keyword" style="color:#00009f">print</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string-interpolation string" style="color:#e3116c">f"[EVENT] </span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">{</span><span class="token string-interpolation interpolation">event</span><span class="token string-interpolation interpolation punctuation" style="color:#393A34">}</span><span class="token string-interpolation string" style="color:#e3116c">"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">async</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">def</span><span class="token plain"> </span><span class="token function" style="color:#d73a49">main</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    url </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"opc.tcp://192.168.1.10:4840"</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword" style="color:#00009f">async</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">with</span><span class="token plain"> Client</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">url</span><span class="token operator" style="color:#393A34">=</span><span class="token plain">url</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">as</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        handler </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> DataChangeHandler</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        subscription </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">await</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">create_subscription</span><span class="token punctuation" style="color:#393A34">(</span><span class="token number" style="color:#36acaa">500</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> handler</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain">  </span><span class="token comment" style="color:#999988;font-style:italic"># 500ms</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        nodes </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">[</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">            client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">get_node</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string" style="color:#e3116c">"ns=2;s=Station_1.Pression"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">            client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">get_node</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string" style="color:#e3116c">"ns=2;s=Station_1.Debit"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token punctuation" style="color:#393A34">]</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        monitored_items </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">await</span><span class="token plain"> subscription</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">subscribe_data_change</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">nodes</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token keyword" style="color:#00009f">print</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string" style="color:#e3116c">"Subscriptions actives, attente changements..."</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token keyword" style="color:#00009f">await</span><span class="token plain"> asyncio</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">sleep</span><span class="token punctuation" style="color:#393A34">(</span><span class="token number" style="color:#36acaa">30</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain">  </span><span class="token comment" style="color:#999988;font-style:italic"># Listen for 30 seconds</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token keyword" style="color:#00009f">await</span><span class="token plain"> subscription</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">unsubscribe</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">monitored_items</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">asyncio</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">run</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">main</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">)</span><br></div></code></pre></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="secure-connection-with-a-certificate">Secure connection with a certificate<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#secure-connection-with-a-certificate" class="hash-link" aria-label="Direct link to Secure connection with a certificate" title="Direct link to Secure connection with a certificate" translate="no">​</a></h3>
<div class="language-python codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-python codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token keyword" style="color:#00009f">from</span><span class="token plain"> asyncua</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">crypto</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">security_policies </span><span class="token keyword" style="color:#00009f">import</span><span class="token plain"> SecurityPolicyBasic256Sha256</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">from</span><span class="token plain"> asyncua</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">crypto</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">cert_man </span><span class="token keyword" style="color:#00009f">import</span><span class="token plain"> CertificateManager</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">async</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">def</span><span class="token plain"> </span><span class="token function" style="color:#d73a49">connect_secure</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">:</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    client </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> Client</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string" style="color:#e3116c">"opc.tcp://192.168.1.10:4840"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword" style="color:#00009f">await</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">set_security</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        SecurityPolicyBasic256Sha256</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        certificate</span><span class="token operator" style="color:#393A34">=</span><span class="token string" style="color:#e3116c">"./client_cert.der"</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        private_key</span><span class="token operator" style="color:#393A34">=</span><span class="token string" style="color:#e3116c">"./client_key.pem"</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        server_certificate</span><span class="token operator" style="color:#393A34">=</span><span class="token string" style="color:#e3116c">"./server_cert.der"</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword" style="color:#00009f">await</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">connect</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token comment" style="color:#999988;font-style:italic"># ... your operations</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword" style="color:#00009f">await</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token plain">disconnect</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><br></div></code></pre></div></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="implementing-opc-ua-in-nodejs">Implementing OPC-UA in Node.js<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#implementing-opc-ua-in-nodejs" class="hash-link" aria-label="Direct link to Implementing OPC-UA in Node.js" title="Direct link to Implementing OPC-UA in Node.js" translate="no">​</a></h2>
<p>The <strong>node-opcua</strong> library is the go-to choice for JavaScript/TypeScript.</p>
<div class="language-bash codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-bash codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token function" style="color:#d73a49">npm</span><span class="token plain"> </span><span class="token function" style="color:#d73a49">install</span><span class="token plain"> node-opcua</span><br></div></code></pre></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="reading-data">Reading Data<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#reading-data" class="hash-link" aria-label="Direct link to Reading Data" title="Direct link to Reading Data" translate="no">​</a></h3>
<div class="language-javascript codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-javascript codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token keyword" style="color:#00009f">const</span><span class="token plain"> opcua </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token function" style="color:#d73a49">require</span><span class="token punctuation" style="color:#393A34">(</span><span class="token string" style="color:#e3116c">"node-opcua"</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">const</span><span class="token plain"> client </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> opcua</span><span class="token punctuation" style="color:#393A34">.</span><span class="token property-access maybe-class-name">OPCUAClient</span><span class="token punctuation" style="color:#393A34">.</span><span class="token method function property-access" style="color:#d73a49">create</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">{</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token literal-property property" style="color:#36acaa">endpointMustExist</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token boolean" style="color:#36acaa">false</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token literal-property property" style="color:#36acaa">connectionStrategy</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">{</span><span class="token plain"> </span><span class="token literal-property property" style="color:#36acaa">maxRetry</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token number" style="color:#36acaa">5</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token literal-property property" style="color:#36acaa">initialDelay</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token number" style="color:#36acaa">2000</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token punctuation" style="color:#393A34">}</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">const</span><span class="token plain"> endpointUrl </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"opc.tcp://192.168.1.10:4840"</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token keyword" style="color:#00009f">async</span><span class="token plain"> </span><span class="token keyword" style="color:#00009f">function</span><span class="token plain"> </span><span class="token function" style="color:#d73a49">main</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">{</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword control-flow" style="color:#00009f">await</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token method function property-access" style="color:#d73a49">connect</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">endpointUrl</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword" style="color:#00009f">const</span><span class="token plain"> session </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token keyword control-flow" style="color:#00009f">await</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token method function property-access" style="color:#d73a49">createSession</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword" style="color:#00009f">const</span><span class="token plain"> nodeToRead </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">{</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token literal-property property" style="color:#36acaa">nodeId</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"ns=2;s=Station_1.Pression"</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">        </span><span class="token literal-property property" style="color:#36acaa">attributeId</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> opcua</span><span class="token punctuation" style="color:#393A34">.</span><span class="token property-access maybe-class-name">AttributeIds</span><span class="token punctuation" style="color:#393A34">.</span><span class="token property-access maybe-class-name">Value</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token punctuation" style="color:#393A34">}</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword" style="color:#00009f">const</span><span class="token plain"> dataValue </span><span class="token operator" style="color:#393A34">=</span><span class="token plain"> </span><span class="token keyword control-flow" style="color:#00009f">await</span><span class="token plain"> session</span><span class="token punctuation" style="color:#393A34">.</span><span class="token method function property-access" style="color:#d73a49">read</span><span class="token punctuation" style="color:#393A34">(</span><span class="token plain">nodeToRead</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token console class-name">console</span><span class="token punctuation" style="color:#393A34">.</span><span class="token method function property-access" style="color:#d73a49">log</span><span class="token punctuation" style="color:#393A34">(</span><span class="token template-string template-punctuation string" style="color:#e3116c">`</span><span class="token template-string string" style="color:#e3116c">Pression: </span><span class="token template-string interpolation interpolation-punctuation punctuation" style="color:#393A34">${</span><span class="token template-string interpolation">dataValue</span><span class="token template-string interpolation punctuation" style="color:#393A34">.</span><span class="token template-string interpolation property-access">value</span><span class="token template-string interpolation punctuation" style="color:#393A34">.</span><span class="token template-string interpolation property-access">value</span><span class="token template-string interpolation interpolation-punctuation punctuation" style="color:#393A34">}</span><span class="token template-string string" style="color:#e3116c"> bar</span><span class="token template-string template-punctuation string" style="color:#e3116c">`</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token console class-name">console</span><span class="token punctuation" style="color:#393A34">.</span><span class="token method function property-access" style="color:#d73a49">log</span><span class="token punctuation" style="color:#393A34">(</span><span class="token template-string template-punctuation string" style="color:#e3116c">`</span><span class="token template-string string" style="color:#e3116c">Timestamp: </span><span class="token template-string interpolation interpolation-punctuation punctuation" style="color:#393A34">${</span><span class="token template-string interpolation">dataValue</span><span class="token template-string interpolation punctuation" style="color:#393A34">.</span><span class="token template-string interpolation property-access">serverTimestamp</span><span class="token template-string interpolation interpolation-punctuation punctuation" style="color:#393A34">}</span><span class="token template-string template-punctuation string" style="color:#e3116c">`</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword control-flow" style="color:#00009f">await</span><span class="token plain"> session</span><span class="token punctuation" style="color:#393A34">.</span><span class="token method function property-access" style="color:#d73a49">close</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token keyword control-flow" style="color:#00009f">await</span><span class="token plain"> client</span><span class="token punctuation" style="color:#393A34">.</span><span class="token method function property-access" style="color:#d73a49">disconnect</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">;</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token punctuation" style="color:#393A34">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token function" style="color:#d73a49">main</span><span class="token punctuation" style="color:#393A34">(</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">.</span><span class="token keyword control-flow" style="color:#00009f">catch</span><span class="token punctuation" style="color:#393A34">(</span><span class="token console class-name">console</span><span class="token punctuation" style="color:#393A34">.</span><span class="token property-access">error</span><span class="token punctuation" style="color:#393A34">)</span><span class="token punctuation" style="color:#393A34">;</span><br></div></code></pre></div></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="opc-ua-on-major-industrial-controllers">OPC-UA on Major Industrial Controllers<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-on-major-industrial-controllers" class="hash-link" aria-label="Direct link to OPC-UA on Major Industrial Controllers" title="Direct link to OPC-UA on Major Industrial Controllers" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="siemens-s7-1500--s7-1200">Siemens S7-1500 / S7-1200<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#siemens-s7-1500--s7-1200" class="hash-link" aria-label="Direct link to Siemens S7-1500 / S7-1200" title="Direct link to Siemens S7-1500 / S7-1200" translate="no">​</a></h3>
<p>The S7-1500 supports native OPC-UA server functionality starting with firmware version 2.0:</p>
<ul>
<li class="">Port: 4840 (TCP)</li>
<li class="">Configuration in TIA Portal: <code>Device Configuration → OPC UA → Server</code></li>
<li class="">Enable the desired nodes in the Access configuration</li>
<li class="">Authentication: Certificates or Username/Password</li>
</ul>
<p>The S7-1200 has supported OPC-UA since firmware version 4.1.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="schneider-electric-m580--m340">Schneider Electric M580 / M340<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#schneider-electric-m580--m340" class="hash-link" aria-label="Direct link to Schneider Electric M580 / M340" title="Direct link to Schneider Electric M580 / M340" translate="no">​</a></h3>
<p>M580: OPC-UA via the <strong>BMENOC0311</strong> module (firmware ≥ V2.0)
M340: No native OPC-UA support → Modbus TCP recommended, or an OPC-UA to Modbus gateway (e.g., Kepware KEPServerEX)</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="allen-bradley--rockwell-ethernetip">Allen-Bradley / Rockwell (EtherNet/IP)<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#allen-bradley--rockwell-ethernetip" class="hash-link" aria-label="Direct link to Allen-Bradley / Rockwell (EtherNet/IP)" title="Direct link to Allen-Bradley / Rockwell (EtherNet/IP)" translate="no">​</a></h3>
<p>Rockwell PLCs do not natively support OPC-UA. Options:</p>
<ul>
<li class=""><strong>KEPServerEX</strong> (Kepware): EtherNet/IP → OPC-UA bridge</li>
<li class=""><strong>FactoryTalk Linx Gateway</strong>: OPC-UA server for the Rockwell ecosystem</li>
<li class=""><strong>Eziwan Gateway</strong>: direct EtherNet/IP/Modbus connection, REST API exposure</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="beckhoff-twincat-3">Beckhoff TwinCAT 3<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#beckhoff-twincat-3" class="hash-link" aria-label="Direct link to Beckhoff TwinCAT 3" title="Direct link to Beckhoff TwinCAT 3" translate="no">​</a></h3>
<p>TwinCAT 3 includes a native OPC-UA server via <strong>TF6100</strong> (OPC-UA module). Configuration is performed via TwinCAT System Manager.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="wago--phoenix-contact--pilz">Wago / Phoenix Contact / Pilz<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#wago--phoenix-contact--pilz" class="hash-link" aria-label="Direct link to Wago / Phoenix Contact / Pilz" title="Direct link to Wago / Phoenix Contact / Pilz" translate="no">​</a></h3>
<p>Most modern PLCs from these manufacturers support OPC-UA. Check the firmware and enable the server in the network configuration.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="opc-ua-pubsub-the-extension-for-the-cloud">OPC-UA PubSub: The Extension for the Cloud<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-pubsub-the-extension-for-the-cloud" class="hash-link" aria-label="Direct link to OPC-UA PubSub: The Extension for the Cloud" title="Direct link to OPC-UA PubSub: The Extension for the Cloud" translate="no">​</a></h2>
<p><strong>OPC-UA PubSub</strong> (IEC 62541-14) is the extension that makes OPC-UA compatible with cloud-based IoT architectures:</p>
<ul>
<li class=""><strong>Publisher</strong>: The device publishes its data to a <strong>Message-Oriented Middleware</strong></li>
<li class=""><strong>Subscriber</strong>: The cloud or SCADA system subscribes to the data stream</li>
</ul>
<p><strong>Supported transport protocols:</strong></p>
<ul>
<li class="">AMQP (port 5672)</li>
<li class=""><strong>MQTT</strong> (port 1883 or 8883) — the most widely used in IoT</li>
<li class="">UDP Multicast (local network)</li>
</ul>
<p><strong>Encodings:</strong></p>
<ul>
<li class="">JSON (human-readable, easy to debug)</li>
<li class="">UADP (binary, compact, embedded)</li>
</ul>
<p><strong>Example of an OPC-UA PubSub JSON message:</strong></p>
<div class="language-json codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-json codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token punctuation" style="color:#393A34">{</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token property" style="color:#36acaa">"MessageId"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"abc123"</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token property" style="color:#36acaa">"PublisherId"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"urn:station1:plc"</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token property" style="color:#36acaa">"DataSetWriterId"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token number" style="color:#36acaa">1</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token property" style="color:#36acaa">"MetaDataVersion"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">{</span><span class="token property" style="color:#36acaa">"MajorVersion"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token number" style="color:#36acaa">1</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"MinorVersion"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token number" style="color:#36acaa">0</span><span class="token punctuation" style="color:#393A34">}</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token property" style="color:#36acaa">"Timestamp"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"2026-08-14T10:30:00.000Z"</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token property" style="color:#36acaa">"Payload"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">{</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token property" style="color:#36acaa">"Station_1.Pression"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">{</span><span class="token property" style="color:#36acaa">"Value"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token number" style="color:#36acaa">4.2</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"StatusCode"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token number" style="color:#36acaa">0</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"SourceTimestamp"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"2026-08-14T10:29:59.950Z"</span><span class="token punctuation" style="color:#393A34">}</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    </span><span class="token property" style="color:#36acaa">"Station_1.Debit"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token punctuation" style="color:#393A34">{</span><span class="token property" style="color:#36acaa">"Value"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token number" style="color:#36acaa">125.3</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"StatusCode"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token number" style="color:#36acaa">0</span><span class="token punctuation" style="color:#393A34">,</span><span class="token plain"> </span><span class="token property" style="color:#36acaa">"SourceTimestamp"</span><span class="token operator" style="color:#393A34">:</span><span class="token plain"> </span><span class="token string" style="color:#e3116c">"2026-08-14T10:29:59.950Z"</span><span class="token punctuation" style="color:#393A34">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  </span><span class="token punctuation" style="color:#393A34">}</span><span class="token plain"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain"></span><span class="token punctuation" style="color:#393A34">}</span><br></div></code></pre></div></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="migration-from-opc-da-to-opc-ua">Migration from OPC-DA to OPC-UA<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#migration-from-opc-da-to-opc-ua" class="hash-link" aria-label="Direct link to Migration from OPC-DA to OPC-UA" title="Direct link to Migration from OPC-DA to OPC-UA" translate="no">​</a></h2>
<p>If you have systems running <strong>OPC-DA</strong> (OPC Classic, Windows DCOM), migrating to OPC-UA offers:</p>
<ul>
<li class="">Elimination of the Windows/DCOM dependency</li>
<li class="">Compatibility with Linux, Raspberry Pi, and Linux-based PLCs</li>
<li class="">Encryption (not available in OPC-DA)</li>
<li class="">Direct internet access (not possible with DCOM without a complex VPN)</li>
</ul>
<p><strong>Migration tool:</strong> <strong>OPC UA Wrapper</strong> (e.g., Kepware) creates an OPC UA server that exposes data from an existing OPC DA server, enabling a phased migration.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="opc-ua-with-the-eziwan-gateway">OPC-UA with the Eziwan Gateway<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#opc-ua-with-the-eziwan-gateway" class="hash-link" aria-label="Direct link to OPC-UA with the Eziwan Gateway" title="Direct link to OPC-UA with the Eziwan Gateway" translate="no">​</a></h2>
<p>The <strong>Eziwan Gateway</strong> includes an <strong>OPC-UA client</strong> capable of connecting to the OPC-UA servers on your devices:</p>
<ul>
<li class="">Siemens S7-1500 OPC-UA connection (port 4840)</li>
<li class="">Connection to any IEC 62541-compliant OPC-UA server</li>
<li class="">Support for <code>None</code>, <code>Sign</code>, and <code>SignAndEncrypt</code> security modes</li>
<li class="">Configuration of NodeIDs in the cloud interface (automatic browsing of the address space)</li>
<li class="">Data transmission to the Eziwan cloud platform via MQTT/TLS</li>
</ul>
<p><strong>Key benefit:</strong> You don't need to write an OPC-UA client yourself. The gateway handles this and exposes a REST API to your SCADA or ERP system.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq--opc-ua">FAQ — OPC-UA<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#faq--opc-ua" class="hash-link" aria-label="Direct link to FAQ — OPC-UA" title="Direct link to FAQ — OPC-UA" translate="no">​</a></h2>
<p><strong>Is OPC-UA more complex than Modbus?</strong>
Yes, but it’s justified for multi-vendor installations and Industry 4.0 projects. For an installation with 2–3 PLCs from the same manufacturer, Modbus TCP may be sufficient. OPC-UA is the way to go when you have heterogeneous equipment, safety requirements, or ERP/MES interoperability needs.</p>
<p><strong>Does port 4840 need to be open on my firewall?</strong>
In a "zero-inbound-port" architecture (such as Eziwan), the gateway initiates the connection to the OPC-UA server internally. No ports are open to the outside. The encrypted VPN tunnel carries the data to the cloud.</p>
<p><strong>Can OPC-UA replace MQTT in an IoT architecture?</strong>
OPC-UA PubSub with MQTT transport combines the best of both worlds: OPC-UA’s semantic information model with MQTT’s lightness and scalability. This is the direction taken by the Industry 4.0 reference frameworks (Industry 4.0 Architecture Reference Model, IDS-R).</p>
<p><strong>What performance can you expect from an embedded OPC-UA server?</strong>
A Siemens S7-1500 CPU 1515 can process ~10,000 OPC-UA read nodes per second. For less powerful PLCs (M221, small WAGO models), limit OPC-UA polling to 100–500 nodes per second. Subscriptions are much more efficient than polling for large volumes.</p>
<p><strong>Are there any free OPC-UA servers available for testing?</strong>
Yes: <strong>ProsysOPC UA Simulation Server</strong> (free, Windows), <strong>Node-RED</strong> with <code>node-red-contrib-opcua</code> (free, cross-platform), <strong>python-opcua</strong> in server mode (example in the GitHub documentation). These allow you to test a client without a physical PLC.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/opc-ua-mqtt-industrial-gateway">Blog: OPC-UA and MQTT — How to Combine the Two on an Industrial Gateway</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/secure-remote-access-plc-scada">Blog: Secure Remote Access to PLCs and SCADA — VPN, Zero-Trust, and NIS2</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/connect-siemens-s7-plc-to-cloud">Blog: Connecting a Siemens S7 PLC to the Cloud — Technical Guide</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/iec-62443-practical-guide">Blog: IEC 62443 — A Practical Guide to Industrial Cybersecurity</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/modbus-tcp-vs-rtu">Blog: Modbus TCP vs. RTU — A Comprehensive Comparison for Industrial IoT</a></li>
</ul>
<p><em>Need help connecting your OPC-UA servers to the cloud? <a class="" href="https://eziwan.com/en/contact">Request a free demo</a> — our team will guide you from proof of concept through deployment.</em></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/opc-ua-mqtt">OPC UA to MQTT</a> — publish OPC UA data to a cloud-based MQTT broker</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-protocols">Industrial Protocols</a> — comparison of OPC UA, Modbus, MQTT, and other protocols</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-iot-gateway">Industrial IoT Gateway</a> — choosing an OPC UA-compatible gateway</li>
<li class=""><a class="" href="https://eziwan.com/en/modbus-tcp-cloud">Modbus TCP to the Cloud</a> — monitoring Modbus TCP PLCs from the cloud</li>
<li class=""><a class="" href="https://eziwan.com/en/scada-cloud">Cloud SCADA</a> — modern SCADA architecture with OPC UA and cloud connectivity</li>
</ul>]]></content:encoded>
            <category>opc-ua</category>
            <category>industrial-iot</category>
            <category>protocols</category>
            <category>scada</category>
            <category>iiot</category>
            <category>automation</category>
        </item>
        <item>
            <title><![CDATA[How to Connect a Schneider Electric M340 or M221 PLC to the IoT Cloud]]></title>
            <link>https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud</link>
            <guid>https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud</guid>
            <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A comprehensive technical guide for connecting your Schneider Electric Modicon M340, M221, and M580 PLCs to the IoT cloud via Modbus RTU/TCP. Register reading, real-time monitoring, and alerts.]]></description>
            <content:encoded><![CDATA[<p>Your <strong>Schneider Electric Modicon M340</strong>, <strong>M221</strong>, or <strong>M580</strong> PLCs have been running for years, but monitoring remains local—on-site operator panel, no remote access, no historical trends. This guide shows you how to connect them to the IoT cloud without modifying your PLC program or interrupting production.</p>
<div class="tableOfContentsInline_prmo"><ul class="table-of-contents"><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#why-connect-your-m340m221-to-the-cloud">Why connect your M340/M221 to the cloud?</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#modbus-compatibility-of-schneider-electric-plcs">Modbus Compatibility of Schneider Electric PLCs</a><ul><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#modicon-m221">Modicon M221</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#modicon-m340">Modicon M340</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#modicon-m580-epac">Modicon M580 (ePAC)</a></li></ul></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#connection-architecture">Connection Architecture</a><ul><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#option-1-via-modbus-tcp-ethernet--recommended">Option 1: Via Modbus TCP (Ethernet) — recommended</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#option-2-via-modbus-rtu-rs-485">Option 2: Via Modbus RTU (RS-485)</a></li></ul></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#configuring-the-eziwan-gateway-for-schneider">Configuring the Eziwan Gateway for Schneider</a><ul><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#add-a-modbus-device">Add a Modbus Device</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#configure-the-variables-to-be-read">Configure the variables to be read</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#recommended-polling-interval">Recommended polling interval</a></li></ul></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#what-you-get-in-the-cloud">What You Get in the Cloud</a><ul><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#real-time-dashboard">Real-Time Dashboard</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#alert-system">Alert System</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#long-term-historical-analysis">Long-Term Historical Analysis</a></li></ul></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#case-study-m340-pumping-station">Case Study: M340 Pumping Station</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#migration-from-somachine--unity-pro">Migration from SoMachine / Unity Pro</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#ecostruxure-compatibility">EcoStruxure Compatibility</a><ul><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#alongside-ecostruxure-plant">Alongside EcoStruxure Plant</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#phased-replacement">Phased Replacement</a></li></ul></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#cloud-connection-comparison-m221-vs-m340-vs-m580">Cloud Connection Comparison: M221 vs. M340 vs. M580</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#faq--connecting-the-m340m221-to-the-cloud">FAQ — Connecting the M340/M221 to the Cloud</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#getting-started-with-your-poc">Getting Started with Your POC</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#further-reading">Further Reading</a></li><li><a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#additional-resources">Additional Resources</a></li></ul></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="why-connect-your-m340m221-to-the-cloud">Why connect your M340/M221 to the cloud?<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#why-connect-your-m340m221-to-the-cloud" class="hash-link" aria-label="Direct link to Why connect your M340/M221 to the cloud?" title="Direct link to Why connect your M340/M221 to the cloud?" translate="no">​</a></h2>
<p>Schneider Electric's Modicon series PLCs are used in thousands of industrial facilities in France: <strong>water treatment</strong>, <strong>pumping stations</strong>, <strong>food processing</strong>, and <strong>packaging lines</strong>. Robust and reliable, they often have a service life of 15–20 years.</p>
<p>But their native communication capabilities are limited:</p>
<ul>
<li class="">No native cloud connectivity</li>
<li class="">Remote access often restricted to a costly MPLS VPN</li>
<li class="">No long-term data logging without an on-premises SCADA server</li>
<li class="">Alerts are either nonexistent or only local (indicator lights, horns)</li>
</ul>
<p>The solution: <strong>an industrial IoT gateway</strong> that reads the Modbus data from your M340/M221 and sends it to the cloud, without modifying the PLC program.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="modbus-compatibility-of-schneider-electric-plcs">Modbus Compatibility of Schneider Electric PLCs<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#modbus-compatibility-of-schneider-electric-plcs" class="hash-link" aria-label="Direct link to Modbus Compatibility of Schneider Electric PLCs" title="Direct link to Modbus Compatibility of Schneider Electric PLCs" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="modicon-m221">Modicon M221<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#modicon-m221" class="hash-link" aria-label="Direct link to Modicon M221" title="Direct link to Modicon M221" translate="no">​</a></h3>
<p>The <strong>M221</strong> (TM221CE16R, TM221CE24T, etc.) features a native <strong>Modbus RTU</strong> port on its RJ45 connector (RS-485 via a TM3TI4 adapter or a specific cable) and a <strong>Modbus TCP</strong> port on its Ethernet port.</p>
<p><strong>Accessible registers:</strong></p>
<ul>
<li class=""><code>%MW0</code> to <code>%MW255</code> — memory words</li>
<li class=""><code>%QW</code> — analog outputs</li>
<li class=""><code>%IW</code> — analog inputs</li>
<li class=""><code>%M</code> — memory bits (coils 0–255)</li>
</ul>
<p><strong>Modbus Slave Configuration on the M221:</strong></p>
<p>In EcoStruxure Machine Expert - Basic:</p>
<ol>
<li class=""><code>Configuration → Modbus Serial</code> or <code>Modbus TCP</code></li>
<li class="">Slave address: 1 (default)</li>
<li class="">Enable "Slave function" → OK</li>
</ol>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="modicon-m340">Modicon M340<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#modicon-m340" class="hash-link" aria-label="Direct link to Modicon M340" title="Direct link to Modicon M340" translate="no">​</a></h3>
<p>The <strong>M340</strong> (BMX P34 2020, BMX P34 2030, etc.) features a <strong>Modbus RTU</strong> serial port (RS-485, 9-pin SUB-D connector) and an <strong>ETH</strong> module (BMX NOE 0100 or BMX NOC 0401) for Modbus TCP.</p>
<p><strong>Registers accessible via Modbus:</strong></p>
<table><thead><tr><th>PLC Zone</th><th>Modbus Type</th><th>Read Function</th><th>Range</th></tr></thead><tbody><tr><td><code>%MW</code></td><td>Holding Registers</td><td>FC03</td><td>400001–465535</td></tr><tr><td><code>%IW</code></td><td>Input Registers</td><td>FC04</td><td>300001–365535</td></tr><tr><td><code>%M</code></td><td>Coils</td><td>FC01</td><td>000001–065536</td></tr><tr><td><code>%I</code></td><td>Discrete Inputs</td><td>FC02</td><td>100001–165536</td></tr></tbody></table>
<p><strong>Modbus Address → Unity Pro Address:</strong></p>
<ul>
<li class="">Register 400001 = <code>%MW0</code></li>
<li class="">Register 400100 = <code>%MW99</code></li>
<li class="">Register 400501 = <code>%MW500</code></li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="modicon-m580-epac">Modicon M580 (ePAC)<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#modicon-m580-epac" class="hash-link" aria-label="Direct link to Modicon M580 (ePAC)" title="Direct link to Modicon M580 (ePAC)" translate="no">​</a></h3>
<p>The <strong>M580</strong> features native Modbus TCP on its <strong>CPU</strong> Ethernet port and supports the same register tables as the M340, plus:</p>
<ul>
<li class="">Access to I/O modules via <strong>BMENOC0311</strong> (Ethernet module)</li>
<li class="">EtherNet/IP support</li>
<li class="">Data Exchange capability with EcoStruxure Plant</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="connection-architecture">Connection Architecture<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#connection-architecture" class="hash-link" aria-label="Direct link to Connection Architecture" title="Direct link to Connection Architecture" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="option-1-via-modbus-tcp-ethernet--recommended">Option 1: Via Modbus TCP (Ethernet) — recommended<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#option-1-via-modbus-tcp-ethernet--recommended" class="hash-link" aria-label="Direct link to Option 1: Via Modbus TCP (Ethernet) — recommended" title="Direct link to Option 1: Via Modbus TCP (Ethernet) — recommended" translate="no">​</a></h3>
<!-- -->
<p><strong>Prerequisites:</strong></p>
<ul>
<li class="">ETH module installed on the rack (BMX NOE 0100 for M340)</li>
<li class="">PLC IP address configured (e.g., 192.168.1.10)</li>
<li class="">Internal firewall allowing port 502 from the gateway's IP address</li>
</ul>
<p><strong>Advantages:</strong></p>
<ul>
<li class="">No additional RS-485 wiring</li>
<li class="">Higher throughput (up to 30 requests per second)</li>
<li class="">Compatibility with Traffic Unity Pro (non-intrusive readings)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="option-2-via-modbus-rtu-rs-485">Option 2: Via Modbus RTU (RS-485)<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#option-2-via-modbus-rtu-rs-485" class="hash-link" aria-label="Direct link to Option 2: Via Modbus RTU (RS-485)" title="Direct link to Option 2: Via Modbus RTU (RS-485)" translate="no">​</a></h3>
<!-- -->
<p><strong>For the M221:</strong> Use the <strong>TCSMCNAM3M002P</strong> cable (RJ45 to RS-485) or the <strong>VW3A8306</strong> adapter, depending on the model.</p>
<p><strong>For the M340:</strong> 9-pin SUB-D connector on the PLC side; pins 3 (+) and 8 (-) for RS-485.</p>
<p><strong>M221/M340 Serial Settings (Default):</strong></p>
<ul>
<li class="">Speed: 19,200 bps</li>
<li class="">Parity: none (8N1)</li>
<li class="">Slave address: 1</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="configuring-the-eziwan-gateway-for-schneider">Configuring the Eziwan Gateway for Schneider<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#configuring-the-eziwan-gateway-for-schneider" class="hash-link" aria-label="Direct link to Configuring the Eziwan Gateway for Schneider" title="Direct link to Configuring the Eziwan Gateway for Schneider" translate="no">​</a></h2>
<p>Once the gateway is connected, you can configure it from the Eziwan cloud interface with just a few clicks.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="add-a-modbus-device">Add a Modbus Device<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#add-a-modbus-device" class="hash-link" aria-label="Direct link to Add a Modbus Device" title="Direct link to Add a Modbus Device" translate="no">​</a></h3>
<ol>
<li class="">Access <code>Flotte → Site → + Équipement</code></li>
<li class="">Select <strong>Modbus TCP</strong> or <strong>Modbus RTU</strong></li>
<li class="">Enter:<!-- -->
<ul>
<li class="">IP: <code>192.168.1.10</code> (or your M340’s address)</li>
<li class="">Port: <code>502</code></li>
<li class="">Slave ID: <code>1</code></li>
</ul>
</li>
</ol>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="configure-the-variables-to-be-read">Configure the variables to be read<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#configure-the-variables-to-be-read" class="hash-link" aria-label="Direct link to Configure the variables to be read" title="Direct link to Configure the variables to be read" translate="no">​</a></h3>
<table><thead><tr><th>Variable</th><th>Modbus Register</th><th>Type</th><th>Description</th></tr></thead><tbody><tr><td>Tank Level</td><td><code>%MW10</code> → 400011</td><td>Holding (FC03)</td><td>0-100%</td></tr><tr><td>Pump Flow</td><td><code>%MW20</code> → 400021</td><td>Holding (FC03)</td><td>0–500 m³/h</td></tr><tr><td>Pressure</td><td><code>%IW0</code> → 300001</td><td>Input (FC04)</td><td>0–16 bar</td></tr><tr><td>General fault</td><td><code>%M0</code> → 000001</td><td>Coil (FC01)</td><td>Boolean</td></tr><tr><td>Pump on</td><td><code>%M1</code> → 000002</td><td>Coil (FC01)</td><td>Boolean</td></tr></tbody></table>
<p><strong>Conversion engineering:</strong> Apply a multiplier if the PLC returns a raw value (e.g., <code>×0.01</code> to convert from 1500 to 15.00 bar).</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommended-polling-interval">Recommended polling interval<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#recommended-polling-interval" class="hash-link" aria-label="Direct link to Recommended polling interval" title="Direct link to Recommended polling interval" translate="no">​</a></h3>
<table><thead><tr><th>Criticality</th><th>Polling</th><th>Use Case</th></tr></thead><tbody><tr><td>Real-time</td><td>1 s</td><td>Safety, critical processes</td></tr><tr><td>Monitoring</td><td>5 s</td><td>Production, energy</td></tr><tr><td>Trends</td><td>30 s</td><td>Meter readings, statistics</td></tr><tr><td>Archive</td><td>5 min</td><td>Simple remote meter reading</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-get-in-the-cloud">What You Get in the Cloud<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#what-you-get-in-the-cloud" class="hash-link" aria-label="Direct link to What You Get in the Cloud" title="Direct link to What You Get in the Cloud" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="real-time-dashboard">Real-Time Dashboard<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#real-time-dashboard" class="hash-link" aria-label="Direct link to Real-Time Dashboard" title="Direct link to Real-Time Dashboard" translate="no">​</a></h3>
<p>As soon as the gateway connects for the first time, data is transmitted in real time to the Eziwan dashboard:</p>
<ul>
<li class=""><strong>Trend graphs</strong> for 1 hour, 24 hours, 7 days, and 30 days</li>
<li class="">Configurable <strong>gauges and indicators</strong></li>
<li class=""><strong>Multi-site tables</strong> to compare your installations</li>
<li class=""><strong>CSV/Excel export</strong> for reporting</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="alert-system">Alert System<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#alert-system" class="hash-link" aria-label="Direct link to Alert System" title="Direct link to Alert System" translate="no">​</a></h3>
<p>Set up specific alerts for each variable:</p>
<div class="language-text codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">Alert: Tank Level</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  Condition : %MW10 &lt; 10 (niveau bas)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  Canal : SMS + Email</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  Recipients: equipe@maintenance.fr, astreinte@maintenance.fr</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  Acquittement : requis</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">Alert: Pump Failure</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  Condition: %M5 = 1 (fault bit active)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  Channel: Instant SMS</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  Priority: Critical</span><br></div></code></pre></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="long-term-historical-analysis">Long-Term Historical Analysis<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#long-term-historical-analysis" class="hash-link" aria-label="Direct link to Long-Term Historical Analysis" title="Direct link to Long-Term Historical Analysis" translate="no">​</a></h3>
<p>All data is archived for <strong>5 years</strong> as standard, at no additional cost. You can:</p>
<ul>
<li class="">View production history for years N-1 and N-2</li>
<li class="">Identify gradual deterioration (e.g., a pump drawing more current)</li>
<li class="">Generate compliance reports (water, energy, pharmaceuticals)</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="case-study-m340-pumping-station">Case Study: M340 Pumping Station<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#case-study-m340-pumping-station" class="hash-link" aria-label="Direct link to Case Study: M340 Pumping Station" title="Direct link to Case Study: M340 Pumping Station" translate="no">​</a></h2>
<p><strong>Background:</strong> A local government agency manages 12 pumping stations equipped with 2020 M340 BMX P34 units. Current maintenance: 3 field rounds per week, 2 technicians.</p>
<p><strong>Deployed Configuration:</strong></p>
<ul>
<li class="">12 × Eziwan Gateway (Modbus TCP, SFR Business SIM)</li>
<li class="">Variables read per station: well level, flow rate, discharge pressure, motor current, operating hours, faults (12 variables)</li>
<li class="">Polling interval: 5 seconds for flow rate/pressure/failures, 1 minute for level/meters</li>
</ul>
<p><strong>Results after 6 months:</strong></p>
<ul>
<li class="">On-site inspections: 3/week → 1/week (-67%)</li>
<li class="">Incidents detected before a shutdown: 4 (overheated pump, stuck valve, seized float)</li>
<li class="">Estimated savings: <strong>€41,000/year</strong> (travel costs + avoided corrective maintenance)</li>
<li class="">ROI on equipment + subscription: <strong>5 months</strong></li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="migration-from-somachine--unity-pro">Migration from SoMachine / Unity Pro<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#migration-from-somachine--unity-pro" class="hash-link" aria-label="Direct link to Migration from SoMachine / Unity Pro" title="Direct link to Migration from SoMachine / Unity Pro" translate="no">​</a></h2>
<p>If you are using <strong>SoMachine</strong> (M221) or <strong>Unity Pro</strong> (M340/M580), no changes to the PLC program are necessary. The Eziwan gateway connects in <strong>read-only</strong> mode by default.</p>
<p>If you also want to <strong>write commands</strong> (setpoints, commands) from the cloud:</p>
<ul>
<li class="">Use Function Codes <strong>FC05</strong> (Write Single Coil) and <strong>FC06</strong> (Write Single Register)</li>
<li class="">Configure access rights in the Eziwan gateway (multi-factor authentication)</li>
<li class="">Create register ranges specifically dedicated to remote commands (e.g., <code>%MW200-MW220</code>)</li>
</ul>
<div class="theme-admonition theme-admonition-caution admonition_xJq3 alert alert--warning"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 16 16"><path fill-rule="evenodd" d="M8.893 1.5c-.183-.31-.52-.5-.887-.5s-.703.19-.886.5L.138 13.499a.98.98 0 0 0 0 1.001c.193.31.53.501.886.501h13.964c.367 0 .704-.19.877-.5a1.03 1.03 0 0 0 .01-1.002L8.893 1.5zm.133 11.497H6.987v-2.003h2.039v2.003zm0-3.004H6.987V5.987h2.039v4.006z"></path></svg></span>Safety Precautions for Remote Commands</div><div class="admonitionContent_BuS1"><p>Writing to a PLC from the cloud must be subject to a risk analysis (HAZOP). Critical addresses (emergency stop, safety instructions) must be protected with read-only access.</p></div></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ecostruxure-compatibility">EcoStruxure Compatibility<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#ecostruxure-compatibility" class="hash-link" aria-label="Direct link to EcoStruxure Compatibility" title="Direct link to EcoStruxure Compatibility" translate="no">​</a></h2>
<p>The Eziwan gateway is <strong>compatible with EcoStruxure</strong> in several ways:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="alongside-ecostruxure-plant">Alongside EcoStruxure Plant<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#alongside-ecostruxure-plant" class="hash-link" aria-label="Direct link to Alongside EcoStruxure Plant" title="Direct link to Alongside EcoStruxure Plant" translate="no">​</a></h3>
<p>The gateway reads the same registers as your EcoStruxure SCADA system, without any interference. Ideal for adding:</p>
<ul>
<li class="">Centralized multi-site monitoring</li>
<li class="">Mobile access for field technicians</li>
<li class="">SMS/email alerts (often missing in the base EcoStruxure system)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="phased-replacement">Phased Replacement<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#phased-replacement" class="hash-link" aria-label="Direct link to Phased Replacement" title="Direct link to Phased Replacement" translate="no">​</a></h3>
<p>If your EcoStruxure Plant license is nearing the end of its lifecycle, you can migrate in phases:</p>
<ol>
<li class="">Deploy the Eziwan gateway in parallel</li>
<li class="">Validate the data for 4–8 weeks</li>
<li class="">Switch the primary monitoring to Eziwan</li>
<li class="">Reduce the EcoStruxure license to the scope that is actually needed</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="cloud-connection-comparison-m221-vs-m340-vs-m580">Cloud Connection Comparison: M221 vs. M340 vs. M580<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#cloud-connection-comparison-m221-vs-m340-vs-m580" class="hash-link" aria-label="Direct link to Cloud Connection Comparison: M221 vs. M340 vs. M580" title="Direct link to Cloud Connection Comparison: M221 vs. M340 vs. M580" translate="no">​</a></h2>
<table><thead><tr><th></th><th>M221</th><th>M340</th><th>M580</th></tr></thead><tbody><tr><td>Native Modbus RTU</td><td>✅ (via cable)</td><td>✅ (SUB-D 9)</td><td>✅</td></tr><tr><td>Native Modbus TCP</td><td>✅ (ETH port)</td><td>✅ (BMX NOE module)</td><td>✅ native</td></tr><tr><td>Max Eziwan variables</td><td>128</td><td>512</td><td>1024</td></tr><tr><td>Min. polling interval</td><td>1 s</td><td>1 s</td><td>500 ms</td></tr><tr><td>Register write</td><td>✅ FC06</td><td>✅ FC06/FC16</td><td>✅ FC06/FC16</td></tr><tr><td>Store-and-forward compatibility</td><td>✅</td><td>✅</td><td>✅</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq--connecting-the-m340m221-to-the-cloud">FAQ — Connecting the M340/M221 to the Cloud<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#faq--connecting-the-m340m221-to-the-cloud" class="hash-link" aria-label="Direct link to FAQ — Connecting the M340/M221 to the Cloud" title="Direct link to FAQ — Connecting the M340/M221 to the Cloud" translate="no">​</a></h2>
<p><strong>Do I need to modify the SoMachine/Unity Pro program?</strong>
No. The Eziwan gateway connects as a Modbus master to the slave PLC. No code is added to the PLC. If the PLC is already configured as a Modbus slave (which is the default setting), the connection is established immediately.</p>
<p><strong>My M340 already has a Unity Pro SCADA system—is it compatible?</strong>
Yes. Multiple Modbus TCP masters can query the same slave simultaneously. The Eziwan gateway and your SCADA system can coexist without conflict, provided you configure a reasonable polling frequency (≥ 1 s).</p>
<p><strong>Can I monitor analog input modules (BMX AMI 0410)?</strong>
Yes. The analog modules are addressed in the <code>%IW</code> (inputs) and <code>%QW</code> (outputs) tables. Refer to the Unity Pro documentation for the register mapping of your specific modules.</p>
<p><strong>Does the gateway work if the 4G network is down?</strong>
Yes. The Eziwan gateway includes an SD card buffer: data continues to be collected locally and is transmitted in batches once connectivity is restored (store-and-forward). Local alerts (direct SMS) remain operational without the cloud.</p>
<p><strong>Is it compatible with the Zelio Logic product line?</strong>
The Zelio Logic Smart Relay supports a limited version of Modbus RTU. Depending on the model (SR2/SR3), access to internal registers may be restricted. Please contact us to confirm compatibility with your specific model.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="getting-started-with-your-poc">Getting Started with Your POC<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#getting-started-with-your-poc" class="hash-link" aria-label="Direct link to Getting Started with Your POC" title="Direct link to Getting Started with Your POC" translate="no">​</a></h2>
<p>Do you have an M340, M221, or M580 on-site and want to verify the cloud connection?</p>
<p><strong>Eziwan offers a free 30-day POC</strong> that includes:</p>
<ul>
<li class="">1 pre-configured gateway shipped within 48 hours</li>
<li class="">Onboarding guided by our technical team</li>
<li class="">Dashboards configured according to your specifications</li>
<li class="">No commitment, no credit card required</li>
</ul>
<p><a class="" href="https://eziwan.com/en/contact">Start the free POC →</a> | <a class="" href="https://eziwan.com/en/roi">Calculate your ROI →</a></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/connect-siemens-s7-plc-to-cloud">Blog: Connecting a Siemens S7 PLC to the Cloud — Technical Guide</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/secure-remote-access-plc-scada">Blog: Secure Remote Access to PLCs and SCADA Systems — VPN and NIS2</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/modbus-tcp-vs-rtu">Blog: Modbus TCP vs. RTU — Which Protocol Should You Choose?</a></li>
<li class=""><a class="" href="https://eziwan.com/en/docs/compatibilite/siemens-s7">Docs: Siemens S7-1200/S7-1500 compatibility</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/predictive-maintenance-iot-field-sensors">Blog: IIoT predictive maintenance — from sensor data to alerts</a></li>
</ul>
<hr>
<p><em>Do you use other Schneider Electric product lines (Altivar, Easergy, PowerLogic)? <a class="" href="https://eziwan.com/en/contact">Contact us</a> to verify compatibility with your specific equipment.</em></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/connect-schneider-m340-m221-plc-to-cloud#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/schneider-plc-remote-access">Schneider PLC Remote Access</a> — secure remote access to Schneider M340, M221, and M580 PLCs</li>
<li class=""><a class="" href="https://eziwan.com/en/connecter-automate-cloud">Connect a PLC to the cloud</a> — connect any industrial PLC to the cloud</li>
<li class=""><a class="" href="https://eziwan.com/en/modbus-tcp-cloud">Modbus TCP to the cloud</a> — monitoring via Modbus TCP from the cloud</li>
<li class=""><a class="" href="https://eziwan.com/en/acces-distant-industriel">Industrial Remote Access</a> — VPN and zero-trust architecture for industrial sites</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-remote-support">Industrial Monitoring and Remote Support</a> — centralized monitoring of your Schneider PLCs</li>
</ul>]]></content:encoded>
            <category>industrial-iot</category>
            <category>schneider-electric</category>
            <category>plc</category>
            <category>modbus</category>
            <category>connectivity</category>
            <category>iiot</category>
        </item>
        <item>
            <title><![CDATA[LoRa, Zigbee, 4G, or Wi-Fi: Which IoT Protocol Should You Choose for Your Industrial Project?]]></title>
            <link>https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol</link>
            <guid>https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol</guid>
            <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A comprehensive comparison of LoRaWAN, Zigbee, 4G LTE, and Wi-Fi for industrial IoT projects in France. Range, data rate, cost, power consumption, and industrial use cases.]]></description>
            <content:encoded><![CDATA[<p>Choosing a wireless communication protocol is one of the most important decisions in an industrial IoT project. LoRaWAN, Zigbee, 4G LTE, or Wi-Fi: each technology has its strengths, weaknesses, and ideal use cases. Choosing the wrong technology can make your deployment impossible to scale, too expensive to operate, or insufficiently reliable for your industrial environment.</p>
<p>This guide compares the four main wireless technologies used in industrial IoT in France, with practical recommendations for each use case.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="overview-4-technologies-for-4-different-needs">Overview: 4 Technologies for 4 Different Needs<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#overview-4-technologies-for-4-different-needs" class="hash-link" aria-label="Direct link to Overview: 4 Technologies for 4 Different Needs" title="Direct link to Overview: 4 Technologies for 4 Different Needs" translate="no">​</a></h2>
<p>Before getting into the details, here’s the gist in one sentence for each technology:</p>
<ul>
<li class=""><strong>LoRaWAN</strong>: for low-power, battery-powered sensors in open environments over long distances (1 to 15 km)</li>
<li class=""><strong>Zigbee</strong>: for dense indoor sensor networks with mesh topologies over short distances (10 to 100 m)</li>
<li class=""><strong>4G LTE</strong>: for remote locations, critical equipment, long-distance WAN connections, and high-speed internet</li>
<li class=""><strong>Wi-Fi</strong>: for locations with existing network infrastructure, mobile devices in covered areas, and local high-speed internet</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="detailed-technical-comparison">Detailed Technical Comparison<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#detailed-technical-comparison" class="hash-link" aria-label="Direct link to Detailed Technical Comparison" title="Direct link to Detailed Technical Comparison" translate="no">​</a></h2>
<table><thead><tr><th>Criterion</th><th>LoRaWAN</th><th>Zigbee</th><th>4G LTE</th><th>Wi-Fi 802.11n/ac</th></tr></thead><tbody><tr><td><strong>Range</strong></td><td>1–15 km (rural) / 0.5–3 km (urban)</td><td>10–100 m (mesh up to 300 m)</td><td>0.5–30 km</td><td>30–150 m</td></tr><tr><td><strong>Data Rate</strong></td><td>250 bps to 50 Kbps</td><td>20–250 Kbps</td><td>5–100 Mbps</td><td>50–1000 Mbps</td></tr><tr><td><strong>Latency</strong></td><td>1–10 s</td><td>10–30 ms</td><td>30–100 ms</td><td>1–10 ms</td></tr><tr><td><strong>Power consumption</strong></td><td>Very low (µA in standby)</td><td>Low (µA–mA)</td><td>Medium (mA–W)</td><td>High (W)</td></tr><tr><td><strong>Battery life</strong></td><td>5–15 years</td><td>1–5 years</td><td>6–24 months</td><td>Days to weeks</td></tr><tr><td><strong>Infrastructure cost</strong></td><td>Low (LoRa hub)</td><td>Medium (coordinator + mesh)</td><td>Low (M2M SIM)</td><td>High (AP + switches)</td></tr><tr><td><strong>Cost per node</strong></td><td>10–80 €</td><td>20–150 €</td><td>100–500 €</td><td>50–300 €</td></tr><tr><td><strong>Frequency</strong></td><td>868 MHz (EU)</td><td>2.4 GHz</td><td>700/800/1800/2600 MHz</td><td>2.4 / 5 GHz</td></tr><tr><td><strong>Native security</strong></td><td>AES-128</td><td>AES-128</td><td>3GPP (TLS, SIM)</td><td>WPA3</td></tr><tr><td><strong>Standardization</strong></td><td>LoRa Alliance</td><td>Zigbee Alliance (CSA)</td><td>3GPP</td><td>IEEE 802.11</td></tr><tr><td><strong>Topology</strong></td><td>Star (via hub)</td><td>Mesh</td><td>Point-to-point (via mobile network)</td><td>Star (via AP)</td></tr><tr><td><strong>Number of nodes per gateway/AP</strong></td><td>2,000 to 10,000</td><td>65,000 (Zigbee 3.0)</td><td>N/A (carrier network)</td><td>30–100 active clients</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="lorawan-in-detail">LoRaWAN in Detail<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#lorawan-in-detail" class="hash-link" aria-label="Direct link to LoRaWAN in Detail" title="Direct link to LoRaWAN in Detail" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="when-to-use-it">When to Use It<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#when-to-use-it" class="hash-link" aria-label="Direct link to When to Use It" title="Direct link to When to Use It" translate="no">​</a></h3>
<p>LoRaWAN is ideal for scenarios where you need <strong>very long ranges</strong> and <strong>very low power consumption</strong>, but where the <strong>data rate is low</strong> (a few bytes per message every few minutes to hours).</p>
<p><strong>Ideal industrial use cases for LoRa:</strong></p>
<ul>
<li class="">Water, gas, and electricity meter reading in urban and suburban areas</li>
<li class="">Monitoring environmental conditions over large areas (temperature, humidity, CO₂ in multiple buildings)</li>
<li class="">Asset tracking using long-life GPS/motion sensors (pallets, mobile tanks)</li>
<li class="">Monitoring of sensors in hard-to-reach areas (sewers, underground infrastructure, rural areas)</li>
<li class="">Opening/closing detection (hatches, silo doors) over large areas</li>
</ul>
<p><strong>LoRaWAN Advantages:</strong></p>
<ul>
<li class="">Exceptional battery life (5 to 10 years on an AA battery)</li>
<li class="">Very simple infrastructure: a LoRa hub covers a radius of 5 to 15 km in rural areas</li>
<li class="">Public networks available in France (Bouygues Telecom LoRa, Objenious, Sewan, CityMesh)</li>
<li class="">Very low cost per node (€10 to €50 for a single sensor)</li>
</ul>
<p><strong>LoRaWAN Limitations:</strong></p>
<ul>
<li class="">Very low data rate: cannot send images, video streams, or more than a few bytes per message</li>
<li class="">High latency: the downlink (cloud → sensor) can take 5 to 10 seconds — not suitable for real-time control</li>
<li class="">Regulatory limitations: the 868 MHz band is limited to a 1% duty cycle (approximately 36 seconds of transmission per hour) — this restricts the frequency of transmissions</li>
<li class="">In dense indoor environments (thick concrete, basements), the range drops to a few dozen meters</li>
</ul>
<p><strong>Typical Industrial LoRa Architecture:</strong></p>
<!-- -->
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="zigbee-in-detail">Zigbee in Detail<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#zigbee-in-detail" class="hash-link" aria-label="Direct link to Zigbee in Detail" title="Direct link to Zigbee in Detail" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="when-to-use-it-1">When to Use It<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#when-to-use-it-1" class="hash-link" aria-label="Direct link to When to Use It" title="Direct link to When to Use It" translate="no">​</a></h3>
<p>Zigbee is ideal for <strong>dense indoor sensor networks</strong> with short ranges, particularly in buildings (smart buildings) and factories where distances are short but the number of nodes is high.</p>
<p><strong>Ideal Industrial Use Cases for Zigbee:</strong></p>
<ul>
<li class="">Building Automation Systems (BAS): lighting, blinds, HVAC</li>
<li class="">Monitoring of environmental conditions in high-density environments (warehouses, cleanrooms)</li>
<li class="">Networks of occupancy sensors, door sensors, and zone-based energy meters</li>
<li class="">Light industrial automation as a replacement for wired systems in commercial buildings</li>
</ul>
<p><strong>Zigbee Advantages:</strong></p>
<ul>
<li class="">Mesh architecture: Zigbee nodes relay data from distant nodes, eliminating dead zones</li>
<li class="">Low battery consumption (1 to 5 years)</li>
<li class="">Large ecosystem of standardized and interoperable sensors (Matter standard since 2022)</li>
<li class="">Sufficient data rate for real-time measurements (alarms, status updates)</li>
<li class="">Very high node density (thousands on a single network)</li>
</ul>
<p><strong>Zigbee Limitations:</strong></p>
<ul>
<li class="">Limited range: 10 to 100 m per hop (mesh networks compensate for this, but require a sufficient number of intermediate nodes)</li>
<li class="">Coordination required: every Zigbee network requires a coordinator (Zigbee hub or gateway)</li>
<li class="">2.4 GHz = interference with Wi-Fi, Bluetooth, and microwave ovens in dense industrial environments</li>
<li class="">Not suitable for long-distance connections between distant buildings</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="4g-lte-in-detail">4G LTE in Detail<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#4g-lte-in-detail" class="hash-link" aria-label="Direct link to 4G LTE in Detail" title="Direct link to 4G LTE in Detail" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="when-to-use-it-2">When to Use It<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#when-to-use-it-2" class="hash-link" aria-label="Direct link to When to Use It" title="Direct link to When to Use It" translate="no">​</a></h3>
<p>4G LTE is the technology of choice for <strong>long-distance WAN connections</strong>, <strong>remote sites without network infrastructure</strong>, and <strong>applications requiring sufficient bandwidth</strong> for monitoring and remote access.</p>
<p><strong>Ideal industrial use cases for 4G:</strong></p>
<ul>
<li class="">Remote sites (pumping stations, cabins, antennas, weather sensors) without a wired connection</li>
<li class="">Backup connection for critical industrial sites (fiber-to-4G failover)</li>
<li class="">IoT gateways that transmit field data to the cloud (Modbus monitoring, OPC-UA)</li>
<li class="">Remote VPN access for remote maintenance of industrial equipment</li>
<li class="">Vehicles and mobile equipment (refrigerated trucks, construction machinery)</li>
<li class="">Rapid deployments where installing a network cable is impossible or too costly</li>
</ul>
<p><strong>Benefits of Industrial 4G LTE:</strong></p>
<ul>
<li class=""><strong>Nationwide coverage</strong>: 99.2% of French municipalities (including remote rural and industrial areas)</li>
<li class=""><strong>Sufficient bandwidth</strong>: 5 to 50 Mbps is more than enough for monitoring and remote maintenance</li>
<li class=""><strong>No local infrastructure</strong>: no cabling, no switches, no access points to maintain</li>
<li class=""><strong>Dual SIM</strong>: automatic switching between carriers to maximize availability</li>
<li class=""><strong>Plug-and-play</strong>: an industrial 4G gateway is up and running in less than an hour</li>
</ul>
<p><strong>4G LTE Limitations:</strong></p>
<ul>
<li class=""><strong>Higher cost per node</strong>: a 4G industrial gateway costs €300 to €600; a SIM subscription costs €10 to €20 per month</li>
<li class=""><strong>Power consumption</strong>: requires a mains power supply (not suitable for battery-powered sensors)</li>
<li class=""><strong>Latency</strong>: 30 to 100 ms (acceptable for monitoring, but not for demanding real-time control)</li>
<li class=""><strong>Dead zones</strong>: some very remote rural areas with no coverage (can be mitigated with an external antenna or satellite)</li>
<li class=""><strong>Dependence on the carrier</strong>: availability depends on the mobile network (acceptable with dual-SIM)</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="wi-fi-in-detail">Wi-Fi in Detail<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#wi-fi-in-detail" class="hash-link" aria-label="Direct link to Wi-Fi in Detail" title="Direct link to Wi-Fi in Detail" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="when-to-use-it-3">When to Use It<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#when-to-use-it-3" class="hash-link" aria-label="Direct link to When to Use It" title="Direct link to When to Use It" translate="no">​</a></h3>
<p>Wi-Fi is suitable for <strong>sites with existing network infrastructure</strong>, <strong>devices requiring high-speed connectivity</strong>, and <strong>areas with full coverage</strong> from access points.</p>
<p><strong>Ideal Industrial Use Cases for Wi-Fi:</strong></p>
<ul>
<li class="">Connecting sensors or industrial equipment in a factory with existing Wi-Fi coverage</li>
<li class="">On-site vehicles or mobile equipment (forklifts, AGVs) in areas with Wi-Fi coverage</li>
<li class="">IP surveillance cameras (requires high-speed Wi-Fi)</li>
<li class="">Local SCADA in real-time monitoring mode (latency &lt; 10 ms)</li>
</ul>
<p><strong>Benefits of Industrial Wi-Fi:</strong></p>
<ul>
<li class="">Very high data rates (supports video streaming and fast firmware updates)</li>
<li class="">Infrastructure often already in place in modern factories</li>
<li class="">Very low latency (1 to 10 ms) — suitable for moderate real-time applications</li>
<li class="">Many industrial devices with built-in Wi-Fi (HMIs, collaborative robots)</li>
</ul>
<p><strong>Limitations of Industrial Wi-Fi:</strong></p>
<ul>
<li class="">Limited range: 30 to 150 m per access point (AP); requires a mesh network to cover large areas</li>
<li class="">Interference: The 2.4 GHz band is congested in dense industrial environments (motors, radio frequencies, CNC machines)</li>
<li class="">High power consumption: not suitable for battery-powered sensors</li>
<li class="">Expensive infrastructure: industrial access points (Cisco, Aruba, Extreme Networks) = €500 to €3,000 per AP</li>
<li class="">Complex network management: roaming for mobile devices requires Wi-Fi expertise</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="decision-guide-how-to-choose">Decision Guide: How to Choose?<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#decision-guide-how-to-choose" class="hash-link" aria-label="Direct link to Decision Guide: How to Choose?" title="Direct link to Decision Guide: How to Choose?" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="decision-tree">Decision Tree<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#decision-tree" class="hash-link" aria-label="Direct link to Decision Tree" title="Direct link to Decision Tree" translate="no">​</a></h3>
<!-- -->
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommendation-table-by-sector">Recommendation Table by Sector<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#recommendation-table-by-sector" class="hash-link" aria-label="Direct link to Recommendation Table by Sector" title="Direct link to Recommendation Table by Sector" translate="no">​</a></h3>
<table><thead><tr><th>Sector</th><th>Primary Recommendation</th><th>Secondary</th><th>Avoid</th></tr></thead><tbody><tr><td>Water/Sewage (remote facilities)</td><td>4G LTE</td><td>LoRaWAN (meters)</td><td>Wi-Fi</td></tr><tr><td>Water/Sewage (urban network)</td><td>LoRaWAN</td><td>4G LTE</td><td>—</td></tr><tr><td>Renewable Energy (rural farms)</td><td>4G LTE</td><td>LoRaWAN (weather)</td><td>Wi-Fi</td></tr><tr><td>Manufacturing (indoor factory)</td><td>Wi-Fi / 4G</td><td>Zigbee</td><td>LoRaWAN</td></tr><tr><td>Warehouse logistics</td><td>Wi-Fi / Zigbee</td><td>4G LTE</td><td>LoRaWAN</td></tr><tr><td>Agriculture (rural farms)</td><td>4G LTE</td><td>LoRaWAN</td><td>Wi-Fi</td></tr><tr><td>Smart buildings (commercial)</td><td>Zigbee / Wi-Fi</td><td>LoRaWAN</td><td>4G LTE</td></tr><tr><td>Remote maintenance (remote access)</td><td>4G LTE</td><td>—</td><td>LoRaWAN, Zigbee</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="hybrid-architecture-the-best-of-both-worlds">Hybrid Architecture: The Best of Both Worlds<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#hybrid-architecture-the-best-of-both-worlds" class="hash-link" aria-label="Direct link to Hybrid Architecture: The Best of Both Worlds" title="Direct link to Hybrid Architecture: The Best of Both Worlds" translate="no">​</a></h2>
<p>In practice, mature industrial IoT deployments use a combination of technologies, selected based on the nature of each piece of equipment.</p>
<p><strong>Example of a hybrid architecture: a 10-hectare industrial site</strong></p>
<!-- -->
<p>The Eziwan gateway acts as a multiprotocol hub: it communicates via Modbus on the local OT network, is compatible with LoRa and Zigbee hubs for wireless sensors, and transmits all data to the cloud via 4G LTE. One subscription, one dashboard.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="5-year-cost-comparison-deployment-of-100-sensors">5-Year Cost Comparison (Deployment of 100 Sensors)<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#5-year-cost-comparison-deployment-of-100-sensors" class="hash-link" aria-label="Direct link to 5-Year Cost Comparison (Deployment of 100 Sensors)" title="Direct link to 5-Year Cost Comparison (Deployment of 100 Sensors)" translate="no">​</a></h2>
<table><thead><tr><th>Criterion</th><th>LoRaWAN (public network)</th><th>Zigbee (private network)</th><th>4G LTE</th><th>Industrial Wi-Fi</th></tr></thead><tbody><tr><td>Hardware per node</td><td>30–60 €</td><td>50–120 €</td><td>300–500 €</td><td>100–250 €</td></tr><tr><td>Infrastructure</td><td>0 € (public network)</td><td>500–2,000 € (hub)</td><td>0 €</td><td>3,000–15,000 € (APs)</td></tr><tr><td>Subscription per node/year</td><td>5–15 €</td><td>0 €</td><td>120–240 €</td><td>0 €</td></tr><tr><td><strong>Total hardware for 100 nodes</strong></td><td>3,000–6,000 €</td><td>5,000–14,000 €</td><td>30,000–50,000 €</td><td>10,000–25,000 €</td></tr><tr><td><strong>Total 5-year subscription</strong></td><td>2,500–7,500 €</td><td>0 €</td><td>60,000–120,000 €</td><td>0 €</td></tr><tr><td><strong>5-year TCO (100 nodes)</strong></td><td>€5,500–13,500</td><td>€5,000–14,000</td><td>€90,000–170,000</td><td>€13,000–40,000</td></tr></tbody></table>
<p><em>Note: 4G LTE is significantly more expensive per node, but provides long-distance WAN connectivity that LoRa and Zigbee cannot offer. This comparison applies only to data-collection sensors, not to industrial gateways that must provide an internet connection.</em></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion">Conclusion<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#conclusion" class="hash-link" aria-label="Direct link to Conclusion" title="Direct link to Conclusion" translate="no">​</a></h2>
<p>There is no single "best" universal IoT technology. The choice depends on three fundamental criteria:</p>
<ol>
<li class=""><strong>Range</strong>: short (Zigbee), medium-to-long (LoRaWAN), very long or WAN (4G LTE)</li>
<li class=""><strong>Power consumption</strong>: long-lasting battery life (LoRaWAN &gt; Zigbee &gt; Wi-Fi), AC power (all)</li>
<li class=""><strong>Data rate</strong>: sensor data (LoRaWAN and Zigbee are sufficient), monitoring and remote access (4G LTE and Wi-Fi required)</li>
</ol>
<p>The Eziwan solution is optimized for <strong>4G LTE</strong> as an industrial WAN connection technology, as it is best suited for gateways that need to connect local OT networks (Modbus, OPC-UA) to the monitoring cloud. It can be supplemented with LoRaWAN or Zigbee concentrators for low-power sensors.</p>
<p>Need help choosing the right architecture for your project? <a class="" href="https://eziwan.com/en/contact">Contact our team of engineers</a> for a free assessment of your situation.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>Can LoRaWAN and 4G LTE be combined at the same site?</strong>
Yes—it’s even recommended. Battery-powered LoRaWAN sensors (water meters, environmental probes, level sensors) transmit data via a LoRa hub. The Eziwan 4G LTE gateway consolidates data from local LoRa sensors and Modbus devices and sends it to the cloud. 4G is used only for the WAN connection, not for each individual sensor.</p>
<p><strong>Is LoRaWAN reliable for critical industrial monitoring?</strong>
LoRaWAN is suitable for non-critical monitoring (meter readings, environmental data, presence detection). For critical monitoring (pump alarms, process values), 4G LTE is preferable due to its low latency and reliability. The two protocols often coexist: LoRaWAN for auxiliary sensors, and 4G for critical PLCs and HMIs.</p>
<p><strong>What is the difference between LoRa and LoRaWAN?</strong>
LoRa is the radio technology (Semtech's CSS modulation). LoRaWAN is the network protocol based on LoRa: it defines the network architecture (nodes → concentrators → Network Server → Application Server), address management, security (AES-128), and device classes (A, B, C). LoRa without LoRaWAN can operate in a proprietary point-to-point mode—which is less interoperable.</p>
<p><strong>Can Zigbee be used in an industrial environment with electromagnetic interference?</strong>
Zigbee (2.4 GHz) is sensitive to industrial radio interference (motors, variable-speed drives, welding). In highly disrupted environments, prioritize Zigbee channels at 915 MHz (available in a sub-GHz version) or use wired connections (RS-485 Modbus) for the most critical equipment. The Zigbee mesh network improves resilience but does not eliminate physical limitations.</p>
<p><strong>Is industrial Wi-Fi suitable for moving machinery (AGVs, conveyors)?</strong>
Wi-Fi with 802.11r roaming (Fast Transition) is used for AGVs (automated guided vehicles) and conveyors. A network of access points covering the entire route enables rapid handover (&lt;50 ms) between APs. This deployment is more complex and costly than a fixed network, but it is the standard solution for moving machines in indoor environments.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/opc-ua-mqtt-industrial-gateway">Blog: OPC-UA, MQTT, Modbus — Choosing an Industrial Gateway</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols">Blog: Modbus, MQTT, OPC-UA — A Comprehensive Comparison of Industrial Protocols</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison">Blog: M2M IoT SIMs — 2026 Comparison of French Operators</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria">Blog: Choosing an Industrial IoT Gateway — 9 Criteria</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide">Blog: Remote Industrial Monitoring — Complete Guide 2026</a></li>
</ul>
<hr>
<p><em>Eziwan specializes in 4G LTE industrial IoT connectivity. Our multi-protocol gateway (Modbus, OPC-UA, MQTT, LoRaWAN, Zigbee) integrates seamlessly with your existing architecture. <a class="" href="https://eziwan.com/en/gateway">Learn more about the Eziwan gateway →</a></em></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/industrial-connectivity">Industrial Connectivity</a> — multi-protocol connectivity solutions for industrial IoT</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-protocols">Industrial Protocols</a> — guide to industrial communication protocols (Modbus, OPC-UA, MQTT, etc.)</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-iot-gateway">Industrial IoT Gateways</a> — multi-protocol wireless and wired gateways for IIoT</li>
<li class=""><a class="" href="https://eziwan.com/en/internet-connection-remote-industrial-site">Internet Connectivity for Remote Industrial Sites</a> — choosing the right radio protocol for sites without wired coverage</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-solutions">Eziwan Industrial Solutions</a> — comprehensive range of industrial connectivity and monitoring solutions</li>
</ul>]]></content:encoded>
            <category>industrial-iot</category>
            <category>connectivity</category>
            <category>protocols</category>
            <category>4g</category>
            <category>lorawan</category>
            <category>zigbee</category>
            <category>wifi</category>
        </item>
        <item>
            <title><![CDATA[IoT and Connected Agriculture: Monitoring Farms in France in 2026]]></title>
            <link>https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring</link>
            <guid>https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring</guid>
            <pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[How the IoT Is Transforming Agriculture and Livestock Farming in France: Monitoring Greenhouses, Silos, Milk Tanks, Irrigation, and Environmental Conditions. A Practical Guide for 2026.]]></description>
            <content:encoded><![CDATA[<p>France is Europe’s leading agricultural nation. However, French farms are facing increasing pressure: rising energy costs, stricter environmental regulations, a shortage of skilled labor, and traceability requirements in the agri-food sector. The Industrial Internet of Things (IIoT) offers concrete solutions to these challenges.</p>
<p>This guide outlines the main use cases for agricultural IoT in France, compatible equipment, costs, and ROI, and explains how to implement a robust agricultural monitoring solution in rural areas—even without a fiber connection.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="agriculture-a-fertile-ground-for-the-industrial-iot">Agriculture: A Fertile Ground for the Industrial IoT<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#agriculture-a-fertile-ground-for-the-industrial-iot" class="hash-link" aria-label="Direct link to Agriculture: A Fertile Ground for the Industrial IoT" title="Direct link to Agriculture: A Fertile Ground for the Industrial IoT" translate="no">​</a></h2>
<p>Modern agriculture already uses a wide range of electronic and electromechanical equipment: automated irrigation systems, fans in livestock buildings, milk cooling tanks, storage silos, climate-controlled greenhouses, and well pumps. The vast majority of these devices have communication interfaces (Modbus RTU, 4–20 mA, pulse outputs) that enable an IoT connection without the need for replacement.</p>
<p><strong>What the IoT Brings to Agriculture:</strong></p>
<ul>
<li class="">24/7 monitoring without the need for the farmer to be present at all times</li>
<li class="">Immediate alerts in the event of an anomaly (equipment failure, threshold exceeded)</li>
<li class="">Historical data for optimizing practices and ensuring traceability</li>
<li class="">Reduced losses (non-compliant milk, poor crop growth, animal mortality)</li>
<li class="">Easier regulatory compliance (animal welfare, water regulations)</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="use-case-1-monitoring-of-livestock-facilities">Use Case 1: Monitoring of Livestock Facilities<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#use-case-1-monitoring-of-livestock-facilities" class="hash-link" aria-label="Direct link to Use Case 1: Monitoring of Livestock Facilities" title="Direct link to Use Case 1: Monitoring of Livestock Facilities" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="pig-barns-chicken-coops-dairy-cattle">Pig barns, chicken coops, dairy cattle<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#pig-barns-chicken-coops-dairy-cattle" class="hash-link" aria-label="Direct link to Pig barns, chicken coops, dairy cattle" title="Direct link to Pig barns, chicken coops, dairy cattle" translate="no">​</a></h3>
<p>Off-the-ground livestock facilities (pig barns, chicken coops, dairy barns) are particularly well-suited for IoT monitoring. The critical parameters to monitor are:</p>
<p><strong>Building Climate Conditions:</strong></p>
<ul>
<li class="">Temperature (°C) and relative humidity (%): Significant fluctuations directly impact the animals’ growth and health</li>
<li class="">CO₂ concentration (ppm): an indicator of air quality and ventilation efficiency</li>
<li class="">NH₃ concentration (ammonia, ppm): a hazardous gas produced by manure, regulated for animal welfare</li>
</ul>
<p><strong>Ventilation Equipment:</strong></p>
<ul>
<li class="">On/off status of each fan (digital input)</li>
<li class="">Rotational speed or damper position (0-10V or 4-20mA output)</li>
<li class="">Power consumption per circuit (current transformer)</li>
</ul>
<p><strong>Feed and Water:</strong></p>
<ul>
<li class="">Feed silo levels (ultrasonic level sensor)</li>
<li class="">Water consumption (pulse flow meter)</li>
<li class="">Status of automatic feeders (ON/OFF)</li>
</ul>
<p><strong>Compatible sensors and interfaces:</strong></p>
<table><thead><tr><th>Parameter</th><th>Recommended Sensor</th><th>Interface</th></tr></thead><tbody><tr><td>Building Temperature/Humidity</td><td>Sensirion SHT31, Rotronic HF5</td><td>Modbus RS-485 or 4-20 mA</td></tr><tr><td>CO₂</td><td>Senseair S8, COZIR-Blink</td><td>Modbus RTU or UART</td></tr><tr><td>NH₃ (ammonia)</td><td>Membrapor NH3/M-100, Winsen ZE07</td><td>4–20 mA or Modbus</td></tr><tr><td>Silo Level</td><td>Pepperl+Fuchs UC6000, SICK UM30</td><td>4-20 mA or IO-Link</td></tr><tr><td>Water Flow Meter</td><td>Sontex Supercal 5, Itron Actaris</td><td>Pulse or Modbus</td></tr></tbody></table>
<p><strong>Typical alert thresholds for livestock buildings:</strong></p>
<table><thead><tr><th>Parameter</th><th>Green Zone</th><th>Orange Zone (Alert)</th><th>Red Zone (Emergency)</th></tr></thead><tbody><tr><td>Temperature in finishing pig barn</td><td>18–22°C</td><td>&lt; 15°C or &gt; 26°C</td><td>&lt; 10°C or &gt; 30°C</td></tr><tr><td>Humidity in poultry house</td><td>50–70%</td><td>&gt;<!-- --> 80%</td><td>&gt;<!-- --> 90%</td></tr><tr><td>CO₂ in poultry house</td><td>&lt;<!-- --> 3000 ppm</td><td>&gt;<!-- --> 3000 ppm</td><td>&gt;<!-- --> 5000 ppm</td></tr><tr><td>NH₃ in swine</td><td>&lt;<!-- --> 10 ppm</td><td>&gt;<!-- --> 10 ppm</td><td>&gt;<!-- --> 20 ppm (regulatory threshold)</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="use-case-2-monitoring-milk-tanks">Use Case 2: Monitoring Milk Tanks<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#use-case-2-monitoring-milk-tanks" class="hash-link" aria-label="Direct link to Use Case 2: Monitoring Milk Tanks" title="Direct link to Use Case 2: Monitoring Milk Tanks" translate="no">​</a></h2>
<p>Cooling milk is a regulatory requirement (amended decree of September 15, 2004): cow's milk must be cooled to 8°C within 2 hours of milking and kept at a maximum of 4°C until it is picked up.</p>
<p><strong>Failure to comply with these temperatures results in:</strong></p>
<ul>
<li class="">Irreversible microbiological spoilage of the milk</li>
<li class="">Refusal by the dairy to collect the milk (direct financial loss)</li>
<li class="">Contractual penalties (quality penalties)</li>
</ul>
<p><strong>IoT Monitoring of the Milk Tank:</strong></p>
<p>Most modern milk tanks (Boumatic, Mueller, DeLaval, GEA, Lemmer-Fullwood) have an RS-232 or RS-485 Modbus port for monitoring. Accessible parameters include:</p>
<ul>
<li class="">Milk temperature (°C) with a resolution of 0.1°C</li>
<li class="">Cooling compressor status</li>
<li class="">Milk volume (if the tank has a gauge)</li>
<li class="">Temperature history (complete curve since the last milking)</li>
</ul>
<p>The Eziwan Gateway connects to the tank via RS-232 or RS-485 and uploads data to the cloud at a configurable 5-minute polling interval. An SMS alert is sent if the temperature exceeds 8°C for more than 15 minutes.</p>
<p><strong>Customer Case Study:</strong> A dairy farmer in Brittany who manages 3 milk tanks (a 120-cow operation) avoided 2 collection rejections in 6 months thanks to nighttime text alerts (compressor failure detected at 2 a.m., repair completed at 4 a.m. before the 6 a.m. pickup). Savings: 2 × 800 L × €0.40/L = €640 in avoided losses, plus quality penalties.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="use-case-3-monitoring-horticultural-and-vegetable-greenhouses">Use Case 3: Monitoring Horticultural and Vegetable Greenhouses<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#use-case-3-monitoring-horticultural-and-vegetable-greenhouses" class="hash-link" aria-label="Direct link to Use Case 3: Monitoring Horticultural and Vegetable Greenhouses" title="Direct link to Use Case 3: Monitoring Horticultural and Vegetable Greenhouses" translate="no">​</a></h2>
<p>Horticultural greenhouses represent a significant investment (50 to 300 €/m²), and their profitability depends on maintaining optimal climatic conditions. IoT monitoring helps detect issues—such as heating failures, blocked ventilation, or torn plastic sheeting—before they cause irreversible damage to crops.</p>
<p><strong>Parameters to monitor in a greenhouse:</strong></p>
<table><thead><tr><th>Parameter</th><th>Importance</th><th>Interface</th></tr></thead><tbody><tr><td>Air temperature (°C)</td><td>Critical</td><td>PT100/PT1000 or Modbus</td></tr><tr><td>Relative humidity (%)</td><td>High</td><td>Modbus RS-485</td></tr><tr><td>Solar radiation (W/m²)</td><td>Medium</td><td>4–20 mA (pyranometer)</td></tr><tr><td>Ambient CO₂ (ppm)</td><td>High (if CO₂ enrichment)</td><td>Modbus RS-485</td></tr><tr><td>Leaf temperature (°C)</td><td>Optional</td><td>Thermocouple</td></tr><tr><td>Irrigation water consumption (m³/day)</td><td>High</td><td>Pulse or Modbus</td></tr><tr><td>Nutrient solution temperature (°C)</td><td>High (soil-less)</td><td>PT100 or 4–20 mA</td></tr><tr><td>Nutrient solution EC (mS/cm)</td><td>High (soil-less)</td><td>4–20 mA</td></tr><tr><td>Nutrient solution pH</td><td>High (soil-less)</td><td>4–20 mA</td></tr></tbody></table>
<p><strong>Greenhouse equipment that can be monitored:</strong></p>
<ul>
<li class="">Boilers and heat pumps (heating): Bosch, Vaillant, Viessmann — via Modbus or digital relays</li>
<li class="">Fans and vents: 0-10V control or relay</li>
<li class="">Irrigation pumps: Modbus variable-frequency drive</li>
<li class="">Water treatment unit (UVA, reverse osmosis system): digital on/off inputs</li>
</ul>
<p><strong>ROI for vegetable greenhouse monitoring:</strong>
For a 5,000 m² tomato greenhouse (annual production ~500 t, resale price ~0.80€/kg = 400,000€ in annual revenue), an undetected heating failure at night in March can destroy an entire crop—resulting in a loss of €100,000 to €200,000. The cost of an Eziwan gateway with SMS alerts: €500 + €100/year for the subscription. Immediate ROI.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="use-case-4-irrigation-management">Use Case 4: Irrigation Management<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#use-case-4-irrigation-management" class="hash-link" aria-label="Direct link to Use Case 4: Irrigation Management" title="Direct link to Use Case 4: Irrigation Management" translate="no">​</a></h2>
<p>Irrigation accounts for 45% of industrial water consumption in France. Regulations are becoming stricter (decrees imposing restrictions during low-flow periods, water fees), making precise irrigation management essential.</p>
<p><strong>IoT-Based Irrigation Monitoring:</strong></p>
<ul>
<li class=""><strong>Field-specific flow meters</strong>: measurement of the volume of water applied per field or per crop (Modbus or pulse)</li>
<li class=""><strong>Soil moisture sensors</strong> (tensiometers, TDR sensors): measure volumetric moisture and soil suction—data used to trigger irrigation</li>
<li class=""><strong>Integrated weather stations</strong>: Potential Evapotranspiration (PET) calculated in real time, integrated with Météo France for forecast PET</li>
<li class=""><strong>Well water meters</strong>: tracking of water volumes withdrawn for DDT reporting (regulatory requirements &gt; 1,000 m³/year)</li>
<li class=""><strong>Well pumps and irrigation units</strong>: monitoring of status and electricity consumption</li>
</ul>
<p><strong>Regulatory Compliance:</strong>
Facilities that withdraw more than 1,000 m³/year of groundwater or surface water must report their withdrawals (Article L214-1 of the Environmental Code). Eziwan automatically generates monthly withdrawal reports for submission to the DDT/DREAL.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="use-case-5-storage-silos">Use Case 5: Storage Silos<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#use-case-5-storage-silos" class="hash-link" aria-label="Direct link to Use Case 5: Storage Silos" title="Direct link to Use Case 5: Storage Silos" translate="no">​</a></h2>
<p>Grain storage is a major economic issue. Inadequate storage conditions (temperature, humidity) can lead to the formation of mycotoxins (aflatoxins, DON) or mold, which can degrade the quality of the grain or render it unsellable.</p>
<p><strong>Parameters to monitor:</strong></p>
<ul>
<li class=""><strong>Temperature</strong>: silo temperature chains (Rolfes, GSI) with 4 to 8 probes per silo at different heights</li>
<li class=""><strong>Moisture</strong>: grain moisture sensors, either continuous or at the silo inlet (receiving silo)</li>
<li class=""><strong>Level</strong>: ultrasonic or pressure-based level sensors to determine stored volume</li>
<li class=""><strong>Ventilation</strong>: status of exhaust and cooling fans, airflow (m³/h)</li>
<li class=""><strong>Electricity consumption</strong>: automatic fan control based on temperature</li>
</ul>
<p><strong>Interface:</strong> Most modern silo control systems (Superchief, GSI Fan Controller, Brock NECO) have a Modbus RS-485 output or an RS-232 port.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="4g-connectivity-for-farms">4G Connectivity for Farms<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#4g-connectivity-for-farms" class="hash-link" aria-label="Direct link to 4G Connectivity for Farms" title="Direct link to 4G Connectivity for Farms" translate="no">​</a></h2>
<p>The vast majority of French farms do not have fiber-optic connectivity. 4G LTE covers <strong>99.2% of French municipalities</strong> (source: Arcep 2025), but coverage inside buildings can be poor.</p>
<p><strong>Solutions for areas with poor coverage:</strong></p>
<ol>
<li class="">
<p><strong>External directional 4G antenna</strong>: gain of 9 to 15 dBi, range of up to 30 km in direct line of sight, compatible with all carriers. Mounts on the edge of a building’s gable or on a mast.</p>
</li>
<li class="">
<p><strong>Eziwan Multi-Carrier SIM</strong>: Tests all three French carriers (Orange, SFR, Bouygues) and connects to the best available signal. Significantly improves coverage in rural areas.</p>
</li>
<li class="">
<p><strong>LoRa + 4G Gateway</strong>: For sensors with very low power consumption and located at great distances (up to 15 km), a LoRaWAN architecture with a LoRa concentrator connected via 4G through the Eziwan Gateway can cover an entire facility.</p>
</li>
<li class="">
<p><strong>Satellite connection (last resort)</strong>: For locations with no 4G coverage, a satellite option (Starlink low-latency or Eutelsat ViaSat) can be integrated with the Eziwan Gateway. Latency is 20–40 ms with Starlink.</p>
</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="agricultural-regulations-and-the-iot">Agricultural Regulations and the IoT<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#agricultural-regulations-and-the-iot" class="hash-link" aria-label="Direct link to Agricultural Regulations and the IoT" title="Direct link to Agricultural Regulations and the IoT" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="animal-welfare">Animal Welfare<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#animal-welfare" class="hash-link" aria-label="Direct link to Animal Welfare" title="Direct link to Animal Welfare" translate="no">​</a></h3>
<p>European Directive 2008/120/EC (pigs), 2007/43/EC (broiler chickens), and 1999/74/EC (laying hens) require minimum standards for temperature, space, ventilation, and lighting. IoT monitoring makes it possible to:</p>
<ul>
<li class="">Continuously document compliance with regulatory thresholds</li>
<li class="">Provide evidence during inspections by the DDPP (Departmental Directorate for Population Protection)</li>
<li class="">Issue immediate alerts if a regulatory threshold is exceeded</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="nitrates-directive">Nitrates Directive<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#nitrates-directive" class="hash-link" aria-label="Direct link to Nitrates Directive" title="Direct link to Nitrates Directive" translate="no">​</a></h3>
<p>Farms located in nitrate-vulnerable zones are subject to the Regional Action Program (PAR). Monitoring of manure application and effluent management (flow meter on the spreader boom, tank level) facilitates compliance with application bans and the calculation of application rates.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="supply-chain-traceability">Supply Chain Traceability<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#supply-chain-traceability" class="hash-link" aria-label="Direct link to Supply Chain Traceability" title="Direct link to Supply Chain Traceability" translate="no">​</a></h3>
<p>Many industry standards (Label Rouge, AOP, IGP, organic farming) require traceability of farming or growing conditions. Eziwan’s IoT data is archived and can be exported to feed into traceability tools (Bluerex, Kite Consulting, OAD-Systèmes).</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="costs-and-roi-for-a-farm">Costs and ROI for a Farm<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#costs-and-roi-for-a-farm" class="hash-link" aria-label="Direct link to Costs and ROI for a Farm" title="Direct link to Costs and ROI for a Farm" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="typical-investment">Typical Investment<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#typical-investment" class="hash-link" aria-label="Direct link to Typical Investment" title="Direct link to Typical Investment" translate="no">​</a></h3>
<table><thead><tr><th>Equipment</th><th>Estimated Cost</th></tr></thead><tbody><tr><td>Eziwan Gateway + M2M SIM</td><td>350–500 €</td></tr><tr><td>External 4G antenna (if needed)</td><td>80–150 €</td></tr><tr><td>Temperature/humidity sensors (×3)</td><td>150–400 €</td></tr><tr><td>RS-485 cabling (50 m)</td><td>40–80 €</td></tr><tr><td>Installation (2 hours by a technician)</td><td>200–400 €</td></tr><tr><td><strong>Total installation (1 building)</strong></td><td><strong>820–1,530 €</strong></td></tr></tbody></table>
<table><thead><tr><th>Subscription</th><th>Annual Cost</th></tr></thead><tbody><tr><td>Eziwan Platform (1 gateway)</td><td>120–240 €</td></tr><tr><td>M2M SIM (200 MB/month plan)</td><td>60–120 €</td></tr><tr><td><strong>Annual Total</strong></td><td><strong>€180–360</strong></td></tr></tbody></table>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="roi-for-a-dairy-farm">ROI for a Dairy Farm<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#roi-for-a-dairy-farm" class="hash-link" aria-label="Direct link to ROI for a Dairy Farm" title="Direct link to ROI for a Dairy Farm" translate="no">​</a></h3>
<ul>
<li class=""><strong>Cost of a collection refusal</strong>: €600 to €2,000 (depending on volume + penalties)</li>
<li class=""><strong>Annual risk without supervision</strong>: 1 to 2 tank incidents per year over 5 years of operation</li>
<li class=""><strong>Annualized cost of an incident</strong>: €600 to €800 per year</li>
<li class=""><strong>Supervision cost</strong>: €250 to €400 per year</li>
<li class=""><strong>Net ROI</strong>: €200 to €550 per year = paid off in less than 1 year</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="available-assistance">Available Assistance<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#available-assistance" class="hash-link" aria-label="Direct link to Available Assistance" title="Direct link to Available Assistance" translate="no">​</a></h3>
<p>The <strong>France 2030</strong> plan and PCAE (Farm Competitiveness and Adaptation Plan) grants partially fund equipment for digital agricultural modernization. Subsidy rates vary by region and program (30 to 50% of eligible investments). Contact your chamber of agriculture or your FranceAgriMer advisor to find out which programs apply to your project.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion">Conclusion<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#conclusion" class="hash-link" aria-label="Direct link to Conclusion" title="Direct link to Conclusion" translate="no">​</a></h2>
<p>Industrial IoT is now accessible to French farms, thanks to widespread 4G coverage, standardized Modbus sensors, and cost-effective cloud platforms like Eziwan. The technical and financial barriers that had been holding back adoption have been significantly reduced.</p>
<p>For an initial investment of €1,000 to €2,000 per building and a subscription fee of less than €400 per year, a farmer benefits from 24/7 monitoring of their critical equipment, immediate SMS alerts, and a documented history to meet their regulatory obligations.</p>
<p><strong>Next step:</strong> Contact the Eziwan team for a free feasibility study tailored to your farm and your type of production.</p>
<hr>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>Is 4G available in rural agricultural areas of France?</strong>
4G coverage in metropolitan France reaches over 99% of the population but only ~80% of the country’s total land area—some farms in “white spots” remain without coverage. For these areas: the NB-IoT (NarrowBand-IoT) network offers better penetration inside buildings and greater range, and satellite solutions (Starlink) are becoming available for completely isolated sites. It is essential to verify coverage at the exact site beforehand before any deployment.</p>
<p><strong>Can an existing grain silo or cooperative warehouse be connected without replacing the equipment?</strong>
In the vast majority of cases, yes. Modern silos have temperature and humidity sensors with 4–20 mA or RS485 Modbus outputs—an IoT gateway connects directly to them. For older equipment without a digital interface, replacement sensors compatible with Modbus RTU are available starting at €50 to €100 per measurement point.</p>
<p><strong>What regulatory requirements can IoT monitoring help document?</strong>
In livestock farming: health traceability requirements (preventive measures, animal identification, transport conditions—EU Regulation 2016/429), animal welfare (temperatures, ventilation, stocking density), and DPE/PAC inspections can rely on IoT data histories as evidence. The automatic log of all measurements with a certified timestamp is a significant advantage during inspections.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/water-wastewater-monitoring-4g-lte">Blog: 4G Water and Wastewater Monitoring — Water Management for Municipalities</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/industrial-iot-roi-calculation">Blog: ROI of Industrial IoT — Calculation and Optimization</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/monitoring-rsrp-rsrq-industrial-4g-signal">Blog: 4G signal monitoring — RSRP, RSRQ, and rural coverage</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison">Blog: M2M IoT SIM cards — comparison of French carriers in 2026</a></li>
</ul>
<hr>
<p><em>Eziwan helps farmers, cooperatives, and storage facilities monitor their operations using IoT technology. Our solution integrates with existing equipment without requiring replacement, featuring 4G connectivity optimized for rural areas. <a class="" href="https://eziwan.com/en/secteurs">Discover our solutions →</a></em></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/iot-agriculture-livestock-monitoring#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/remote-irrigation-monitoring">Remote Irrigation Monitoring</a> — control and monitoring of irrigation systems via IoT</li>
<li class=""><a class="" href="https://eziwan.com/en/internet-connection-remote-industrial-site">Internet Connection for Remote Industrial Sites</a> — 4G connectivity for farms in rural areas</li>
<li class=""><a class="" href="https://eziwan.com/en/monitoring-equipements-industriels">Industrial Equipment Monitoring</a> — monitoring of agricultural and storage equipment</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-connectivity">Industrial Connectivity</a> — robust connectivity solutions for rural areas</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-solutions">Eziwan Industrial Solutions</a> — a range of IoT solutions tailored to primary sectors</li>
</ul>]]></content:encoded>
            <category>agriculture</category>
            <category>industrial-iot</category>
            <category>monitoring</category>
            <category>supervision</category>
            <category>4g</category>
            <category>edge-computing</category>
        </item>
        <item>
            <title><![CDATA[Drinking Water Network Monitoring: An IoT Guide for French Municipalities 2026]]></title>
            <link>https://eziwan.com/en/blog/drinking-water-network-monitoring-guide</link>
            <guid>https://eziwan.com/en/blog/drinking-water-network-monitoring-guide</guid>
            <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A Comprehensive Guide to Modernizing the Monitoring of Your Drinking Water Networks: SOFREL Migration, M-Bus/Modbus Protocols, ARS Compliance, NIS2, and ROI for French Municipalities.]]></description>
            <content:encoded><![CDATA[<p>Modernizing the remote management of drinking water networks has become a priority for French local governments. Faced with increasing regulatory requirements (self-monitoring, NIS2, GDPR), aging remote monitoring equipment from the 2000s, and the performance requirements of public service delegation contracts, water utilities must rethink their monitoring architecture.</p>
<p>This practical guide is intended for technical managers, water and wastewater directors, and chief information officers (CIOs) at local government entities—water districts, municipal utilities, and intermunicipal associations—that oversee drinking water systems.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="current-status-the-water-remote-management-infrastructure-in-france">Current Status: The Water Remote Management Infrastructure in France<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#current-status-the-water-remote-management-infrastructure-in-france" class="hash-link" aria-label="Direct link to Current Status: The Water Remote Management Infrastructure in France" title="Direct link to Current Status: The Water Remote Management Infrastructure in France" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="an-aging-fleet">An Aging Fleet<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#an-aging-fleet" class="hash-link" aria-label="Direct link to An Aging Fleet" title="Direct link to An Aging Fleet" translate="no">​</a></h3>
<p>Remote management of drinking water networks in France currently relies heavily on equipment installed between 2000 and 2015. The dominant technologies are:</p>
<ul>
<li class=""><strong>SOFREL S4W/S500 Modems</strong>: Deployed on a large scale by concession operators (Veolia, Suez, Saur) across water networks, these GSM/GPRS modems use the 2G/EDGE network, which is currently being phased out</li>
<li class=""><strong>Servelec RTUs</strong> (formerly Sontay) and <strong>Lacroix Sofrel</strong>: a range of RTUs designed specifically for water systems, used at pumping and treatment plants</li>
<li class=""><strong>Concessionaires’ proprietary systems</strong>: Each concession operator has deployed its own infrastructure (Veolia Hub Eau, Suez IntelliO) using proprietary protocols that limit the ability to take over operations directly</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-2g-shutdown-a-catalyst-for-modernization">The 2G Shutdown: A Catalyst for Modernization<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#the-2g-shutdown-a-catalyst-for-modernization" class="hash-link" aria-label="Direct link to The 2G Shutdown: A Catalyst for Modernization" title="Direct link to The 2G Shutdown: A Catalyst for Modernization" translate="no">​</a></h3>
<p>Orange has officially announced that it will shut down its 2G network in <strong>2026</strong> (after several delays). SFR has already shut down its 2G network in several areas. Bouygues Telecom is following the same path.</p>
<p>SOFREL S4W modems and other 2G/GPRS RTUs used at water towers, pumping stations, and lift stations <strong>will no longer work</strong> after these shutdowns.</p>
<p>This is a major opportunity to modernize by transitioning to 4G LTE solutions with a centralized cloud-based monitoring platform.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="modern-monitoring-architecture-for-a-drinking-water-network">Modern Monitoring Architecture for a Drinking Water Network<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#modern-monitoring-architecture-for-a-drinking-water-network" class="hash-link" aria-label="Direct link to Modern Monitoring Architecture for a Drinking Water Network" title="Direct link to Modern Monitoring Architecture for a Drinking Water Network" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="typical-sites-to-monitor">Typical Sites to Monitor<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#typical-sites-to-monitor" class="hash-link" aria-label="Direct link to Typical Sites to Monitor" title="Direct link to Typical Sites to Monitor" translate="no">​</a></h3>
<table><thead><tr><th>Site Type</th><th>Key Parameters</th><th>Field Equipment</th></tr></thead><tbody><tr><td>Pumping station</td><td>Discharge flow rate, pressure, tank level, operating hours, power consumption</td><td>Schneider M340 or Siemens S7-1200 PLC, 4-20 mA sensors</td></tr><tr><td>Water tower / reservoir</td><td>Water level, inlet/outlet pressure, fill valve</td><td>Ultrasonic or pressure level sensor, Modbus flow meter</td></tr><tr><td>Treatment plant</td><td>Turbidity, residual chlorine, pH, conductivity, temperature, treated flow rate</td><td>YSI, Hach, and WTW multiparameter sensors via Modbus RS-485</td></tr><tr><td>Booster station</td><td>Downstream pressure, flow rate, pump status, motor faults</td><td>Modbus variable frequency drives, local PLC</td></tr><tr><td>Utility meter</td><td>Flow rate, meter reading, nighttime leak detection</td><td>MID-compliant meter with pulse or Modbus output</td></tr></tbody></table>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="recommended-architecture">Recommended Architecture<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#recommended-architecture" class="hash-link" aria-label="Direct link to Recommended Architecture" title="Direct link to Recommended Architecture" translate="no">​</a></h3>
<!-- -->
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="migration-from-existing-systems">Migration from Existing Systems<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#migration-from-existing-systems" class="hash-link" aria-label="Direct link to Migration from Existing Systems" title="Direct link to Migration from Existing Systems" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="replacing-a-sofrel-s4w-modem">Replacing a SOFREL S4W Modem<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#replacing-a-sofrel-s4w-modem" class="hash-link" aria-label="Direct link to Replacing a SOFREL S4W Modem" title="Direct link to Replacing a SOFREL S4W Modem" translate="no">​</a></h3>
<p>The SOFREL S4W is the most widely used modem on French water networks. The migration to the Eziwan Gateway is designed to be non-invasive.</p>
<p><strong>Migration Steps:</strong></p>
<ol>
<li class=""><strong>Preliminary Audit</strong> (1 hour remotely): identification of the Modbus registers configured on the S4W, mapping of the I/O used (digital inputs, analog inputs, relay outputs), list of current SMS recipients</li>
<li class=""><strong>Delivery of the pre-configured Gateway</strong>: The Eziwan Gateway is delivered with your configuration template (Modbus registers identical to those on the S4W, same alarm thresholds, same SMS recipients)</li>
<li class=""><strong>Physical Replacement</strong> (30–45 minutes per site): The Gateway connects to the same RS-485 wiring. The 4G SIM card is inserted and activated. The cloud connection is established automatically</li>
<li class=""><strong>Verification</strong>: An Eziwan technician takes remote control to validate data transmission and alerts</li>
<li class=""><strong>Commissioning</strong>: The site appears in the cloud dashboard with all its historical data (starting from the migration—S4W historical data is not transferred)</li>
</ol>
<p><strong>Compatibility:</strong> The Eziwan Gateway reads all Modbus registers configured on your PLC (Schneider M340, Siemens S7-1200, Lacroix E30, etc.). The migration does not require any modifications to the field PLC.</p>
<p><strong>Migration Cost:</strong> The Eziwan Gateway is less expensive than a new SOFREL S4W and offers expanded features (VPN, multi-protocol support, OTA). For a fleet of 50 stations, the return on investment compared to purchasing new S4W units is immediate.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="migration-from-a-delegated-system-end-of-dsp">Migration from a delegated system (end of DSP)<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#migration-from-a-delegated-system-end-of-dsp" class="hash-link" aria-label="Direct link to Migration from a delegated system (end of DSP)" title="Direct link to Migration from a delegated system (end of DSP)" translate="no">​</a></h3>
<p>When a project is brought back under direct municipal management or there is a change in the contractor, the local government often loses access to the outgoing operator’s proprietary monitoring system. The transition can result in weeks or months without centralized monitoring.</p>
<p><strong>Eziwan's Approach to DSP Transitions:</strong></p>
<ol>
<li class=""><strong>Early deployment</strong>: Install the Eziwan gateways 3–6 months before the end of the DSP contract, running in parallel with the existing system</li>
<li class=""><strong>Parallel validation</strong>: Compare Eziwan data with data from the outgoing operator to verify consistency</li>
<li class=""><strong>Smooth transition</strong>: By the end of the DSP contract, the Eziwan monitoring system is already operational and validated</li>
<li class=""><strong>Historical data continuity</strong>: 3–6 months of historical data are already available on the Eziwan platform</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="regulatory-compliance">Regulatory Compliance<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#regulatory-compliance" class="hash-link" aria-label="Direct link to Regulatory Compliance" title="Direct link to Regulatory Compliance" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="self-monitoring-and-ars-requirements">Self-Monitoring and ARS Requirements<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#self-monitoring-and-ars-requirements" class="hash-link" aria-label="Direct link to Self-Monitoring and ARS Requirements" title="Direct link to Self-Monitoring and ARS Requirements" translate="no">​</a></h3>
<p>The decree of July 21, 2015, amending the decree of May 2, 2007, imposes self-monitoring requirements on wastewater treatment plants (WWTPs) and drinking water production units (DWPUs):</p>
<p><strong>Parameters to Monitor and Log (UPEP):</strong></p>
<ul>
<li class="">Treated water flow rate (m³/h and m³/day)</li>
<li class="">Turbidity of treated water (NTU) — alert threshold: &gt; 1 NTU</li>
<li class="">Residual chlorine content (mg/L) — alert threshold: &lt; 0.1 mg/L</li>
<li class="">pH (6.5 to 9.0)</li>
<li class="">Conductivity (μS/cm)</li>
<li class="">Temperature (°C)</li>
</ul>
<p><strong>Archiving Requirements:</strong></p>
<ul>
<li class="">Minimum retention period of 5 years</li>
<li class="">Certified UTC timestamp</li>
<li class="">SANDRE-compatible export format for transmission to government agencies</li>
<li class="">Access available to DDETSPP (formerly DDASS) upon request</li>
</ul>
<p><strong>How Eziwan Meets These Requirements:</strong></p>
<ul>
<li class="">Minimum 10-year data retention (beyond the regulatory 5-year requirement)</li>
<li class="">UTC timestamps on each measurement, digitally signed</li>
<li class="">CSV and JSON exports in SANDRE format</li>
<li class="">API access for regulatory agencies</li>
<li class="">Configurable automatic daily and weekly reports</li>
</ul>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="nis2-directive-applicability-to-drinking-water">NIS2 Directive: Applicability to Drinking Water<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#nis2-directive-applicability-to-drinking-water" class="hash-link" aria-label="Direct link to NIS2 Directive: Applicability to Drinking Water" title="Direct link to NIS2 Directive: Applicability to Drinking Water" translate="no">​</a></h3>
<p>The transposition of the NIS2 Directive into French law (Law of April 16, 2024) classifies water operators into categories based on their size:</p>
<p><strong>Key Entities:</strong></p>
<ul>
<li class="">Drinking water operators serving &gt; 50,000 people OR</li>
<li class="">Revenue &gt; 50 M€ OR</li>
<li class="">Designated as OIV (Operators of Vital Importance)</li>
</ul>
<p><strong>Significant Entities:</strong></p>
<ul>
<li class="">Drinking water utilities serving more than 10,000 people OR</li>
<li class="">Revenue greater than 10 M€</li>
</ul>
<p><strong>NIS2 requirements relevant to remote water management:</strong></p>
<table><thead><tr><th>Requirement</th><th>Requirement</th><th>How Eziwan Meets It</th></tr></thead><tbody><tr><td>OT/IT network segmentation</td><td>OT gateway isolated from the office network</td><td>Gateway operates in the OT zone; no incoming traffic</td></tr><tr><td>Remote access control</td><td>MFA + logging</td><td>OpenVPN/IPSec VPN + MFA + full session log</td></tr><tr><td>Vulnerability management</td><td>Patch management</td><td>Automatic OTA firmware updates for the gateway</td></tr><tr><td>Incident notification</td><td>&lt; 24 hours to ANSSI</td><td>Exportable incident log, documented procedure</td></tr><tr><td>Subcontracting chain</td><td>Vendor audit</td><td>Eziwan ISO 27001 certified, hosting in France, GDPR compliant</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="case-study-water-district-with-80-stations">Case Study: Water District with 80 Stations<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#case-study-water-district-with-80-stations" class="hash-link" aria-label="Direct link to Case Study: Water District with 80 Stations" title="Direct link to Case Study: Water District with 80 Stations" translate="no">​</a></h2>
<p><strong>Background:</strong> An intermunicipal association manages 80 pumping stations (12 to 350 m³/h) and 6 water towers across a rural area comprising 45 municipalities. Existing equipment: SOFREL S4W 2G modems, limited local monitoring, 3 technicians.</p>
<p><strong>Issues:</strong></p>
<ul>
<li class="">40% of stations lack automatic alarms (outages are detected through calls from residents)</li>
<li class="">The 2G network is being phased out in the region</li>
<li class="">NIS2 requirement (municipal district serving &gt; 15,000 residents)</li>
<li class="">Performance contract requiring a service availability rate of &gt; 99.5%</li>
</ul>
<p><strong>Eziwan Deployment:</strong></p>
<ul>
<li class="">80 Eziwan gateways (1 per station) delivered pre-configured within 3 weeks</li>
<li class="">Migration from S4W systems in 6 weeks (13 stations per week, 2 technicians)</li>
<li class="">Configuration: 8 to 24 Modbus registers per station, SMS/email alerts</li>
<li class="">Centralized dashboard: real-time view of all 80 stations, GIS mapping</li>
</ul>
<p><strong>6-Month Results:</strong></p>
<ul>
<li class="">Unplanned service calls reduced by 68% (from 240 to 77 calls per year)</li>
<li class="">Detection of a major leak in a discharge line (abnormal nighttime flow automatically detected at 2 a.m., repair completed at 6 a.m.)</li>
<li class="">Documented NIS2 compliance (external audit passed)</li>
<li class="">Estimated savings: €95,000 per year (avoided service calls + avoided damage)</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="compatible-protocols-and-equipment">Compatible Protocols and Equipment<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#compatible-protocols-and-equipment" class="hash-link" aria-label="Direct link to Compatible Protocols and Equipment" title="Direct link to Compatible Protocols and Equipment" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="water-meters">Water Meters<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#water-meters" class="hash-link" aria-label="Direct link to Water Meters" title="Direct link to Water Meters" translate="no">​</a></h3>
<table><thead><tr><th>Protocol</th><th>Compatible Meters</th><th>Collected Parameters</th></tr></thead><tbody><tr><td>M-Bus (EN 13757)</td><td>Sensus iPERL, Itron Actaris BDE, Landis+Gyr E120, Sagemcom</td><td>Reading (m³), instantaneous flow rate, alarms (tampering, dry run)</td></tr><tr><td>Pulse (digital input)</td><td>Any meter with a pulse output (reed switch output)</td><td>Cumulative reading, calculated flow rate (number of pulses × volume per pulse)</td></tr><tr><td>Modbus RTU</td><td>Endress+Hauser Promag, Krohne Optiflux, Siemens Sitrans FM</td><td>Flow rate (m³/h), velocity (m/s), temperature, cumulative reading</td></tr><tr><td>MBUS LoRaWAN</td><td>LoRaWAN meters for areas without coverage</td><td>Via LoRaWAN concentrator + Eziwan gateway (MQTT)</td></tr></tbody></table>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="water-sensors">Water Sensors<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#water-sensors" class="hash-link" aria-label="Direct link to Water Sensors" title="Direct link to Water Sensors" translate="no">​</a></h3>
<table><thead><tr><th>Parameter</th><th>Compatible Sensors</th><th>Interface</th></tr></thead><tbody><tr><td>Residual Chlorine</td><td>Hach CL17sc, YSI MultiLab, Bürkert Type 8905</td><td>Modbus RS-485 or 4-20 mA</td></tr><tr><td>pH/ORP</td><td>WTW IQ SensorNet, Endress+Hauser CPS11D</td><td>Modbus RS-485 or 4–20 mA</td></tr><tr><td>Turbidity</td><td>Hach TU5200, Yokogawa FLXA21</td><td>Modbus RS-485</td></tr><tr><td>Conductivity</td><td>Endress+Hauser Liquiline CM44</td><td>Modbus RS-485</td></tr><tr><td>Level</td><td>Vega Vegapuls, Endress+Hauser FMR51, Keller Series 26</td><td>4–20 mA or Modbus</td></tr></tbody></table>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="water-field-controllers">Water Field Controllers<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#water-field-controllers" class="hash-link" aria-label="Direct link to Water Field Controllers" title="Direct link to Water Field Controllers" translate="no">​</a></h3>
<table><thead><tr><th>PLC</th><th>Interface</th><th>Compatibility</th></tr></thead><tbody><tr><td>Schneider Electric M340</td><td>Modbus RTU RS-485</td><td>✅ Tested and validated</td></tr><tr><td>Schneider Electric M221/M241</td><td>Modbus RTU RS-485 + Modbus TCP</td><td>✅ Tested and validated</td></tr><tr><td>Siemens S7-1200/S7-1500</td><td>Modbus TCP (via Ethernet)</td><td>✅ Tested and validated</td></tr><tr><td>Lacroix Tbox LT2 / MS3</td><td>Modbus RTU / TCP</td><td>✅ Compatible</td></tr><tr><td>Wago 750-860</td><td>Modbus TCP</td><td>✅ Compatible</td></tr><tr><td>CODESYS Modbus Slave</td><td>Modbus RTU / TCP</td><td>✅ Compatible</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="calculating-roi-for-a-local-government">Calculating ROI for a Local Government<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#calculating-roi-for-a-local-government" class="hash-link" aria-label="Direct link to Calculating ROI for a Local Government" title="Direct link to Calculating ROI for a Local Government" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="costs-avoided-through-iot-monitoring">Costs Avoided Through IoT Monitoring<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#costs-avoided-through-iot-monitoring" class="hash-link" aria-label="Direct link to Costs Avoided Through IoT Monitoring" title="Direct link to Costs Avoided Through IoT Monitoring" translate="no">​</a></h3>
<p><strong>Technician Service Calls:</strong></p>
<ul>
<li class="">Average cost of an unscheduled service call: €180 to €350 (1.5 hours round trip + diagnosis)</li>
<li class="">Typical reduction with Eziwan: 60 to 75% of unscheduled service calls avoided</li>
<li class="">Example: 80 stations, 3 technicians: 240 service calls/year → 77 service calls/year = <strong>163 service calls avoided × €250 = €40,750/year</strong></li>
</ul>
<p><strong>Damage Avoided (Leaks, Failures, Overflows):</strong></p>
<ul>
<li class="">Undetected discharge line leak: 5,000 to 50,000 m³ lost before manual detection</li>
<li class="">Cost per m³ of treated water: €0.80 to €1.20</li>
<li class="">Example: 1 leak of 15,000 m³ prevented = <strong>€12,000 to €18,000 per year</strong></li>
</ul>
<p><strong>On-Call Duty:</strong></p>
<ul>
<li class="">Reduction in nighttime emergency calls: -40 to 60%</li>
<li class="">Savings on on-call premiums and overtime: €10,000 to €25,000 per year, depending on the fleet</li>
</ul>
<p><strong>Regulatory Compliance:</strong></p>
<ul>
<li class="">Avoid receiving a formal notice from the ARS due to an undetected threshold violation</li>
<li class="">Estimated cost of a documented non-compliance: €15,000 to €50,000 (urgent repairs + external audit)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="example-of-an-roi-calculation-for-80-stations">Example of an ROI calculation for 80 stations<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#example-of-an-roi-calculation-for-80-stations" class="hash-link" aria-label="Direct link to Example of an ROI calculation for 80 stations" title="Direct link to Example of an ROI calculation for 80 stations" translate="no">​</a></h3>
<table><thead><tr><th>Item</th><th>Annual Value</th></tr></thead><tbody><tr><td>Avoided travel</td><td>40,750 €</td></tr><tr><td>Early detection of leaks</td><td>15,000 €</td></tr><tr><td>Reduction in on-call fees</td><td>15,000 €</td></tr><tr><td>Avoided regulatory non-compliance</td><td>10,000 €</td></tr><tr><td><strong>Total estimated annual savings</strong></td><td><strong>80,750 €</strong></td></tr></tbody></table>
<table><thead><tr><th>Investment</th><th>Amount</th></tr></thead><tbody><tr><td>80 Eziwan gateways + installation</td><td>48,000 €</td></tr><tr><td>Cloud subscription (80 sites/year)</td><td>14,400 €</td></tr><tr><td>4G M2M SIM cards (80 sites × 10€/month)</td><td>9,600 €</td></tr><tr><td><strong>Total investment for Year 1</strong></td><td><strong>72,000 €</strong></td></tr></tbody></table>
<p><strong>ROI in Year 1:</strong> 80,750 − 72,000 = <strong>+8,750 € in the first year</strong>
<strong>ROI starting in Year 2:</strong> 80,750 − (14,400 + 9,600) = <strong>+56,750 €/year</strong></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="funding-and-available-assistance">Funding and Available Assistance<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#funding-and-available-assistance" class="hash-link" aria-label="Direct link to Funding and Available Assistance" title="Direct link to Funding and Available Assistance" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="erdf-and-regional-allocations">ERDF and Regional Allocations<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#erdf-and-regional-allocations" class="hash-link" aria-label="Direct link to ERDF and Regional Allocations" title="Direct link to ERDF and Regional Allocations" translate="no">​</a></h3>
<p>Projects to modernize remote management systems for drinking water networks may be eligible for ERDF (European Regional Development Fund) funding under the 2021–2027 regional operational programs, specifically under the "Digital Transition of Public Services" priority axis.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="water-agencies">Water Agencies<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#water-agencies" class="hash-link" aria-label="Direct link to Water Agencies" title="Direct link to Water Agencies" translate="no">​</a></h3>
<p>The six French water agencies (Artois-Picardie, Rhine-Meuse, Seine-Normandy, Loire-Brittany, Adour-Garonne, Rhône-Mediterranean-Corsica) offer grants to modernize water network management. Eligibility criteria include reducing leaks (network efficiency), regulatory compliance, and digital transformation.</p>
<p>Contact your local water agency to find out about current programs and the subsidy rates applicable to your project.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="local-investment-support-grant-dsil-and-detr">Local Investment Support Grant (DSIL) and DETR<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#local-investment-support-grant-dsil-and-detr" class="hash-link" aria-label="Direct link to Local Investment Support Grant (DSIL) and DETR" title="Direct link to Local Investment Support Grant (DSIL) and DETR" translate="no">​</a></h3>
<p>The DSIL and the DETR (Fund for Rural Infrastructure) can provide funding for digital projects in rural communities. Projects to modernize water networks using IoT technology align with the “local services” and “digital transition” objectives of these funding programs.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>Is IoT monitoring eligible for the France Relance Plan or regional grants?</strong>
Yes, several programs may apply. The DSIL (Local Investment Support Grant) funds local governments’ digital projects. The DETR (Rural Areas Infrastructure Grant) covers rural municipalities. Water agencies (Seine-Normandy, Loire-Brittany, etc.) have specific programs for reducing water loss and self-monitoring. A technical proposal with a quantified ROI (savings from reduced leaks, avoided costs) is generally required.</p>
<p><strong>Is migrating from an existing SOFREL system disruptive?</strong>
No. The Eziwan gateway connects in parallel with existing SOFREL equipment via Modbus RTU/TCP or 4–20 mA. There is no need to shut down the existing system during the transition. The migration can be carried out in phases: first, data reading; then, a gradual switchover of pilot stations; and finally, complete replacement according to your equipment replacement schedule.</p>
<p><strong>How does the solution meet the ARS self-monitoring reporting requirements?</strong>
The Eziwan platform allows self-monitoring data to be exported in the required formats (CSV, Excel) with certified timestamps. Performance indicators (loss rates, nominal vs. actual flow, pressure incidents) are automatically calculated from the meter readings and can be extracted for the time periods requested by the ARS.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion-and-next-steps">Conclusion and Next Steps<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#conclusion-and-next-steps" class="hash-link" aria-label="Direct link to Conclusion and Next Steps" title="Direct link to Conclusion and Next Steps" translate="no">​</a></h2>
<p>Modernizing remote management systems for drinking water is no longer an option for French municipalities. The phase-out of 2G networks, NIS2 requirements, ARS self-monitoring requirements, and pressure to reduce operating costs are all converging to make this investment essential.</p>
<p>The good news: ROI is quick (usually less than 18 months), migration from existing systems (SOFREL, etc.) is well-documented and non-invasive, and modern solutions (4G gateway + cloud) are significantly less expensive than first-generation proprietary equipment.</p>
<p><strong>Your next steps:</strong></p>
<ol>
<li class=""><strong>Audit of your current infrastructure</strong>: equipment inventory, identification of 2G modems, mapping of field controllers</li>
<li class=""><strong>ROI simulation</strong>: our team can prepare a customized calculation based on your infrastructure</li>
<li class=""><strong>Pilot project</strong>: Start with 5 to 10 pilot stations to validate the solution before a full-scale deployment</li>
</ol>
<p><a class="" href="https://eziwan.com/en/contact">Contact the Eziwan team</a> for a free audit of your remote water management infrastructure.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/water-wastewater-monitoring-4g-lte">Blog: 4G Water and Wastewater Monitoring — Feedback from the Field</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/remote-meter-reading-gprs-4g">Blog: GPRS to 4G Remote Meter Reading — A Practical Migration</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/modbus-tcp-vs-rtu">Blog: Modbus TCP vs. RTU — A Comprehensive Guide for Water Networks</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry">Blog: NIS2 Checklist — 30 Checkpoints for Local Governments</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison">Blog: M2M IoT SIM Cards — Operator Comparison for Rural Networks</a></li>
</ul>
<hr>
<p><em>Eziwan partners with local governments, water utilities, and municipal agencies to modernize their remote management systems. We support DSP transitions and migrations from SOFREL, Lacroix, and other water RTU systems. <a class="" href="https://eziwan.com/en/solution-eau-assainissement">Learn more about our water solution →</a></em></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/drinking-water-network-monitoring-guide#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/solution-eau-assainissement">Water &amp; Wastewater Solutions</a> — IoT monitoring of drinking water networks for municipalities</li>
<li class=""><a class="" href="https://eziwan.com/en/water-tower-monitoring">Water Tower Monitoring</a> — remote management of municipal water towers and reservoirs</li>
<li class=""><a class="" href="https://eziwan.com/en/wireless-m-bus-remote-metering">Wireless M-Bus Meter Reading</a> — automatic water meter reading via radio</li>
<li class=""><a class="" href="https://eziwan.com/en/water-tank-monitoring">Water Tank Monitoring</a> — real-time monitoring of levels and pressures</li>
<li class=""><a class="" href="https://eziwan.com/en/solution-stations-pompage">Pumping Station Solution</a> — remote monitoring and control of pumping stations</li>
</ul>]]></content:encoded>
            <category>water-and-sanitation</category>
            <category>supervision</category>
            <category>industrial-iot</category>
            <category>community</category>
            <category>modbus</category>
            <category>4g</category>
        </item>
        <item>
            <title><![CDATA[Cloud vs. On-Premise SCADA: A Decision-Making Guide for French Manufacturers, 2026]]></title>
            <link>https://eziwan.com/en/blog/scada-cloud-vs-on-premise</link>
            <guid>https://eziwan.com/en/blog/scada-cloud-vs-on-premise</guid>
            <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Cloud-Based or On-Premises SCADA? A Comparison of TCO, Security, Latency, and Compliance. A Comprehensive Guide to Choosing the Right Industrial Monitoring Architecture for Your Situation.]]></description>
            <content:encoded><![CDATA[<p><strong>Cloud or on-premises?</strong> That’s the question most industrial automation managers and CIOs are asking themselves today. SCADA monitoring is evolving: SaaS cloud solutions are gaining ground over traditional on-premises installations, but the choice isn’t always clear-cut.</p>
<p>This guide objectively compares the two architectures based on seven key criteria—total cost, security, latency, scalability, compliance, maintainability, and resilience—to help you make the right decision based on your industrial context.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-were-comparing">What We're Comparing<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#what-were-comparing" class="hash-link" aria-label="Direct link to What We're Comparing" title="Direct link to What We're Comparing" translate="no">​</a></h2>
<p><strong>On-premises (traditional) SCADA:</strong>
Physical server(s) installed on your premises or in your server room. SCADA software installed locally (Wonderware InTouch/System Platform, Ignition, PCVue, WinCC). Data history stored on a local SQL server. Access via the local area network (LAN) or via VPN for remote access.</p>
<p><strong>Cloud-based SCADA / IIoT SaaS:</strong>
A platform hosted in the cloud (AWS, Azure, GCP, or a French sovereign cloud). On-site industrial gateways that collect field data and send it to the cloud. Dashboard accessible from any browser. Historical data stored in the cloud. Examples: Eziwan, Axonize, Samsara, Siemens MindSphere, AWS IoT SiteWise.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-1-total-cost-of-ownership-tco-over-3-years">Criterion 1: Total Cost of Ownership (TCO over 3 years)<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#criterion-1-total-cost-of-ownership-tco-over-3-years" class="hash-link" aria-label="Direct link to Criterion 1: Total Cost of Ownership (TCO over 3 years)" title="Direct link to Criterion 1: Total Cost of Ownership (TCO over 3 years)" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="on-premises-scada--typical-tco-for-10-industrial-sites">On-Premises SCADA — Typical TCO for 10 Industrial Sites<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#on-premises-scada--typical-tco-for-10-industrial-sites" class="hash-link" aria-label="Direct link to On-Premises SCADA — Typical TCO for 10 Industrial Sites" title="Direct link to On-Premises SCADA — Typical TCO for 10 Industrial Sites" translate="no">​</a></h3>
<table><thead><tr><th>Item</th><th>Cost (3 years)</th></tr></thead><tbody><tr><td>SCADA software licenses (Wonderware System Platform, 10 connections)</td><td>45,000 – 80,000 €</td></tr><tr><td>Physical servers (2 redundant servers)</td><td>18,000 – 30,000 €</td></tr><tr><td>Network infrastructure (managed switches, routers)</td><td>8,000 – 15,000 €</td></tr><tr><td>Installation and configuration (system integrator)</td><td>20,000 – 40,000 €</td></tr><tr><td>Annual maintenance and support (15–20% of the license cost)</td><td>€20,000 – €45,000</td></tr><tr><td>Major updates (1 version every 3 years)</td><td>€15,000 – €25,000</td></tr><tr><td>Internal IT resources (administration, backups)</td><td>15,000 – 30,000 €</td></tr><tr><td><strong>3-Year Total</strong></td><td><strong>141,000 – 265,000 €</strong></td></tr></tbody></table>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="cloud-based-scada-saas--typical-tco-for-10-industrial-sites">Cloud-Based SCADA SaaS — Typical TCO for 10 Industrial Sites<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#cloud-based-scada-saas--typical-tco-for-10-industrial-sites" class="hash-link" aria-label="Direct link to Cloud-Based SCADA SaaS — Typical TCO for 10 Industrial Sites" title="Direct link to Cloud-Based SCADA SaaS — Typical TCO for 10 Industrial Sites" translate="no">​</a></h3>
<table><thead><tr><th>Item</th><th>Cost (3 years)</th></tr></thead><tbody><tr><td>Cloud platform subscription (10 sites, 500 data points)</td><td>18,000 – 36,000 €</td></tr><tr><td>Industrial gateways (1 per site × 10)</td><td>8,000 – 15,000 €</td></tr><tr><td>Installation and commissioning (simpler)</td><td>5,000 – 15,000 €</td></tr><tr><td>4G/M2M SIM connectivity (if no fiber)</td><td>3,600 – 7,200 €</td></tr><tr><td>Team training</td><td>2,000 – 5,000 €</td></tr><tr><td><strong>3-Year Total</strong></td><td><strong>36,600 – 78,200 €</strong></td></tr></tbody></table>
<p><strong>TCO Verdict:</strong> SaaS cloud solutions are <strong>2 to 4 times cheaper</strong> over a 3-year period for multi-site deployments. The cost advantage increases as the number of sites grows. For a single site with an existing SCADA system that has already been amortized, an on-premises solution may still be a viable option.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-2-safety">Criterion 2: Safety<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#criterion-2-safety" class="hash-link" aria-label="Direct link to Criterion 2: Safety" title="Direct link to Criterion 2: Safety" translate="no">​</a></h2>
<p>This is often the main argument put forward by advocates of on-premises solutions. Let's take a closer look at what's actually true.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="whats-true-for-on-premises-solutions">What's true for on-premises solutions:<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#whats-true-for-on-premises-solutions" class="hash-link" aria-label="Direct link to What's true for on-premises solutions:" title="Direct link to What's true for on-premises solutions:" translate="no">​</a></h3>
<ul>
<li class=""><strong>Data is physically located on your premises</strong> — no data is transmitted outside your premises</li>
<li class=""><strong>No reliance on a third party</strong> for data access</li>
<li class=""><strong>Possible isolation</strong> from the Internet (air gap)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="common-misconceptions-about-on-premises-systems">Common misconceptions about on-premises systems:<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#common-misconceptions-about-on-premises-systems" class="hash-link" aria-label="Direct link to Common misconceptions about on-premises systems:" title="Direct link to Common misconceptions about on-premises systems:" translate="no">​</a></h3>
<ul>
<li class=""><strong>"On-premises = more secure"</strong> — false in most cases. SMEs generally do not have a dedicated cybersecurity team. Their on-premises servers often run on unpatched Windows Server 2012/2016, without access monitoring or intrusion detection. An ISO 27001-certified cloud provider with a dedicated security team is generally <strong>more secure</strong> than an unmonitored server in a machine room.</li>
<li class=""><strong>"My data never leaves the facility"</strong> — true only if you have actually isolated the SCADA server. If you access the SCADA system from the Internet (RDP, VPN), the data is still transmitted.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-the-cloud-offers">What the cloud offers:<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#what-the-cloud-offers" class="hash-link" aria-label="Direct link to What the cloud offers:" title="Direct link to What the cloud offers:" translate="no">​</a></h3>
<ul>
<li class=""><strong>ISO 27001-certified hosting</strong> with a 24/7 security team</li>
<li class=""><strong>Encryption in transit and at rest</strong> (TLS 1.3, AES-256)</li>
<li class=""><strong>Automatic security updates</strong> — no unpatched CVEs for 3 years</li>
<li class="">Native <strong>MFA authentication</strong> for all access</li>
<li class="">Comprehensive, centralized <strong>audit logs</strong></li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-following-are-real-cloud-risks">The following are real cloud risks:<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#the-following-are-real-cloud-risks" class="hash-link" aria-label="Direct link to The following are real cloud risks:" title="Direct link to The following are real cloud risks:" translate="no">​</a></h3>
<ul>
<li class=""><strong>Internet availability</strong> — if the Internet connection goes down, you lose access to the remote SCADA system (but not local control, which remains on the PLCs)</li>
<li class=""><strong>Sovereign data compliance</strong> — if you process sensitive data (OIV, personal data), the choice of cloud provider is critical (France vs. the U.S.)</li>
</ul>
<p><strong>Security Verdict:</strong> At the same level of maturity, an ISO 27001-certified cloud hosted in France is generally more secure than an unmanaged on-premises solution. For OIVs (Operators of Vital Importance) or highly sensitive sectors, the French sovereign cloud (ANSSI-certified SecNumCloud) is recommended.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-3-latency-and-real-time">Criterion 3: Latency and Real Time<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#criterion-3-latency-and-real-time" class="hash-link" aria-label="Direct link to Criterion 3: Latency and Real Time" title="Direct link to Criterion 3: Latency and Real Time" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-truth-about-cloud-latency">The Truth About Cloud Latency<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#the-truth-about-cloud-latency" class="hash-link" aria-label="Direct link to The Truth About Cloud Latency" title="Direct link to The Truth About Cloud Latency" translate="no">​</a></h3>
<p>The round-trip latency between a field gateway and a cloud server hosted in Paris ranges from <strong>50 to 200 ms</strong>, depending on the quality of the 4G or fiber connection.</p>
<p><strong>Is this acceptable for your application?</strong></p>
<table><thead><tr><th>Application</th><th>Required Latency</th><th>Cloud OK?</th></tr></thead><tbody><tr><td>PLC control loop (PID)</td><td>1–10 ms</td><td>❌ No — remains on the local PLC</td></tr><tr><td>Motion control</td><td>1–5 ms</td><td>❌ No — remains on the drive/servo</td></tr><tr><td>Safety alarms (SIL, PLe)</td><td>10–100 ms</td><td>❌ No — remains on the safety PLC</td></tr><tr><td>Machine status monitoring</td><td>100 ms–1 s</td><td>✅ Yes</td></tr><tr><td>Alerts and notifications</td><td>1–30 s</td><td>✅ Yes</td></tr><tr><td>Production dashboards</td><td>1 – 60 s</td><td>✅ Yes</td></tr><tr><td>Reports and history</td><td>No time constraints</td><td>✅ Yes</td></tr><tr><td>Remote maintenance (VNC/SSH)</td><td>50 – 500 ms</td><td>✅ Yes (acceptable)</td></tr></tbody></table>
<p><strong>Golden Rule:</strong> Real-time control ALWAYS remains on the local PLC. The cloud handles monitoring, alerts, historical data, and remote maintenance. This separation of responsibilities is the key to a proper IIoT architecture.</p>
<p><strong>Latency Verdict:</strong> Cloud latency is perfectly acceptable for 95% of industrial monitoring scenarios. Only the real-time control loop must remain local.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-4-scalability">Criterion 4: Scalability<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#criterion-4-scalability" class="hash-link" aria-label="Direct link to Criterion 4: Scalability" title="Direct link to Criterion 4: Scalability" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="on-premises-scalability-is-difficult-and-costly">On-premises: Scalability Is Difficult and Costly<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#on-premises-scalability-is-difficult-and-costly" class="hash-link" aria-label="Direct link to On-premises: Scalability Is Difficult and Costly" title="Direct link to On-premises: Scalability Is Difficult and Costly" translate="no">​</a></h3>
<p>Scaling from 10 to 50 on-premises monitored sites requires:</p>
<ul>
<li class="">Additional servers (or memory/storage upgrades)</li>
<li class="">Additional licenses (often prorated based on the number of tags or connections)</li>
<li class="">Assistance from an integrator for configuration</li>
<li class="">Migration of historical data</li>
<li class="">Testing and validation before going live</li>
</ul>
<p>Typical turnaround time: 4 to 12 weeks. High marginal cost.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="cloud-nearly-instant-scalability">Cloud: Nearly Instant Scalability<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#cloud-nearly-instant-scalability" class="hash-link" aria-label="Direct link to Cloud: Nearly Instant Scalability" title="Direct link to Cloud: Nearly Instant Scalability" translate="no">​</a></h3>
<p>Add a new SaaS cloud site:</p>
<ol>
<li class="">Order a gateway (delivered in 5–7 days)</li>
<li class="">Install it and connect it to the site’s OT network (30–60 minutes)</li>
<li class="">Configure the data points from the web dashboard</li>
<li class="">The site appears in the centralized dashboard—immediately</li>
</ol>
<p>Typical lead time: 1 to 2 weeks (determined primarily by hardware availability). Low marginal cost.</p>
<p><strong>Scalability verdict:</strong> The cloud wins by a wide margin. This is particularly crucial for multi-site deployments or system integrators that manage portfolios ranging from several dozen to several hundred client sites.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-5-compliance-and-regulation">Criterion 5: Compliance and Regulation<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#criterion-5-compliance-and-regulation" class="hash-link" aria-label="Direct link to Criterion 5: Compliance and Regulation" title="Direct link to Criterion 5: Compliance and Regulation" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="nis2-european-cybersecurity-directive">NIS2 (European Cybersecurity Directive)<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#nis2-european-cybersecurity-directive" class="hash-link" aria-label="Direct link to NIS2 (European Cybersecurity Directive)" title="Direct link to NIS2 (European Cybersecurity Directive)" translate="no">​</a></h3>
<p>For essential and important entities subject to NIS2 (water, energy, critical industries), the cybersecurity requirements are the same regardless of the architecture. The difference lies in the ability to <strong>demonstrate</strong> compliance:</p>
<ul>
<li class=""><strong>On-premises:</strong> You are responsible for the entire chain (OS, application, network, access). The NIS2 audit will review your logs, update procedures, and network segmentation.</li>
<li class=""><strong>Certified cloud:</strong> The ISO 27001-certified cloud provider covers part of the requirements (infrastructure, hosting). You remain responsible for application configuration and user access.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="gdpr-and-personal-data">GDPR and Personal Data<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#gdpr-and-personal-data" class="hash-link" aria-label="Direct link to GDPR and Personal Data" title="Direct link to GDPR and Personal Data" translate="no">​</a></h3>
<p>If your SCADA system processes personal data (operator attendance records, biometric access), the location of the data is important:</p>
<ul>
<li class=""><strong>EU Cloud (AWS Paris, OVHCloud)</strong>: GDPR-compliant if the contract includes the appropriate DPA clauses</li>
<li class=""><strong>US Cloud (without SCCs)</strong>: non-compliant for personal data of European citizens</li>
<li class=""><strong>On-premises in France</strong>: compliant by nature if access is properly controlled</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="regulated-industries-pharmaceuticals-agri-food">Regulated Industries (Pharmaceuticals, Agri-Food)<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#regulated-industries-pharmaceuticals-agri-food" class="hash-link" aria-label="Direct link to Regulated Industries (Pharmaceuticals, Agri-Food)" title="Direct link to Regulated Industries (Pharmaceuticals, Agri-Food)" translate="no">​</a></h3>
<p>FDA 21 CFR Part 11 (electronic traceability in the pharmaceutical industry) and EU GMP Annex 11 are compatible with the cloud, provided you choose a service provider that can supply the validation certificates (IQ/OQ/PQ) required by auditors.</p>
<p><strong>Compliance Verdict:</strong> The cloud, hosted in France by an ISO 27001-certified provider, is compliant with NIS2, the GDPR, and major industry regulations. Check the provider’s certifications.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-6-maintainability">Criterion 6: Maintainability<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#criterion-6-maintainability" class="hash-link" aria-label="Direct link to Criterion 6: Maintainability" title="Direct link to Criterion 6: Maintainability" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="on-premises-the-hidden-it-burden">On-premises: The Hidden IT Burden<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#on-premises-the-hidden-it-burden" class="hash-link" aria-label="Direct link to On-premises: The Hidden IT Burden" title="Direct link to On-premises: The Hidden IT Burden" translate="no">​</a></h3>
<p>Manufacturers often underestimate the maintenance burden of an on-premises SCADA system:</p>
<ul>
<li class="">OS updates (monthly Windows Server patches)</li>
<li class="">Antivirus updates (daily)</li>
<li class="">Backup management and restore testing</li>
<li class="">SQL database updates (PostgreSQL, MS SQL)</li>
<li class="">SSL certificate renewal</li>
<li class="">License management (renewal, Microsoft audit)</li>
<li class="">Internal user support</li>
</ul>
<p>In practice, an on-premises SCADA system requires <strong>0.3 to 0.5 IT FTEs</strong> over the course of its lifecycle (shared with other systems).</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="cloud-outsourced-maintenance">Cloud: Outsourced Maintenance<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#cloud-outsourced-maintenance" class="hash-link" aria-label="Direct link to Cloud: Outsourced Maintenance" title="Direct link to Cloud: Outsourced Maintenance" translate="no">​</a></h3>
<p>On a SaaS cloud platform, the provider manages:</p>
<ul>
<li class="">The entire infrastructure (servers, network, storage)</li>
<li class="">Security updates (without service interruption)</li>
<li class="">Backups (contractually guaranteed RTO/RPO)</li>
<li class="">Infrastructure scalability based on workload</li>
</ul>
<p>Your team only maintains the field gateways (with automatable OTA firmware updates) and the application configuration.</p>
<p><strong>Maintainability Assessment:</strong> The cloud reduces the operational burden by 70–80%. This is crucial for small and medium-sized businesses without a dedicated IT team.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-7-resilience-and-availability">Criterion 7: Resilience and Availability<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#criterion-7-resilience-and-availability" class="hash-link" aria-label="Direct link to Criterion 7: Resilience and Availability" title="Direct link to Criterion 7: Resilience and Availability" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="on-premises-a-double-edged-sword-in-terms-of-resilience">On-premises: A Double-Edged Sword in Terms of Resilience<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#on-premises-a-double-edged-sword-in-terms-of-resilience" class="hash-link" aria-label="Direct link to On-premises: A Double-Edged Sword in Terms of Resilience" title="Direct link to On-premises: A Double-Edged Sword in Terms of Resilience" translate="no">​</a></h3>
<p><strong>Key Features:</strong></p>
<ul>
<li class="">Works even when the Internet is down (continuous local monitoring)</li>
<li class="">No reliance on a third party for local access</li>
</ul>
<p><strong>Weaknesses:</strong></p>
<ul>
<li class="">Server failure = complete shutdown of monitoring</li>
<li class="">Requires hardware redundancy for high availability (doubles the cost)</li>
<li class="">Complex disaster recovery (server reconstruction)</li>
<li class="">Actual SLA is often poor (99% = 3.65 days of downtime per year)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="cloud-high-availability-by-design">Cloud: High Availability by Design<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#cloud-high-availability-by-design" class="hash-link" aria-label="Direct link to Cloud: High Availability by Design" title="Direct link to Cloud: High Availability by Design" translate="no">​</a></h3>
<p>Reputable industrial cloud platforms guarantee <strong>99.9% availability</strong> (contractual SLA = &lt; 8.76 hours of downtime per year) or even 99.95%.</p>
<p>Multi-AZ (multi-datacenter) architecture: A failure in one datacenter does not affect service. Disaster recovery (DR) is automatic.</p>
<p><strong>Main cloud risk:</strong> If the site’s Internet/4G connection is lost, the gateway loses its connection to the cloud. Data is buffered locally (store-and-forward) and retransmitted once the connection is restored. Remote monitoring is unavailable during the outage.</p>
<p><strong>Answer:</strong> For critical sites, deploy a backup connection (dual-operator 4G SIM with failover to fiber, or satellite VSAT as a last resort).</p>
<p><strong>Resilience verdict:</strong> The cloud offers better platform availability. On-premises solutions are more resilient for local monitoring without network dependencies. A hybrid approach (local control + cloud monitoring) offers the best of both worlds.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="hybrid-architecture-the-best-of-both-worlds">Hybrid Architecture: The Best of Both Worlds<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#hybrid-architecture-the-best-of-both-worlds" class="hash-link" aria-label="Direct link to Hybrid Architecture: The Best of Both Worlds" title="Direct link to Hybrid Architecture: The Best of Both Worlds" translate="no">​</a></h2>
<p>Most new industrial deployments adopt a <strong>hybrid architecture</strong>:</p>
<!-- -->
<p><strong>Advantages of the hybrid solution:</strong></p>
<ul>
<li class="">Critical controls and alarms remain local (zero latency)</li>
<li class="">Monitoring, history, and remote access are in the cloud</li>
<li class="">In the event of an Internet outage, the process continues (PLC) and data is buffered (gateway)</li>
<li class="">Edge intelligence (local automation rules) reduces dependence on the cloud</li>
</ul>
<p>This is exactly the architecture that Eziwan deploys: an industrial gateway at each site (edge), and a cloud platform for centralized monitoring.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="summary-table">Summary Table<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#summary-table" class="hash-link" aria-label="Direct link to Summary Table" title="Direct link to Summary Table" translate="no">​</a></h2>
<table><thead><tr><th>Criterion</th><th>On-premises</th><th>SaaS Cloud</th><th>Hybrid</th></tr></thead><tbody><tr><td>3-Year TCO (10 sites)</td><td>141–265 k€</td><td>37–78 k€</td><td>50–100 k€</td></tr><tr><td>Security</td><td>Depends on your IT</td><td>ISO 27001</td><td>ISO 27001 + OT isolation</td></tr><tr><td>Control latency</td><td>Excellent</td><td>Not applicable</td><td>Excellent (local)</td></tr><tr><td>Monitoring latency</td><td>Excellent</td><td>50–200 ms</td><td>50–200 ms</td></tr><tr><td>Scalability</td><td>Difficult</td><td>Easy</td><td>Easy</td></tr><tr><td>Maintainability</td><td>IT workload: 0.3–0.5 FTE</td><td>Minimal</td><td>Minimal</td></tr><tr><td>Platform availability</td><td>~99% (if redundant)</td><td>99.9%+ (SLA)</td><td>99.9%+</td></tr><tr><td>Resilience to Internet Outages</td><td>Full</td><td>Limited</td><td>Good (store-and-forward)</td></tr><tr><td>NIS2/GDPR Compliance</td><td>Possible</td><td>Possible</td><td>Possible</td></tr><tr><td>Deployment Time</td><td>4–12 weeks</td><td>1–2 weeks</td><td>1–2 weeks</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="when-to-choose-what">When to Choose What?<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#when-to-choose-what" class="hash-link" aria-label="Direct link to When to Choose What?" title="Direct link to When to Choose What?" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="choose-the-saas-cloud-if">Choose the SaaS cloud if:<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#choose-the-saas-cloud-if" class="hash-link" aria-label="Direct link to Choose the SaaS cloud if:" title="Direct link to Choose the SaaS cloud if:" translate="no">​</a></h3>
<ul>
<li class="">You manage multiple sites (3+) and want centralized monitoring</li>
<li class="">You don’t have a dedicated IT team to maintain servers</li>
<li class="">You’re deploying a new solution (greenfield) without legacy SCADA</li>
<li class="">Your budget is limited and you’re looking to minimize capital expenditures</li>
<li class="">You need high-quality remote access for your technicians or contractors</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="choose-the-on-premises-option-if">Choose the on-premises option if:<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#choose-the-on-premises-option-if" class="hash-link" aria-label="Direct link to Choose the on-premises option if:" title="Direct link to Choose the on-premises option if:" translate="no">​</a></h3>
<ul>
<li class="">You have a recent, existing SCADA system that has already been fully depreciated (Wonderware, Ignition)</li>
<li class="">You are an OIV and have strict network isolation requirements</li>
<li class="">You have an in-house IT team capable of maintaining the infrastructure</li>
<li class="">Your site is a single location with no need for multi-site monitoring</li>
<li class="">Your latency requirements are extremely strict (real-time critical &lt; 10 ms)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="choose-the-hybrid-option-if">Choose the hybrid option if:<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#choose-the-hybrid-option-if" class="hash-link" aria-label="Direct link to Choose the hybrid option if:" title="Direct link to Choose the hybrid option if:" translate="no">​</a></h3>
<ul>
<li class="">You have an existing SCADA system that you want to supplement with remote access</li>
<li class="">You want the best ROI without overhauling your on-premises SCADA architecture</li>
<li class="">Your process requires local control but you want cloud-based monitoring</li>
<li class="">This is the most common scenario for new IIoT projects</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion">Conclusion<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#conclusion" class="hash-link" aria-label="Direct link to Conclusion" title="Direct link to Conclusion" translate="no">​</a></h2>
<p>There is no one-size-fits-all answer. The choice depends on the number of your sites, your IT maturity, your regulatory requirements, and your scalability goals.</p>
<p><strong>One thing is certain:</strong> for multi-site deployments, the TCO balance clearly favors the SaaS cloud. And the security argument only holds water if your on-premises infrastructure is properly maintained—which is rarely the case in small and medium-sized businesses without a dedicated cybersecurity team.</p>
<p>The hybrid edge-and-cloud architecture, exemplified by solutions such as Eziwan, now makes it possible to combine local control (zero latency, offline operation) with the power of the cloud (centralized monitoring, remote access, unlimited history)—without having to choose between them.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>Can a cloud-based SCADA system operate if the Internet is down?</strong>
With a hybrid architecture (edge gateway + cloud), the industrial process continues to operate (the PLC runs autonomously), and data is buffered locally by the gateway (store-and-forward). Real-time monitoring is interrupted during the outage, but the data is not lost—it is transmitted as soon as the connection is restored. For critical alarms, configure local alerts (relays, SMS messages from the edge gateway) that function without an Internet connection.</p>
<p><strong>Which on-premises SCADA systems are compatible with a cloud-based IoT gateway?</strong>
Wonderware AVEVA, Ignition (Inductive Automation), CODESYS, FactoryTalk (Rockwell), WinCC (Siemens), Citect—all integrate with cloud-based IoT gateways via OPC-UA, Modbus TCP, or REST APIs. The hybrid architecture involves letting the on-premises SCADA system handle local control and adding a cloud-based IoT gateway for remote monitoring and technician access.</p>
<p><strong>Is SaaS cloud computing suitable for trade secrets (formulas, proprietary processes)?</strong>
Critical process data (recipes, proprietary parameters) can be excluded from cloud transmission—you only send what you need for monitoring (temperatures, pressures, machine statuses). For the most sensitive data, cloud hosting in France (OVHCloud, Scaleway), which is subject to French law, offers an additional level of protection compared to U.S. hosting providers subject to the CLOUD Act.</p>
<p><strong>How long does it take to migrate from an on-premises SCADA system to the cloud?</strong>
For a site with an existing SCADA system, deploying a cloud layer (remote access, multi-site monitoring) takes 1 to 4 weeks without disrupting the on-premises SCADA system. The existing SCADA system remains in place; the cloud IoT gateway is added in parallel. A complete migration to a cloud-based SCADA system (without an on-premises SCADA system) takes 2 to 6 months, depending on the complexity of the installation.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide">Blog: Remote Industrial Monitoring — Complete Guide 2026</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry">Blog: Edge Computing vs. Industrial Cloud — When to Use Which?</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/secure-remote-access-plc-scada">Blog: Secure Remote Access to PLCs and SCADA — VPN and NIS2</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/industrial-iot-roi-calculation">Blog: ROI of Industrial IoT — Calculation and Optimization</a></li>
<li class=""><a class="" href="https://eziwan.com/en/docs/architecture">Docs: Eziwan Platform Architecture</a></li>
</ul>
<hr>
<p><em>Are you trying to decide between cloud and on-premises solutions for your monitoring project? <a class="" href="https://eziwan.com/en/contact">Contact our team</a> for personalized advice tailored to your industrial context.</em></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/scada-cloud">Cloud SCADA</a> — cloud-based SCADA platform for centralized industrial monitoring</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-remote-support">Industrial Monitoring and Remote Support</a> — remote monitoring solutions for industry</li>
<li class=""><a class="" href="https://eziwan.com/en/edge-computing-industriel">Industrial edge computing</a> — local data processing to reduce reliance on the cloud</li>
<li class=""><a class="" href="https://eziwan.com/en/guides/scada-4g-architecture">Guide: 4G SCADA Architecture</a> — designing a SCADA architecture with 4G connectivity</li>
</ul>]]></content:encoded>
            <category>scada</category>
            <category>cloud</category>
            <category>supervision</category>
            <category>industry-4-0</category>
            <category>industrial-iot</category>
            <category>infrastructure</category>
        </item>
        <item>
            <title><![CDATA[OT Cybersecurity: 2026 Threat Landscape for French Industry]]></title>
            <link>https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026</link>
            <guid>https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026</guid>
            <pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A Comprehensive Overview of Cyber Threats Targeting Industrial OT Systems in 2026: ICS ransomware, attacks on PLCs, SCADA vulnerabilities. A Practical Guide to Protecting Your OT.]]></description>
            <content:encoded><![CDATA[<p>Industrial systems have become the primary target of cybercriminals. In 2025, <strong>68% of cybersecurity incidents reported to ANSSI involved OT</strong> (Operational Technology) systems, compared to 41% in 2022. The growing interconnection between IT and OT networks, accelerated by Industry 4.0, has significantly expanded the attack surface of factories, power plants, and water systems.</p>
<p>This guide outlines the main OT threats identified in 2025–2026, the sectors most at risk in France, and concrete steps you can take to reduce your exposure.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="why-ot-systems-have-become-the-number-one-target">Why OT Systems Have Become the Number One Target<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#why-ot-systems-have-become-the-number-one-target" class="hash-link" aria-label="Direct link to Why OT Systems Have Become the Number One Target" title="Direct link to Why OT Systems Have Become the Number One Target" translate="no">​</a></h2>
<p>For decades, industrial systems were protected by the <strong>air gap</strong>: their complete physical isolation from IT networks and the Internet. This natural protection has disappeared with the digitization of industry.</p>
<p><strong>The game-changing factors:</strong></p>
<ul>
<li class=""><strong>IT/OT Convergence</strong>: PLCs, SCADA systems, and sensors are now connected to ERP and MES systems and the cloud for remote monitoring</li>
<li class=""><strong>Equipment Lifespan</strong>: A programmable logic controller (PLC) has a lifespan of 15 to 25 years. PLCs installed between 2005 and 2010 often run on obsolete operating systems (Windows XP, CE) that are no longer supported</li>
<li class=""><strong>Protocols without native security</strong>: Modbus, DNP3, Profibus, and BACnet were designed for reliability, not security. They support neither authentication nor encryption</li>
<li class=""><strong>Limited resources</strong>: A PLC or RTU lacks the processing power to run antivirus software or modern cryptographic algorithms</li>
<li class=""><strong>Slow update cycle</strong>: Applying a patch to a controller may require a planned production shutdown—many companies delay updates for years</li>
</ul>
<p><strong>Consequence:</strong> OT systems are rife with unpatched vulnerabilities, insecure protocols, and increasing network exposure. For an attacker, this is an ideal target.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-top-6-ot-threats-in-2026">The Top 6 OT Threats in 2026<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#the-top-6-ot-threats-in-2026" class="hash-link" aria-label="Direct link to The Top 6 OT Threats in 2026" title="Direct link to The Top 6 OT Threats in 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-industrial-ransomware-ics-ransomware">1. Industrial Ransomware (ICS Ransomware)<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#1-industrial-ransomware-ics-ransomware" class="hash-link" aria-label="Direct link to 1. Industrial Ransomware (ICS Ransomware)" title="Direct link to 1. Industrial Ransomware (ICS Ransomware)" translate="no">​</a></h3>
<p>Ransomware remains the number one threat. But in 2025–2026, cybercriminal groups developed variants <strong>specific to industrial systems</strong>, capable of:</p>
<ul>
<li class=""><strong>Encrypt SCADA configuration files</strong> (Wonderware, Ignition, and Siemens TIA Portal projects)</li>
<li class=""><strong>Modify PLC parameters</strong> to cause a physical failure in addition to encryption</li>
<li class=""><strong>Exploit OPC-UA and Modbus TCP interfaces</strong> to move laterally within the OT network</li>
</ul>
<p><strong>Active Groups in Europe:</strong> LockBit 3.0, BlackCat/ALPHV, Play, and Cl0p all targeted French industries in 2024–2025. The manufacturing sector accounts for 28% of ransomware victims in Europe.</p>
<p><strong>Average impact of industrial ransomware:</strong></p>
<ul>
<li class="">Production downtime: 12 to 21 days</li>
<li class="">Total cost (ransom + recovery + lost revenue): €2.5 to 8 million for an SME</li>
<li class="">Ransom payment rate: 42% of industrial companies pay (vs. 30% across all sectors)</li>
</ul>
<p><strong>Most Common Entry Points:</strong></p>
<ol>
<li class="">VPNs without MFA compromised via credential stuffing</li>
<li class="">Remote access by maintenance contractors (TeamViewer, AnyDesk) using shared credentials</li>
<li class="">Phishing attacks targeting engineers with access to OT systems</li>
<li class="">Exploitation of vulnerabilities in HMI (Human-Machine Interface) systems exposed to the Internet</li>
</ol>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-attacks-on-programmable-logic-controllers-plcs-and-remote-terminal-units-rtus">2. Attacks on Programmable Logic Controllers (PLCs) and Remote Terminal Units (RTUs)<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#2-attacks-on-programmable-logic-controllers-plcs-and-remote-terminal-units-rtus" class="hash-link" aria-label="Direct link to 2. Attacks on Programmable Logic Controllers (PLCs) and Remote Terminal Units (RTUs)" title="Direct link to 2. Attacks on Programmable Logic Controllers (PLCs) and Remote Terminal Units (RTUs)" translate="no">​</a></h3>
<p>Programmable logic controllers are now being targeted directly. The most sophisticated attacks modify the <strong>program logic</strong> (firmware or ladder logic) to:</p>
<ul>
<li class="">Cause unintended emergency shutdowns</li>
<li class="">Force equipment to operate outside its normal operating ranges</li>
<li class="">Hide actual values from operators (manipulation of monitoring data)</li>
</ul>
<p><strong>Recurring vulnerabilities identified by ANSSI (2024–2025):</strong></p>
<table><thead><tr><th>Vendor</th><th>Vulnerability Type</th><th>CVE</th></tr></thead><tbody><tr><td>Siemens S7-1500</td><td>Buffer overflow in the Modbus TCP server</td><td>CVE-2023-46156</td></tr><tr><td>Schneider Electric M340</td><td>Lack of authentication on the FTP port</td><td>CVE-2024-8935</td></tr><tr><td>Rockwell Automation ControlLogix</td><td>RCE via EtherNet/IP without authentication</td><td>CVE-2024-6077</td></tr><tr><td>Mitsubishi MELSEC iQ-R</td><td>Denial of service via malformed packets</td><td>CVE-2024-7419</td></tr><tr><td>Wago 750 Series</td><td>Default credentials not changed</td><td>CVE-2023-4156</td></tr></tbody></table>
<p><strong>Key preventive measure:</strong> Isolate PLCs in dedicated VLANs, prohibit direct connections from the IT network, and use industrial DMZs that comply with the Purdue architecture.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-attacks-on-unsecured-industrial-protocols">3. Attacks on Unsecured Industrial Protocols<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#3-attacks-on-unsecured-industrial-protocols" class="hash-link" aria-label="Direct link to 3. Attacks on Unsecured Industrial Protocols" title="Direct link to 3. Attacks on Unsecured Industrial Protocols" translate="no">​</a></h3>
<p>Modbus, DNP3, BACnet, and Profinet were designed between the 1970s and 1990s with reliability and speed in mind. None of them include native authentication. Any device on the same network can:</p>
<ul>
<li class=""><strong>Read all registers</strong> on a Modbus controller without restriction</li>
<li class=""><strong>Write values</strong> to coils and registers without authentication</li>
<li class=""><strong>Send DNP3 commands</strong> to electrical or water distribution equipment</li>
</ul>
<p><strong>Typical attack:</strong> An attacker who gains access to the OT network (via a compromised VPN, an infected maintenance workstation, or a physically connected cable) can directly send Modbus commands to the controller of a pump or compressor.</p>
<p><strong>Mitigation:</strong></p>
<ul>
<li class="">Deploy <strong>industrial gateways</strong> with application firewalls that block unauthorized Modbus write commands (whitelist source IPs and function codes)</li>
<li class="">Implement <strong>mutual TLS authentication</strong> for OPC-UA communications</li>
<li class="">Monitor Modbus communications to detect abnormal function codes (FC05/FC06/FC15/FC16 outside of maintenance windows)</li>
</ul>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-attacks-on-hmi-and-scada-interfaces">4. Attacks on HMI and SCADA Interfaces<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#4-attacks-on-hmi-and-scada-interfaces" class="hash-link" aria-label="Direct link to 4. Attacks on HMI and SCADA Interfaces" title="Direct link to 4. Attacks on HMI and SCADA Interfaces" translate="no">​</a></h3>
<p>Human-machine interfaces (HMIs) and SCADA servers are often the weak links because:</p>
<ul>
<li class="">They run on Windows Server (2012, 2016, or even 2008) that is rarely updated</li>
<li class="">They are accessible from IT networks for production monitoring</li>
<li class="">They include web servers for remote access (often without MFA)</li>
</ul>
<p><strong>Common Attack Scenario:</strong></p>
<ol>
<li class="">An attacker compromises an IT workstation via phishing</li>
<li class="">Network scan → detects a Wonderware SCADA server on port 80</li>
<li class="">Exploitation of a web vulnerability or default credentials</li>
<li class="">Access to production monitoring → modification of alarm thresholds to mask an anomaly</li>
<li class="">Deployment of ransomware from the SCADA system to the rest of the OT network</li>
</ol>
<p><strong>Fact Check 2025:</strong> The Shodan platform lists more than <strong>15,000 industrial HMIs accessible directly from the Internet</strong> in France, including approximately 3,400 that do not have authentication configured.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="5-attacks-on-the-supply-chain-ot-supply-chain">5. Attacks on the Supply Chain (OT Supply Chain)<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#5-attacks-on-the-supply-chain-ot-supply-chain" class="hash-link" aria-label="Direct link to 5. Attacks on the Supply Chain (OT Supply Chain)" title="Direct link to 5. Attacks on the Supply Chain (OT Supply Chain)" translate="no">​</a></h3>
<p>The OT supply chain threat is growing rapidly. It involves compromising <strong>equipment, software, or a service provider</strong> before it reaches the end victim.</p>
<p><strong>Identified vectors:</strong></p>
<ul>
<li class=""><strong>Malicious firmware</strong> in imported industrial routers or IoT gateways (mostly from Asia) that contain backdoors</li>
<li class=""><strong>Compromised software updates</strong> for SCADA software or industrial protocol libraries</li>
<li class=""><strong>Maintenance contractors</strong> who access the OT network using their own devices (USB drives, laptops) from other infected client sites</li>
<li class=""><strong>Integration of third-party components</strong> into PLCs (communication cards, industrial modules) with unverified firmware</li>
</ul>
<p><strong>Directly Related NIS2 Requirements:</strong> Article 21 of the NIS2 Directive explicitly requires supply chain security management for essential and significant entities.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="6-internal-threats-insiders">6. Internal Threats (Insiders)<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#6-internal-threats-insiders" class="hash-link" aria-label="Direct link to 6. Internal Threats (Insiders)" title="Direct link to 6. Internal Threats (Insiders)" translate="no">​</a></h3>
<p>Internal threats are often underestimated in the industry. They include:</p>
<ul>
<li class=""><strong>Dissatisfied employees</strong> with access to control systems</li>
<li class=""><strong>Contractors</strong> with permanent remote access that is not revoked after their assignment ends</li>
<li class=""><strong>Intentional sabotage</strong> of critical systems (documented cases in the water and energy sectors)</li>
</ul>
<p><strong>2024 Statistics (Verizon DBIR Report):</strong> 18% of OT incidents involve an insider or a compromised trusted third party.</p>
<p><strong>Key Measure:</strong> Zero Trust Access — every access attempt must be authenticated (MFA), time-limited, and audited. A third-party vendor must never have permanent, unlimited access.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sectors-most-vulnerable-in-france">Sectors Most Vulnerable in France<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#sectors-most-vulnerable-in-france" class="hash-link" aria-label="Direct link to Sectors Most Vulnerable in France" title="Direct link to Sectors Most Vulnerable in France" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-water-and-sanitation">1. Water and Sanitation<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#1-water-and-sanitation" class="hash-link" aria-label="Direct link to 1. Water and Sanitation" title="Direct link to 1. Water and Sanitation" translate="no">​</a></h3>
<p>The water sector is the <strong>number one target of OT attacks</strong>, according to ANSSI and Europol. The reasons:</p>
<ul>
<li class="">Critical infrastructure with a direct impact on public health</li>
<li class="">Aging systems (many Sofrel RTUs from the 2000s–2010s)</li>
<li class="">Staff often lack cybersecurity training</li>
<li class="">Limited IT/OT budgets in local governments</li>
</ul>
<p><strong>Reference Incident:</strong> In February 2021, an attacker altered the caustic soda level at a water treatment plant in Florida via an unsecured TeamViewer connection. An alert operator detected the anomaly in time. The same type of attack is possible on any water SCADA system without rigorous access controls.</p>
<p>In France, NIS2 classifies water utilities serving more than 10,000 residents as <strong>critical entities</strong>, subject to enhanced cybersecurity requirements effective October 17, 2024.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-energy-and-electric-grids">2. Energy and Electric Grids<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#2-energy-and-electric-grids" class="hash-link" aria-label="Direct link to 2. Energy and Electric Grids" title="Direct link to 2. Energy and Electric Grids" translate="no">​</a></h3>
<p>Attacks on energy infrastructure (generation, transmission, and distribution) have tripled in Europe since 2022. Distribution system operators (DSOs), renewable energy producers, and industrial sites with electrical substations are at risk.</p>
<p><strong>Targeted protocols:</strong> IEC 60870-5-101/104, IEC 61850 GOOSE, DNP3 — none of which include native authentication in their base versions.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-pharmaceutical-and-food-industries">3. Pharmaceutical and Food Industries<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#3-pharmaceutical-and-food-industries" class="hash-link" aria-label="Direct link to 3. Pharmaceutical and Food Industries" title="Direct link to 3. Pharmaceutical and Food Industries" translate="no">​</a></h3>
<p>These sectors combine strict regulations (FDA 21 CFR Part 11, EU GMP Annex 11) with critical OT systems. Contamination of a manufacturing process resulting from the manipulation of PLCs can have serious health consequences.</p>
<p>Attacks aimed at halting production (competitive sabotage) are on the rise in these high-value-added sectors.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-local-governments-and-smart-cities">4. Local Governments and Smart Cities<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#4-local-governments-and-smart-cities" class="hash-link" aria-label="Direct link to 4. Local Governments and Smart Cities" title="Direct link to 4. Local Governments and Smart Cities" translate="no">​</a></h3>
<p>Smart cities are deploying IoT sensors, actuators, and gateways on a massive scale, often with insufficient security budgets. Street lighting, parking management, and urban transportation systems are now all connected—and potentially vulnerable.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-10-priority-steps-to-secure-your-ot-in-2026">The 10 Priority Steps to Secure Your OT in 2026<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#the-10-priority-steps-to-secure-your-ot-in-2026" class="hash-link" aria-label="Direct link to The 10 Priority Steps to Secure Your OT in 2026" title="Direct link to The 10 Priority Steps to Secure Your OT in 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="level-1-fundamentals-to-be-completed-immediately">Level 1: Fundamentals (to be completed immediately)<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#level-1-fundamentals-to-be-completed-immediately" class="hash-link" aria-label="Direct link to Level 1: Fundamentals (to be completed immediately)" title="Direct link to Level 1: Fundamentals (to be completed immediately)" translate="no">​</a></h3>
<p><strong>1. Inventory of All OT Assets</strong>
You can’t protect what you don’t know about. Map all PLCs, SCADA systems, HMIs, gateways, and network devices, including their operating systems, firmware, protocols, and connections. Use passive discovery tools (Nozomi Networks, Claroty, Dragos) that do not disrupt the OT network.</p>
<p><strong>2. IT/OT Network Segmentation</strong>
Isolate your OT network from the IT network using an industrial firewall or a dedicated DMZ. The Purdue architecture (levels 0 through 5) remains the industry standard. At a minimum: prohibit any direct communication between desktop PCs and field controllers.</p>
<p><strong>3. Eliminate unsecured remote access</strong>
Audit all existing remote access methods (VPN, TeamViewer, AnyDesk, RDP). Disable those that are not strictly necessary. For legitimate access, implement MFA and limit access time windows.</p>
<p><strong>4. Changing Default Credentials</strong>
All equipment (controllers, switches, HMIs, routers) shipped with default credentials (admin/admin, root/root) must have those credentials changed upon initial deployment. Document the credentials in a password vault (Bitwarden, HashiCorp Vault).</p>
<p><strong>5. Backing Up PLC Configurations</strong>
Export and back up TIA Portal, Unity Pro, and Studio 5000 projects offline to a location isolated from the OT network. In the event of a ransomware attack, restoration from a clean backup must be possible within hours, not weeks.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="level-2-strengthening-to-be-planned-over-612-months">Level 2: Strengthening (to be planned over 6–12 months)<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#level-2-strengthening-to-be-planned-over-612-months" class="hash-link" aria-label="Direct link to Level 2: Strengthening (to be planned over 6–12 months)" title="Direct link to Level 2: Strengthening (to be planned over 6–12 months)" translate="no">​</a></h3>
<p><strong>6. Strong Authentication for Remote Access</strong>
Deploy an industrial VPN with MFA (TOTP or FIDO2) for all remote access—in-house technicians, contractors, and integrators. Each session must be recorded for auditing purposes.</p>
<p><strong>7. OT Network Behavior Monitoring (NDR)</strong>
Deploy a passive monitoring sensor on your OT network to detect communication anomalies: new devices, unusual Modbus function codes, communications to unknown IP addresses, and firmware changes. Nozomi Networks, Claroty, and Dragos are the market leaders.</p>
<p><strong>8. OT Vulnerability Management</strong>
Subscribe to your manufacturers’ security bulletins (Siemens ProductCERT, Schneider Electric PSIRT, Rockwell Automation Security Advisories). Assess critical CVEs (CVSS ≥ 7.0) and schedule patches during upcoming maintenance windows.</p>
<p><strong>9. OT Incident Response Plan</strong>
Document the specific OT response process: who to contact (ANSSI if the entity is NIS2-compliant), how to isolate a compromised segment without halting production, and procedures for restoring systems from backups. Test the plan once a year through a simulation.</p>
<p><strong>10. Team Training (OT Security Awareness)</strong>
Automation engineers generally have not received cybersecurity training. Sessions lasting 2–4 hours on OT-specific threats, phishing, USB drive management, and secure remote access significantly reduce internal risk.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-eziwan-meets-ot-security-requirements">How Eziwan Meets OT Security Requirements<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#how-eziwan-meets-ot-security-requirements" class="hash-link" aria-label="Direct link to How Eziwan Meets OT Security Requirements" title="Direct link to How Eziwan Meets OT Security Requirements" translate="no">​</a></h2>
<p>The Eziwan gateway and platform were designed from the outset with OT security as a critical non-functional requirement.</p>
<p><strong>Zero Trust Architecture:</strong></p>
<ul>
<li class="">All gateway → cloud communications are encrypted using TLS 1.3 with mutual authentication via X.509 certificates</li>
<li class="">Each gateway has a unique, non-modifiable identifier pre-programmed at the factory (Device Identity)</li>
<li class="">No incoming ports are open on the gateway: connections are initiated exclusively from the OT to the cloud (push model)</li>
</ul>
<p><strong>Granular remote access control:</strong></p>
<ul>
<li class="">OpenVPN/IPSec VPN with mandatory MFA for all remote access</li>
<li class="">Time-limited sessions (configurable automatic expiration: 1 hour, 4 hours, 24 hours)</li>
<li class="">Comprehensive audit log: who logged in, from which IP address, for how long, and what actions were performed</li>
<li class="">Vendor access: restricted by source IP address, target device, and time window</li>
</ul>
<p><strong>Integrated OT Monitoring:</strong></p>
<ul>
<li class="">Anomaly detection for Modbus values (out-of-range variations, static values, communication interruptions)</li>
<li class="">Real-time alerts via SMS/email for any detected anomalies</li>
<li class="">Complete history of values for post-incident investigation</li>
</ul>
<p><strong>Sovereign Hosting:</strong></p>
<ul>
<li class="">Infrastructure hosted in France (AWS Paris eu-west-3), ISO 27001</li>
<li class="">Data not transferred outside the EU</li>
<li class="">Compliance with GDPR, NIS2, and ANSSI requirements</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ot-security-checklist-2026">OT Security Checklist 2026<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#ot-security-checklist-2026" class="hash-link" aria-label="Direct link to OT Security Checklist 2026" title="Direct link to OT Security Checklist 2026" translate="no">​</a></h2>
<p>Use this checklist to assess your OT cybersecurity maturity level:</p>
<p><strong>Governance</strong></p>
<ul class="contains-task-list containsTaskList_mC6p">
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Up-to-date OT asset mapping (complete inventory)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Formalized OT security policy approved by management</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Designated OT cybersecurity manager (or specialized MSSP)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Classification of systems by criticality (IEC 62443 Security Levels)</li>
</ul>
<p><strong>Network Architecture</strong></p>
<ul class="contains-task-list containsTaskList_mC6p">
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->IT/OT segmentation with industrial firewall/DMZ</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Dedicated VLANs by Purdue zone (levels 0, 1, 2, 3)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->No OT equipment directly accessible from the Internet</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->No direct connections between IT workstations and field controllers</li>
</ul>
<p><strong>Access and Identities</strong></p>
<ul class="contains-task-list containsTaskList_mC6p">
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Default credentials removed from all devices</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->MFA deployed for all remote access methods (VPN, RDP, web-based SCADA)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Limited access for contractors (duration, scope, time window)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Audit log of remote access archived for ≥ 1 year</li>
</ul>
<p><strong>Maintenance and Updates</strong></p>
<ul class="contains-task-list containsTaskList_mC6p">
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Documented OT vulnerability management process</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->PLC configuration backups tested and stored off-network</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Scheduled firmware update procedure during maintenance windows</li>
</ul>
<p><strong>Detection and Response</strong></p>
<ul class="contains-task-list containsTaskList_mC6p">
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Monitoring of OT network behavior (OT NDR or OT SIEM)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Documented and tested OT incident response plan</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->ANSSI notification procedure (mandatory for NIS2 entities)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Identified cybersecurity emergency contacts (internal or external CERT)</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq--ot-cybersecurity-and-industrial-threats-in-2026">FAQ — OT Cybersecurity and Industrial Threats in 2026<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#faq--ot-cybersecurity-and-industrial-threats-in-2026" class="hash-link" aria-label="Direct link to FAQ — OT Cybersecurity and Industrial Threats in 2026" title="Direct link to FAQ — OT Cybersecurity and Industrial Threats in 2026" translate="no">​</a></h2>
<p><strong>Can ransomware that infects the IT network also affect OT controllers?</strong></p>
<p>Yes, if the OT and IT networks are interconnected without strict segmentation. This is exactly how NotPetya (2017) and many industrial incidents since then spread. The ransomware encrypts IT servers, spreads via Active Directory and network shares, and if the OT network is on the same LAN or accessible via the same Windows domain, SCADA monitoring stations—and sometimes PLCs—are compromised.</p>
<p><strong>Can Siemens or Schneider PLCs be directly infected by malware?</strong></p>
<p>Industrial control systems do not “become infected” in the traditional sense (they lack a standard file system, and arbitrary code cannot be executed via typical vectors). However, they can be reprogrammed remotely if access is gained (see Stuxnet). The real risk is more often the shutdown or manipulation of PLCs by a compromised operator or through poorly secured remote access, rather than a direct infection of the firmware.</p>
<p><strong>What is the requirement to report to ANSSI in the event of an OT incident under NIS2?</strong></p>
<p>For entities subject to NIS2 (Essential Entities and Important Entities), the requirements are as follows: preliminary notification within 24 hours if the incident is likely to have a significant impact, an interim report within 72 hours, and a final report within one month. ANSSI can be notified using the dedicated form on its website. Failure to comply may result in fines of up to €10 million or 2% of global revenue.</p>
<p><strong>Are OT network segmentation solutions very expensive for a small-to-medium-sized enterprise?</strong></p>
<p>No. Basic segmentation (OT/IT VLANs on a managed switch costing €200–400, with restrictive inter-VLAN rules) is within reach of any small and medium-sized business. For a higher level of protection, compact industrial firewalls (such as the Stormshield SNi40 or Fortinet FortiGate Rugged) start at 500–800€. Segmentation offers the best cost-effectiveness in OT cybersecurity—it contains incidents before they spread.</p>
<p><strong>Should unsecured protocols such as Modbus TCP be disabled on the OT network?</strong></p>
<p>On the internal OT network, Modbus TCP can remain active—its lack of authentication is acceptable in a physically isolated and segmented network. The critical mistake is to expose the Modbus port (502) to the Internet or the IT network without any controls. The priority is to ensure that no OT ports are accessible from the outside, not necessarily to replace Modbus with a more secure protocol in the short term.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion">Conclusion<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#conclusion" class="hash-link" aria-label="Direct link to Conclusion" title="Direct link to Conclusion" translate="no">​</a></h2>
<p>OT cybersecurity is no longer an option for French manufacturers. The NIS2 Directive, the requirements of the IEC 62443 standard, and the reality of incidents (ransomware, attacks on water networks, sabotage of energy infrastructure) make protecting OT systems essential.</p>
<p><strong>The good news:</strong> Contrary to what many business leaders believe, it’s not necessary to start from scratch to make significant progress. The five fundamental measures outlined in this guide—inventory, segmentation, removal of unsecured access, default credentials, and backups—reduce the risk of a major incident by 80%, at a reasonable cost and with manageable complexity.</p>
<p><strong>Your next step:</strong> Conduct an OT audit of your infrastructure (Eziwan offers a free audit of your remote connections) and identify the three priority actions to implement within the next 30 days.</p>
<hr>
<p><em>Article written by the Eziwan team. Eziwan is a provider of IIoT gateways and industrial monitoring platforms for small and medium-sized industrial companies, local governments, and French automation integrators. <a class="" href="https://eziwan.com/en/fonctionnalites">Learn more about our approach to OT security →</a></em></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/cybersecurite">Industrial Cybersecurity</a> — Overview of protection solutions for OT networks</li>
<li class=""><a class="" href="https://eziwan.com/en/cybersecurite-acces-distant-ot">OT Remote Access Cybersecurity</a> — Securing remote connections to ICS</li>
<li class=""><a class="" href="https://eziwan.com/en/nis2-industrie">NIS2 for Industry</a> — Regulatory Requirements and Penalties for Manufacturers</li>
<li class=""><a class="" href="https://eziwan.com/en/vpn-industriel">Industrial VPN</a> — Protecting Remote Access with Strong Encryption</li>
</ul>]]></content:encoded>
            <category>cybersecurity</category>
            <category>ot-security</category>
            <category>nis2</category>
            <category>iec-62443</category>
            <category>industry-4-0</category>
            <category>scada</category>
        </item>
        <item>
            <title><![CDATA[IEC 62443: A Practical Guide for French Manufacturers in 2026]]></title>
            <link>https://eziwan.com/en/blog/iec-62443-practical-guide</link>
            <guid>https://eziwan.com/en/blog/iec-62443-practical-guide</guid>
            <pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Comprehensive Guide to IEC 62443 for French Industry: Security Levels, Practical Requirements, and Compliance Process. Effective in 2026 with the NIS2 Directive.]]></description>
            <content:encoded><![CDATA[<p>The <strong>IEC 62443</strong> standard has become the international benchmark for cybersecurity in industrial control systems (ICS/SCADA/OT). With the entry into force of the NIS2 Directive in France, it is now explicitly cited as the technical standard applicable to critical and important entities.</p>
<p>However, the standard is considered complex and extensive. This practical guide distills the essentials for French manufacturers: what the standard actually requires, how to comply with it, and the priorities for 2026.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-is-iec-62443">What is IEC 62443?<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#what-is-iec-62443" class="hash-link" aria-label="Direct link to What is IEC 62443?" title="Direct link to What is IEC 62443?" translate="no">​</a></h2>
<p>IEC 62443 (formerly ISA-99) is a family of standards developed by the ISA (International Society of Automation) and published by the IEC. It covers the cybersecurity of <strong>industrial automation and control systems</strong> (IACS).</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-structure-of-the-standard">The Structure of the Standard<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#the-structure-of-the-standard" class="hash-link" aria-label="Direct link to The Structure of the Standard" title="Direct link to The Structure of the Standard" translate="no">​</a></h3>
<p>The standard is organized into four series:</p>
<table><thead><tr><th>Series</th><th>Title</th><th>Target Audience</th></tr></thead><tbody><tr><td><strong>62443-1.x</strong></td><td>General (concepts, models, terminology)</td><td>All</td></tr><tr><td><strong>62443-2.x</strong></td><td>Policies &amp; Procedures</td><td>Industrial operators, CISOs</td></tr><tr><td><strong>62443-3.x</strong></td><td>System (architecture, security levels)</td><td>Architects, integrators</td></tr><tr><td><strong>62443-4.x</strong></td><td>Components (product security)</td><td>Equipment manufacturers</td></tr></tbody></table>
<p>For a French manufacturer seeking to comply with NIS2, the most relevant sections are:</p>
<ul>
<li class=""><strong>IEC 62443-2-1</strong>: security policies and procedures</li>
<li class=""><strong>IEC 62443-3-3</strong>: system security requirements</li>
<li class=""><strong>IEC 62443-4-2</strong>: component requirements (for evaluating your equipment)</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="security-levels-sl-understanding-security-levels">Security Levels (SL): Understanding Security Levels<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#security-levels-sl-understanding-security-levels" class="hash-link" aria-label="Direct link to Security Levels (SL): Understanding Security Levels" title="Direct link to Security Levels (SL): Understanding Security Levels" translate="no">​</a></h2>
<p>The central concept of IEC 62443 is the <strong>Security Level</strong>—the level of protection required based on the system's criticality.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-4-levels">The 4 Levels<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#the-4-levels" class="hash-link" aria-label="Direct link to The 4 Levels" title="Direct link to The 4 Levels" translate="no">​</a></h3>
<table><thead><tr><th>Security Level</th><th>Description</th><th>Against what threat?</th></tr></thead><tbody><tr><td><strong>SL 0</strong></td><td>No specific protection</td><td>— (offline systems)</td></tr><tr><td><strong>SL 1</strong></td><td>Protection against accidental attacks</td><td>Human error, non-targeted malicious acts</td></tr><tr><td><strong>SL 2</strong></td><td>Protection against deliberate attacks using limited resources</td><td>Hacktivists, opportunists</td></tr><tr><td><strong>SL 3</strong></td><td>Protection against attacks using sophisticated methods</td><td>Organized criminal groups</td></tr><tr><td><strong>SL 4</strong></td><td>Protection against state-sponsored attacks</td><td>State-sponsored APTs</td></tr></tbody></table>
<p><strong>For the vast majority of French manufacturers:</strong> Level <strong>SL 2</strong> is the appropriate target. SL 3 is reserved for operators of vital importance (OIV) with highly critical systems. SL 4 is almost exclusively for military and nuclear infrastructure.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-do-you-determine-the-required-sl-for-your-system">How do you determine the required SL for your system?<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#how-do-you-determine-the-required-sl-for-your-system" class="hash-link" aria-label="Direct link to How do you determine the required SL for your system?" title="Direct link to How do you determine the required SL for your system?" translate="no">​</a></h3>
<p>The process consists of three steps:</p>
<p><strong>1. Identify Zones and Conduits (IEC 62443-3-2)</strong></p>
<p>Start by mapping your OT systems into <strong>security zones</strong>:</p>
<ul>
<li class="">Production zone (PLCs, sensors, local HMIs)</li>
<li class="">Monitoring zone (SCADA, historian servers)</li>
<li class="">OT DMZ (IT/OT interface)</li>
<li class="">Remote access zone</li>
</ul>
<p>Next, identify the <strong>pipes</strong> (Conduits)—the communication paths between zones (remote access VPNs, SCADA links, IT/OT gateways).</p>
<p><strong>2. Assess the criticality of each zone (CASC)</strong></p>
<p>For each area, assess the consequences of a compromise based on the CASC criteria:</p>
<ul>
<li class=""><strong>C</strong>onfidentiality: Does the data need to remain confidential?</li>
<li class=""><strong>I</strong>ntegrity: Could a change to the data or commands cause damage?</li>
<li class=""><strong>D</strong>availability: Would a system outage cause significant harm?</li>
<li class=""><strong>Safety</strong>: Could a malfunction endanger lives?</li>
</ul>
<p><strong>3. Define the target SL by zone</strong></p>
<p>The assessed criticality determines the target safety level (SL): an area with safety-related logic controllers (SIL) in a SEVESO facility will aim for SL 3, while a control room at a drinking water pumping station generally aims for SL 2.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-7-foundational-requirements-of-iec-62443-3-3">The 7 Foundational Requirements of IEC 62443-3-3<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#the-7-foundational-requirements-of-iec-62443-3-3" class="hash-link" aria-label="Direct link to The 7 Foundational Requirements of IEC 62443-3-3" title="Direct link to The 7 Foundational Requirements of IEC 62443-3-3" translate="no">​</a></h2>
<p>The IEC 62443-3-3 standard defines 7 fundamental requirements (FR) for systems. Each FR is broken down into detailed requirements based on the SL level.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="fr-1--identification-and-authentication-checks">FR 1 — Identification and Authentication Checks<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#fr-1--identification-and-authentication-checks" class="hash-link" aria-label="Direct link to FR 1 — Identification and Authentication Checks" title="Direct link to FR 1 — Identification and Authentication Checks" translate="no">​</a></h3>
<p><strong>What this means in practice:</strong></p>
<ul>
<li class="">Each user and device must be uniquely identified (no shared accounts)</li>
<li class="">Default passwords on OT devices must be changed</li>
<li class="">For SL 2: two-factor authentication (MFA) for remote access</li>
</ul>
<p><strong>Eziwan App:</strong> Each technician has an individual OpenVPN/IPSec VPN key. MFA authentication is available on the cloud platform.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="fr-2--usage-monitoring">FR 2 — Usage Monitoring<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#fr-2--usage-monitoring" class="hash-link" aria-label="Direct link to FR 2 — Usage Monitoring" title="Direct link to FR 2 — Usage Monitoring" translate="no">​</a></h3>
<p><strong>What this means:</strong></p>
<ul>
<li class="">Each user has access only to the resources necessary for their role (principle of least privilege)</li>
<li class="">Actions on critical equipment require explicit authorization</li>
</ul>
<p><strong>Application:</strong> Eziwan RBAC allows you to define access rights by site, by piece of equipment, and by time slot for each technician.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="fr-3--data-integrity">FR 3 — Data Integrity<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#fr-3--data-integrity" class="hash-link" aria-label="Direct link to FR 3 — Data Integrity" title="Direct link to FR 3 — Data Integrity" translate="no">​</a></h3>
<p><strong>What this means:</strong></p>
<ul>
<li class="">Data transmitted between devices must not be alterable in transit</li>
<li class="">The integrity of the PLC configurations must be verifiable</li>
</ul>
<p><strong>Application:</strong> All Eziwan communications are encrypted using OpenVPN (authentication + encryption). The configurations are digitally signed.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="fr-4--data-confidentiality">FR 4 — Data Confidentiality<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#fr-4--data-confidentiality" class="hash-link" aria-label="Direct link to FR 4 — Data Confidentiality" title="Direct link to FR 4 — Data Confidentiality" translate="no">​</a></h3>
<p><strong>What this means:</strong></p>
<ul>
<li class="">Sensitive data (recipes, production parameters, personal data) must be encrypted in transit and at rest</li>
</ul>
<p><strong>Implementation:</strong> AES-256-GCM encryption of all communications; stored data is encrypted on the French cloud infrastructure.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="fr-5--limited-data-flow">FR 5 — Limited Data Flow<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#fr-5--limited-data-flow" class="hash-link" aria-label="Direct link to FR 5 — Limited Data Flow" title="Direct link to FR 5 — Limited Data Flow" translate="no">​</a></h3>
<p><strong>What this means:</strong></p>
<ul>
<li class="">Communications between security zones must be controlled and limited to the minimum necessary</li>
<li class="">No direct communication between the office IT zone and OT controllers without a DMZ</li>
</ul>
<p><strong>Eziwan App:</strong> zero-inbound-port architecture—the OT network is never directly exposed. Traffic passes through the Eziwan cloud, which acts as a centralized control point.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="fr-6--response-to-events">FR 6 — Response to Events<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#fr-6--response-to-events" class="hash-link" aria-label="Direct link to FR 6 — Response to Events" title="Direct link to FR 6 — Response to Events" translate="no">​</a></h3>
<p><strong>What this means:</strong></p>
<ul>
<li class="">Security incidents must be detected, recorded, and addressed</li>
<li class="">For NIS2: mandatory notification within 24 hours for critical entities</li>
</ul>
<p><strong>Application:</strong> Comprehensive logging of all security events, configurable alerts for connection anomalies, and log export for SIEM.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="fr-7--availability-of-resources">FR 7 — Availability of Resources<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#fr-7--availability-of-resources" class="hash-link" aria-label="Direct link to FR 7 — Availability of Resources" title="Direct link to FR 7 — Availability of Resources" translate="no">​</a></h3>
<p><strong>What this means:</strong></p>
<ul>
<li class="">The system must remain available even in the event of an attempted attack (DoS protection)</li>
<li class="">Backup and recovery mechanisms must be in place</li>
</ul>
<p><strong>Application:</strong> Dual SIM failover, multi-AZ cloud infrastructure, automatic backups of gateway configurations.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-6-step-iec-62443-compliance-process">The 6-Step IEC 62443 Compliance Process<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#the-6-step-iec-62443-compliance-process" class="hash-link" aria-label="Direct link to The 6-Step IEC 62443 Compliance Process" title="Direct link to The 6-Step IEC 62443 Compliance Process" translate="no">​</a></h2>
<p>Here is a practical approach for French manufacturers who must comply with NIS2 by referencing IEC 62443.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-1-inventory-of-ot-assets-35-days">Step 1: Inventory of OT Assets (3–5 days)<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#step-1-inventory-of-ot-assets-35-days" class="hash-link" aria-label="Direct link to Step 1: Inventory of OT Assets (3–5 days)" title="Direct link to Step 1: Inventory of OT Assets (3–5 days)" translate="no">​</a></h3>
<p>List all your OT systems:</p>
<ul>
<li class="">Controllers (PLCs, DCSs, RTUs)</li>
<li class="">HMIs and operator stations</li>
<li class="">SCADA servers and historians</li>
<li class="">OT network equipment (switches, routers, firewalls)</li>
<li class="">Gateways and connectivity equipment</li>
</ul>
<p>For each asset: firmware/software version, network connectivity, date of the last security update, existing remote access capabilities.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-2-mapping-areas-and-ducts-23-days">Step 2: Mapping Areas and Ducts (2–3 days)<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#step-2-mapping-areas-and-ducts-23-days" class="hash-link" aria-label="Direct link to Step 2: Mapping Areas and Ducts (2–3 days)" title="Direct link to Step 2: Mapping Areas and Ducts (2–3 days)" translate="no">​</a></h3>
<p>Draw a diagram of the current OT network, including security zones and communication flows. Identify:</p>
<ul>
<li class="">Existing IT/OT interfaces</li>
<li class="">Remote access methods (VPN, RDP, TeamViewer)</li>
<li class="">Devices with ports exposed to the Internet (search for your IP addresses on Shodan)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-3-simplified-risk-analysis-1-week">Step 3: Simplified Risk Analysis (1 week)<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#step-3-simplified-risk-analysis-1-week" class="hash-link" aria-label="Direct link to Step 3: Simplified Risk Analysis (1 week)" title="Direct link to Step 3: Simplified Risk Analysis (1 week)" translate="no">​</a></h3>
<p>For each area, assess:</p>
<ul>
<li class=""><strong>Criticality</strong> (impact of a breach: production, security, environment)</li>
<li class=""><strong>Threat</strong> (who might want to attack your sector?)</li>
<li class=""><strong>Vulnerability</strong> (current security status of the area)</li>
</ul>
<p>Prioritize the areas to be addressed first: high criticality + high vulnerability = Priority 1.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-4-defining-the-target-sl-level-by-zone">Step 4: Defining the Target SL Level by Zone<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#step-4-defining-the-target-sl-level-by-zone" class="hash-link" aria-label="Direct link to Step 4: Defining the Target SL Level by Zone" title="Direct link to Step 4: Defining the Target SL Level by Zone" translate="no">​</a></h3>
<p>Based on the risk analysis:</p>
<ul>
<li class="">Standard production areas → SL 2</li>
<li class="">Areas with SIL safety controllers → SL 3</li>
<li class="">OT office areas (engineering workstations) → SL 1 to SL 2</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-5-remediation-plan-spanning-618-months">Step 5: Remediation Plan (spanning 6–18 months)<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#step-5-remediation-plan-spanning-618-months" class="hash-link" aria-label="Direct link to Step 5: Remediation Plan (spanning 6–18 months)" title="Direct link to Step 5: Remediation Plan (spanning 6–18 months)" translate="no">​</a></h3>
<p>For each area where the current level is below the target SL, define corrective actions:</p>
<p><strong>SL 2 Priority Actions:</strong></p>
<ol>
<li class="">Remove all default passwords from OT devices</li>
<li class="">Replace unsecured remote access methods (exposed RDP, TeamViewer) with a zero-trust VPN</li>
<li class="">Implement MFA authentication for all remote access</li>
<li class="">Create named accounts (no shared generic accounts)</li>
<li class="">Enable access logging on all devices that support it</li>
<li class="">Segment the OT network from the office IT network (DMZ or VLAN with ACL)</li>
</ol>
<p><strong>Key Actions for SL 2:</strong>
7. Update the firmware on OT equipment (gateways, industrial switches)
8. Document incident response procedures
9. Train maintenance teams on OT cybersecurity risks</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-6-evaluation-and-continuous-improvement">Step 6: Evaluation and Continuous Improvement<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#step-6-evaluation-and-continuous-improvement" class="hash-link" aria-label="Direct link to Step 6: Evaluation and Continuous Improvement" title="Direct link to Step 6: Evaluation and Continuous Improvement" translate="no">​</a></h3>
<p>IEC 62443 compliance is not a one-time project but an ongoing process. Plan for:</p>
<ul>
<li class="">Annual review of the inventory and mapping</li>
<li class="">Annual (or semi-annual) penetration testing of remote access points</li>
<li class="">Update the remediation plan after each incident or infrastructure change</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="iec-62443-and-nis2-what-french-entities-need-to-do">IEC 62443 and NIS2: What French Entities Need to Do<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#iec-62443-and-nis2-what-french-entities-need-to-do" class="hash-link" aria-label="Direct link to IEC 62443 and NIS2: What French Entities Need to Do" title="Direct link to IEC 62443 and NIS2: What French Entities Need to Do" translate="no">​</a></h2>
<p>The NIS2 Directive (transposed into French law by the Act of October 8, 2024) does not explicitly cite IEC 62443, but the measures it requires are directly in line with it.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-entities-involved">The Entities Involved<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#the-entities-involved" class="hash-link" aria-label="Direct link to The Entities Involved" title="Direct link to The Entities Involved" translate="no">​</a></h3>
<p><strong>Critical infrastructure</strong>: energy (electricity, natural gas, oil), transportation (air, rail, maritime, road), banking, financial infrastructure, water (supply, wastewater), healthcare, digital infrastructure.</p>
<p><strong>Key sectors</strong>: postal services, waste management, chemicals, food, industrial manufacturing (medical devices, electronic equipment, mechanical engineering), digital service providers.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="required-cybersecurity-measures-art-21-nis2">Required Cybersecurity Measures (Art. 21 NIS2)<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#required-cybersecurity-measures-art-21-nis2" class="hash-link" aria-label="Direct link to Required Cybersecurity Measures (Art. 21 NIS2)" title="Direct link to Required Cybersecurity Measures (Art. 21 NIS2)" translate="no">​</a></h3>
<ol>
<li class=""><strong>Information Systems Security Policy</strong> (IEC 62443-2-1)</li>
<li class=""><strong>Incident Management</strong>: detection, response, notification within 24 hours (IEC 62443-2-1, FR 6)</li>
<li class=""><strong>Business Continuity</strong>: Backups, recovery plans (IEC 62443-3-3 FR 7)</li>
<li class=""><strong>Supply Chain Security</strong>: Security of subcontractors with OT access (IEC 62443-2-4)</li>
<li class=""><strong>Procurement Security</strong>: security assessment prior to deployment of OT equipment (IEC 62443-4-2)</li>
<li class=""><strong>Training and Awareness</strong>: all personnel with access to OT systems</li>
<li class=""><strong>Cryptography and Encryption</strong>: encrypted communications, protected sensitive data</li>
<li class=""><strong>Access Control</strong>: strong authentication, RBAC, logging (IEC 62443-3-3 FR 1, FR 2)</li>
<li class=""><strong>Human Resources Security</strong>: background checks, exit procedures</li>
<li class=""><strong>Risk Assessment</strong>: formal, documented process (IEC 62443-3-2)</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="5-mistakes-to-avoid-in-an-iec-62443-project">5 Mistakes to Avoid in an IEC 62443 Project<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#5-mistakes-to-avoid-in-an-iec-62443-project" class="hash-link" aria-label="Direct link to 5 Mistakes to Avoid in an IEC 62443 Project" title="Direct link to 5 Mistakes to Avoid in an IEC 62443 Project" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="mistake-1-starting-with-the-documentation-before-the-site-survey">Mistake 1: Starting with the documentation before the site survey<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#mistake-1-starting-with-the-documentation-before-the-site-survey" class="hash-link" aria-label="Direct link to Mistake 1: Starting with the documentation before the site survey" title="Direct link to Mistake 1: Starting with the documentation before the site survey" translate="no">​</a></h3>
<p>Many manufacturers commission security policies before conducting an actual inventory. The result: theoretical documents that are out of touch with the reality on the ground. Always start with the inventory and mapping.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="mistake-2-treating-iec-62443-as-an-it-project">Mistake 2: Treating IEC 62443 as an IT project<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#mistake-2-treating-iec-62443-as-an-it-project" class="hash-link" aria-label="Direct link to Mistake 2: Treating IEC 62443 as an IT project" title="Direct link to Mistake 2: Treating IEC 62443 as an IT project" translate="no">​</a></h3>
<p>OT security has specific constraints: equipment cannot be taken offline for updates, the protocols are legacy (Modbus from 1979), and the teams are automation engineers—not IT professionals. Involve the production teams from the very beginning.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="mistake-3-aiming-for-sl-3-or-sl-4-without-a-valid-reason">Mistake 3: Aiming for SL 3 or SL 4 without a valid reason<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#mistake-3-aiming-for-sl-3-or-sl-4-without-a-valid-reason" class="hash-link" aria-label="Direct link to Mistake 3: Aiming for SL 3 or SL 4 without a valid reason" title="Direct link to Mistake 3: Aiming for SL 3 or SL 4 without a valid reason" translate="no">​</a></h3>
<p>SL 3 and SL 4 have very strict requirements (strong authentication on PLCs, encryption of all industrial protocols, including Modbus) that often necessitate replacing OT equipment. For most manufacturers, SL 2 is a realistic and sufficient target.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="mistake-4-neglecting-third-party-access-security">Mistake 4: Neglecting Third-Party Access Security<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#mistake-4-neglecting-third-party-access-security" class="hash-link" aria-label="Direct link to Mistake 4: Neglecting Third-Party Access Security" title="Direct link to Mistake 4: Neglecting Third-Party Access Security" translate="no">​</a></h3>
<p>The most common OT incidents involve remote access by maintenance contractors. Prioritize third-party access security (named accounts, MFA, audit trails) before addressing the more technical aspects.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="mistake-5-thinking-that-nis2-compliance-equals-iec-62443-compliance">Mistake 5: Thinking that NIS2 compliance equals IEC 62443 compliance<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#mistake-5-thinking-that-nis2-compliance-equals-iec-62443-compliance" class="hash-link" aria-label="Direct link to Mistake 5: Thinking that NIS2 compliance equals IEC 62443 compliance" title="Direct link to Mistake 5: Thinking that NIS2 compliance equals IEC 62443 compliance" translate="no">​</a></h3>
<p>NIS2 mandates security measures but does not certify compliance with IEC 62443. IEC 62443 certification (by an accredited body) is distinct from NIS2 compliance. For most manufacturers, documented compliance with IEC 62443 without formal certification is sufficient to meet NIS2 requirements.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>Is IEC 62443 certification required to comply with NIS2?</strong>
No. The NIS2 directive mandates technical and organizational security measures but does not require formal IEC 62443 certification (which is issued by accredited bodies such as TÜV, Bureau Veritas, etc.). However, documenting that your practices are <em>aligned</em> with IEC 62443 is an excellent way to demonstrate your NIS2 compliance to ANSSI.</p>
<p><strong>Which part of IEC 62443 should an industrial PMI start with?</strong>
For an industrial PMI, start with IEC 62443-2-1 (policies and procedures) and IEC 62443-3-3 (system requirements for Security Levels 1 and 2). These are the most directly applicable parts and the ones most frequently requested by clients. The 4.x parts (components) are of greater interest to equipment manufacturers.</p>
<p><strong>What is a security zone in IEC 62443?</strong>
A security zone is a group of systems with the same required security level, separated from other zones by conduits (controlled communication channels). Example: Zone 1 = production PLCs (SL2), Zone 2 = SCADA (SL2), Zone 3 = IT (SL1). Communications between zones must pass through a firewall or a controlled DMZ.</p>
<p><strong>How do I determine the target Security Level (SL) for my facility?</strong>
The target SL depends on the consequences of an incident: SL1 for a limited risk (temporary shutdown of a non-critical process), SL2 for a significant risk (impact on production or personal safety), and SL3 for critical systems (energy, water, healthcare). Most industrial SMEs aim for SL2 for their SCADA systems and SL1 for support systems.</p>
<p><strong>Does IEC 62443 cover VPN remote access security?</strong>
Yes. IEC 62443-3-3 explicitly addresses authentication (SR 1.1, SR 1.2), communication encryption (SR 4.1), session management (SR 1.3), and auditability (SR 2.8). An OpenVPN/IPSec VPN with certificate-based authentication and logging meets the requirements of Security Levels 1 and 2 in these areas.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/nis2-cybersecurity-industrial-infrastructure">Guide: NIS2 for Industry — Requirements, Penalties, Action Plan</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry">Blog: NIS2 Compliance Checklist — 30 Checkpoints</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026">Blog: OT Cybersecurity — Threats and Incidents in 2026</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/zero-inbound-port-ot-security">Blog: Zero Inbound Ports — Secure OT Architecture</a></li>
<li class=""><a class="" href="https://eziwan.com/en/docs/guides/securite-acces-distant">Docs: Eziwan Remote Access Security</a></li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources-1">Additional Resources<a href="https://eziwan.com/en/blog/iec-62443-practical-guide#additional-resources-1" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/cybersecurite">Industrial Cybersecurity</a> — protection solutions for OT and ICS networks</li>
<li class=""><a class="" href="https://eziwan.com/en/nis2-industrie">NIS2 for Industry</a> — regulatory requirements and compliance plan</li>
<li class=""><a class="" href="https://eziwan.com/en/cybersecurite-acces-distant-ot">OT Remote Access Cybersecurity</a> — Securing remote access to PLCs</li>
<li class=""><a class="" href="https://eziwan.com/en/acces-distant-industriel">Industrial Remote Access</a> — IEC 62443-compliant zero-trust architectures</li>
<li class=""><a class="" href="https://eziwan.com/en/guides/secure-ot-network">Guide to Securing OT Networks</a> — Segmentation, VPN, and NIS2 Compliance</li>
</ul>]]></content:encoded>
            <category>cybersecurity</category>
            <category>iec-62443</category>
            <category>nis2</category>
            <category>ot-security</category>
            <category>industry-4-0</category>
        </item>
        <item>
            <title><![CDATA[ROI of Industrial IoT: How to Calculate and Maximize Your Return on Investment]]></title>
            <link>https://eziwan.com/en/blog/industrial-iot-roi-calculation</link>
            <guid>https://eziwan.com/en/blog/industrial-iot-roi-calculation</guid>
            <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A comprehensive method for calculating the ROI of an industrial IoT project: reduced travel, maintenance savings, and productivity gains. Quantified examples by sector.]]></description>
            <content:encoded><![CDATA[<p>One of the main barriers to the adoption of industrial IoT is the difficulty in justifying the investment to decision-makers: <strong>What is the actual ROI?</strong> How can it be measured? How long will it take to achieve it?</p>
<p>This guide provides a structured method for calculating the return on investment for an industrial IoT monitoring project, with numerical examples drawn from real-world deployments.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="why-iot-roi-is-often-underestimated">Why IoT ROI Is Often Underestimated<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#why-iot-roi-is-often-underestimated" class="hash-link" aria-label="Direct link to Why IoT ROI Is Often Underestimated" title="Direct link to Why IoT ROI Is Often Underestimated" translate="no">​</a></h2>
<p>Most IoT ROI calculations focus on direct and obvious savings. But industrial IoT generates benefits in <strong>four categories</strong> that are often underestimated:</p>
<ol>
<li class=""><strong>Direct savings</strong>: costs avoided (travel, emergency service calls, unplanned outages)</li>
<li class=""><strong>Productivity gains</strong>: time saved through automated monitoring</li>
<li class=""><strong>Risk reduction</strong>: avoided incident costs (contractual penalties, regulatory fines, reputational damage)</li>
<li class=""><strong>Value of data</strong>: optimizations made possible by newly available data</li>
</ol>
<p>Projects that measure only Category 1 consistently attribute an overly low ROI to the IoT.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-industrial-iot-roi-formula">The Industrial IoT ROI Formula<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#the-industrial-iot-roi-formula" class="hash-link" aria-label="Direct link to The Industrial IoT ROI Formula" title="Direct link to The Industrial IoT ROI Formula" translate="no">​</a></h2>
<p>ROI is calculated over a given period (usually 1, 2, or 3 years):</p>
<div class="language-text codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">ROI (%) = [(Total Profits - Total Costs) / Total Costs] × 100</span><br></div></code></pre></div></div>
<p><strong>Total Costs = Initial Investment + Recurring Costs</strong></p>
<ul>
<li class="">Initial investment: hardware (gateways, sensors), installation, configuration, training</li>
<li class="">Recurring costs: platform subscriptions, M2M SIM cards, hardware maintenance</li>
</ul>
<p><strong>Total benefits = the sum of savings and gains across the 4 categories</strong></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="category-1-direct-savings">Category 1: Direct Savings<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#category-1-direct-savings" class="hash-link" aria-label="Direct link to Category 1: Direct Savings" title="Direct link to Category 1: Direct Savings" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="reducing-technician-travel">Reducing Technician Travel<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#reducing-technician-travel" class="hash-link" aria-label="Direct link to Reducing Technician Travel" title="Direct link to Reducing Technician Travel" translate="no">​</a></h3>
<p>This is often the most important item and the easiest to quantify.</p>
<p><strong>Actual cost of a technician's service call (France, 2026):</strong></p>
<table><thead><tr><th>Component</th><th>Estimated Cost</th></tr></thead><tbody><tr><td>Travel time (2-hour round trip)</td><td>60–120€</td></tr><tr><td>Mileage allowance (50 km × 0.33€)</td><td>33€</td></tr><tr><td>On-site service time (1–2 hours)</td><td>60–120€</td></tr><tr><td>On-call duty (25–50% surcharge)</td><td>+30–80€</td></tr><tr><td><strong>Total on-call travel cost</strong></td><td><strong>180–350€</strong></td></tr><tr><td><strong>Total full-day travel cost</strong></td><td><strong>150–250€</strong></td></tr></tbody></table>
<p><strong>How IoT Monitoring Reduces Travel:</strong></p>
<ul>
<li class="">Remote diagnostics: The technician determines the cause of the problem before leaving → he brings the right part instead of making two trips</li>
<li class="">False alarms avoided: Without supervision, every operator alert results in a service call. With IoT, the dashboard distinguishes between real failures and false alarms</li>
<li class="">Scheduled service calls: Predictive alerts allow service calls at a single site to be grouped together during a single scheduled visit</li>
</ul>
<p><strong>Typical savings observed:</strong></p>
<ul>
<li class="">Water utilities: 1.5 to 3 trips avoided per pumping station per year</li>
<li class="">Multi-site industries: 2 to 4 emergency calls converted to scheduled maintenance per site per year</li>
<li class="">Solar farms: 60–70% reduction in reactive maintenance visits</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="reducing-unplanned-downtime">Reducing Unplanned Downtime<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#reducing-unplanned-downtime" class="hash-link" aria-label="Direct link to Reducing Unplanned Downtime" title="Direct link to Reducing Unplanned Downtime" translate="no">​</a></h3>
<p>An unexpected breakdown costs, on average, <strong>3 to 5 times more</strong> than an equivalent preventive maintenance service.</p>
<p><strong>Cost of an unplanned shutdown (example: industrial SME):</strong></p>
<ul>
<li class="">Production losses: 500 to 5,000€/hour (depending on the sector)</li>
<li class="">Emergency labor (+50% on-call rate): 500–1,500€</li>
<li class="">Express parts (cost × 2 vs. normal stock): +€200–500</li>
<li class=""><strong>Total cost of a 4-hour shutdown for an SME</strong>: €2,500 to €22,000</li>
</ul>
<p>With IoT monitoring and early warnings, signs of malfunction are detected before a failure occurs: vibration levels rise gradually, temperature exceeds its threshold, or motor current increases abnormally. Maintenance is scheduled during a planned shutdown.</p>
<p><strong>ROI of prevention:</strong> Avoiding just 1 to 2 unplanned shutdowns per site per year is often enough to recoup the total IoT investment.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="category-2-productivity-gains">Category 2: Productivity Gains<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#category-2-productivity-gains" class="hash-link" aria-label="Direct link to Category 2: Productivity Gains" title="Direct link to Category 2: Productivity Gains" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="operator-time-saved-through-the-automation-of-monitoring">Operator time saved through the automation of monitoring<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#operator-time-saved-through-the-automation-of-monitoring" class="hash-link" aria-label="Direct link to Operator time saved through the automation of monitoring" title="Direct link to Operator time saved through the automation of monitoring" translate="no">​</a></h3>
<p>Without IoT monitoring, operators and technicians spend time:</p>
<ul>
<li class="">Conducting regular monitoring rounds</li>
<li class="">Manually entering readings into spreadsheets</li>
<li class="">Compiling performance reports</li>
<li class="">Responding to phone calls reporting outages</li>
</ul>
<p><strong>Estimated time saved (for 20 monitored pieces of equipment):</strong></p>
<table><thead><tr><th>Task eliminated or reduced</th><th>Time/week before</th><th>Time/week after</th><th>Savings</th></tr></thead><tbody><tr><td>Monitoring rounds</td><td>8h</td><td>2h</td><td>6h</td></tr><tr><td>Manual data entry</td><td>3h</td><td>0h</td><td>3h</td></tr><tr><td>Report compilation</td><td>2h</td><td>0h (automatic)</td><td>2h</td></tr><tr><td>On-call management</td><td>4 hours</td><td>1 hour</td><td>3 hours</td></tr><tr><td><strong>Total</strong></td><td><strong>17 hours</strong></td><td><strong>3 hours</strong></td><td><strong>14 hours/week</strong></td></tr></tbody></table>
<p>14 hours/week × hourly rate (60€) = <strong>840€/week in productivity savings</strong>, or <strong>43,000€/year</strong>.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="reducing-diagnostic-time">Reducing Diagnostic Time<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#reducing-diagnostic-time" class="hash-link" aria-label="Direct link to Reducing Diagnostic Time" title="Direct link to Reducing Diagnostic Time" translate="no">​</a></h3>
<p>With historical data available in the cloud, diagnosing a failure takes 10–15 minutes instead of 1–2 hours on-site. The technician reviews the trend graph, identifies the anomaly, and plans a targeted intervention.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="category-3-risk-reduction">Category 3: Risk Reduction<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#category-3-risk-reduction" class="hash-link" aria-label="Direct link to Category 3: Risk Reduction" title="Direct link to Category 3: Risk Reduction" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="avoided-regulatory-compliance-issues">Avoided Regulatory Compliance Issues<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#avoided-regulatory-compliance-issues" class="hash-link" aria-label="Direct link to Avoided Regulatory Compliance Issues" title="Direct link to Avoided Regulatory Compliance Issues" translate="no">​</a></h3>
<p>For sectors subject to NIS2 (water, energy, transportation, healthcare), fines for noncompliance can reach <strong>2% of global annual revenue</strong> for a critical entity.</p>
<p>IoT monitoring—which includes access logging, traceability of interventions, and automatic audit reports—significantly reduces the risk of noncompliance.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="avoided-service-penalties">Avoided service penalties<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#avoided-service-penalties" class="hash-link" aria-label="Direct link to Avoided service penalties" title="Direct link to Avoided service penalties" translate="no">​</a></h3>
<p>For companies covered by an SLA (maintenance providers, network operators), every hour of downtime can result in contractual penalties.</p>
<p><strong>Example:</strong> A water network operator subject to a penalty of €2,000 per hour of non-compliance with pressure requirements. One outage detected 4 hours earlier thanks to IoT = €8,000 in penalties avoided.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="category-4-data-value">Category 4: Data Value<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#category-4-data-value" class="hash-link" aria-label="Direct link to Category 4: Data Value" title="Direct link to Category 4: Data Value" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="energy-consumption-optimization">Energy Consumption Optimization<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#energy-consumption-optimization" class="hash-link" aria-label="Direct link to Energy Consumption Optimization" title="Direct link to Energy Consumption Optimization" translate="no">​</a></h3>
<p>Real-time electricity consumption data helps identify unnecessary consumption spikes, underutilized equipment, and load reduction opportunities.</p>
<p><strong>Typical savings:</strong> A 5 to 15% reduction in the electricity bill for monitored equipment.</p>
<p><strong>Real-world example:</strong> A pumping station with pumps running at full power 24 hours a day. IoT analysis reveals that demand at night is 40% lower. Reducing the pumps’ speed using a variable-speed drive (already in place) → 22% savings on electricity consumption.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="data-driven-decisions-vs-intuition">Data-Driven Decisions vs. Intuition<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#data-driven-decisions-vs-intuition" class="hash-link" aria-label="Direct link to Data-Driven Decisions vs. Intuition" title="Direct link to Data-Driven Decisions vs. Intuition" translate="no">​</a></h3>
<p>Before the IoT, maintenance decisions were based on experience and paper records. After the IoT, they are based on real data:</p>
<ul>
<li class="">Maintenance frequency adjusted to actual usage (vs. a fixed schedule)</li>
<li class="">Prioritization of investments based on actual performance data</li>
<li class="">Quantified demonstration of the impact of the improvements made</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="examples-of-roi-calculations-by-industry">Examples of ROI Calculations by Industry<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#examples-of-roi-calculations-by-industry" class="hash-link" aria-label="Direct link to Examples of ROI Calculations by Industry" title="Direct link to Examples of ROI Calculations by Industry" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="water-utility--network-of-40-pumping-stations">Water utility — network of 40 pumping stations<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#water-utility--network-of-40-pumping-stations" class="hash-link" aria-label="Direct link to Water utility — network of 40 pumping stations" title="Direct link to Water utility — network of 40 pumping stations" translate="no">​</a></h3>
<p><strong>Initial investment:</strong></p>
<ul>
<li class="">40 IoT gateways: 40 × €400 = €16,000</li>
<li class="">Installation (0.5 days per technician per site): 40 × €200 = €8,000</li>
<li class=""><strong>Total: €24,000</strong></li>
</ul>
<p><strong>Annual recurring costs:</strong></p>
<ul>
<li class="">Platform subscriptions + SIM cards: 40 × 480€/year = 19,200€/year</li>
</ul>
<p><strong>Annual savings:</strong></p>
<ul>
<li class="">Trips avoided (2 per station per year × €200): 40 × €400 = €16,000</li>
<li class="">Avoided on-call duty (1 per station per year × €300): 40 × €300 = €12,000</li>
<li class="">Avoided unplanned downtime (0.5/year × €3,000): 20 × €3,000 = €60,000</li>
<li class="">Operator productivity gains (5 hours/week freed up × 60€): 15,600€</li>
<li class=""><strong>Total savings: 103,600€/year</strong></li>
</ul>
<p><strong>ROI in Year 1:</strong> (103,600 - 24,000 - 19,200) / 43,200 = <strong>140%</strong>
<strong>Payback period: 4 to 5 months</strong></p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="industrial-sme--3-production-sites">Industrial SME — 3 production sites<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#industrial-sme--3-production-sites" class="hash-link" aria-label="Direct link to Industrial SME — 3 production sites" title="Direct link to Industrial SME — 3 production sites" translate="no">​</a></h3>
<p><strong>Initial investment:</strong></p>
<ul>
<li class="">15 gateways (5 per site): 15 × €400 = €6,000</li>
<li class="">Installation and configuration: €3,000</li>
<li class=""><strong>Total: €9,000</strong></li>
</ul>
<p><strong>Annual recurring costs:</strong></p>
<ul>
<li class="">Subscriptions + SIM cards: 15 × 480€ = 7,200€/year</li>
</ul>
<p><strong>Annual savings:</strong></p>
<ul>
<li class="">Travel between sites avoided: 24 trips × €250 = €6,000</li>
<li class="">Downtime avoided (1.5 per site per year × €8,000): €36,000</li>
<li class="">Reduction in preventive maintenance (20% of service calls): €12,000</li>
<li class=""><strong>Total savings: €54,000/year</strong></li>
</ul>
<p><strong>ROI in Year 1:</strong> (54,000 - 9,000 - 7,200) / 16,200 = <strong>234%</strong>
<strong>Payback period: 3 months</strong></p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="factors-that-maximize-roi">Factors That Maximize ROI<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#factors-that-maximize-roi" class="hash-link" aria-label="Direct link to Factors That Maximize ROI" title="Direct link to Factors That Maximize ROI" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-start-with-the-most-critical-sites-and-equipment">1. Start with the most critical sites and equipment<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#1-start-with-the-most-critical-sites-and-equipment" class="hash-link" aria-label="Direct link to 1. Start with the most critical sites and equipment" title="Direct link to 1. Start with the most critical sites and equipment" translate="no">​</a></h3>
<p>ROI is highest for equipment with high downtime costs and at the most remote sites (high travel costs). Prioritize:</p>
<ul>
<li class="">Critical pumps in the drinking water supply</li>
<li class="">Equipment in continuous production (high cost per hour of downtime)</li>
<li class="">Sites more than 1 hour’s travel time from the on-call technician</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-integrating-monitoring-into-maintenance-processes">2. Integrating Monitoring into Maintenance Processes<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#2-integrating-monitoring-into-maintenance-processes" class="hash-link" aria-label="Direct link to 2. Integrating Monitoring into Maintenance Processes" title="Direct link to 2. Integrating Monitoring into Maintenance Processes" translate="no">​</a></h3>
<p>An IoT system that isn't integrated into maintenance workflows generates little value. ROI is maximized when:</p>
<ul>
<li class="">IoT alerts automatically trigger work orders in the CMMS</li>
<li class="">IoT reports replace manual reports</li>
<li class="">Technicians use remote access before each site visit (for preliminary diagnostics)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-continuously-measure-and-optimize">3. Continuously Measure and Optimize<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#3-continuously-measure-and-optimize" class="hash-link" aria-label="Direct link to 3. Continuously Measure and Optimize" title="Direct link to 3. Continuously Measure and Optimize" translate="no">​</a></h3>
<p>Establish KPIs for monitoring at the outset:</p>
<ul>
<li class="">Number of service calls avoided (compared to pre-IoT data)</li>
<li class="">MTTR (Mean Time To Repair): average time to resolve incidents</li>
<li class="">OEE (Overall Equipment Effectiveness) for production lines</li>
<li class="">Number of unplanned shutdowns</li>
</ul>
<p>Compare results on a quarterly basis to identify opportunities for improvement.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="mistakes-that-reduce-roi">Mistakes That Reduce ROI<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#mistakes-that-reduce-roi" class="hash-link" aria-label="Direct link to Mistakes That Reduce ROI" title="Direct link to Mistakes That Reduce ROI" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="underestimating-initial-deployment-costs">Underestimating Initial Deployment Costs<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#underestimating-initial-deployment-costs" class="hash-link" aria-label="Direct link to Underestimating Initial Deployment Costs" title="Direct link to Underestimating Initial Deployment Costs" translate="no">​</a></h3>
<p>A sloppy installation leads to costly rework. Budget 30 to 50 percent of the hardware cost for installation, configuration, and training.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="neglecting-change-management">Neglecting Change Management<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#neglecting-change-management" class="hash-link" aria-label="Direct link to Neglecting Change Management" title="Direct link to Neglecting Change Management" translate="no">​</a></h3>
<p>To maximize ROI, teams must truly adopt the new practices. A technician who doesn't use remote access before traveling to a site doesn't save anything.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="choosing-a-non-scalable-platform">Choosing a Non-Scalable Platform<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#choosing-a-non-scalable-platform" class="hash-link" aria-label="Direct link to Choosing a Non-Scalable Platform" title="Direct link to Choosing a Non-Scalable Platform" translate="no">​</a></h3>
<p>The cost of migrating from one IoT platform to another is often higher than the initial cost. Check the provider's scalability, open API, and long-term viability before committing.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion">Conclusion<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#conclusion" class="hash-link" aria-label="Direct link to Conclusion" title="Direct link to Conclusion" translate="no">​</a></h2>
<p>The ROI of industrial IoT is rarely the problem people imagine: for the vast majority of industrial deployments, it is achieved in less than 12 months—often in 3 to 6 months.</p>
<p>The real question isn't "Is it cost-effective?"—it's "Where do I start?" The answer: Start with 5 to 10 high-criticality sites or pieces of equipment, measure the actual ROI over 3 months, and then roll out the solution at scale based on concrete data.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>How to Calculate the ROI of an Industrial IoT Project Without Historical Downtime Data?</strong>
Use industry estimates as a starting point: an unplanned outage costs the manufacturing industry an average of 5 to 15% of its annual production value. For water utilities, expect costs of €2,500 to €5,000 per unplanned emergency response. Refine these estimates with your actual data after a 3-month pilot deployment.</p>
<p><strong>Is the ROI of industrial IoT the same for an SME as for a large corporation?</strong>
No. Large corporations benefit from economies of scale on gateways and subscriptions, and have more critical equipment—so the absolute ROI is higher. On the other hand, the <em>relative</em> ROI (percentage of savings vs. maintenance budget) is often better for SMEs, since they lack dedicated IT resources and save proportionally more by automating monitoring.</p>
<p><strong>Should you calculate the ROI before or after launching a pilot?</strong>
Both. Before: An estimated ROI justifies the pilot’s budget to management. Afterward: the measured ROI (based on actual data) justifies full-scale deployment and validates the initial assumptions. Experience shows that the actual ROI is often higher than the estimated ROI, as unexpected benefits emerge during the pilot (greater visibility, faster decision-making, etc.).</p>
<p><strong>What Costs Should Be Factored Into an Industrial IoT Project?</strong>
Common underestimated costs: RS-485 cabling installation (allow €200–500 per site), training for maintenance teams (at least 2 days), SCADA configuration (integrating new data into existing tools), and change management (getting field technicians to adopt the new tools).</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="resources-for-further-study">Resources for Further Study<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#resources-for-further-study" class="hash-link" aria-label="Direct link to Resources for Further Study" title="Direct link to Resources for Further Study" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/predictive-maintenance-iot-field-sensors">Blog: IIoT Predictive Maintenance — From Sensor Data to Alerts</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/water-wastewater-monitoring-4g-lte">Blog: Water and Wastewater Monitoring — 300 4G Stations</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide">Blog: Remote Industrial Monitoring — Complete Guide 2026</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise">Blog: Cloud SCADA vs. On-Premises SCADA — Decision Guide</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/zero-touch-provisioning">Blog: Zero-Touch Provisioning — Deploy 50 Routers in 2 Hours</a></li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/industrial-iot-roi-calculation#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/roi">Eziwan ROI Calculator</a> — estimate the return on investment for your industrial IoT project</li>
<li class=""><a class="" href="https://eziwan.com/en/guides/industrial-iot-roi">Industrial IoT ROI Guide</a> — methodology and real-world examples of IIoT ROI calculations</li>
<li class=""><a class="" href="https://eziwan.com/en/maintenance-predictive-iiot">IIoT Predictive Maintenance</a> — reduce maintenance costs with predictive IoT</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-solutions">Eziwan Industrial Solutions</a> — a comprehensive range of solutions to maximize industrial ROI</li>
<li class=""><a class="" href="https://eziwan.com/en/monitoring-equipements-industriels">Industrial Equipment Monitoring</a> — monitoring of industrial assets to optimize performance</li>
</ul>]]></content:encoded>
            <category>roi</category>
            <category>industrial-iot</category>
            <category>maintenance</category>
            <category>industry-4-0</category>
            <category>supervision</category>
        </item>
        <item>
            <title><![CDATA[Remote Industrial Monitoring: The Complete Guide 2026]]></title>
            <link>https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide</link>
            <guid>https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide</guid>
            <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A Comprehensive Guide to Remote Industrial Monitoring: Cloud-Based SCADA Architectures, Protocols, Cybersecurity, and Deployment. For automation engineers and maintenance managers.]]></description>
            <content:encoded><![CDATA[<p><strong>Remote industrial monitoring</strong> has become a strategic issue for French manufacturers. Between the phase-out of the 2G GPRS network (Bouygues and SFR will discontinue service by the end of 2026), the NIS2 Directive, which mandates enhanced cybersecurity measures, and pressure to reduce maintenance costs, companies must modernize their approach to remote monitoring.</p>
<p>This guide covers the entire subject: definitions, technical architectures, protocol selection, cybersecurity, and practical implementation for deployments ranging from 1 to 1,000 sites.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-is-remote-industrial-monitoring">What is remote industrial monitoring?<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#what-is-remote-industrial-monitoring" class="hash-link" aria-label="Direct link to What is remote industrial monitoring?" title="Direct link to What is remote industrial monitoring?" translate="no">​</a></h2>
<p><strong>Remote industrial monitoring</strong> (or <strong>industrial telemetry</strong>) refers to the range of technologies that enable:</p>
<ul>
<li class=""><strong>View</strong> the status of industrial equipment (machines, PLCs, sensors) from a remote location</li>
<li class=""><strong>Receive alerts</strong> in real time in the event of an anomaly, threshold exceedance, or failure</li>
<li class=""><strong>Remotely operate</strong> equipment (adjust setpoints, restart, reconfigure)</li>
<li class=""><strong>Analyze</strong> historical data to optimize performance and plan maintenance</li>
</ul>
<p>It applies to all sectors: manufacturing, water and wastewater, energy, agriculture, and building services.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="monitoring-vs-scada-vs-iiot-what-are-the-differences">Monitoring vs. SCADA vs. IIoT: What Are the Differences?<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#monitoring-vs-scada-vs-iiot-what-are-the-differences" class="hash-link" aria-label="Direct link to Monitoring vs. SCADA vs. IIoT: What Are the Differences?" title="Direct link to Monitoring vs. SCADA vs. IIoT: What Are the Differences?" translate="no">​</a></h3>
<p>These terms are often confused. Here are the differences:</p>
<table><thead><tr><th>Term</th><th>Scope</th><th>Infrastructure</th></tr></thead><tbody><tr><td><strong>SCADA</strong> (Supervisory Control and Data Acquisition)</td><td>Single site or network of sites with centralized architecture</td><td>On-premises server + local HMIs</td></tr><tr><td><strong>Remote Monitoring / Remote Supervision</strong></td><td>Multi-site, access from anywhere</td><td>WAN (4G, fiber) + cloud or central server</td></tr><tr><td><strong>IIoT</strong> (Industrial Internet of Things)</td><td>Networked sensors &amp; equipment</td><td>Cloud, edge computing, APIs</td></tr></tbody></table>
<p>In 2026, the lines between them are blurring: modern IIoT platforms (including Eziwan) offer cloud-based SCADA capabilities while integrating legacy industrial protocols (Modbus, OPC-UA).</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="remote-monitoring-architectures">Remote Monitoring Architectures<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#remote-monitoring-architectures" class="hash-link" aria-label="Direct link to Remote Monitoring Architectures" title="Direct link to Remote Monitoring Architectures" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="architecture-1-centralized-cloud-monitoring-recommended">Architecture 1: Centralized Cloud Monitoring (Recommended)<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#architecture-1-centralized-cloud-monitoring-recommended" class="hash-link" aria-label="Direct link to Architecture 1: Centralized Cloud Monitoring (Recommended)" title="Direct link to Architecture 1: Centralized Cloud Monitoring (Recommended)" translate="no">​</a></h3>
<!-- -->
<p><strong>Benefits:</strong></p>
<ul>
<li class="">Rapid deployment, with no on-site server infrastructure required</li>
<li class="">Access from any browser, tablet, or smartphone</li>
<li class="">Scalability from 1 to thousands of sites without requiring an architectural overhaul</li>
<li class="">Centralized updates with no on-site intervention required</li>
</ul>
<p><strong>Typical use cases:</strong> water utilities, power distribution networks, solar farms, and geographically dispersed fleets of industrial equipment.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="architecture-2-on-premises-scada-with-vpn-remote-access">Architecture 2: On-premises SCADA with VPN remote access<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#architecture-2-on-premises-scada-with-vpn-remote-access" class="hash-link" aria-label="Direct link to Architecture 2: On-premises SCADA with VPN remote access" title="Direct link to Architecture 2: On-premises SCADA with VPN remote access" translate="no">​</a></h3>
<!-- -->
<p><strong>Advantages:</strong></p>
<ul>
<li class="">Data remains within the company's IT infrastructure</li>
<li class="">Compatible with existing SCADA systems (Wonderware, WinCC, Vijeo Citect)</li>
<li class="">Full control over hosting and security</li>
</ul>
<p><strong>Typical use cases:</strong> large industrial companies with existing SCADA systems, industries with data sovereignty requirements.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="architecture-3-edge-computing--hybrid-cloud">Architecture 3: Edge Computing + Hybrid Cloud<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#architecture-3-edge-computing--hybrid-cloud" class="hash-link" aria-label="Direct link to Architecture 3: Edge Computing + Hybrid Cloud" title="Direct link to Architecture 3: Edge Computing + Hybrid Cloud" translate="no">​</a></h3>
<p>For sites that generate large amounts of data (production lines, presses, CNC machines), edge computing allows critical data to be processed locally and only aggregated data to be sent to the cloud.</p>
<!-- -->
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="industrial-protocols-for-remote-monitoring">Industrial Protocols for Remote Monitoring<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#industrial-protocols-for-remote-monitoring" class="hash-link" aria-label="Direct link to Industrial Protocols for Remote Monitoring" title="Direct link to Industrial Protocols for Remote Monitoring" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="modbus-rtutcp--the-universal-standard">Modbus RTU/TCP — the universal standard<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#modbus-rtutcp--the-universal-standard" class="hash-link" aria-label="Direct link to Modbus RTU/TCP — the universal standard" title="Direct link to Modbus RTU/TCP — the universal standard" translate="no">​</a></h3>
<p>Modbus is the most widely used protocol in the industry. It comes in two variants:</p>
<ul>
<li class=""><strong>Modbus RTU</strong>: over an RS-485 serial connection. Up to 32 devices over 1,200 m of cable. Data rate: 9,600 to 115,200 bps.</li>
<li class=""><strong>Modbus TCP</strong>: Modbus encapsulation over Ethernet/IP. Port 502. Data rate limited only by the network.</li>
</ul>
<p><strong>What Modbus allows you to monitor:</strong> all modern industrial PLCs (Siemens S7, Schneider Modicon, ABB, Allen Bradley), as well as the vast majority of energy meters, variable-speed drives, and industrial sensors.</p>
<p><strong>Limitation:</strong> Master/slave architecture only. No event notifications—the master must poll the slaves regularly.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="mqtt--the-iiot-protocol">MQTT — The IIoT Protocol<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#mqtt--the-iiot-protocol" class="hash-link" aria-label="Direct link to MQTT — The IIoT Protocol" title="Direct link to MQTT — The IIoT Protocol" translate="no">​</a></h3>
<p>MQTT (Message Queuing Telemetry Transport) is a lightweight publish/subscribe protocol designed for low-bandwidth connections.</p>
<p><strong>Key Features for Remote Monitoring:</strong></p>
<ul>
<li class=""><strong>Persistent Connection</strong>: The MQTT client (gateway) connects to the broker once and maintains the session</li>
<li class=""><strong>Configurable QoS</strong>: Guaranteed delivery of critical messages (QoS 1 or 2)</li>
<li class=""><strong>Hierarchical topics</strong>: <code>usine/ligne1/pompe3/courant</code> — logical data structure</li>
<li class=""><strong>Last Will &amp; Testament</strong>: automatic notification if a device disconnects</li>
</ul>
<p><strong>Cloud integration:</strong> MQTT is natively supported by AWS IoT Core, Azure IoT Hub, Google Cloud IoT, and HiveMQ.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="opc-ua--for-demanding-scada-environments">OPC-UA — for demanding SCADA environments<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#opc-ua--for-demanding-scada-environments" class="hash-link" aria-label="Direct link to OPC-UA — for demanding SCADA environments" title="Direct link to OPC-UA — for demanding SCADA environments" translate="no">​</a></h3>
<p>OPC-UA (Unified Architecture) is the interoperability standard for Industry 4.0.</p>
<p><strong>Key Features:</strong></p>
<ul>
<li class="">Object-oriented information model (not just digital registers)</li>
<li class="">Built-in security: authentication, encryption, message signing</li>
<li class="">Compatible with major SCADA systems (WinCC, FactoryTalk, Ignition)</li>
<li class="">Standard for MES and ERP applications</li>
</ul>
<p><strong>When to choose OPC-UA:</strong> Integrations with existing SCADA, MES, and SAP ERP systems. Environments where data semantics (not just raw values) are important.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="cybersecurity-in-remote-monitoring">Cybersecurity in Remote Monitoring<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#cybersecurity-in-remote-monitoring" class="hash-link" aria-label="Direct link to Cybersecurity in Remote Monitoring" title="Direct link to Cybersecurity in Remote Monitoring" translate="no">​</a></h2>
<p>Remote industrial monitoring is a major attack vector if it is not properly secured. In 2024–2025, several incidents involved unsecured remote access to OT equipment.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-5-golden-rules-of-ot-cybersecurity">The 5 Golden Rules of OT Cybersecurity<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#the-5-golden-rules-of-ot-cybersecurity" class="hash-link" aria-label="Direct link to The 5 Golden Rules of OT Cybersecurity" title="Direct link to The 5 Golden Rules of OT Cybersecurity" translate="no">​</a></h3>
<p><strong>1. No open incoming ports on the industrial network</strong></p>
<p>The <strong>zero-inbound-port</strong> architecture is the fundamental principle: industrial devices themselves initiate the connection to the monitoring cloud. No RDP, VNC, or Modbus ports are directly exposed to the Internet.</p>
<p><strong>2. VPN and Encryption Required</strong></p>
<p>All communications between industrial sites and the monitoring platform must be encrypted. OpenVPN with AES-256-GCM encryption is the 2026 recommendation for new deployments.</p>
<p><strong>3. Strong Authentication for Remote Access</strong></p>
<p>Every technician accessing the system remotely must authenticate using a personal cryptographic key (not a shared password). Multi-factor authentication (MFA) is mandatory for entities subject to NIS2.</p>
<p><strong>4. Principle of Least Privilege</strong></p>
<p>A maintenance technician for a specific PLC has access only to that PLC—not to the entire OT network. Fine-grained access segmentation limits the spread of a breach.</p>
<p><strong>5. Complete audit log</strong></p>
<p>All remote connections, configuration changes, and actions are logged with a timestamp, user ID, and source IP address. These logs are required by the NIS2 directive for critical and important entities.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="nis2-and-remote-monitoring">NIS2 and Remote Monitoring<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#nis2-and-remote-monitoring" class="hash-link" aria-label="Direct link to NIS2 and Remote Monitoring" title="Direct link to NIS2 and Remote Monitoring" translate="no">​</a></h3>
<p>The NIS2 Directive (transposed into French law in October 2024) requires <strong>critical entities</strong> and <strong>important entities</strong> to implement specific measures for remote access:</p>
<ul>
<li class="">Identity-based access control (no shared accounts)</li>
<li class="">Encryption of communications</li>
<li class="">Access logging and monitoring</li>
<li class="">Incident management with notification within 24 hours (critical entities)</li>
</ul>
<p>Sectors involved: water and sanitation, energy, transportation, health care, waste management, and critical industrial production.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="practical-deployment-from-1-to-1000-sites">Practical Deployment: From 1 to 1,000 Sites<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#practical-deployment-from-1-to-1000-sites" class="hash-link" aria-label="Direct link to Practical Deployment: From 1 to 1,000 Sites" title="Direct link to Practical Deployment: From 1 to 1,000 Sites" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="for-a-single-site-poc-or-pilot">For a single site (POC or pilot)<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#for-a-single-site-poc-or-pilot" class="hash-link" aria-label="Direct link to For a single site (POC or pilot)" title="Direct link to For a single site (POC or pilot)" translate="no">​</a></h3>
<p><strong>Required equipment:</strong></p>
<ul>
<li class="">1 IoT gateway with 4G connectivity and RS-485 interfaces</li>
<li class="">M2M SIM subscription (or use your carrier's SIM)</li>
<li class="">Access to the cloud-based monitoring platform</li>
</ul>
<p><strong>Deployment time:</strong> 2 to 4 hours for a technician (hardware installation + cloud configuration + Modbus data validation).</p>
<p><strong>Estimated cost:</strong> €300–600 for equipment + €30–80/month for platform subscription + M2M SIM card.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="for-10-to-50-sites">For 10 to 50 sites<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#for-10-to-50-sites" class="hash-link" aria-label="Direct link to For 10 to 50 sites" title="Direct link to For 10 to 50 sites" translate="no">​</a></h3>
<p>At this scale, <strong>Zero-Touch Provisioning (ZTP)</strong> becomes essential for reducing deployment costs.</p>
<p><strong>Eziwan ZTP Process:</strong></p>
<ol>
<li class="">You set up a standard configuration in the cloud (protocols, alerts, VPN)</li>
<li class="">Each gateway is shipped preconfigured from the factory (or configured remotely)</li>
<li class="">On-site: connect power, SIM, and RS-485—the gateway configures itself</li>
<li class="">Less than 30 minutes of technician time per site</li>
</ol>
<p><strong>Cost savings vs. manual configuration:</strong> For 50 sites, ZTP typically saves 2 to 3 person-days of network configuration time.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="for-100-sites-fleet-management">For 100+ sites (fleet management)<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#for-100-sites-fleet-management" class="hash-link" aria-label="Direct link to For 100+ sites (fleet management)" title="Direct link to For 100+ sites (fleet management)" translate="no">​</a></h3>
<p>For large fleets, <strong>centralized management</strong> features become critical:</p>
<ul>
<li class=""><strong>Fleet Dashboard</strong>: Overview of connectivity and status for each site</li>
<li class=""><strong>Aggregated Alerts</strong>: Filtering of false alarms, automatic escalation</li>
<li class=""><strong>OTA firmware updates</strong>: Deploy updates across the entire fleet without on-site visits</li>
<li class=""><strong>SIM management</strong>: Data usage by site, one-click SIM replacement</li>
<li class=""><strong>Automated Reports</strong>: network availability, incidents, service calls—for CSR or contractual reporting</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="real-world-use-cases">Real-World Use Cases<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#real-world-use-cases" class="hash-link" aria-label="Direct link to Real-World Use Cases" title="Direct link to Real-World Use Cases" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="water-utility--network-of-80-pumping-stations">Water utility — network of 80 pumping stations<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#water-utility--network-of-80-pumping-stations" class="hash-link" aria-label="Direct link to Water utility — network of 80 pumping stations" title="Direct link to Water utility — network of 80 pumping stations" translate="no">​</a></h3>
<p><strong>Previous situation:</strong> weekly supervisory rounds, 2–3 on-call shifts per week for emergency response.</p>
<p><strong>Solution deployed:</strong> 80 4G LTE gateways with Modbus RTU, real-time alerts on pump levels and faults, and remote access for technicians via OpenVPN/IPSec.</p>
<p><strong>Results:</strong></p>
<ul>
<li class="">Inspection rounds reduced by 70% (from weekly to monthly for routine checks)</li>
<li class="">Fault detection in less than 30 seconds (vs. 4–48 hours previously)</li>
<li class="">ROI achieved in 4 months</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="food-processing-industry--3-production-sites">Food Processing Industry — 3 Production Sites<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#food-processing-industry--3-production-sites" class="hash-link" aria-label="Direct link to Food Processing Industry — 3 Production Sites" title="Direct link to Food Processing Industry — 3 Production Sites" translate="no">​</a></h3>
<p><strong>Previous situation:</strong> Each site had its own local SCADA system, with no consolidated visibility at the group level.</p>
<p><strong>Solution deployed:</strong> 3 IoT gateways that consolidate Modbus data from each site into a single cloud-based dashboard. Remote access for the group's maintenance team.</p>
<p><strong>Results:</strong></p>
<ul>
<li class="">A single dashboard for all three sites (vs. three separate SCADA interfaces)</li>
<li class="">Incident response time reduced by 65%</li>
<li class="">Secure and traceable access for maintenance contractors</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="solar-farm--15-power-plants">Solar Farm — 15 Power Plants<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#solar-farm--15-power-plants" class="hash-link" aria-label="Direct link to Solar Farm — 15 Power Plants" title="Direct link to Solar Farm — 15 Power Plants" translate="no">​</a></h3>
<p><strong>Previous situation:</strong> Proprietary data loggers that were incompatible across different inverter manufacturers.</p>
<p><strong>Deployed solution:</strong> IoT gateways with a universal Modbus parser supporting the SunSpec, SMA, ABB, and Fronius protocols. Performance monitoring dashboard (kWh, performance ratio, availability).</p>
<p><strong>Results:</strong></p>
<ul>
<li class="">Consolidation of monitoring into a single dashboard</li>
<li class="">Detection of performance drops of +3% → planned preventive action</li>
<li class="">Automatic reports for investors and the network operator</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="remote-monitoring-deployment-checklist">Remote Monitoring Deployment Checklist<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#remote-monitoring-deployment-checklist" class="hash-link" aria-label="Direct link to Remote Monitoring Deployment Checklist" title="Direct link to Remote Monitoring Deployment Checklist" translate="no">​</a></h2>
<p>Before launching your remote monitoring project, check the following:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="connectivity">Connectivity<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#connectivity" class="hash-link" aria-label="Direct link to Connectivity" title="Direct link to Connectivity" translate="no">​</a></h3>
<ul class="contains-task-list containsTaskList_mC6p">
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->4G LTE coverage verified at each site (carrier tests)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Dual SIM option evaluated for critical sites</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Estimated data usage per site (Modbus polling frequency × register size)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="field-equipment">Field Equipment<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#field-equipment" class="hash-link" aria-label="Direct link to Field Equipment" title="Direct link to Field Equipment" translate="no">​</a></h3>
<ul class="contains-task-list containsTaskList_mC6p">
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Protocol inventory: Modbus RTU (RS-485), Modbus TCP, or proprietary?</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->List of variables to monitor per device (Modbus registers)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Power supply available in the cabinet (24V DC or 230V AC)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="cybersecurity">Cybersecurity<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#cybersecurity" class="hash-link" aria-label="Direct link to Cybersecurity" title="Direct link to Cybersecurity" translate="no">​</a></h3>
<ul class="contains-task-list containsTaskList_mC6p">
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Zero-inbound-port architecture selected</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->OpenVPN/IPSec or IPSec VPN planned</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Technician access policy defined (permissions, time slots)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Is NIS2 applicable to your organization? (critical/important entities)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="cloud-platform">Cloud Platform<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#cloud-platform" class="hash-link" aria-label="Direct link to Cloud Platform" title="Direct link to Cloud Platform" translate="no">​</a></h3>
<ul class="contains-task-list containsTaskList_mC6p">
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Data hosted in France or the EU (GDPR)</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->API available for integration with existing SCADA/MES systems</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Platform availability SLA (minimum 99.5%)</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion">Conclusion<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#conclusion" class="hash-link" aria-label="Direct link to Conclusion" title="Direct link to Conclusion" translate="no">​</a></h2>
<p>Remote industrial monitoring is no longer an option in 2026: the phase-out of 2G GPRS, the NIS2 Directive, and economic pressure to reduce maintenance costs make it a necessity for all industrial companies with remote sites.</p>
<p>The good news: With 4G LTE solutions featuring Zero-Touch Provisioning, you can now connect an industrial site in less than an hour, for less than 50€/month, all-inclusive.</p>
<p>The key to success is choosing a <strong>secure cloud-native</strong> architecture from the start—not adding security as an afterthought on top of an architecture that wasn't designed for it.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq--remote-industrial-monitoring">FAQ — Remote Industrial Monitoring<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#faq--remote-industrial-monitoring" class="hash-link" aria-label="Direct link to FAQ — Remote Industrial Monitoring" title="Direct link to FAQ — Remote Industrial Monitoring" translate="no">​</a></h2>
<p><strong>What is the difference between SCADA and cloud-based IoT monitoring?</strong></p>
<p>A traditional SCADA system is a centralized (often on-premises) system with thick clients (dedicated PC software), local data archiving, and a star architecture. Cloud-based IoT monitoring is a distributed architecture: each site sends its data to the cloud via a gateway, without a central on-site server. The cloud offers multi-site access, mobile access, and a REST API for integration—whereas traditional SCADA requires a site-to-site VPN and a license per client. The two can coexist via OPC-UA or Modbus connectors to the existing SCADA system.</p>
<p><strong>How many variables can be monitored simultaneously across 100 sites?</strong></p>
<p>There is no fixed limit on the cloud side—modern IIoT platforms are designed to handle millions of measurement points. The practical limit lies with the gateway and network: a standard gateway collects up to 500 Modbus variables per site with a 5-second polling interval, or 6,000 values per minute per site. Across 100 sites, that’s 600,000 values per minute—manageable if the cloud is scaled accordingly (time series, site-based partitioning).</p>
<p><strong>Can remote monitoring work if the PLC is in STOP mode (program stop)?</strong></p>
<p>Yes, for monitoring the PLC's status (CPU in STOP mode, time of last alarm, I/O status). No for Modbus collection of process variables—the PLC’s Modbus TCP server stops responding in STOP mode on certain models (the S7-1200 stops the MB_SERVER when in STOP mode). Check the specific behavior of the PLC in STOP mode before relying on Modbus data collection to detect CPU stops.</p>
<p><strong>What is the minimum latency between a state change on the PLC and its appearance on the dashboard?</strong></p>
<p>With a 1-second Modbus polling interval and a properly sized cloud infrastructure, the total latency is typically 2 to 5 seconds (1 second of polling wait time + 1 to 2 seconds of 4G transit time + 1 to 2 seconds of cloud processing time). For critical alarms (threshold exceedances), Eziwan can send SMS/email notifications in less than 10 seconds after detecting the exceedance. For a real-time response (&lt; 100 ms), local logic is required on the PLC or gateway—not the cloud.</p>
<p><strong>Can non-Ethernet devices (RS-485 meters, 4-20 mA sensors) be monitored?</strong></p>
<p>Yes, via the gateway's RS-485 port for Modbus RTU, and via the analog inputs for 4–20 mA or 0–10 V signals. Sensors without a digital protocol (simple dry contacts, level switches) connect to the digital inputs of the gateway or an expansion module. The goal is to monitor the entire site from a single gateway, regardless of the heterogeneity of the equipment.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/secure-remote-access-plc-scada">Guide: Secure Remote Access for PLCs and SCADA — VPN Architecture</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/industrial-lte-router">Guide: Industrial 4G LTE Router — Migrating from ADSL</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/connect-siemens-s7-plc-to-cloud">Guide: Connecting a Siemens S7 PLC to the Cloud</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/nis2-cybersecurity-industrial-infrastructure">NIS2: Specific Requirements for Manufacturers</a></li>
<li class=""><a class="" href="https://eziwan.com/en/docs/guides/supervision-multi-sites">Docs: Eziwan Multi-Site Monitoring</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/industrial-iot-roi-calculation">Blog: ROI of Industrial IoT — Calculation and Optimization</a></li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources-1">Additional Resources<a href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide#additional-resources-1" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/industrial-remote-support">Industrial Monitoring and Remote Support</a> — monitoring and remote support solutions for industry</li>
<li class=""><a class="" href="https://eziwan.com/en/monitoring-equipements-industriels">Industrial Equipment Monitoring</a> — monitor your industrial equipment in real time</li>
<li class=""><a class="" href="https://eziwan.com/en/scada-cloud">Cloud SCADA</a> — cloud-based SCADA platform for multi-site monitoring</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-remote-diagnostics">Industrial Remote Diagnostics</a> — remote diagnostics for your industrial facilities</li>
<li class=""><a class="" href="https://eziwan.com/en/guides/isolated-site-monitoring">Guide: Monitoring Remote Sites</a> — monitor sites without a wired connection</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-cloud-data-logger">Cloud-Based Industrial Data Logger</a> — recording and archiving your process data</li>
</ul>]]></content:encoded>
            <category>supervision</category>
            <category>scada</category>
            <category>remote-access</category>
            <category>maintenance</category>
            <category>monitoring</category>
            <category>industrial-iot</category>
        </item>
        <item>
            <title><![CDATA[Modbus, MQTT, OPC-UA: Which Industrial Protocol Should You Choose in 2026?]]></title>
            <link>https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols</link>
            <guid>https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols</guid>
            <pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Comprehensive Comparison of Modbus RTU/TCP, MQTT, and OPC-UA: Architectures, Performance, Use Cases, and Limitations. A Guide to Choosing the Right Protocol for Your Industrial IoT Project.]]></description>
            <content:encoded><![CDATA[<p>The question “Which protocol should I use for my industrial IoT project?” comes up time and again in factory modernization projects. Modbus, MQTT, and OPC-UA are the three most commonly mentioned protocols—but they are not direct alternatives. They operate at different layers, address different needs, and often complement rather than compete with one another.</p>
<p>This article explains their fundamental differences, strengths, and limitations, and provides a decision-making guide to help you choose the right protocol for your use case.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="first-lets-understand-protocols-of-different-types">First, let's understand: protocols of different types<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#first-lets-understand-protocols-of-different-types" class="hash-link" aria-label="Direct link to First, let's understand: protocols of different types" title="Direct link to First, let's understand: protocols of different types" translate="no">​</a></h2>
<p>Before making a comparison, it is important to understand that Modbus, MQTT, and OPC-UA do not operate at the same level:</p>
<p><strong>Modbus</strong> is a <strong>data read</strong> protocol: it allows you to query a device to read its registers (measurements, statuses). It is a field protocol—master/slave—designed for data acquisition from industrial equipment.</p>
<p><strong>MQTT</strong> is a <strong>messaging</strong> protocol: it allows users to publish and subscribe to data streams through a centralized broker. It is a message transport protocol, not a protocol for direct data acquisition from a device.</p>
<p><strong>OPC-UA</strong> is a <strong>service architecture</strong>: it combines data acquisition, data model access, security, alarms, and history into a single, unified industry standard. It is the most comprehensive—and the most complex—solution.</p>
<p><strong>In practice:</strong> Most modern industrial IoT architectures use all three: Modbus to read field devices, MQTT to transmit data to the cloud, and OPC-UA for interoperability between complex systems.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="modbus-rtu-and-modbus-tcp">Modbus RTU and Modbus TCP<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#modbus-rtu-and-modbus-tcp" class="hash-link" aria-label="Direct link to Modbus RTU and Modbus TCP" title="Direct link to Modbus RTU and Modbus TCP" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-is-modbus">What is Modbus?<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#what-is-modbus" class="hash-link" aria-label="Direct link to What is Modbus?" title="Direct link to What is Modbus?" translate="no">​</a></h3>
<p>Modbus was created in 1979 by Modicon (now Schneider Electric). It is the oldest industrial protocol still in active use—and by far the most widely used in the French industrial sector.</p>
<p><strong>Modbus RTU</strong> operates over an RS-485 (or RS-232) serial connection. It is asynchronous, master/slave, with a linear (multidrop) bus topology. Up to 247 slaves can be connected to a single RS-485 bus.</p>
<p><strong>Modbus TCP</strong> is Modbus encapsulated in TCP/IP packets. It operates over Ethernet on port 502. It retains the master/slave model but allows for arbitrary network topologies (star, tree). There is no strict limit on the number of slaves on the network.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-modbus-allows-you-to-read">What Modbus Allows You to Read<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#what-modbus-allows-you-to-read" class="hash-link" aria-label="Direct link to What Modbus Allows You to Read" title="Direct link to What Modbus Allows You to Read" translate="no">​</a></h3>
<p>Modbus exposes 4 types of data:</p>
<ul>
<li class=""><strong>Coils (0x)</strong>: read/write digital outputs (Booleans)</li>
<li class=""><strong>Discrete Inputs (1x)</strong>: read-only digital inputs (Booleans)</li>
<li class=""><strong>Input Registers (3x)</strong>: 16-bit read-only registers (sensor measurements)</li>
<li class=""><strong>Holding Registers (4x)</strong>: 16-bit read/write registers (setpoints, parameters)</li>
</ul>
<p>To read a temperature measurement from a sensor: the master sends a request to "read registers 3x01 through 3x02," and the slave responds with the two registers containing the value (typically a 32-bit float spread across two contiguous registers).</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="strengths-of-modbus">Strengths of Modbus<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#strengths-of-modbus" class="hash-link" aria-label="Direct link to Strengths of Modbus" title="Direct link to Strengths of Modbus" translate="no">​</a></h3>
<p><strong>Absolute universality:</strong> If you have industrial equipment with an RS-485 port or an Ethernet port and don't know which protocol it uses, start by testing Modbus. It is highly likely that it supports Modbus.</p>
<p><strong>Simplicity:</strong> The protocol is simple—numbered registers, standard read/write functions. Any developer can implement a Modbus client in a matter of hours.</p>
<p><strong>Resilience:</strong> No dependence on a broker or a central server. The master polls each slave directly. A failure of the master does not affect the slaves' communication with each other.</p>
<p><strong>Maturity:</strong> 45 years of industrial deployment. Modbus libraries are available in all programming languages (Python, C, Java, JavaScript, etc.).</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="limitations-of-modbus">Limitations of Modbus<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#limitations-of-modbus" class="hash-link" aria-label="Direct link to Limitations of Modbus" title="Direct link to Limitations of Modbus" translate="no">​</a></h3>
<p><strong>Pull-only architecture:</strong> The master must proactively poll each slave. The devices do not send data on their own. On a bus with 50 slaves polled every second, the actual polling interval per slave can drop to 20 seconds.</p>
<p><strong>No built-in security:</strong> Modbus RTU and Modbus TCP have no authentication or encryption mechanisms. Any device on the network can read or write the registers of an exposed Modbus device. Security must be implemented at the network level (VPN, segmentation).</p>
<p><strong>No automatic discovery:</strong> There is no mechanism for discovering Modbus devices on a bus. You must know the slave address and register addresses for each device.</p>
<p><strong>No semantic naming:</strong> Registry entry 40001 does not indicate what it contains—you need the manufacturer's documentation to know that it is "water inlet temperature." No self-description.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="when-to-use-modbus">When to Use Modbus<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#when-to-use-modbus" class="hash-link" aria-label="Direct link to When to Use Modbus" title="Direct link to When to Use Modbus" translate="no">​</a></h3>
<ul>
<li class="">Reading data from field devices (energy meters, pressure sensors, variable-speed drives, PLCs)</li>
<li class="">Existing field networks with RS-485 cabling already in place</li>
<li class="">Projects involving heterogeneous equipment from different manufacturers (Modbus is the most widely used)</li>
<li class="">Limited budgets or teams without specialized expertise</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="mqtt-message-queuing-telemetry-transport">MQTT (Message Queuing Telemetry Transport)<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#mqtt-message-queuing-telemetry-transport" class="hash-link" aria-label="Direct link to MQTT (Message Queuing Telemetry Transport)" title="Direct link to MQTT (Message Queuing Telemetry Transport)" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-is-mqtt">What is MQTT?<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#what-is-mqtt" class="hash-link" aria-label="Direct link to What is MQTT?" title="Direct link to What is MQTT?" translate="no">​</a></h3>
<p>MQTT was created in 1999 by IBM for telemetry over low-bandwidth satellite links. It was standardized by OASIS in 2014 (MQTT 3.1.1) and 2019 (MQTT 5.0).</p>
<p>MQTT is a <strong>publish/subscribe</strong> protocol: publishers send messages to topics, and subscribers receive messages on the topics they are subscribed to. A central MQTT <strong>broker</strong> routes messages between publishers and subscribers.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="mqtt-architecture">MQTT Architecture<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#mqtt-architecture" class="hash-link" aria-label="Direct link to MQTT Architecture" title="Direct link to MQTT Architecture" translate="no">​</a></h3>
<!-- -->
<p>The broker is at the heart of the MQTT architecture. Clients (publishers and subscribers) connect to the broker—they never communicate directly with each other.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="strengths-of-mqtt">Strengths of MQTT<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#strengths-of-mqtt" class="hash-link" aria-label="Direct link to Strengths of MQTT" title="Direct link to Strengths of MQTT" translate="no">​</a></h3>
<p><strong>Push architecture:</strong> Publishers send data when they have something to say. No polling—the subscriber receives the data immediately upon publication. Typical latency: 10–50 ms end-to-end.</p>
<p><strong>Lightweight:</strong> The protocol was designed for resource-constrained devices (microcontrollers, 2G modems). An MQTT message can fit into 2 bytes (minimum header). Very bandwidth-efficient.</p>
<p><strong>Configurable QoS:</strong> Three levels of quality of service: QoS 0 (at most once), QoS 1 (at least once), QoS 2 (exactly once). For mission-critical applications, QoS 2 guarantees delivery exactly once.</p>
<p><strong>Cloud interoperability:</strong> All major cloud providers (AWS IoT Core, Azure IoT Hub, Google Cloud IoT) offer a native MQTT broker. MQTT is the de facto protocol for cloud-based IoT architectures.</p>
<p><strong>Native TLS:</strong> MQTT natively supports TLS 1.3. Security is built into the protocol; it is not an add-on.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="limitations-of-mqtt">Limitations of MQTT<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#limitations-of-mqtt" class="hash-link" aria-label="Direct link to Limitations of MQTT" title="Direct link to Limitations of MQTT" translate="no">​</a></h3>
<p><strong>Cannot read devices directly:</strong> A Modbus RTU device does not natively support MQTT. A gateway is required to read the Modbus data and publish it via MQTT. This is why Modbus and MQTT are often used together in industrial IoT architectures.</p>
<p><strong>Dependence on the broker:</strong> If the MQTT broker goes down, the entire messaging architecture fails. The broker's resilience is critical. Managed brokers (AWS IoT, HiveMQ Cloud) are very reliable, but create a dependency on an external service.</p>
<p><strong>No standardized data model:</strong> MQTT does not define the message format or the structure of topics. Each implementation is free to choose its own approach—which hinders interoperability. Two MQTT systems from different vendors may not be able to communicate without some adaptation.</p>
<p><strong>No native request/response:</strong> MQTT is designed for unidirectional events. To implement a request/response pattern (e.g., requesting a parameter from a device), you must use MQTT 5.0 with correlated response topics—this is possible but more complex.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="when-to-use-mqtt">When to Use MQTT<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#when-to-use-mqtt" class="hash-link" aria-label="Direct link to When to Use MQTT" title="Direct link to When to Use MQTT" translate="no">​</a></h3>
<ul>
<li class="">Data transmission from the field to the cloud (Modbus → Gateway → MQTT → Cloud)</li>
<li class="">Event-driven architectures where data changes irregularly</li>
<li class="">Embedded IoT deployments on microcontrollers or resource-constrained devices</li>
<li class="">Integration with cloud-native brokers (AWS IoT, Azure IoT Hub)</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="opc-ua-opc-unified-architecture">OPC-UA (OPC Unified Architecture)<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#opc-ua-opc-unified-architecture" class="hash-link" aria-label="Direct link to OPC-UA (OPC Unified Architecture)" title="Direct link to OPC-UA (OPC Unified Architecture)" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-is-opc-ua">What is OPC-UA?<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#what-is-opc-ua" class="hash-link" aria-label="Direct link to What is OPC-UA?" title="Direct link to What is OPC-UA?" translate="no">​</a></h3>
<p>OPC-UA (IEC 62541) was developed by the OPC Foundation beginning in 2006 as the successor to OPC Classic (based on Windows COM/DCOM). It is the most comprehensive industry standard: it combines data acquisition, a semantic model, security, history, alarms, and method access into a single protocol.</p>
<p>OPC-UA is now the preferred protocol among PLC manufacturers for Industry 4.0 architectures: Siemens TIA Portal (S7-1500), Rockwell ControlLogix, Beckhoff TwinCAT, and B&amp;R Automation—all of which have supported OPC-UA natively for the past 5 to 10 years.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="opc-ua-capabilities">OPC-UA Capabilities<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#opc-ua-capabilities" class="hash-link" aria-label="Direct link to OPC-UA Capabilities" title="Direct link to OPC-UA Capabilities" translate="no">​</a></h3>
<p><strong>Semantic data model:</strong> Unlike Modbus (which uses anonymous, numbered registers), OPC-UA exposes a tree of named and typed objects. The node "ns=2;i=1001" can be named "Machine1/MainMotor/BearingTemperature" and include metadata (unit, range, description). Self-description is built-in.</p>
<p><strong>Built-in security:</strong> Authentication, authorization, encryption, message integrity—it's all built into the protocol. OPC-UA supports several security profiles (None, Sign, SignAndEncrypt) using modern algorithms (AES-256, RSA-2048+).</p>
<p><strong>Publish/Subscribe via OPC-UA PubSub (2017):</strong> OPC-UA can now operate in asynchronous (push) publication mode, not just in request/response (pull) mode. It can publish to MQTT brokers, making OPC-UA and MQTT complementary rather than competing technologies.</p>
<p><strong>Access to Methods:</strong> OPC-UA allows you to call methods on devices—not just read values. Whether it's actuating a valve or issuing a motor start command, everything is modeled as an OPC-UA object.</p>
<p><strong>Semantics and Interoperability:</strong> The OPC-UA "Companion Specifications" define industry-standardized models: OPC-UA for Plastics, for Robotics, for PackML (packaging), for Mining... SCADA software that supports OPC-UA for PackML can connect to any compliant packaging line without requiring any specific configuration.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="limitations-of-opc-ua">Limitations of OPC-UA<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#limitations-of-opc-ua" class="hash-link" aria-label="Direct link to Limitations of OPC-UA" title="Direct link to Limitations of OPC-UA" translate="no">​</a></h3>
<p><strong>Complexity:</strong> OPC-UA is the most complex protocol to implement and configure. The specifications are over 1,000 pages long. The learning curve is significant for teams with no prior OPC-UA experience.</p>
<p><strong>Required resources:</strong> A full-featured OPC-UA server requires more resources than a Modbus slave. Older PLCs or resource-constrained microcontrollers cannot run a full OPC-UA stack (although there are lightweight "nano" profiles available).</p>
<p><strong>Not universally used in the field:</strong> Older equipment (manufactured before 2010–2015) does not support OPC-UA. In a heterogeneous industrial environment, you will encounter Modbus much more frequently than OPC-UA on existing field equipment.</p>
<p><strong>Network overhead:</strong> OPC-UA messages are larger than Modbus messages (XML or binary, depending on the transport). On low-bandwidth 4G connections, this can be a factor.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="when-to-use-opc-ua">When to Use OPC-UA<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#when-to-use-opc-ua" class="hash-link" aria-label="Direct link to When to Use OPC-UA" title="Direct link to When to Use OPC-UA" translate="no">​</a></h3>
<ul>
<li class="">Recent Siemens S7-1200/1500 PLCs with TIA Portal (native OPC-UA)</li>
<li class="">Industry 4.0 architectures with SCADA/MES/ERP interoperability</li>
<li class="">Projects requiring strong security and traceability for access</li>
<li class="">Multi-vendor environments requiring semantic interoperability</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="decision-guide-which-combination-is-right-for-your-project">Decision Guide: Which Combination Is Right for Your Project?<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#decision-guide-which-combination-is-right-for-your-project" class="hash-link" aria-label="Direct link to Decision Guide: Which Combination Is Right for Your Project?" title="Direct link to Decision Guide: Which Combination Is Right for Your Project?" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="a-simple-typical-industrial-iot-architecture">A Simple, Typical Industrial IoT Architecture<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#a-simple-typical-industrial-iot-architecture" class="hash-link" aria-label="Direct link to A Simple, Typical Industrial IoT Architecture" title="Direct link to A Simple, Typical Industrial IoT Architecture" translate="no">​</a></h3>
<!-- -->
<p><strong>Usage:</strong> Process monitoring, alerts, historical data. 80% of French industrial IoT projects follow this model.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="architecture-with-a-cloud-integration-bus">Architecture with a Cloud Integration Bus<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#architecture-with-a-cloud-integration-bus" class="hash-link" aria-label="Direct link to Architecture with a Cloud Integration Bus" title="Direct link to Architecture with a Cloud Integration Bus" translate="no">​</a></h3>
<!-- -->
<p><strong>Usage:</strong> Projects with multiple data consumers (SCADA + ERP + BI). MQTT as an integration bus.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="industry-40-architecture-with-opc-ua">Industry 4.0 Architecture with OPC-UA<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#industry-40-architecture-with-opc-ua" class="hash-link" aria-label="Direct link to Industry 4.0 Architecture with OPC-UA" title="Direct link to Industry 4.0 Architecture with OPC-UA" translate="no">​</a></h3>
<!-- -->
<p><strong>Applications:</strong> Factories with modern PLCs, Industry 4.0 projects, MES integration.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="decision-matrix">Decision Matrix<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#decision-matrix" class="hash-link" aria-label="Direct link to Decision Matrix" title="Direct link to Decision Matrix" translate="no">​</a></h3>
<table><thead><tr><th>Requirement</th><th>Modbus RTU</th><th>Modbus TCP</th><th>MQTT</th><th>OPC-UA</th></tr></thead><tbody><tr><td>Read RS-485 field sensors</td><td>✓✓</td><td>—</td><td>—</td><td>—</td></tr><tr><td>Read PLCs on the network</td><td>✓</td><td>✓✓</td><td>—</td><td>✓</td></tr><tr><td>Send data to the cloud</td><td>—</td><td>—</td><td>✓✓</td><td>✓</td></tr><tr><td>SCADA/MES Interoperability</td><td>✗</td><td>✗</td><td>Partial</td><td>✓✓</td></tr><tr><td>Built-in Security</td><td>✗</td><td>✗</td><td>TLS</td><td>✓✓</td></tr><tr><td>Legacy equipment</td><td>✓✓</td><td>✓</td><td>—</td><td>✗</td></tr><tr><td>Recent PLCs (&gt;2015)</td><td>✓</td><td>✓</td><td>—</td><td>✓✓</td></tr><tr><td>Cloud-native architectures</td><td>✗</td><td>✗</td><td>✓✓</td><td>✓</td></tr><tr><td>SMEs without protocol expertise</td><td>✓✓</td><td>✓✓</td><td>✓</td><td>✗</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-eziwan-handles-the-three-protocols">How Eziwan Handles the Three Protocols<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#how-eziwan-handles-the-three-protocols" class="hash-link" aria-label="Direct link to How Eziwan Handles the Three Protocols" title="Direct link to How Eziwan Handles the Three Protocols" translate="no">​</a></h2>
<p>The Eziwan gateway is agnostic to field-side protocols:</p>
<ul>
<li class=""><strong>Modbus RTU</strong>: native RS-485 port, master mode, up to 247 slaves per bus, configurable polling interval from 1 second to 15 minutes</li>
<li class=""><strong>Modbus TCP</strong>: Modbus TCP client, simultaneous connections to multiple Modbus servers</li>
<li class=""><strong>MQTT</strong>: MQTT publisher (publishes collected data), subscriber support available for commands</li>
<li class=""><strong>OPC-UA</strong>: OPC-UA client (reads nodes, subscribes to value changes) — available upon request for OPC-UA deployments</li>
</ul>
<p>On the cloud side, data is standardized internally and exposed via:</p>
<ul>
<li class=""><strong>REST API</strong> (JSON) for cloud applications</li>
<li class=""><strong>Webhooks</strong> for real-time events</li>
<li class="">Outbound <strong>MQTT</strong> for message bus integrations</li>
</ul>
<p>You can combine Modbus RTU on field devices with MQTT to your AWS/Azure cloud without changing anything—the gateway handles the translation.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion">Conclusion<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#conclusion" class="hash-link" aria-label="Direct link to Conclusion" title="Direct link to Conclusion" translate="no">​</a></h2>
<p>In 2026, the answer to "Modbus, MQTT, or OPC-UA?" is generally "all three":</p>
<ul>
<li class=""><strong>Modbus</strong> to read your field devices (that's the language they use)</li>
<li class=""><strong>MQTT</strong> to transmit data to your cloud and distribute it to multiple applications</li>
<li class=""><strong>OPC-UA</strong> if you have recent Siemens/Rockwell/Beckhoff PLCs and need SCADA/MES interoperability</li>
</ul>
<p>This isn't a competition—it's a layered architecture. The choice isn't "which protocol," but "which protocol at which layer for which device."</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq--modbus-mqtt-and-opc-ua">FAQ — Modbus, MQTT, and OPC-UA<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#faq--modbus-mqtt-and-opc-ua" class="hash-link" aria-label="Direct link to FAQ — Modbus, MQTT, and OPC-UA" title="Direct link to FAQ — Modbus, MQTT, and OPC-UA" translate="no">​</a></h2>
<p><strong>Can Modbus and MQTT be used simultaneously on the same gateway?</strong></p>
<p>Yes, and that’s the most common architecture in IIoT. The gateway collects data from PLCs via Modbus TCP or RTU (field layer) and publishes it via MQTT to the cloud (transport layer). Modbus stops at the gateway—it is never exposed to the Internet. MQTT takes over for transport to the cloud, using TLS 1.3 and authentication.</p>
<p><strong>Can OPC-UA replace Modbus on existing PLCs (S7-1200, M340)?</strong></p>
<p>On Siemens S7-1200 controllers, the OPC-UA server is only available starting with firmware version 4.4 and requires explicit configuration in TIA Portal. On S7-1500 controllers, it has been supported natively since firmware version 2.0. On Schneider M340 controllers, OPC-UA is not built-in—an additional module is required. In practice, for existing installations, Modbus TCP remains the universal solution; OPC-UA is primarily relevant for new projects using recent PLCs.</p>
<p><strong>MQTT with QoS 0 vs. QoS 1 vs. QoS 2 — Which Should You Choose for Industrial Monitoring?</strong></p>
<p>For monitoring process data (temperatures, pressures), QoS 1 (At Least Once) strikes the right balance: delivery is guaranteed even after reconnection, at the risk of a few duplicates (which are acceptable for monitoring data). QoS 2 (Exactly Once) is more resource-intensive due to the round-trip confirmation and is rarely necessary for measurements. QoS 0 (At Most Once) is suitable for very frequent data (&gt; 1/s) where occasional loss is acceptable.</p>
<p><strong>Is a public MQTT broker (HiveMQ, EMQX Cloud) sufficient for industrial applications?</strong></p>
<p>For pilot projects or non-critical applications, yes. But for a production environment with confidentiality requirements (process data, equipment identifiers), a private broker hosted in France is preferable. MQTT data passing through U.S. public brokers is potentially subject to the CLOUD Act—this should be evaluated based on the sensitivity of the data and the industry.</p>
<p><strong>Does OPC-UA affect the PLC's performance compared to Modbus?</strong></p>
<p>OPC-UA places significantly greater demands on CPU and memory than Modbus TCP. On an S7-1500 CPU 1511 with an active OPC-UA server and 50 client connections, the cycle time can increase by 5 to 15 percent. On an S7-1200, resources are more limited—always test the impact using the complete production program before deploying OPC-UA in production.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/modbus-tcp-vs-rtu">Blog: Modbus TCP vs. RTU — Which Protocol Should You Choose?</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/opc-ua-mqtt-industrial-gateway">Blog: OPC-UA, MQTT, Modbus — Choosing Your Industrial Gateway</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/complete-opc-ua-guide-industry">Blog: Complete OPC-UA Guide for Industry</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/mqtt-rs485-protocols">Blog: MQTT, RS485, Modbus — Industrial IoT Protocols Explained</a></li>
<li class=""><a class="" href="https://eziwan.com/en/docs/integration/modbus">Docs: Modbus configuration on the Eziwan Gateway</a></li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/industrial-protocols">Industrial Protocols</a> — A Comprehensive Comparison of Modbus, MQTT, OPC UA, and DNP3</li>
<li class=""><a class="" href="https://eziwan.com/en/modbus-rtu-cloud">Modbus RTU to the Cloud</a> — Connect Your RS-485 Modbus RTU Devices to the Cloud</li>
<li class=""><a class="" href="https://eziwan.com/en/opc-ua-mqtt">OPC UA to MQTT</a> — Publish OPC UA Data to an MQTT Broker</li>
<li class=""><a class="" href="https://eziwan.com/en/rs485-modbus-4g">RS-485 Modbus 4G</a> — RS-485 Modbus data transmission via 4G network</li>
<li class=""><a class="" href="https://eziwan.com/en/passerelle-iiot">IIoT Gateway</a> — IIoT gateway solutions for industry</li>
<li class=""><a class="" href="https://eziwan.com/en/guides/modbus-to-cloud">Guide: Modbus to the Cloud</a> — comprehensive guide to transmitting your Modbus data</li>
</ul>]]></content:encoded>
            <category>modbus</category>
            <category>mqtt</category>
            <category>opc-ua</category>
            <category>industrial-protocols</category>
            <category>industrial-iot</category>
        </item>
        <item>
            <title><![CDATA[How to Choose an Industrial IoT Gateway: 9 Essential Criteria (2026 Guide)]]></title>
            <link>https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria</link>
            <guid>https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria</guid>
            <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A Comprehensive Guide to Choosing an Industrial IoT Gateway in 2026: Supported Protocols, 4G/5G Connectivity, Zero Trust Security, Certifications, ZTP, and Data Hosting. Comparison and Checklist.]]></description>
            <content:encoded><![CDATA[<p>The market for industrial IoT gateways has expanded significantly in recent years. With such a vast array of options—from Taiwanese brands priced at €80 to integrated solutions costing €2,000, and from simple Modbus devices to gateways with VPN and edge computing—how can you make sense of it all?</p>
<p>This guide describes the nine criteria that help distinguish a gateway truly suited for industrial environments from a poorly repurposed consumer-grade product. It is intended for maintenance managers, automation engineers, and industrial IT directors who are planning a connectivity or monitoring project.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-1-industrially-supported-protocols">Criterion 1: Industrially supported protocols<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#criterion-1-industrially-supported-protocols" class="hash-link" aria-label="Direct link to Criterion 1: Industrially supported protocols" title="Direct link to Criterion 1: Industrially supported protocols" translate="no">​</a></h2>
<p>This is the number one criterion. If your gateway doesn't "speak" the same protocol as your devices, all other criteria become secondary.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="essential-protocols-in-france-in-2026">Essential Protocols in France in 2026<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#essential-protocols-in-france-in-2026" class="hash-link" aria-label="Direct link to Essential Protocols in France in 2026" title="Direct link to Essential Protocols in France in 2026" translate="no">​</a></h3>
<p><strong>Modbus RTU (RS-485)</strong> — The gold standard in French industry. Energy meters, HVAC controllers, sensors, variable-frequency drives: if your equipment has an RS-485 serial port, it likely uses Modbus RTU. Any industrial gateway worth its salt must support it natively.</p>
<p><strong>Modbus TCP (Ethernet)</strong> — The network version of Modbus. Newer PLCs, Modbus-Ethernet gateways, and devices with RJ45 interfaces. Check whether the gateway supports the role of <strong>Modbus master</strong> (active polling) or only that of a server (passive).</p>
<p><strong>MQTT</strong> — The quintessential IoT messaging protocol. Used to publish data to cloud brokers (AWS IoT, Azure IoT Hub, local Mosquitto MQTT). Essential for cloud-native architectures.</p>
<p><strong>OPC-UA</strong> — IEC 62541 industrial standard, adopted by Siemens, Rockwell, and Beckhoff for recent PLCs. If your IT system includes Siemens S7-1500/1200 PLCs or a recent version of TIA Portal, check for OPC-UA compatibility.</p>
<p><strong>Specific Protocols:</strong></p>
<ul>
<li class=""><em>DNP3</em>: power grids, drinking water, gas (France, North America)</li>
<li class=""><em>IEC 61850</em>: high-voltage substations</li>
<li class=""><em>M-Bus</em>: heat, water, and gas meters (buildings, district heating networks)</li>
<li class=""><em>BACnet</em>: HVAC and building automation systems (BAS)</li>
</ul>
<p><strong>Protocol Checklist:</strong></p>
<ul class="contains-task-list containsTaskList_mC6p">
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Modbus RTU (RS-485) in master mode</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Modbus TCP in master mode</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->MQTT with TLS 1.2/1.3</li>
<li class="task-list-item"><input type="checkbox" disabled=""> <!-- -->Industry-specific protocols</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-2-network-connectivity-and-redundancy">Criterion 2: Network Connectivity and Redundancy<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#criterion-2-network-connectivity-and-redundancy" class="hash-link" aria-label="Direct link to Criterion 2: Network Connectivity and Redundancy" title="Direct link to Criterion 2: Network Connectivity and Redundancy" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4g-lte-the-current-standard">4G LTE: The Current Standard<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#4g-lte-the-current-standard" class="hash-link" aria-label="Direct link to 4G LTE: The Current Standard" title="Direct link to 4G LTE: The Current Standard" translate="no">​</a></h3>
<p>An industrial gateway in 2026 must include at least a 4G LTE Cat-M1/Cat-4 module. 4G covers 97% of France’s population and is sufficient for 95% of industrial IoT applications (real-time monitoring, alerts, remote access).</p>
<p><strong>Points to Consider:</strong></p>
<ul>
<li class="">Is the 4G module built-in (internal M2M SIM) or external (USB dongle)?</li>
<li class="">An external module is an additional source of failure and poor thermal management</li>
<li class="">Some gateways are labeled “4G compatible” but require an external modem—proceed with caution</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="dual-sim-true-network-redundancy">Dual SIM: True Network Redundancy<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#dual-sim-true-network-redundancy" class="hash-link" aria-label="Direct link to Dual SIM: True Network Redundancy" title="Direct link to Dual SIM: True Network Redundancy" translate="no">​</a></h3>
<p><strong>One SIM card = one carrier = one point of failure.</strong> In certain industrial areas (partial dead zones, tunnels, areas with poor coverage), one carrier may lose signal while the other maintains it.</p>
<p>Dual SIM, which supports two SIM cards from different carriers and automatic switching, is the solution for mission-critical applications. Eziwan supports Dual SIM natively.</p>
<p><strong>Questions to Ask:</strong></p>
<ul>
<li class="">Does the gateway support two SIM cards simultaneously?</li>
<li class="">Is the failover automatic (without human intervention)?</li>
<li class="">Is the failover time acceptable for your application (target: less than 30 seconds)?</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="wired-backup-connection">Wired Backup Connection<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#wired-backup-connection" class="hash-link" aria-label="Direct link to Wired Backup Connection" title="Direct link to Wired Backup Connection" translate="no">​</a></h3>
<p>For sites with fiber or Ethernet available, a gateway with an Ethernet WAN port allows you to use fiber as the primary connection and 4G as a backup. Both connections must be managed simultaneously with automatic and transparent failover.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-3-security-and-zero-trust-architecture">Criterion 3: Security and Zero Trust Architecture<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#criterion-3-security-and-zero-trust-architecture" class="hash-link" aria-label="Direct link to Criterion 3: Security and Zero Trust Architecture" title="Direct link to Criterion 3: Security and Zero Trust Architecture" translate="no">​</a></h2>
<p>Cybersecurity for industrial IoT gateways has become a non-negotiable requirement, driven by NIS2, which now covers a wide range of industrial companies.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-to-check">What to Check<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#what-to-check" class="hash-link" aria-label="Direct link to What to Check" title="Direct link to What to Check" translate="no">​</a></h3>
<p><strong>Outbound-only architecture:</strong> The gateway must establish outbound connections only. No inbound ports should be open on your OT network. This eliminates the attack surface accessible from the Internet. This is the Zero Trust architecture: "Never trust, always verify."</p>
<p><strong>VPN Protocol:</strong> OpenVPN is currently the industry standard: robust, extensively audited, it traverses firewalls via TCP port 443 and authenticates using X.509 certificates (AES-256-GCM encryption). IPSec (IKEv2) remains relevant for FIPS 140-2-regulated environments.</p>
<p><strong>Data encryption in transit:</strong> TLS 1.3 or higher for cloud communications. Verify that the gateway does not communicate in plain text with an unencrypted MQTT broker.</p>
<p><strong>Authentication:</strong> Cryptographic keys per device, individually revocable. Avoid gateways that use a single administrator password shared across all devices.</p>
<p><strong>Secure firmware updates (OTA):</strong> Gateways that have not been updated become attack vectors. Verify that the gateway supports cryptographically signed OTA updates.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="nis2-and-liability">NIS2 and Liability<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#nis2-and-liability" class="hash-link" aria-label="Direct link to NIS2 and Liability" title="Direct link to NIS2 and Liability" translate="no">​</a></h3>
<p>Since October 2024, NIS2 has required essential and significant entities to manage the security of their digital supply chains, including IoT gateways. A gateway that opens incoming ports on the OT network or communicates in plain text is considered a NIS2 non-compliance.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-4-robustness-in-industrial-environments">Criterion 4: Robustness in Industrial Environments<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#criterion-4-robustness-in-industrial-environments" class="hash-link" aria-label="Direct link to Criterion 4: Robustness in Industrial Environments" title="Direct link to Criterion 4: Robustness in Industrial Environments" translate="no">​</a></h2>
<p>An "industrial" gateway must be able to withstand real-world industrial environments. Here are the certifications and specifications to check:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="operating-temperature">Operating Temperature<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#operating-temperature" class="hash-link" aria-label="Direct link to Operating Temperature" title="Direct link to Operating Temperature" translate="no">​</a></h3>
<table><thead><tr><th>Application</th><th>Min. temperature</th><th>Max. temperature</th></tr></thead><tbody><tr><td>Air-conditioned equipment room</td><td>-10°C</td><td>+40°C</td></tr><tr><td>Non-air-conditioned cabinet</td><td>-20°C</td><td>+60°C</td></tr><tr><td>Outdoor / cold environment</td><td>-40°C</td><td>+70°C</td></tr></tbody></table>
<p>A standard IT gateway operates between 0°C and +40°C. A true industrial gateway typically operates between -20°C and +70°C.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="ip-rating">IP Rating<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#ip-rating" class="hash-link" aria-label="Direct link to IP Rating" title="Direct link to IP Rating" translate="no">​</a></h3>
<p><strong>IP20:</strong> Minimum protection; for use only in a closed cabinet in a clean room.<br>
<strong>IP40:</strong> Protection against solid objects larger than 1 mm. Standard equipment cabinet.<br>
<strong>IP65:</strong> Dust-tight and protected against water jets. For dusty environments (food processing, construction, outdoor use under cover).<br>
<strong>IP67:</strong> Temporary submersion up to 1 meter. For very humid environments.<br>
<strong>IP68:</strong> Prolonged submersion. Rarely necessary but useful for underground equipment.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="vibrations-and-shocks">Vibrations and Shocks<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#vibrations-and-shocks" class="hash-link" aria-label="Direct link to Vibrations and Shocks" title="Direct link to Vibrations and Shocks" translate="no">​</a></h3>
<p>For applications in industrial vehicles, overhead cranes, compressors, or vibrating environments: verify compliance with EN 61131-2 or IEC 60068 for mechanical testing.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="din-rail-mounting">DIN Rail Mounting<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#din-rail-mounting" class="hash-link" aria-label="Direct link to DIN Rail Mounting" title="Direct link to DIN Rail Mounting" translate="no">​</a></h3>
<p>For installation in an electrical cabinet, mounting on a 35mm DIN rail is the industry standard. Avoid gateways that require wall screws or non-standard 19" rack mounting for industrial installations.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="regulatory-certifications">Regulatory Certifications<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#regulatory-certifications" class="hash-link" aria-label="Direct link to Regulatory Certifications" title="Direct link to Regulatory Certifications" translate="no">​</a></h3>
<p><strong>CE (EU requirement):</strong> CE marking is required for all electronic equipment sold in Europe.<br>
<strong>ATEX (explosive atmospheres):</strong> For chemical and oil facilities with potentially explosive atmospheres. ATEX Zone 1/2 or Zone 21/22, depending on the application.<br>
<strong>EN 61131-2:</strong> Specific standard for equipment used with programmable logic controllers (PLCs).</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-5-zero-touch-provisioning-ztp">Criterion 5: Zero-Touch Provisioning (ZTP)<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#criterion-5-zero-touch-provisioning-ztp" class="hash-link" aria-label="Direct link to Criterion 5: Zero-Touch Provisioning (ZTP)" title="Direct link to Criterion 5: Zero-Touch Provisioning (ZTP)" translate="no">​</a></h2>
<p>ZTP is a criterion that is often underestimated, especially when deploying dozens or hundreds of gateways.</p>
<p><strong>Without ZTP:</strong> Each gateway must be configured manually before deployment. A technician must log in to the local interface, enter the cloud server's IP address, credentials, network settings, etc. For 50 sites, that’s 50 visits of at least 30 minutes each = 25 hours of technical work, plus travel time.</p>
<p><strong>With ZTP:</strong> The gateway automatically connects to the management cloud the first time it is powered on (via a preconfigured M2M SIM). It downloads its configuration from the server and is operational in less than 5 minutes without any local intervention.</p>
<p><strong>Questions to Ask the Provider:</strong></p>
<ul>
<li class="">Is ZTP truly "zero-touch," or does it still require initial configuration?</li>
<li class="">Is the M2M SIM preconfigured with the cloud server settings?</li>
<li class="">If there is a provisioning issue, how is remote diagnostics performed?</li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-6-edge-computing-and-local-logic">Criterion 6: Edge Computing and Local Logic<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#criterion-6-edge-computing-and-local-logic" class="hash-link" aria-label="Direct link to Criterion 6: Edge Computing and Local Logic" title="Direct link to Criterion 6: Edge Computing and Local Logic" translate="no">​</a></h2>
<p>The most advanced gateways have enough computing power to execute logic locally, without relying on the cloud:</p>
<p><strong>Local aggregation:</strong> Calculate averages, min/max values, and totals over a period (e.g., energy consumed in kWh per hour) before sending the data to the cloud. This reduces the required bandwidth.</p>
<p><strong>Local Alerts:</strong> Trigger a local alarm (relay, buzzer, direct SMS) without going through the cloud. Useful in the event of a network outage—the gateway continues to monitor and send alerts locally.</p>
<p><strong>Data Filtering:</strong> Send only data that has changed by more than a defined threshold. This drastically reduces mobile data costs at sites with high traffic.</p>
<p><strong>Logic Scripts:</strong> On advanced gateways (Eziwan, certain Teltonika models), you can run Python or JavaScript scripts locally to handle complex business logic.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-7-management-and-monitoring-from-a-centralized-console">Criterion 7: Management and monitoring from a centralized console<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#criterion-7-management-and-monitoring-from-a-centralized-console" class="hash-link" aria-label="Direct link to Criterion 7: Management and monitoring from a centralized console" title="Direct link to Criterion 7: Management and monitoring from a centralized console" translate="no">​</a></h2>
<p>For multi-site projects (3–4 sites or more), the centralized management console is a key differentiator:</p>
<p><strong>Fleet Dashboard:</strong> Real-time view of the status of all gateways (connected/disconnected, signal strength, active alerts).</p>
<p><strong>Remote firmware updates:</strong> Deploy a security update to 50 gateways with just a few clicks, without having to travel to the site.</p>
<p><strong>Remote Configuration:</strong> Change an alarm threshold, add a new sensor, or modify a network setting—all from the web console.</p>
<p><strong>Fleet Alerts:</strong> Receive a notification when a gateway loses its connection or when a device exceeds a threshold.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-8-data-hosting-and-digital-sovereignty">Criterion 8: Data Hosting and Digital Sovereignty<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#criterion-8-data-hosting-and-digital-sovereignty" class="hash-link" aria-label="Direct link to Criterion 8: Data Hosting and Digital Sovereignty" title="Direct link to Criterion 8: Data Hosting and Digital Sovereignty" translate="no">​</a></h2>
<p>This criterion has become strategic for French companies in light of NIS2 and digital sovereignty requirements.</p>
<p><strong>Key Questions:</strong></p>
<ul>
<li class="">Where is the data collected by the gateway hosted?</li>
<li class="">Is the software provider subject to the U.S. CLOUD Act (as a subsidiary of a U.S. company)?</li>
<li class="">Can the data be seized by foreign authorities without notification?</li>
<li class="">Is the service provider ISO 27001 certified? Is it SecNumCloud (ANSSI) certified for OIVs?</li>
</ul>
<p>For NIS2 essential entities and operators of critical infrastructure, hosting data in France with a service provider not subject to foreign extraterritorial laws is a de facto requirement.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="criterion-9-technical-support-and-assistance">Criterion 9: Technical Support and Assistance<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#criterion-9-technical-support-and-assistance" class="hash-link" aria-label="Direct link to Criterion 9: Technical Support and Assistance" title="Direct link to Criterion 9: Technical Support and Assistance" translate="no">​</a></h2>
<p>Even the best gateway in the world is worthless without support that can answer your technical questions in real time:</p>
<p><strong>Support SLA:</strong> What is the guaranteed response time? 4 hours, 8 hours, or 24 hours? For mission-critical industrial applications, an SLA of less than 4 business hours is recommended.</p>
<p><strong>Industrial expertise:</strong> Is the support team familiar with the Modbus, PROFIBUS, and Siemens S7 industrial protocols? Or is it a general IT support team?</p>
<p><strong>Documentation:</strong> Is the API documented (OpenAPI 3.0)? Are there code examples? Are there Python/Node libraries?</p>
<p><strong>Project Support:</strong> Does the vendor offer support during the initial deployment?</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="summary-checklist-9-criteria">Summary Checklist: 9 Criteria<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#summary-checklist-9-criteria" class="hash-link" aria-label="Direct link to Summary Checklist: 9 Criteria" title="Direct link to Summary Checklist: 9 Criteria" translate="no">​</a></h2>
<div class="language-text codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">□ Protocoles</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Modbus RTU (RS-485) master</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Modbus TCP Master</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ MQTT TLS</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Industry-specific protocols</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">□ Connectivité</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Built-in 4G LTE</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Dual SIM with two carriers</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Port Ethernet WAN (optionnel)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Délai failover &lt; 30 secondes</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">□ Sécurité</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Architecture outbound-only (zero inbound port)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ OpenVPN/IPSec VPN or a modern equivalent</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ TLS 1.3 for cloud communications</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Authentication using a cryptographic key</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Signed OTA update</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">□ Robustesse</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Temperature: -20°C / +70°C minimum</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ IP40 minimum (IP65 if the environment is dusty)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Montage rail DIN 35mm</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ CE Certifications (+ ATEX if necessary)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">□ ZTP</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Deployment without local intervention</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Preconfigured M2M SIM</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">□ Edge computing</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Local aggregation</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Alertes locales sans cloud</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Logique locale configurable</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">□ Centralized console</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Real-time Fleet Dashboard</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ OTA firmware updates</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Remote configuration</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">□ Data hosting</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Hosting in France or the EU</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Non soumis au CLOUD Act</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ ISO 27001 minimum</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain" style="display:inline-block"></span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">□ Support</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Documented SLA</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ Expertise protocoles industriels</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">  □ OpenAPI-documented API</span><br></div></code></pre></div></div>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>What is the difference between an industrial IoT gateway and an industrial 4G router?</strong>
An industrial 4G router provides IP network connectivity (routing, NAT, VPN). An industrial IoT gateway adds field capabilities: an RS-485 port for Modbus RTU, edge computing, and cloud-native integration (MQTT, REST API). Some products, such as the Eziwan Gateway, combine both functions in a single device.</p>
<p><strong>Can an industrial IoT gateway be used without an Eziwan cloud subscription?</strong>
The Eziwan Gateway hardware can operate in standalone mode with your own MQTT broker or API. The Eziwan cloud platform (dashboard, ZTP, fleet management, alerts) is optional. That said, it is included in the subscription and eliminates the need to manage server infrastructure.</p>
<p><strong>How many Modbus registers can be collected simultaneously?</strong>
The Eziwan Gateway can handle up to 500 Modbus registers (RTU or TCP) per polling interval. For deployments with higher requirements (multi-circuit energy meters, lines with numerous sensors), polling can be distributed across multiple configurable time slots.</p>
<p><strong>What is edge computing on an industrial gateway, and do I need it?</strong>
Edge computing allows logic to be executed directly on the gateway (aggregation, filtering, local anomaly detection, cloud-free alerts). Useful when: connectivity is intermittent (data is processed and buffered locally), the volume of raw data is too large to send to the cloud, or a rapid response is required (&lt;1 s) without going through the cloud.</p>
<p><strong>How can you verify that a gateway complies with NIS2 regulations?</strong>
NIS2 compliance for gateways includes: communication encryption (TLS 1.3 minimum), strong authentication (X.509 certificates, no default passwords), access traceability (audit log), security updates (signed OTA updates), and data hosting within the EU (GDPR). Ask your provider for their compliance attestation or ISO 27001 certifications.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/industrial-vs-consumer-4g-router">Blog: Industrial 4G Router vs. Consumer Router — 10 Differences</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/zero-touch-provisioning">Blog: Zero-Touch Provisioning — Deploy 50 Routers in 2 Hours</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/nis2-cybersecurity-industrial-infrastructure">Blog: NIS2 and Industrial Cybersecurity — Requirements and Action Plan</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide">Guide: Remote Industrial Monitoring — Architecture and Security</a></li>
<li class=""><a class="" href="https://eziwan.com/en/docs/integration/modbus">Docs: Modbus RTU integration on the Eziwan Gateway</a></li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="resources">Resources<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#resources" class="hash-link" aria-label="Direct link to Resources" title="Direct link to Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/gateway">Eziwan Gateway — Technical Specifications</a></li>
<li class=""><a class="" href="https://eziwan.com/en/comparatif/routeur-industriel-vs-box-internet">Comparison: Industrial Router vs. Internet Router</a></li>
<li class=""><a class="" href="https://eziwan.com/en/comparatif/modbus-rtu-vs-tcp">Guide: Modbus RTU vs. Modbus TCP</a></li>
<li class=""><a class="" href="https://eziwan.com/en/comparatif/vpn-vs-zero-trust-industriel">Industrial VPN vs. Zero Trust</a></li>
<li class=""><a class="" href="https://eziwan.com/en/roi">Industrial IoT ROI Calculator</a></li>
<li class=""><a class="" href="https://eziwan.com/en/alternative-ewon-iiot">Ewon Alternatives — IIoT Solutions Comparison</a></li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/industrial-iot-gateway">Industrial IoT Gateway</a> — Selection Criteria and Comparison of Industrial IoT Gateways</li>
<li class=""><a class="" href="https://eziwan.com/en/gateway">Eziwan Gateway</a> — Specifications and Features of the Eziwan Gateway</li>
<li class=""><a class="" href="https://eziwan.com/en/passerelle-iiot">IIoT Gateway</a> — IIoT gateway solutions for industry</li>
<li class=""><a class="" href="https://eziwan.com/en/iot-gateway-guide">IoT Gateway</a> — complete range of Eziwan IoT gateways</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-routers">Industrial Routers</a> — Industrial 4G LTE routers for your remote sites</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-connectivity">Industrial Connectivity</a> — Connectivity solutions for Industry 4.0</li>
</ul>]]></content:encoded>
            <category>gateway-iot</category>
            <category>connectivity</category>
            <category>industrial-router</category>
            <category>industrial-iot</category>
            <category>buying-guide</category>
        </item>
        <item>
            <title><![CDATA[Preventive, Predictive, or Condition-Based Maintenance: Which Model for French Industry in 2026?]]></title>
            <link>https://eziwan.com/en/blog/predictive-condition-based-maintenance</link>
            <guid>https://eziwan.com/en/blog/predictive-condition-based-maintenance</guid>
            <pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[A comprehensive comparison of industrial maintenance strategies: corrective, systematic preventive, IoT-based condition-based, and ML-based predictive. What is the ROI, what equipment is involved, and how are they implemented?]]></description>
            <content:encoded><![CDATA[<p>The terminology surrounding industrial maintenance is often a source of confusion: <strong>predictive maintenance</strong>, <strong>condition-based maintenance</strong>, <strong>preventive maintenance</strong>, <strong>corrective maintenance</strong>—these terms are frequently used interchangeably, but they refer to fundamentally different approaches with very different ROIs.</p>
<p>This article clarifies the definitions, compares approaches based on concrete criteria, and helps you choose the strategy best suited to your situation in 2026—whether it’s a small factory with 20 pieces of equipment or a large industrial site with 500+ assets.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-4-maintenance-strategies-precise-definitions">The 4 Maintenance Strategies: Precise Definitions<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#the-4-maintenance-strategies-precise-definitions" class="hash-link" aria-label="Direct link to The 4 Maintenance Strategies: Precise Definitions" title="Direct link to The 4 Maintenance Strategies: Precise Definitions" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-corrective-maintenance">1. Corrective Maintenance<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#1-corrective-maintenance" class="hash-link" aria-label="Direct link to 1. Corrective Maintenance" title="Direct link to 1. Corrective Maintenance" translate="no">​</a></h3>
<p><strong>Definition:</strong> We step in after a breakdown. When the equipment breaks down, we fix it.</p>
<p><strong>Variants:</strong></p>
<ul>
<li class=""><em>Deferred corrective action</em>: The failure is detected, but the repair is scheduled (non-critical equipment)</li>
<li class=""><em>Emergency corrective action</em>: Critical failure; immediate action required</li>
</ul>
<p><strong>Typical cost:</strong> 4 to 5 times higher than the equivalent preventive maintenance (express parts, overtime, lost production).</p>
<p><strong>When it is acceptable:</strong> Non-critical equipment that is easily replaceable, where the cost of monitoring exceeds the cost of failure.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-systematic-preventive-maintenance">2. Systematic Preventive Maintenance<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#2-systematic-preventive-maintenance" class="hash-link" aria-label="Direct link to 2. Systematic Preventive Maintenance" title="Direct link to 2. Systematic Preventive Maintenance" translate="no">​</a></h3>
<p><strong>Definition:</strong> Items are replaced or overhauled according to a fixed schedule (based on time or production intervals), regardless of their actual condition.</p>
<p><strong>Example:</strong> Change the oil in a gearbox every 2,000 hours, even if it is still in good condition.</p>
<p><strong>Main problem:</strong> 30 to 40% of the parts replaced during preventive maintenance visits are still usable. This results in a waste of both resources AND components.</p>
<p><strong>Typical cost:</strong> 2 to 3 times higher than well-calibrated condition-based maintenance.</p>
<p><strong>When applicable:</strong> Equipment with well-known and predictable degradation patterns over time, in a regulatory context that requires periodic inspections.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-condition-based-maintenance-cbm">3. Condition-Based Maintenance (CBM)<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#3-condition-based-maintenance-cbm" class="hash-link" aria-label="Direct link to 3. Condition-Based Maintenance (CBM)" title="Direct link to 3. Condition-Based Maintenance (CBM)" translate="no">​</a></h3>
<p><strong>Definition:</strong> Action is taken when the actual condition of the equipment warrants it, based on continuous physical measurements (vibration, temperature, current, acoustic levels, etc.).</p>
<p><strong>Principle:</strong> Every piece of equipment "speaks" through its data. We listen to it.</p>
<p><strong>Example:</strong> The bearing is replaced when the vibration exceeds a critical threshold established during commissioning, not on a fixed schedule.</p>
<p><strong>Documented ROI:</strong> A 25–55% reduction in unplanned downtime; 10–30% savings on total maintenance costs.</p>
<p><strong>What's needed:</strong> Sensors installed on equipment, real-time data collection, configured alert thresholds.</p>
<hr>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-predictive-maintenance-pdm">4. Predictive Maintenance (PdM)<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#4-predictive-maintenance-pdm" class="hash-link" aria-label="Direct link to 4. Predictive Maintenance (PdM)" title="Direct link to 4. Predictive Maintenance (PdM)" translate="no">​</a></h3>
<p><strong>Definition:</strong> The date of a future failure is predicted using a mathematical model (statistical or machine learning) fed with historical and real-time data.</p>
<p><strong>Difference from the conditional:</strong> The CBM says, "The equipment is in poor condition; take action soon." The PdM says, "The equipment will break down in 3 to 5 days with an 87% probability."</p>
<p><strong>What's needed:</strong> At least 12–18 months of historical data per piece of equipment, expertise in modeling, and teams capable of acting on the predictions.</p>
<p><strong>The Reality on the Ground in 2026:</strong> True predictive maintenance (machine learning + physical models) is now accessible to large companies and mid-sized enterprises with dedicated data teams. For small and medium-sized businesses, condition-based maintenance offers 80% of the benefits with only 20% of the complexity.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="comparison-based-on-7-criteria">Comparison Based on 7 Criteria<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#comparison-based-on-7-criteria" class="hash-link" aria-label="Direct link to Comparison Based on 7 Criteria" title="Direct link to Comparison Based on 7 Criteria" translate="no">​</a></h2>
<table><thead><tr><th>Criterion</th><th>Corrective</th><th>Preventive</th><th>Conditional</th><th>Predictive</th></tr></thead><tbody><tr><td>Implementation cost</td><td>Very low</td><td>Low</td><td>Medium</td><td>High</td></tr><tr><td>Operating cost</td><td>Very high</td><td>Medium</td><td>Low</td><td>Medium</td></tr><tr><td>Technical complexity</td><td>None</td><td>Low</td><td>Medium</td><td>High</td></tr><tr><td>Data required</td><td>None</td><td>Scheduled</td><td>Real-time</td><td>Historical + RT</td></tr><tr><td>ROI timeframe</td><td>Immediate</td><td>12–18 months</td><td>8–14 months</td><td>18–36 months</td></tr><tr><td>Predictability</td><td>None</td><td>Good</td><td>Good</td><td>Excellent</td></tr><tr><td>Suitable for SMEs</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Sometimes</td></tr></tbody></table>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="which-sensors-are-best-for-condition-based-maintenance">Which Sensors Are Best for Condition-Based Maintenance?<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#which-sensors-are-best-for-condition-based-maintenance" class="hash-link" aria-label="Direct link to Which Sensors Are Best for Condition-Based Maintenance?" title="Direct link to Which Sensors Are Best for Condition-Based Maintenance?" translate="no">​</a></h2>
<p>Condition-based maintenance relies on physical measurements. Here are the most commonly used sensors, ranked by ROI:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-vibration-accelerometer">1. Vibration (accelerometer)<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#1-vibration-accelerometer" class="hash-link" aria-label="Direct link to 1. Vibration (accelerometer)" title="Direct link to 1. Vibration (accelerometer)" translate="no">​</a></h3>
<p><strong>What we detect:</strong> Rotational imbalance, shaft misalignment, bearing damage, pump cavitation, gear wear.</p>
<p><strong>Applications:</strong> Electric motors, centrifugal pumps, compressors, fans, conveyors.</p>
<p><strong>Early warning signs:</strong> Increase in the overall vibration level (RMS), appearance of characteristic harmonic frequencies, increase in kurtosis (impulsivity).</p>
<p><strong>Sensor cost:</strong> €50 (basic industrial model) to €500 (broadband + ICP).</p>
<p><strong>Time to Failure:</strong> Detection 2 to 12 weeks before bearing failure.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-infraredthermal-temperature">2. Infrared/Thermal Temperature<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#2-infraredthermal-temperature" class="hash-link" aria-label="Direct link to 2. Infrared/Thermal Temperature" title="Direct link to 2. Infrared/Thermal Temperature" translate="no">​</a></h3>
<p><strong>What is detected:</strong> Abnormal overheating of motors, transformers, electrical connections, bearings, and brakes.</p>
<p><strong>Applications:</strong> Electrical panels, motors, bearings, cooling systems.</p>
<p><strong>Warning signs:</strong> Operating temperature rises above the established reference value.</p>
<p><strong>Sensor cost:</strong> €20 (PT100 contact probe) to €2,000 (fixed thermal imaging camera).</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-electric-current-current-clamp">3. Electric Current (Current Clamp)<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#3-electric-current-current-clamp" class="hash-link" aria-label="Direct link to 3. Electric Current (Current Clamp)" title="Direct link to 3. Electric Current (Current Clamp)" translate="no">​</a></h3>
<p><strong>What we detect:</strong> Load imbalance, insulation degradation, abnormal harmonics, difficult startup.</p>
<p><strong>Applications:</strong> Induction motors, servo motors, drive systems.</p>
<p><strong>Advantage:</strong> No mechanical installation required—the measurement is non-intrusive. Ideal for equipment that is difficult to access.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-acoustics--ultrasound">4. Acoustics / Ultrasound<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#4-acoustics--ultrasound" class="hash-link" aria-label="Direct link to 4. Acoustics / Ultrasound" title="Direct link to 4. Acoustics / Ultrasound" translate="no">​</a></h3>
<p><strong>What we detect:</strong> Compressed gas leaks, electric arcs, bearing degradation under low load, lubrication issues.</p>
<p><strong>Applications:</strong> Compressed air systems, high-voltage electrical cabinets, low-speed bearings.</p>
<p><strong>Typical ROI:</strong> An ultrasonic compressed air audit typically identifies 15 to 30% of leaks—resulting in immediate savings on compressor electricity consumption.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="5-oil-analysis-in-line">5. Oil Analysis (In-Line)<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#5-oil-analysis-in-line" class="hash-link" aria-label="Direct link to 5. Oil Analysis (In-Line)" title="Direct link to 5. Oil Analysis (In-Line)" translate="no">​</a></h3>
<p><strong>What is detected:</strong> Particle contamination, viscosity degradation, presence of water, wear particles.</p>
<p><strong>Applications:</strong> Gear reducers, gearboxes, turbines, compressors.</p>
<p><strong>In-line sensors:</strong> Enable continuous monitoring without sampling, with automatic alerts for particles or dielectric substances.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="practical-implementation-how-to-get-started">Practical Implementation: How to Get Started?<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#practical-implementation-how-to-get-started" class="hash-link" aria-label="Direct link to Practical Implementation: How to Get Started?" title="Direct link to Practical Implementation: How to Get Started?" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-1-identify-critical-equipment-simplified-fmea">Step 1: Identify Critical Equipment (Simplified FMEA)<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#step-1-identify-critical-equipment-simplified-fmea" class="hash-link" aria-label="Direct link to Step 1: Identify Critical Equipment (Simplified FMEA)" title="Direct link to Step 1: Identify Critical Equipment (Simplified FMEA)" translate="no">​</a></h3>
<p>List your equipment and evaluate each item based on:</p>
<ul>
<li class=""><strong>Criticality</strong> (impact of a failure: production shutdown, safety, environment)</li>
<li class=""><strong>Failure Frequency</strong> (CMMS history, if available)</li>
<li class=""><strong>Detectability</strong> (Does the failure give advance warning, or is it sudden?)</li>
</ul>
<p>Focus CBM sensors on equipment with <strong>high criticality</strong> and <strong>progressive failures</strong>.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-2-define-key-metrics-by-equipment">Step 2: Define Key Metrics by Equipment<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#step-2-define-key-metrics-by-equipment" class="hash-link" aria-label="Direct link to Step 2: Define Key Metrics by Equipment" title="Direct link to Step 2: Define Key Metrics by Equipment" translate="no">​</a></h3>
<p>For each piece of critical equipment, define which parameters to measure. Example for a centrifugal pump:</p>
<ul>
<li class="">Vibration (accelerometer on the motor-side and pump-side bearings)</li>
<li class="">Bearing temperature (PT100 or infrared)</li>
<li class="">Motor current (current clamp)</li>
<li class="">Differential pressure (if pressure is critical)</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-3-install-and-connect-the-sensors">Step 3: Install and Connect the Sensors<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#step-3-install-and-connect-the-sensors" class="hash-link" aria-label="Direct link to Step 3: Install and Connect the Sensors" title="Direct link to Step 3: Install and Connect the Sensors" translate="no">​</a></h3>
<p>The sensors connect to the Eziwan gateway via RS-485/Modbus RTU for standard industrial sensors, or via 4–20 mA outputs for process transmitters. The gateway transmits all measurements to the cloud platform in real time.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-4-establish-baseline-values">Step 4: Establish Baseline Values<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#step-4-establish-baseline-values" class="hash-link" aria-label="Direct link to Step 4: Establish Baseline Values" title="Direct link to Step 4: Establish Baseline Values" translate="no">​</a></h3>
<p>During commissioning, record the reference values for each parameter on new equipment or equipment in good condition. These reference values are used to:</p>
<ul>
<li class="">Set alarm thresholds (alarm at +20%, emergency at +50% of the reference)</li>
<li class="">Detect a gradual drift from the baseline</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-5-calibrate-the-alarm-thresholds">Step 5: Calibrate the alarm thresholds<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#step-5-calibrate-the-alarm-thresholds" class="hash-link" aria-label="Direct link to Step 5: Calibrate the alarm thresholds" title="Direct link to Step 5: Calibrate the alarm thresholds" translate="no">​</a></h3>
<p>Too sensitive = false alarms that discourage teams. Not sensitive enough = missed failures. Calibrating the thresholds requires 2 to 4 weeks of observation under normal conditions to fine-tune them.</p>
<p>Eziwan allows you to adjust thresholds from the cloud platform without on-site intervention.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="step-6-integrate-with-the-cmms">Step 6: Integrate with the CMMS<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#step-6-integrate-with-the-cmms" class="hash-link" aria-label="Direct link to Step 6: Integrate with the CMMS" title="Direct link to Step 6: Integrate with the CMMS" translate="no">​</a></h3>
<p>A CBM alarm is only useful if it triggers a planned action in the CMMS. The Eziwan REST API allows you to automatically create a work order in your CMMS (SAP PM, Infor EAM, Hive Maintenix) as soon as an alarm is triggered.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="feedback-from-the-field">Feedback from the Field<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#feedback-from-the-field" class="hash-link" aria-label="Direct link to Feedback from the Field" title="Direct link to Feedback from the Field" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="cement-plant--main-grinder-gearbox">Cement Plant — Main Grinder Gearbox<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#cement-plant--main-grinder-gearbox" class="hash-link" aria-label="Direct link to Cement Plant — Main Grinder Gearbox" title="Direct link to Cement Plant — Main Grinder Gearbox" translate="no">​</a></h3>
<p><strong>Background:</strong> 800-kW gearbox, replacement cost €180,000, delivery time 6 weeks.</p>
<p><strong>Before CBM:</strong> 2 catastrophic failures in 4 years. Each failure = 6 weeks of partial downtime = €420,000 in lost production.</p>
<p><strong>After CBM (vibration + temperature + oil analysis):</strong> Detection of gradual deterioration 8 weeks before failure. Repair scheduled during a planned shutdown. Cost of preventive repair: €28,000 vs. €180,000 for catastrophic replacement.</p>
<p><strong>ROI:</strong> 9 months.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="food-processing-plant--packaging-line">Food processing plant — packaging line<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#food-processing-plant--packaging-line" class="hash-link" aria-label="Direct link to Food processing plant — packaging line" title="Direct link to Food processing plant — packaging line" translate="no">​</a></h3>
<p><strong>Background:</strong> 12 gearmotors on a critical production line. Preventive maintenance at 3,000 hours (routine oil change + inspection).</p>
<p><strong>After CBM (current + vibration):</strong> Of the 12 gearmotors monitored, CBM made it possible to:</p>
<ul>
<li class="">Prevent 3 unplanned shutdowns</li>
<li class="">Reduce unnecessary preventive maintenance by 40% (oil was still clean according to analysis)</li>
<li class="">Detect 2 alignment issues that were imperceptible to the naked eye</li>
</ul>
<p><strong>ROI:</strong> 11 months.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion-what-strategy-should-we-adopt">Conclusion: What Strategy Should We Adopt?<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#conclusion-what-strategy-should-we-adopt" class="hash-link" aria-label="Direct link to Conclusion: What Strategy Should We Adopt?" title="Direct link to Conclusion: What Strategy Should We Adopt?" translate="no">​</a></h2>
<p><strong>For an industrial SME (fewer than 50 pieces of equipment):</strong>
Start with <strong>condition-based maintenance</strong> on your 5 to 10 most critical pieces of equipment. The investment is affordable, the ROI is quick, and the complexity is manageable even without a dedicated data team.</p>
<p><strong>For a mid-sized or large company:</strong>
<strong>Condition-based maintenance</strong> remains the foundation. For the most critical equipment with sufficient historical data, supplement this with <strong>predictive models</strong> (starting with 2 to 3 priority pieces of equipment).</p>
<p><strong>What we see in 2026:</strong> The majority of French manufacturers that have truly improved their maintenance performance have done so using IoT-based condition-based maintenance—not through complex ML projects. The ROI is measurable in less than a year.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>What is the difference between predictive maintenance and condition-based maintenance (CBM)?</strong>
Condition-based maintenance triggers an action when a threshold is exceeded (e.g., temperature &gt; 85°C → immediate alert). Predictive maintenance analyzes trends over time to anticipate deterioration before the critical threshold is reached (e.g., temperature has been rising by 2°C per week for the past 3 weeks → schedule an intervention in 2 weeks). Condition-based maintenance is easier to implement, while predictive maintenance offers a longer lead time for intervention.</p>
<p><strong>What type of sensor is most useful for implementing condition-based maintenance?</strong>
For motors and pumps: the current sensor (current transformer on the power cable) is the most versatile—it detects overloads, hard starts, and mechanical degradation without requiring any modifications to the equipment. For mechanical transmissions (gearboxes, bearings): the accelerometer vibration sensor. These two types of sensors cover 80% of preventable failures in industry.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/predictive-maintenance-iot-field-sensors">Blog: IIoT Predictive Maintenance — From Sensor Data to Real-Time Alerts</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/industrial-iot-roi-calculation">Blog: ROI of Industrial IoT — Calculation and Optimization</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/modbus-tcp-vs-rtu">Blog: Modbus TCP vs. RTU — Which Protocol for Sensor Data Collection?</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus">Blog: Grafana for Modbus Industrial Monitoring</a></li>
<li class=""><a class="" href="https://eziwan.com/en/docs/use-cases/constructeur-machine-oem">Docs: OEM Machine Manufacturer Use Case</a></li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/predictive-condition-based-maintenance#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/maintenance-predictive-iiot">IIoT Predictive Maintenance</a> — predictive maintenance solutions based on industrial IoT</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-remote-diagnostics">Industrial Remote Diagnostics</a> — remote diagnostics to anticipate breakdowns</li>
<li class=""><a class="" href="https://eziwan.com/en/monitoring-equipements-industriels">Industrial Equipment Monitoring</a> — continuous monitoring of your industrial machinery</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-remote-support">Industrial Monitoring and Remote Assistance</a> — centralized monitoring to manage maintenance remotely</li>
<li class=""><a class="" href="https://eziwan.com/en/guides/reduce-field-visits">Guide: Reducing Field Visits</a> — optimizing service calls through condition-based maintenance</li>
</ul>]]></content:encoded>
            <category>maintenance</category>
            <category>industrial-iot</category>
            <category>industry-4-0</category>
            <category>monitoring</category>
            <category>sensors</category>
        </item>
        <item>
            <title><![CDATA[Industrial Data Hosted in France: Why It's Essential for NIS2 and the GDPR]]></title>
            <link>https://eziwan.com/en/blog/industrial-data-hosting-france-nis2</link>
            <guid>https://eziwan.com/en/blog/industrial-data-hosting-france-nis2</guid>
            <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Hosting Industrial IoT Data in France: NIS2 Requirements for OIVs, GDPR Compliance, and Protection Against the CLOUD Act. A Comprehensive Guide for French Manufacturers.]]></description>
            <content:encoded><![CDATA[<p>The issue of <strong>the location of industrial data</strong> evolved from a technical debate into a major regulatory challenge in 2025–2026. With the gradual implementation of NIS2, new GDPR sanctions on transfers outside the EU, and growing awareness of the risks associated with the U.S. CLOUD Act, French industrial companies must know <strong>where their OT/IoT monitoring data is hosted</strong>.</p>
<p>This article explores why hosting in France has become a non-negotiable selection criterion for many manufacturers, and what that means in practical terms for your choice of IIoT solution.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-is-industrial-data-and-why-does-its-location-matter">What is "industrial data," and why does its location matter?<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#what-is-industrial-data-and-why-does-its-location-matter" class="hash-link" aria-label="Direct link to What is &quot;industrial data,&quot; and why does its location matter?" title="Direct link to What is &quot;industrial data,&quot; and why does its location matter?" translate="no">​</a></h2>
<p>The industrial data generated by your IoT gateways, PLCs, sensors, and SCADA systems covers a wide range:</p>
<ul>
<li class=""><strong>Process data</strong>: temperatures, pressures, flow rates, levels—the physical measurements of your production</li>
<li class=""><strong>Operational data</strong>: alarm statuses, machine events, maintenance logs</li>
<li class=""><strong>Network topology data</strong>: IP addresses, installation diagrams, equipment firmware versions</li>
<li class=""><strong>Access data</strong>: who logged in to which device, when, and from where</li>
</ul>
<p>Taken together, these data points form a <strong>detailed map of your industrial infrastructure</strong>: its production capacity, vulnerabilities, and failure modes. If they fall into the wrong hands—competitors, hostile state actors, cybercriminals—the consequences could be severe.</p>
<p>So the question is not "Is my data sensitive?" but "Who has access to it, and under which jurisdiction?"</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-problem-with-the-us-cloud-act">The Problem with the U.S. CLOUD Act<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#the-problem-with-the-us-cloud-act" class="hash-link" aria-label="Direct link to The Problem with the U.S. CLOUD Act" title="Direct link to The Problem with the U.S. CLOUD Act" translate="no">​</a></h2>
<p>Since 2018, the <strong>Clarifying Lawful Overseas Use of Data Act (CLOUD Act)</strong> has required U.S. companies to provide U.S. federal authorities with the data they host—even if that data is physically stored in Europe.</p>
<p>In practical terms, this means that if you use <strong>AWS, Microsoft Azure, or Google Cloud</strong>, your business data can be accessed by the FBI or the NSA, <strong>even if your servers are located in Paris or Frankfurt</strong>, without you necessarily being notified, and without any effective legal recourse under European law.</p>
<p>When it comes to industrial data, this risk is particularly concerning:</p>
<ul>
<li class=""><strong>Industrial espionage</strong>: Your production parameters, production rates, and formulations could be exploited by U.S. competitors</li>
<li class=""><strong>Critical infrastructure</strong>: For OIVs (Operators of Vital Importance), the disclosure of monitoring data could pose a national security risk</li>
<li class=""><strong>Economic intelligence</strong>: a plant’s actual production capacity, its suppliers, and its logistics flows—all of these may be of interest to state actors</li>
</ul>
<p>Both the European Commission and ANSSI have recommended avoiding service providers subject to the CLOUD Act when handling sensitive data. NIS2 reinforces this recommendation by making it a de facto requirement for critical entities.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-nis2-says-about-data-localization">What NIS2 Says About Data Localization<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#what-nis2-says-about-data-localization" class="hash-link" aria-label="Direct link to What NIS2 Says About Data Localization" title="Direct link to What NIS2 Says About Data Localization" translate="no">​</a></h2>
<p>NIS2 does not explicitly require that all data be hosted in France or the EU. However, several of its requirements indirectly lead to this:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="1-digital-supply-chain-management">1. Digital Supply Chain Management<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#1-digital-supply-chain-management" class="hash-link" aria-label="Direct link to 1. Digital Supply Chain Management" title="Direct link to 1. Digital Supply Chain Management" translate="no">​</a></h3>
<p>Article 21 of NIS2 requires <strong>supply chain risk management</strong>, including cloud service providers. This involves a formal assessment of each cloud provider: Where is it domiciled? Under which jurisdiction can its data be seized? What security certifications do they hold?</p>
<p>For critical entities (CE)—which include many companies in the energy, water, transportation, healthcare, and digital infrastructure sectors—this assessment must be documented and defensible in the event of an ANSSI audit.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2-incident-reporting-and-availability-of-evidence-data">2. Incident Reporting and Availability of Evidence Data<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#2-incident-reporting-and-availability-of-evidence-data" class="hash-link" aria-label="Direct link to 2. Incident Reporting and Availability of Evidence Data" title="Direct link to 2. Incident Reporting and Availability of Evidence Data" translate="no">​</a></h3>
<p>NIS2 imposes very short notification deadlines: <strong>24 hours for the initial alert, 72 hours for the incident report</strong>. To meet these deadlines, you must have immediate access to audit logs, connection logs, and monitoring data. If this data is hosted by a U.S. service provider subject to legal procedures, you may not be able to access it in a timely manner.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="3-business-continuity-and-resilience">3. Business Continuity and Resilience<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#3-business-continuity-and-resilience" class="hash-link" aria-label="Direct link to 3. Business Continuity and Resilience" title="Direct link to 3. Business Continuity and Resilience" translate="no">​</a></h3>
<p>NIS2 requires a business continuity plan that includes the resilience of information systems. A cloud service provider whose operations could be compromised by a U.S. court order (such as an injunction or asset freeze) poses an unacceptable continuity risk for critical entities.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="4-penalties">4. Penalties<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#4-penalties" class="hash-link" aria-label="Direct link to 4. Penalties" title="Direct link to 4. Penalties" translate="no">​</a></h3>
<p>For critical entities, NIS2 penalties can reach <strong>10 million euros or 2% of global revenue</strong>. Senior executives are also held personally liable. In this context, choosing “cheap but risky” hosting is no longer economically rational.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-gdpr-and-industrial-data">The GDPR and Industrial Data<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#the-gdpr-and-industrial-data" class="hash-link" aria-label="Direct link to The GDPR and Industrial Data" title="Direct link to The GDPR and Industrial Data" translate="no">​</a></h2>
<p>The GDPR applies to <strong>personal data</strong>—which may include business data if it can be used to identify a natural person. Typical examples include:</p>
<ul>
<li class=""><strong>Remote access data</strong>: who logged in to which PLC (user ID)</li>
<li class=""><strong>Production logs</strong>: productivity data by operator/machine (if linked to an individual)</li>
<li class=""><strong>Maintenance data</strong>: who performed which maintenance task (named technician)</li>
<li class=""><strong>Alarms with assignment</strong>: which person acknowledged which alarm</li>
</ul>
<p>For this data, the GDPR prohibits any <strong>transfer outside the European Economic Area</strong> without an adequate protection mechanism (Standard Contractual Clauses, Binding Corporate Rules, etc.). Since the Privacy Shield was invalidated in 2020 (Schrems II ruling), transfers to the United States have been particularly vulnerable from a legal standpoint.</p>
<p><strong>Hosting in France</strong> eliminates any ambiguity: the data remains within the EEA, under GDPR jurisdiction, without the need to justify any data transfer mechanisms.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="certifications-that-matter-to-french-industry">Certifications That Matter to French Industry<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#certifications-that-matter-to-french-industry" class="hash-link" aria-label="Direct link to Certifications That Matter to French Industry" title="Direct link to Certifications That Matter to French Industry" translate="no">​</a></h2>
<p>Not all French hosting providers are created equal. For a mission-critical industrial IoT infrastructure, look for these certifications:</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="iso-27001">ISO 27001<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#iso-27001" class="hash-link" aria-label="Direct link to ISO 27001" title="Direct link to ISO 27001" translate="no">​</a></h3>
<p>The gold standard for information security certification. Essential. Requires a documented Information Security Management System (ISMS) that is audited annually.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="hds-health-data-host">HDS (Health Data Host)<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#hds-health-data-host" class="hash-link" aria-label="Direct link to HDS (Health Data Host)" title="Direct link to HDS (Health Data Host)" translate="no">​</a></h3>
<p>Mandatory for health data (pharmaceuticals, hospitals, medical devices). ANSSI/MiPih standards.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="secnumcloud">SecNumCloud<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#secnumcloud" class="hash-link" aria-label="Direct link to SecNumCloud" title="Direct link to SecNumCloud" translate="no">​</a></h3>
<p>The ANSSI certification for trusted cloud services. The highest security level available for the French cloud. Recommended for OIVs and NIS2-essential entities. Current providers: OVHcloud, Outscale (Dassault Systèmes), Oodrive.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="anssi-certified-csp-cloud-service-provider">ANSSI-Certified CSP (Cloud Service Provider)<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#anssi-certified-csp-cloud-service-provider" class="hash-link" aria-label="Direct link to ANSSI-Certified CSP (Cloud Service Provider)" title="Direct link to ANSSI-Certified CSP (Cloud Service Provider)" translate="no">​</a></h3>
<p>List of service providers certified for sensitive information systems.</p>
<p><strong>Warning</strong>: Some service providers advertise "hosting in France" even though they are subsidiaries of U.S. companies subject to the CLOUD Act. Insist on a written confirmation that the service provider is not subject to any extraterritorial law that would allow access to your data without notification.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="real-world-examples-which-manufacturers-are-affected">Real-world examples: Which manufacturers are affected?<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#real-world-examples-which-manufacturers-are-affected" class="hash-link" aria-label="Direct link to Real-world examples: Which manufacturers are affected?" title="Direct link to Real-world examples: Which manufacturers are affected?" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="operators-of-vital-importance-ovi">Operators of Vital Importance (OVI)<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#operators-of-vital-importance-ovi" class="hash-link" aria-label="Direct link to Operators of Vital Importance (OVI)" title="Direct link to Operators of Vital Importance (OVI)" translate="no">​</a></h3>
<p>The 12 OIV sectors in France (energy, water, transportation, food, finance, healthcare, etc.) have had specific cybersecurity obligations since the 2013 Military Programming Act (LPM). For these sectors, hosting monitoring data in certified French data centers is not an option—it is a contractual requirement of ANSSI.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="essential-and-important-entities-under-nis2">Essential and Important Entities Under NIS2<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#essential-and-important-entities-under-nis2" class="hash-link" aria-label="Direct link to Essential and Important Entities Under NIS2" title="Direct link to Essential and Important Entities Under NIS2" translate="no">​</a></h3>
<p>With NIS2, the scope expands significantly:</p>
<ul>
<li class="">All companies with 250 or more employees in the covered sectors</li>
<li class="">Critical defense contractors</li>
<li class="">Local water and energy network operators (even medium-sized ones)</li>
<li class="">Pharmaceutical and medical device companies</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="industrial-smes-that-export-to-sensitive-customers">Industrial SMEs that export to sensitive customers<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#industrial-smes-that-export-to-sensitive-customers" class="hash-link" aria-label="Direct link to Industrial SMEs that export to sensitive customers" title="Direct link to Industrial SMEs that export to sensitive customers" translate="no">​</a></h3>
<p>An SME that is a subcontractor for Airbus, Dassault Aviation, or a pharmaceutical company may be contractually required to host its data in a manner that complies with the client’s requirements. Major industrial groups are increasingly including these clauses in their supplier requests for proposals.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-to-evaluate-your-current-iot-solution">How to Evaluate Your Current IoT Solution<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#how-to-evaluate-your-current-iot-solution" class="hash-link" aria-label="Direct link to How to Evaluate Your Current IoT Solution" title="Direct link to How to Evaluate Your Current IoT Solution" translate="no">​</a></h2>
<p>Here are 5 questions to ask your current or future IIoT provider:</p>
<p><strong>1. Where is my data physically hosted?</strong>
Ask for a specific data center address, not just “in Europe.” “Europe” hosting could mean Ireland (Amazon), the Netherlands (Microsoft), or Finland (Google)—all of which are subject to the CLOUD Act.</p>
<p><strong>2. Is the parent company subject to the CLOUD Act?</strong>
If your service provider is a subsidiary of a U.S. company, it is subject to the CLOUD Act regardless of where its servers are located.</p>
<p><strong>3. What security certifications do you have?</strong>
ISO 27001 at a minimum. SecNumCloud if you are an OIV or a NIS2-designated critical entity.</p>
<p><strong>4. Have you signed a GDPR Data Processing Agreement (DPA)?</strong>
This is required whenever personal data is processed (which is often the case with access logs).</p>
<p><strong>5. Can you provide me with a recent penetration test report?</strong>
Reputable service providers publish summaries of their penetration tests or share them under an NDA.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="eziwans-position">Eziwan's Position<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#eziwans-position" class="hash-link" aria-label="Direct link to Eziwan's Position" title="Direct link to Eziwan's Position" translate="no">​</a></h2>
<p>The Eziwan platform is hosted <strong>exclusively in France</strong> by ISO 27001-certified service providers. We are a French company (an SAS under French law) and are not subject to any extraterritorial laws that would allow access to your data without your consent and without a French court order.</p>
<p>Our concrete commitments:</p>
<ul>
<li class=""><strong>Data hosted in France</strong>: ISO 27001-certified data center located in France</li>
<li class=""><strong>Company incorporated under French law</strong>: no disclosure obligations under foreign law</li>
<li class=""><strong>GDPR DPA</strong>: GDPR-compliant data processing agreement available upon request</li>
<li class=""><strong>NIS2 audit log</strong>: All access to data and equipment is logged and available for ANSSI audits</li>
<li class=""><strong>End-to-end encryption</strong>: Data encrypted in transit (TLS 1.3) and at rest (AES-256)</li>
</ul>
<p>For NIS2 critical entities and OIVs, we can provide a comprehensive package that includes the security policy, certifications, and contractual SLAs tailored to regulatory requirements.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="conclusion-industrial-digital-sovereignty-is-no-longer-optional">Conclusion: Industrial Digital Sovereignty Is No Longer Optional<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#conclusion-industrial-digital-sovereignty-is-no-longer-optional" class="hash-link" aria-label="Direct link to Conclusion: Industrial Digital Sovereignty Is No Longer Optional" title="Direct link to Conclusion: Industrial Digital Sovereignty Is No Longer Optional" translate="no">​</a></h2>
<p>By 2026, the question “Where is my industrial data stored?” had become just as important as “Is my equipment redundant?” or “Do I have a backup of my PLC configurations?”</p>
<p>The risks are real and well-documented:</p>
<ul>
<li class=""><strong>Regulatory</strong>: NIS2 penalties of up to €10 million for critical entities</li>
<li class=""><strong>Legal</strong>: unlawful GDPR data transfers that could result in fines from the CNIL</li>
<li class=""><strong>Operational</strong>: data unavailability in the event of a dispute with a foreign service provider</li>
<li class=""><strong>Competitive</strong>: potential disclosure of production data to foreign entities</li>
</ul>
<p>The good news is that high-performance, affordable sovereign hosting solutions are available in France. It’s no longer a matter of choosing between security and convenience—modern IIoT platforms hosted in France offer the same features as their U.S. counterparts, with the added assurance of digital sovereignty.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="checklist-assessing-the-sovereignty-of-your-entire-iot-chain">Checklist: Assessing the Sovereignty of Your Entire IoT Chain<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#checklist-assessing-the-sovereignty-of-your-entire-iot-chain" class="hash-link" aria-label="Direct link to Checklist: Assessing the Sovereignty of Your Entire IoT Chain" title="Direct link to Checklist: Assessing the Sovereignty of Your Entire IoT Chain" translate="no">​</a></h2>
<p>The location of the data center is not enough: industrial data travels through an entire chain that must be evaluated link by link.</p>
<table><thead><tr><th>Component</th><th>Question to Ask</th><th>Point of Concern</th></tr></thead><tbody><tr><td>SIM Card / Carrier</td><td>Where does mobile data pass through (APN)?</td><td>A public APN routes data through the open Internet; a private APN keeps the data within the carrier’s network</td></tr><tr><td>Gateway / router</td><td>Does the firmware and its telemetry data get sent to a third-party cloud?</td><td>Some Asian manufacturers require the use of their own management cloud</td></tr><tr><td>Transport</td><td>Is encryption end-to-end (VPN, TLS)?</td><td>A tunnel terminating at an intermediary creates a point of interception</td></tr><tr><td>Cloud platform</td><td>Who is the ultimate host, and which jurisdiction’s laws apply?</td><td>A French interface on AWS remains subject to the CLOUD Act</td></tr><tr><td>Backups</td><td>Where is the data replicated?</td><td>Backups are sometimes stored in another jurisdiction</td></tr><tr><td>Support</td><td>From where do support teams access the data?</td><td>Offshore support = de facto access from outside Europe</td></tr></tbody></table>
<p>This end-to-end audit takes half a day and helps you avoid unpleasant surprises during a customer security questionnaire or a NIS2 audit.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq--industrial-data-hosting-in-france">FAQ — Industrial Data Hosting in France<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#faq--industrial-data-hosting-in-france" class="hash-link" aria-label="Direct link to FAQ — Industrial Data Hosting in France" title="Direct link to FAQ — Industrial Data Hosting in France" translate="no">​</a></h2>
<p><strong>Is all industrial IoT data subject to the GDPR?</strong></p>
<p>The GDPR applies to personal data—typically location data linked to identifiable vehicles, access logs containing personal identifiers, or production data linked to identifiable operators. Purely process-related data (such as temperatures, pressures, and flow rates from an anonymized line) is not personal data. However, VPN access logs (including technicians’ identities) and geolocation data for mobile assets are indeed personal data subject to the GDPR.</p>
<p><strong>Does the U.S. CLOUD Act apply to a cloud service provider based in Europe?</strong></p>
<p>Yes, if that service provider is a subsidiary or a company subject to U.S. law (headquartered in the United States, listed on the NYSE or Nasdaq, or part of a U.S. corporate group). AWS Europe (Frankfurt), Azure Europe, and Google Cloud EU are all entities subject to the CLOUD Act through their U.S. parent companies. Only hosting providers governed exclusively by French or European law (OVHcloud, Scaleway, 3DS Outscale, Outscale) fall outside the scope of the CLOUD Act.</p>
<p><strong>Does NIS2 explicitly require hosting in France or the EU?</strong></p>
<p>NIS2 does not explicitly require a specific country of hosting, but mandates “appropriate technical and organizational measures,” including supply chain security and data protection. For OIVs (Operators of Vital Importance) governed by the LPM, the SGDSN often requires hosting on SecNumCloud-certified infrastructure—which effectively excludes non-European clouds for the most sensitive data.</p>
<p><strong>What is the SecNumCloud certification, and who can obtain it?</strong></p>
<p>SecNumCloud is ANSSI’s certification framework for “trusted” cloud service providers. Qualified providers must, among other things, guarantee immunity from non-European laws (no CLOUD Act), ensure that data is stored in France, and maintain audited security standards. As of the end of 2025, SecNumCloud-certified providers include OVHcloud, Outscale (3DS), and a few others.</p>
<p><strong>Can a manufacturer require its end customer to host its data in France?</strong></p>
<p>Yes, through contractual provisions (SLA, DPA—Data Processing Agreement). In industrial B2B contracts, particularly in regulated sectors (defense, energy, water), it is common to contractually require that data be hosted in France or the EU. Compliance with these clauses can be verified through annual audits.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/nis2-cybersecurity-industrial-infrastructure">Blog: NIS2 for Industry — Specific Requirements and Action Plan</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry">Blog: NIS2 Compliance Checklist — 30 Checkpoints</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/iec-62443-practical-guide">Blog: IEC 62443 — A Practical Guide for French Industry</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise">Blog: Cloud vs. On-Premise SCADA — A Decision Guide</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026">Blog: OT Cybersecurity — Threats and Incidents in 2026</a></li>
</ul>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="related-eziwan-solutions">Related Eziwan Solutions<a href="https://eziwan.com/en/blog/industrial-data-hosting-france-nis2#related-eziwan-solutions" class="hash-link" aria-label="Direct link to Related Eziwan Solutions" title="Direct link to Related Eziwan Solutions" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/cloud">Cloud Eziwan</a> — sovereign hosting of industrial data in France</li>
<li class=""><a class="" href="https://eziwan.com/en/scada-cloud">SCADA Cloud</a> — secure, NIS2-compliant cloud-based SCADA platform</li>
<li class=""><a class="" href="https://eziwan.com/en/edge-computing-industriel">Industrial edge computing</a> — edge processing to minimize the transfer of sensitive data</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-remote-support">Remote industrial monitoring</a> — secure monitoring of critical OT infrastructure</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-solutions">Eziwan Industrial Solutions</a> — a range of monitoring solutions compliant with regulatory requirements</li>
</ul>]]></content:encoded>
            <category>NIS2</category>
            <category>gdpr</category>
            <category>sovereign-cloud</category>
            <category>industrial-iot</category>
            <category>cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Edge Computing vs. the Cloud for Industry: How to Choose in 2026?]]></title>
            <link>https://eziwan.com/en/blog/edge-computing-vs-cloud-industry</link>
            <guid>https://eziwan.com/en/blog/edge-computing-vs-cloud-industry</guid>
            <pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Edge Computing or the Cloud for Your Factory? Latency, Bandwidth, Data Sovereignty, Costs: A Decision-Making Guide for Industry.]]></description>
            <content:encoded><![CDATA[<p>"Put everything in the cloud" was the mantra of industrial digital transformation until 2020. Then the projects ran into the reality on the ground: a pumping station with 500 ms of network latency cannot close a control loop via the cloud. A production site that generates 2 TB of data per day cannot send it all to AWS without incurring prohibitive bandwidth costs. And a defense contractor cannot host its production data on a server whose physical location is beyond its control.</p>
<p>In 2026, the dominant architecture in industrial IoT is hybrid: local processing at the source for tasks that require it, and the cloud for tasks that benefit from scale and centralization. This guide helps you make the right decision for each use case.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="definitions-edge-cloud-fog--without-the-jargon">Definitions: edge, cloud, fog — without the jargon<a href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry#definitions-edge-cloud-fog--without-the-jargon" class="hash-link" aria-label="Direct link to Definitions: edge, cloud, fog — without the jargon" title="Direct link to Definitions: edge, cloud, fog — without the jargon" translate="no">​</a></h2>
<p>Before we compare them, let's clarify what these terms actually mean in an industrial context.</p>
<p><strong>The cloud</strong> is a collection of remote servers accessible via the Internet or a private WAN. In industrial applications, the cloud hosts monitoring dashboards, historical databases, advanced analytics algorithms, and collaborative tools. The dominant hyperscalers are AWS, Microsoft Azure, and Google Cloud, but French sovereign cloud offerings (OVHcloud, Outscale/Dassault, Scaleway) are becoming increasingly relevant for sensitive data.</p>
<p><strong>Edge computing</strong> refers to processing data as close as possible to its source—physically on-site, in the control cabinet, or within the equipment itself. The “edge” in “edge computing” is the boundary between the field OT network and the rest of the network—that’s where the industrial gateway is located. In practice, the edge is your gateway or your local server.</p>
<p><strong>Fog computing</strong> is an intermediate term referring to distributed processing in the layers between the field and the cloud (zone aggregators, building servers, factory servers). By 2026, the term “fog” is used less frequently in the industry than in academic publications—most industry professionals simply refer to a hybrid edge + cloud architecture.</p>
<p><strong>The Hierarchy in a Factory</strong>:</p>
<ul>
<li class="">Level 0: Sensors, actuators (no processing)</li>
<li class="">Level 1: PLCs, RTUs (real-time processing, cycle time &lt;10 ms)</li>
<li class="">Level 2: Local SCADA, HMI (site monitoring and control)</li>
<li class="">Level 3: <strong>Edge gateway</strong> (data collection, normalization, pre-processing, local alerts)</li>
<li class="">Level 4: <strong>Cloud</strong> (long-term data archiving, analytics, multi-site monitoring)</li>
</ul>
<p>The Eziwan industrial gateway operates at level 3 of this hierarchy: it serves as the interface between the field OT network and the monitoring cloud.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="when-edge-computing-is-mandatory">When Edge Computing Is Mandatory<a href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry#when-edge-computing-is-mandatory" class="hash-link" aria-label="Direct link to When Edge Computing Is Mandatory" title="Direct link to When Edge Computing Is Mandatory" translate="no">​</a></h2>
<p>There are three situations in which cloud-based processing alone is technically insufficient or unacceptable.</p>
<p><strong>Real-time latency constraint</strong></p>
<p>The control loop of an industrial PLC must complete in less than 1 to 10 ms, depending on the process. This requirement is physically incompatible with a round-trip network connection to a remote cloud, which takes at least 10 to 50 ms over a 4G LTE connection and 5 to 20 ms over a fiber connection to the nearest server in France.</p>
<p>Applications that <em>require</em> local processing to function:</p>
<ul>
<li class="">Emergency shutdown when a threshold is exceeded (machine shutdown if temperature &gt; 85 °C)</li>
<li class="">Flow or pressure control (closed-loop PID control via edge gateway)</li>
<li class="">Abnormal vibration detection with local alarm activation</li>
<li class="">Vision-based quality control with rejection of defective parts from the production line</li>
</ul>
<p><strong>Bandwidth Constraint</strong></p>
<p>A high-frequency industrial vibration sensor (10 kHz accelerometer) generates approximately 80 MB of raw data per minute. A production line with 100 such sensors generates 8 GB per minute, or 11.5 TB per day. Transmitting all of this data in real time to the cloud would cost tens of thousands of euros per month in bandwidth and cloud storage.</p>
<p>The edge device solves this problem through two mechanisms:</p>
<ul>
<li class=""><strong>Downsampling</strong>: reducing the sampling frequency from 10 kHz to 1 Hz for routine monitoring, and transmitting high-frequency data only on event (threshold exceeded)</li>
<li class=""><strong>Feature extraction</strong>: locally calculate relevant indicators (vibration RMS, characteristic FFT frequencies) and transmit only these indicators, rather than the raw data</li>
</ul>
<p>In practice, edge computing can reduce the amount of data transmitted to the cloud by 70 to 95 percent, depending on the application.</p>
<p><strong>Data Sovereignty Requirement</strong></p>
<p>Certain types of industrial data cannot leave the company or the country:</p>
<ul>
<li class="">Production data related to confidential markets (defense, aerospace, nuclear)</li>
<li class="">Product formulas and process parameters that constitute trade secrets</li>
<li class="">Data covered by client confidentiality agreements</li>
<li class="">Data whose location is subject to regulatory requirements (health data under the SNDS, financial data)</li>
</ul>
<p>In these cases, both edge processing <em>and</em> storage are local. The cloud may receive anonymized or aggregated data (performance KPIs), but not sensitive raw data.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="when-the-cloud-alone-is-enough">When the Cloud Alone Is Enough<a href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry#when-the-cloud-alone-is-enough" class="hash-link" aria-label="Direct link to When the Cloud Alone Is Enough" title="Direct link to When the Cloud Alone Is Enough" translate="no">​</a></h2>
<p>For most industrial monitoring applications, the cloud alone is perfectly suited and greatly simplifies the architecture.</p>
<p><strong>Non-critical supervision and monitoring</strong></p>
<p>Remote monitoring of a pumping station (level, pressure, and flow rate readings every 5 seconds) has no latency requirements below 1 second. A “low level” alarm that is triggered in 200 ms rather than 10 ms has no operational impact: the operator sees the alarm within a second, and the pumping process has response times on the order of minutes or hours.</p>
<p><strong>Analytics and Machine Learning Using Historical Data</strong></p>
<p>Predictive maintenance algorithms trained on 18 months of historical data run very efficiently in the cloud, where computing resources are elastic and storage is inexpensive. An anomaly detection model that runs once an hour on data from the past 24 hours does not need to be deployed at the edge.</p>
<p><strong>Centralized Multi-Site Monitoring</strong></p>
<p>A network manager overseeing 50 water treatment plants spread across a department has every reason to centralize data in the cloud: unified dashboards, cross-site correlation, performance benchmarking, and automated regulatory reports. Implementing these functions across 50 local edge devices would not only be costly but also nearly impossible to maintain.</p>
<p><strong>Update and Configuration Management</strong></p>
<p>Centralized management of router configurations, firmware versions, and alert rules is a native cloud feature. Zero Touch Provisioning (ZTP) is, by definition, a cloud service that configures devices remotely.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="hybrid-edge--cloud-architecture-the-best-of-both-worlds">Hybrid Edge + Cloud Architecture: The Best of Both Worlds<a href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry#hybrid-edge--cloud-architecture-the-best-of-both-worlds" class="hash-link" aria-label="Direct link to Hybrid Edge + Cloud Architecture: The Best of Both Worlds" title="Direct link to Hybrid Edge + Cloud Architecture: The Best of Both Worlds" translate="no">​</a></h2>
<p>The recommended architecture for serious industrial IoT projects in 2026 is a hybrid one, with a clear division of responsibilities between the edge and the cloud.</p>
<p><strong>Roles of the edge (local industrial gateway)</strong>:</p>
<ul>
<li class="">Local collection of field data via Modbus RTU/TCP, OPC-UA, Profibus, SNMP</li>
<li class="">Data normalization and formatting (unit conversion, local timestamping, equipment identifiers)</li>
<li class="">Local evaluation of alarm rules and triggering of alerts without network dependency</li>
<li class="">Store &amp; forward: temporary storage if connectivity is interrupted, automatic retransmission upon reconnection</li>
<li class="">Pre-processing: downsampling, feature extraction, outlier filtering</li>
<li class="">VPN tunnel to the cloud: TLS encryption, mutual authentication</li>
</ul>
<p><strong>Cloud Functions</strong>:</p>
<ul>
<li class="">Collection and archiving of standardized data</li>
<li class="">Real-time and historical dashboards</li>
<li class="">Advanced alerting engine (multi-site correlation, trend-based alerts)</li>
<li class="">Analytics and machine learning</li>
<li class="">User management, access rights, security audits</li>
<li class="">APIs for integration with ERP, CMMS, and BI systems</li>
<li class="">Monitoring of the gateway fleet (network health, connectivity, firmware versions)</li>
</ul>
<p><strong>The Synchronization Protocol</strong>:
The gateway publishes data to the cloud via MQTT over TLS or HTTPS REST, depending on the configuration. In the event of a loss of connectivity, data is buffered locally (typically in 4 to 32 GB of flash storage) and sent in bulk once connectivity is restored. This architecture ensures that no data is lost, even in the event of a network outage lasting several hours.</p>
<p><strong>Monitoring the gateway itself</strong>:
The edge gateway itself must be monitored from the cloud: availability, LTE signal (RSRP/RSRQ), CPU/RAM usage, disk space, and firmware version. A gateway that has been silently down for 48 hours without being detected is unacceptable at a critical site.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="edge-computing-in-practice-examples-by-industry">Edge Computing in Practice: Examples by Industry<a href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry#edge-computing-in-practice-examples-by-industry" class="hash-link" aria-label="Direct link to Edge Computing in Practice: Examples by Industry" title="Direct link to Edge Computing in Practice: Examples by Industry" translate="no">​</a></h2>
<p><strong>Food Industry — Cold Storage Monitoring</strong></p>
<p>A cold storage room requires a local alarm in the event that the temperature is exceeded (&gt; +4 °C for a positive-temperature room), regardless of network connectivity. The edge gateway measures the temperature locally and triggers a local audible alarm, sends an SMS, and makes an on-call alert within 30 seconds, without any round-trip communication to the cloud. At the same time, temperature data is uploaded to the cloud every 5 minutes for traceability and HACCP compliance.</p>
<p><strong>Water Distribution — Pressure Regulation</strong></p>
<p>A pumping station equipped with a variable-frequency drive on the main pump uses the edge for local pressure control (setpoint 3.5 bars, measured every 100 ms, pump speed adjustment). This control loop runs entirely locally—it cannot tolerate the latency of a round trip to the cloud. The cloud receives pressure and energy consumption trends every minute.</p>
<p><strong>Energy — Solar Farm</strong></p>
<p>A 500 kWp solar farm with 10 inverters generates approximately 50,000 Modbus values per hour. The edge device calculates the Performance Ratio and the soiling indicator locally every 5 minutes, compares the strings with each other, and generates an alert if a string is more than 15% below the median. The cloud receives the calculated metrics (not the 50,000 raw values), the aggregated production curves, and the alerts.</p>
<p><strong>Construction and Civil Engineering — Equipment Monitoring</strong></p>
<p>A compactor on a construction site generates data on vibration, speed, and GPS position. The edge device calculates “compaction passes” (a combination of GPS position and compaction energy) locally and uploads only the business-relevant result (compaction map) to the cloud. This reduces the volume of LTE data transmitted by a factor of 100 and allows the device to operate even in areas with weak coverage.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="edge-computing-with-eziwan-what-the-gateway-does-locally">Edge Computing with Eziwan: What the Gateway Does Locally<a href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry#edge-computing-with-eziwan-what-the-gateway-does-locally" class="hash-link" aria-label="Direct link to Edge Computing with Eziwan: What the Gateway Does Locally" title="Direct link to Edge Computing with Eziwan: What the Gateway Does Locally" translate="no">​</a></h2>
<p>The Eziwan gateway is designed as an industrial edge computing node, not as a simple transparent router.</p>
<p><strong>Data Collection and Local Normalization</strong>:
The gateway polls field devices (Modbus RTU controllers, M-Bus meters, local MQTT sensors) at configurable intervals ranging from 100 ms to 24 hours, depending on the data type. The values are normalized (unit, scale factor, offset) and precisely time-stamped (NTP synchronized with French time servers).</p>
<p><strong>Local Alarm Rules</strong>:
Simple alarm rules (high threshold, low threshold, out-of-range value, loss of communication) are evaluated on the gateway. Alerts can be sent via SMS, email, or webhook directly from the edge, without relying on the Eziwan cloud. This ensures that critical alerts are delivered even during cloud platform maintenance.</p>
<p><strong>Store and forward</strong>:
The collected data is buffered locally on the gateway’s flash memory. In the event of a connectivity outage (loss of LTE signal, network maintenance), the data is stored locally and automatically transmitted to the cloud once connectivity is restored. The local storage capacity allows the system to handle outages lasting several days without any data loss.</p>
<p><strong>Permanent VPN Tunnel</strong>:
The connection between the gateway and the Eziwan cloud is established via OpenVPN, initiated from the gateway (no inbound ports on the device). Remote access to local OT devices goes exclusively through this encrypted tunnel, without ever exposing a port to the Internet.</p>
<p><strong>Locally Supported Protocols</strong>:</p>
<ul>
<li class="">Modbus RTU (RS-232, RS-485)</li>
<li class="">Modbus TCP</li>
<li class="">Local MQTT broker</li>
<li class="">SNMP</li>
<li class="">M-Bus (sub-meters for electricity, water, and gas)</li>
<li class="">Local REST API for custom integrations</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-to-plan-your-edgecloud-architecture">How to Plan Your Edge/Cloud Architecture<a href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry#how-to-plan-your-edgecloud-architecture" class="hash-link" aria-label="Direct link to How to Plan Your Edge/Cloud Architecture" title="Direct link to How to Plan Your Edge/Cloud Architecture" translate="no">​</a></h2>
<p>A successful edge/cloud architecture is defined before selecting the equipment. Here is the recommended process.</p>
<p><strong>Step 1: Map Data Sources</strong>
List each piece of equipment or sensor, its communication protocol, its data generation frequency, the volume of raw data, and the business criticality of the data.</p>
<p><strong>Step 2: Classify Constraints by Use Case</strong>
For each use case (alarm, control, reporting, analytics), identify the main constraint: latency (&lt; 100 ms? &lt; 1 s?), offline availability (yes/no), sovereignty (sensitive data?), volume (&gt; 1 MB/min per source?).</p>
<p><strong>Step 3: Apply the decision rule</strong></p>
<table><thead><tr><th>Constraint</th><th>Edge processing</th><th>Cloud processing</th></tr></thead><tbody><tr><td>Latency &lt; 500 ms</td><td>Required</td><td>Not possible</td></tr><tr><td>Offline availability</td><td>Required</td><td>Not possible</td></tr><tr><td>Volume &gt; 1 MB/min per source</td><td>Recommended</td><td>Costly</td></tr><tr><td>Sensitive data (sovereignty)</td><td>Required</td><td>Subject to conditions</td></tr><tr><td>ML analytics on historical data</td><td>Optional</td><td>Recommended</td></tr><tr><td>Multi-site monitoring</td><td>Optional</td><td>Recommended</td></tr><tr><td>User interface</td><td>Optional</td><td>Recommended</td></tr></tbody></table>
<p><strong>Step 4: Sizing the Edge</strong>
Calculate the CPU, RAM, and storage required for the local processing tasks identified in Step 3. An entry-level gateway with 512 MB of RAM and 1 GB of storage covers 90% of typical industrial edge requirements. Video analytics and on-device ML inference applications require more powerful gateways (4–8 GB of RAM, on-device GPU).</p>
<p><strong>Step 5: Verify Connectivity</strong>
Estimate the network bandwidth required after edge preprocessing. An uplink bandwidth of 1 Mbps is sufficient for most industrial IoT installations with edge processing (a few hundred normalized data points per minute). Compare this with the M2M SIM plans available in your area.</p>
<p>This process takes 2 to 4 hours for a standard industrial site and results in better-sized architectures that are less costly in the long run and more robust under actual operating conditions.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>What exactly is industrial edge computing—is it complicated to deploy?</strong>
In practice, industrial edge computing refers to your IoT gateway executing local processing logic: calculating averages, detecting thresholds, filtering, and aggregating data. At Eziwan, these rules are configured via the cloud dashboard (no programming required). For advanced processing (embedded ML, Docker containers), a more complex deployment is required, but most industrial needs are covered by rule configuration.</p>
<p><strong>When is edge computing not enough, and is the cloud absolutely necessary?</strong>
When data needs to be correlated across multiple sites (e.g., comparing the performance of 50 factories), when analysis requires a long history (18 months of trends), or when remote teams need access to monitoring. Edge computing alone cannot provide consolidated, multi-site visibility—that’s the role of the cloud.</p>
<p><strong>Does 4G LTE latency (30–100 ms) prevent the use of the cloud for critical alerts?</strong>
For critical alerts requiring a response in less than 500 ms, yes—the cloud alone is not reliable. But with edge computing, detection and local alert triggering (SMS, relay, audible alarm) occur in a matter of milliseconds. The cloud receives the alert notification a few seconds later. The combination of edge and cloud computing offers the best of both worlds.</p>
<p><strong>Does edge computing on an IoT gateway allow you to send write commands to the PLC?</strong>
Yes. The edge device can send Modbus TCP write commands to the PLC (setpoints, on/off commands). This feature should be used with caution: it requires a security analysis (determining who can write what), limits on permitted values, and comprehensive logging. NIS2 mandates traceability for all remote actions on OT systems.</p>
<p><strong>What is the difference between store-and-forward and edge computing?</strong>
Store-and-forward is a feature of edge computing: data is collected locally and buffered if the cloud connection is unavailable, then transmitted as soon as the connection is restored. Edge computing in the broader sense also includes local processing (calculations, alerts, control), not just buffering. Both are useful and complementary.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/remote-industrial-monitoring-complete-guide">Blog: Remote Industrial Monitoring — Complete Guide 2026</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/predictive-maintenance-iot-field-sensors">Blog: IIoT Predictive Maintenance — From Sensor Data to Alerts</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/scada-cloud-vs-on-premise">Blog: Cloud SCADA vs. On-Premises SCADA — Decision Guide</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/choosing-industrial-iot-gateway-criteria">Blog: Choosing an Industrial IoT Gateway — 9 Criteria</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/industrial-iot-roi-calculation">Blog: ROI of Industrial IoT — Calculation and Optimization</a></li>
</ul>
<hr>
<p><strong>Want to learn more?</strong> The Eziwan team helps manufacturers design and deploy edge/cloud architectures tailored to their specific needs. <a class="" href="https://eziwan.com/en/gateway">Discover the edge capabilities of the Eziwan gateway</a> or <a class="" href="https://eziwan.com/en/telegestion-industrielle">check out our industrial remote management solutions</a> to discuss your project.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/edge-computing-industriel">Industrial edge computing</a> — local data processing for industrial sites</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-iot-gateway">Industrial IoT Gateway</a> — choosing the right gateway for your edge architecture</li>
<li class=""><a class="" href="https://eziwan.com/en/scada-cloud">Cloud SCADA</a> — SCADA monitoring from the cloud for hybrid architectures</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-cloud-data-logger">Industrial Cloud Data Logger</a> — cloud-based historical data storage for your industrial data</li>
<li class=""><a class="" href="https://eziwan.com/en/passerelle-iiot">IIoT Gateway</a> — IIoT gateway solutions for industrial edge computing</li>
</ul>]]></content:encoded>
            <category>edge-computing</category>
            <category>cloud</category>
            <category>industry-40</category>
            <category>iiot</category>
        </item>
        <item>
            <title><![CDATA[NIS2 Industry 2026: The Complete Compliance Checklist (30 Points)]]></title>
            <link>https://eziwan.com/en/blog/nis2-compliance-checklist-industry</link>
            <guid>https://eziwan.com/en/blog/nis2-compliance-checklist-industry</guid>
            <pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[NIS2 Checklist for Industry: 30 checkpoints to verify your compliance. Critical and important entities, deadlines, penalties.]]></description>
            <content:encoded><![CDATA[<p>The NIS2 (Network and Information Security 2) Directive has been transposed into French law since October 2024. In 2026, industrial entities that have not yet begun the compliance process are operating in a high-risk environment: the first penalties from ANSSI are expected, and cyberattacks on industrial infrastructure continue to rise—according to CERT-FR, OT incidents increased by 38% between 2023 and 2025.</p>
<p>This article provides a clear overview of the requirements NIS2 imposes on the industry and a structured 30-point checklist to assess your level of compliance.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="nis2-at-a-glance-whats-changing-for-french-industry">NIS2 at a Glance: What's Changing for French Industry<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#nis2-at-a-glance-whats-changing-for-french-industry" class="hash-link" aria-label="Direct link to NIS2 at a Glance: What's Changing for French Industry" title="Direct link to NIS2 at a Glance: What's Changing for French Industry" translate="no">​</a></h2>
<p>NIS2 succeeds NIS1 (2016) with a significantly expanded scope of application. European Directive 2022/2555 has been transposed into French law through a specific statute that grants ANSSI the powers to supervise, audit, and impose sanctions.</p>
<p><strong>What has fundamentally changed compared to NIS1</strong>:</p>
<ul>
<li class="">
<p><strong>The scope is expanding significantly</strong>: NIS1 primarily covered operators of critical infrastructure (OCI) and a few critical service providers. NIS2 adds tens of thousands of additional companies, particularly in the manufacturing industry, medical device manufacturing, the chemical industry, and the production of critical materials.</p>
</li>
<li class="">
<p><strong>Responsibility extends to senior management</strong>: Executives may be held personally liable in the event of serious noncompliance. They must approve security measures and complete basic cybersecurity training.</p>
</li>
<li class="">
<p><strong>The notification deadlines are short</strong>: 24 hours for the initial notification in the event of a significant incident, 72 hours for the interim report, and one month for the final report.</p>
</li>
<li class="">
<p><strong>These obligations extend to the subcontracting chain</strong>: You must assess the security of your critical suppliers and service providers who have access to your systems.</p>
</li>
</ul>
<p>The directive distinguishes between two categories of entities based on their size and industry, with slightly different requirements.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="who-is-affected-essential-entities-vs-significant-entities">Who Is Affected: Essential Entities vs. Significant Entities<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#who-is-affected-essential-entities-vs-significant-entities" class="hash-link" aria-label="Direct link to Who Is Affected: Essential Entities vs. Significant Entities" title="Direct link to Who Is Affected: Essential Entities vs. Significant Entities" translate="no">​</a></h2>
<p><strong>Essential Entities (EE)</strong></p>
<p>Essential entities are defined as large organizations (&gt; 250 employees OR &gt; 50 M€ in revenue OR &gt; 43 M€ in total assets) in the following sectors:</p>
<ul>
<li class="">Energy (electricity, gas, oil, hydrogen)</li>
<li class="">Transportation (air, rail, maritime, road)</li>
<li class="">Banking and financial market infrastructure</li>
<li class="">Healthcare</li>
<li class="">Drinking water and wastewater</li>
<li class="">Digital infrastructure</li>
<li class="">ICT services management</li>
<li class="">Public administration</li>
<li class="">Space</li>
</ul>
<p>Critical entities are subject to <em>proactive</em> oversight by ANSSI: scheduled audits, on-site inspections, and a requirement to report uncertainties.</p>
<p><strong>Significant Entities (SE)</strong></p>
<p>The following medium-sized organizations (&gt;50 employees OR &gt;€10 million in revenue) in the following sectors are classified as significant entities:</p>
<ul>
<li class="">Postal and shipping services</li>
<li class="">Waste management</li>
<li class="">Manufacturing, production, and distribution of chemicals</li>
<li class="">Production, processing, and distribution of food products</li>
<li class=""><strong>Manufacturing</strong> (including the manufacture of medical devices, computers, electronics, electrical equipment, machinery, vehicles, and transportation equipment)</li>
<li class="">Digital service providers</li>
<li class="">Research</li>
</ul>
<p>Significant entities are subject to <em>reactive</em> oversight: ANSSI does not conduct audits on its own initiative, but may initiate an audit upon notification of an incident or a report.</p>
<p><strong>The Case of French Industrial SMEs</strong></p>
<p>An industrial SME with 75 employees and €12 million in revenue is considered a significant entity under NIS2. It is subject to all technical requirements, although compliance deadlines may be extended depending on the sector.</p>
<p>ANSSI has published a self-assessment tool for determining the scope of coverage, available on the anssi.fr website. If you haven't yet performed this check, this is the first step.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="technical-checklist--30-checkpoints">Technical Checklist — 30 Checkpoints<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#technical-checklist--30-checkpoints" class="hash-link" aria-label="Direct link to Technical Checklist — 30 Checkpoints" title="Direct link to Technical Checklist — 30 Checkpoints" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="a-inventory-of-assets-5-points">A. Inventory of Assets (5 points)<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#a-inventory-of-assets-5-points" class="hash-link" aria-label="Direct link to A. Inventory of Assets (5 points)" title="Direct link to A. Inventory of Assets (5 points)" translate="no">​</a></h3>
<p>☐ <strong>A1. Complete Inventory of IT Assets</strong>
You have an up-to-date inventory of all IT equipment (servers, workstations, network equipment), including operating system versions, critical software versions, the person responsible, and business criticality. Updated at least every 6 months.</p>
<p>☐ <strong>A2. Complete Inventory of OT Assets</strong>
Your inventory includes controllers (PLCs, RTUs), HMIs, SCADA supervisors, IoT gateways, industrial routers, and any equipment connected to the OT network. The firmware version and the date of the last update are documented.</p>
<p>☐ <strong>A3. Data Flow Mapping</strong>
Communication flows between IT and OT systems are documented in the form of data flow diagrams. Undocumented flows are blocked by default (whitelist policy).</p>
<p>☐ <strong>A4. Classification of Assets by Criticality</strong>
Each asset is classified according to its criticality for business continuity: critical (immediate production shutdown if compromised), important (significant degradation), standard. This classification guides security priorities.</p>
<p>☐ <strong>A5. Lifecycle Management</strong>
A documented process manages the end of life for equipment: removal of unsupported equipment, secure decommissioning (data erasure, account removal), and recycling.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="b-access-management-and-authentication-5-points">B. Access Management and Authentication (5 points)<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#b-access-management-and-authentication-5-points" class="hash-link" aria-label="Direct link to B. Access Management and Authentication (5 points)" title="Direct link to B. Access Management and Authentication (5 points)" translate="no">​</a></h3>
<p>☐ <strong>B1. MFA for Remote Access</strong>
Multi-factor authentication (MFA) is mandatory for all remote access to information systems, including VPN access to OT networks. ANSSI advises against using SMS OTP solutions; instead, use TOTP (Google Authenticator, Aegis) or FIDO2 keys.</p>
<p>☐ <strong>B2. Principle of Least Privilege</strong>
User accounts have only the permissions necessary to perform their duties. Dedicated administrator accounts are separate from accounts used for day-to-day work. Permissions are reviewed at least once a year and whenever a user changes positions.</p>
<p>☐ <strong>B3. Management of Shared and Service Accounts</strong>
Shared accounts (generic "admin" and "operator" accounts) are deleted or replaced with named accounts. Application service accounts are managed in a vault (CyberArk, Hashicorp Vault, Bitwarden Business) with automatic password rotation.</p>
<p>☐ <strong>B4. Physical Access Control</strong>
Physical access to server rooms, control cabinets, and technical rooms is controlled by access cards or keys, with access logs maintained. Access by external personnel is tracked.</p>
<p>☐ <strong>B5. Revocation of Access</strong>
A formalized process ensures that access is immediately revoked upon an employee’s departure or a change in role. The revocation timeframe is documented and is less than 24 hours for critical access.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="c-vpns-and-encryption-of-ot-communications-5-points">C. VPNs and Encryption of OT Communications (5 points)<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#c-vpns-and-encryption-of-ot-communications-5-points" class="hash-link" aria-label="Direct link to C. VPNs and Encryption of OT Communications (5 points)" title="Direct link to C. VPNs and Encryption of OT Communications (5 points)" translate="no">​</a></h3>
<p>☐ <strong>C1. VPN for All Remote OT Access</strong>
All remote access to an OT network (SCADA, monitoring, PLCs) must go through an encrypted VPN (IPsec, OpenVPN, or mutual TLS). Direct Internet access to OT equipment is prohibited and technically blocked.</p>
<p>☐ <strong>C2. IT/OT Segmentation</strong>
The OT network is physically or logically separated from the IT network (office, company). Communication between zones goes through a DMZ or a dedicated firewall with explicit rules. The default policy is "deny all."</p>
<p>☐ <strong>C3. Cloud Communication Encryption</strong>
All communications between field devices and cloud platforms (MQTT, HTTPS, REST API) use at least TLS 1.2 (TLS 1.3 recommended). The certificates are valid, not self-signed, and their expiration dates are monitored.</p>
<p>☐ <strong>C4. No Inbound Ports Open to the Internet</strong>
No OT equipment, HMI, or supervisor is directly accessible from the Internet via an incoming port. All remote access is initiated from the equipment to the platform (using the “call home” model or access via a client VPN).</p>
<p>☐ <strong>C5. Key and Certificate Management</strong>
An inventory of TLS certificates, VPN keys, and application secrets is maintained. Keys and certificates set to expire within 30 days trigger an alert. A rotation process is documented.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="d-incident-detection-and-response-4-points">D. Incident Detection and Response (4 points)<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#d-incident-detection-and-response-4-points" class="hash-link" aria-label="Direct link to D. Incident Detection and Response (4 points)" title="Direct link to D. Incident Detection and Response (4 points)" translate="no">​</a></h3>
<p>☐ <strong>D1. Security Event Logging</strong>
Critical equipment (firewalls, VPNs, HMIs, SCADA servers) generates security logs that are collected in a centralized system (SIEM, syslog server). Logs are retained for at least 12 months for essential entities and 6 months for important entities.</p>
<p>☐ <strong>D2. Anomaly Monitoring</strong>
Anomaly detection rules are active on OT network flows: connections to unknown destinations, unusual traffic volumes, connections outside of production hours, and repeated failed authentication attempts.</p>
<p>☐ <strong>D3. Documented Incident Response Procedure</strong>
An incident response plan (IRP) is documented, approved by management, and tested at least once a year (through a simulation exercise or tabletop drill). It covers the detection, containment, eradication, recovery, and communication phases.</p>
<p>☐ <strong>D4. CERT-FR and ANSSI Contact Information Up to Date</strong>
The company has registered its contact information with ANSSI via the NIS2 portal. The contact information for the security officer and management is up to date. The relevant teams are aware of the CERT-FR contact information (cert-fr.cert.gouv.fr, +33 3 51 14 17 41).</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="e-business-continuity-4-points">E. Business Continuity (4 points)<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#e-business-continuity-4-points" class="hash-link" aria-label="Direct link to E. Business Continuity (4 points)" title="Direct link to E. Business Continuity (4 points)" translate="no">​</a></h3>
<p>☐ <strong>E1. Documented Business Continuity Plan (BCP)</strong>
A BCP covering cyberattack scenarios (ransomware, SCADA compromise) is documented and tested. It defines procedures for operating under degraded conditions (manual mode, restarting from clean backups).</p>
<p>☐ <strong>E2. Regular and Tested Backups</strong>
The configurations of PLCs, SCADA systems, HMIs, and servers are backed up in accordance with a documented policy. Backups are stored offline or in an isolated environment. Their restoration is tested at least once every six months.</p>
<p>☐ <strong>E3. Network Access Redundancy</strong>
Critical sites have redundant connectivity (dual SIM with multiple carriers, fiber + 4G LTE) to maintain remote monitoring access in the event of a carrier failure.</p>
<p>☐ <strong>E4. Documented Recovery Time and Point Objectives (RTO/RPO)</strong>
Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and documented for each critical system. These objectives are consistent with contractual commitments to customers.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="f-training-and-awareness-3-points">F. Training and Awareness (3 points)<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#f-training-and-awareness-3-points" class="hash-link" aria-label="Direct link to F. Training and Awareness (3 points)" title="Direct link to F. Training and Awareness (3 points)" translate="no">​</a></h3>
<p>☐ <strong>F1. Mandatory Cybersecurity Training for Management</strong>
NIS2 requires that executives receive training on cybersecurity risks and the security measures applicable to the organization. This training (at least 4 hours) must be documented with the date and a certificate of completion.</p>
<p>☐ <strong>F2. Regular Employee Awareness Training</strong>
An awareness training session on cyber risks (phishing, social engineering, passwords) is held at least once a year for all staff. This includes contractors with access to the systems.</p>
<p>☐ <strong>F3. Phishing Exercise</strong>
A simulated phishing exercise is conducted at least once a year to assess employees’ level of vigilance and identify those at risk so they can receive additional training.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="g-management-of-third-parties-and-contractors-4-points">G. Management of Third Parties and Contractors (4 points)<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#g-management-of-third-parties-and-contractors-4-points" class="hash-link" aria-label="Direct link to G. Management of Third Parties and Contractors (4 points)" title="Direct link to G. Management of Third Parties and Contractors (4 points)" translate="no">​</a></h3>
<p>☐ <strong>G1. Inventory of Critical Subcontractors</strong>
Service providers who have access to your information systems or OT systems (integrators, maintenance providers, software vendors) are listed along with the criticality level of their access. This inventory is kept up to date.</p>
<p>☐ <strong>G2. Contractual Security Provisions</strong>
Contracts with critical service providers include security provisions: obligation to report incidents, NIS2 compliance for subject entities, right to audit, and confidentiality.</p>
<p>☐ <strong>G3. Limited and Logged Subcontractor Access</strong>
Remote access granted to subcontractors (PLC maintenance access, remote support) is time-limited, logged, and can be revoked immediately. Dedicated VPNs for each service provider are preferable to shared accounts.</p>
<p>☐ <strong>G4. Security Assessment of Critical Suppliers</strong>
Suppliers of critical software or hardware undergo a minimum security assessment (questionnaire, ISO 27001 certifications, audit).</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ot-remote-access-management-the-nis2-blind-spot">OT Remote Access Management: The NIS2 Blind Spot<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#ot-remote-access-management-the-nis2-blind-spot" class="hash-link" aria-label="Direct link to OT Remote Access Management: The NIS2 Blind Spot" title="Direct link to OT Remote Access Management: The NIS2 Blind Spot" translate="no">​</a></h2>
<p>Secure remote access to OT systems is often the most critical blind spot for industrial companies. It is also one of the most commonly exploited attack vectors—the ENISA 2025 report on OT incidents cites poorly secured remote access as the primary entry point in 42% of documented incidents.</p>
<p><strong>The Most Common Security Mispractices</strong>:</p>
<ul>
<li class="">Port 3389 (RDP) open directly to the Internet and connected to a SCADA supervisor</li>
<li class="">An "admin" account with the password "password" on a web-accessible HMI</li>
<li class="">Shared operator VPN without network segmentation (the user has access to the entire network)</li>
<li class="">TeamViewer or AnyDesk without MFA, with permanent access</li>
</ul>
<p><strong>The NIS2-compliant approach</strong>:</p>
<ol>
<li class="">No incoming ports open to the Internet from the OT network</li>
<li class="">All remote access goes through a VPN with MFA (OpenVPN + client certificate + TOTP OTP)</li>
<li class="">VPN access is limited to the subnets necessary for the service provider’s work (segmentation by VLAN)</li>
<li class="">Each remote access session is logged with a timestamp, user identity, and actions performed</li>
<li class="">Exceptional access (emergency troubleshooting) is granted temporarily via an approval workflow and automatically revoked after the session</li>
</ol>
<p>This architecture is accessible to an industrial SME with modern equipment—an Eziwan industrial router with <a class="" href="https://eziwan.com/en/vpn-industriel">built-in OpenVPN/IPSec VPN</a> and remote access via the Eziwan Cloud platform meets these requirements without requiring complex infrastructure.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="incident-reporting-deadlines-24-hours--72-hours">Incident Reporting Deadlines (24 hours / 72 hours)<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#incident-reporting-deadlines-24-hours--72-hours" class="hash-link" aria-label="Direct link to Incident Reporting Deadlines (24 hours / 72 hours)" title="Direct link to Incident Reporting Deadlines (24 hours / 72 hours)" translate="no">​</a></h2>
<p>NIS2 imposes strict notification deadlines in the event of a significant security incident, defined as an incident that has or is likely to have a significant impact on service continuity.</p>
<p><strong>Initial Notification (Early Warning) — 24 hours</strong>:
Report to ANSSI via the dedicated portal if the incident is likely to have a cross-border impact, if it results from a criminal offense, or if it may affect other entities. This notification should be brief: nature of the incident, affected systems, and estimated initial impact.</p>
<p><strong>Interim Notification — 72 hours</strong>:
A more detailed report including a preliminary assessment of the severity, the probable cause, and the containment measures currently in place.</p>
<p><strong>Final Report — 1 month</strong>:
Complete description of the incident, identified cause, actual impact, corrective actions taken, and measures to prevent recurrence.</p>
<p><strong>Practical Tip</strong>: The time limits begin to run from the moment the company becomes <em>aware</em> of the incident—not from the moment the incident actually began. A ransomware incident discovered 3 weeks after the initial intrusion triggers the timer on the date of discovery, not on the date of the intrusion. Document the timeline of the discovery in detail.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="penalties-up-to-10-m-or-2-of-global-revenue">Penalties: up to 10 M€ or 2% of global revenue<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#penalties-up-to-10-m-or-2-of-global-revenue" class="hash-link" aria-label="Direct link to Penalties: up to 10 M€ or 2% of global revenue" title="Direct link to Penalties: up to 10 M€ or 2% of global revenue" translate="no">​</a></h2>
<p>NIS2 introduces a system of administrative penalties that is significantly stricter than that of NIS1.</p>
<p><strong>Key Provisions</strong>:</p>
<ul>
<li class="">Fines of up to <strong>10 M€</strong> or <strong>2% of total global annual revenue</strong> (whichever is higher)</li>
<li class="">Possible temporary suspension of business operations or executive functions</li>
</ul>
<p><strong>Significant entities</strong>:</p>
<ul>
<li class="">Fines of up to <strong>7 M€</strong> or <strong>1.4% of total global annual revenue</strong></li>
</ul>
<p><strong>Criteria for Determining Penalties</strong>:</p>
<ul>
<li class="">Severity and duration of the violation</li>
<li class="">Whether the violation was intentional or negligent</li>
<li class="">Measures taken to mitigate the damage</li>
<li class="">The entity’s compliance history</li>
<li class="">Cooperation with ANSSI</li>
</ul>
<p>In practice, the first French penalties will likely target large, critical entities before being extended to other significant entities. But the experience with the GDPR shows that enforcement efforts ramp up quickly once the framework is in place.</p>
<p><strong>Liability of Executives</strong>: In the event of a serious violation resulting from gross negligence, NIS2 provides that executives may be personally liable. This provision is a significant new development that elevates cybersecurity to the executive committee level.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="official-resources-anssi-cert-fr">Official Resources (ANSSI, CERT-FR)<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#official-resources-anssi-cert-fr" class="hash-link" aria-label="Direct link to Official Resources (ANSSI, CERT-FR)" title="Direct link to Official Resources (ANSSI, CERT-FR)" translate="no">​</a></h2>
<ul>
<li class=""><strong>ANSSI — NIS2 portal</strong>: <a href="https://www.cert.ssi.gouv.fr/nis2" target="_blank" rel="noopener noreferrer" class="">https://www.cert.ssi.gouv.fr/nis2</a> — scope self-assessment tool, sector-specific guides, compliance timeline</li>
<li class=""><strong>ANSSI — IT Security Best Practices Guide</strong>: a set of 42 basic measures, available for free, a good starting point for SMEs</li>
<li class=""><strong>CERT-FR</strong>: cert-fr.cert.gouv.fr — security bulletins, alerts on critical vulnerabilities, incident reporting (<a href="mailto:signalement@cert.gouv.fr" target="_blank" rel="noopener noreferrer" class="">signalement@cert.gouv.fr</a>)</li>
<li class=""><strong>ANSSI — Industrial Systems Security Guide</strong>: a specific OT/SCADA framework, highly relevant for the manufacturing industry</li>
<li class=""><strong>CNIL and NIS2</strong>: NIS2 compliance complements the GDPR—technical security measures often satisfy both regulations simultaneously</li>
</ul>
<p>For small organizations, ANSSI recommends starting with the CyberDC assessment available at cybermalveillance.gouv.fr, and then prioritizing measures based on the results.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>Is my industrial SME subject to NIS2?</strong>
If you have between 50 and 249 employees (or annual revenue between €10 million and €50 million) and operate in a sector listed in NIS2 (critical manufacturing, water, energy, healthcare, etc.), you are likely a significant entity (SE). Below these thresholds, you are generally not directly subject to the regulation, but your clients (EEs or SEs) may impose contractual security obligations on you. Use the ANSSI self-assessment tool available at cert.ssi.gouv.fr/nis2 to check.</p>
<p><strong>When are the first NIS2 penalties expected in France?</strong>
The French implementation has been in effect since October 2024. ANSSI is initially prioritizing the notification of affected entities and providing support for compliance. The first administrative penalties are expected to be imposed starting in 2026, beginning with large critical entities. SMEs will generally be given a grace period before penalties are imposed.</p>
<p><strong>Does NIS2 cover OT/SCADA systems or only management IT systems?</strong>
NIS2 explicitly applies to OT (Operational Technology), SCADA, ICS, and industrial control systems. ANSSI has published a specific guide titled “Security of Industrial Systems” that describes concrete measures for PLCs, HMIs, SCADA, and OT networks. IT/OT segmentation and securing remote access to PLCs are direct requirements.</p>
<p><strong>Can a single NIS2 incident automatically trigger penalties?</strong>
No. A reporting requirement is not a penalty. The requirement to report an incident to ANSSI within 24 hours does not automatically result in a penalty—it is a procedural requirement. Penalties are imposed in cases of non-compliance with technical and organizational measures (unsecured access, lack of backups, failure to manage vulnerabilities), or in cases of non-cooperation with ANSSI.</p>
<p><strong>How to Demonstrate NIS2 Compliance to ANSSI?</strong>
ANSSI may request documentary evidence: security policies approved by management, security logs, audit results, training plans, and a tested business continuity plan. For critical entities, on-site audits are possible. The best way to prepare is to systematically document your measures starting now: implementation date, person in charge, and results.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/nis2-cybersecurity-industrial-infrastructure">Comprehensive Guide: NIS2 for Industry — Requirements, Penalties, and Action Plan</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/iec-62443-practical-guide">Blog: IEC 62443 — A Practical Guide for French Industry</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/ot-cybersecurity-threats-industry-2026">Blog: OT Cybersecurity — Threats and Incidents in 2026</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/zero-inbound-port-ot-security">Blog: Zero Inbound Ports — Secure OT Network Architecture</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/wireguard-vs-openvpn-industrial-comparison">Blog: Industrial VPNs: WireGuard vs. OpenVPN vs. IPSec</a></li>
</ul>
<hr>
<p><strong>Want to learn more?</strong> Eziwan helps manufacturers secure their OT remote access in accordance with NIS2 requirements: OpenVPN/IPSec VPNs, network segmentation, and no open inbound ports. <a class="" href="https://eziwan.com/en/cybersecurite">Check out our guide to OT cybersecurity</a> or <a class="" href="https://eziwan.com/en/acces-distant-industriel">contact us for an audit of your remote access</a>.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/nis2-compliance-checklist-industry#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/nis2-industrie">NIS2 for Industry</a> — Regulatory Requirements and Applicable Penalties</li>
<li class=""><a class="" href="https://eziwan.com/en/cybersecurite">Industrial Cybersecurity</a> — Protection Solutions for OT Networks</li>
<li class=""><a class="" href="https://eziwan.com/en/cybersecurite-acces-distant-ot">OT Remote Access Cybersecurity</a> — Securing Remote Connections</li>
<li class=""><a class="" href="https://eziwan.com/en/acces-distant-industriel">Industrial Remote Access</a> — NIS2-Compliant Architectures for OT</li>
</ul>]]></content:encoded>
            <category>nis2</category>
            <category>cybersecurity</category>
            <category>compliance</category>
            <category>industry</category>
        </item>
        <item>
            <title><![CDATA[Supervision and Monitoring of Solar Farms: IoT Guide 2026]]></title>
            <link>https://eziwan.com/en/blog/solar-farm-monitoring</link>
            <guid>https://eziwan.com/en/blog/solar-farm-monitoring</guid>
            <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[How to Monitor a Solar Farm Using the IoT: Architecture, Protocols, Predictive Alerts, and 4G Connectivity for Remote Sites.]]></description>
            <content:encoded><![CDATA[<p>France currently has more than 21 GWp of installed photovoltaic capacity, with a target of 100 GWp by 2050. Behind these figures lies an operational reality that is often underestimated: every watt-hour not generated costs money, and without active monitoring, a solar farm consistently leaves potential output on the table.</p>
<p>A short-circuited string, an inverter in silent alert mode, a temperature sensor outside the specified range: these minor incidents go unnoticed for weeks or months without monitoring, resulting in significant cumulative production losses. This guide explains how to set up effective IoT monitoring for a solar power plant, ranging from a 10 kWp industrial rooftop system to a ground-mounted solar field of several megawatts.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="the-hidden-costs-of-an-unmonitored-solar-farm">The Hidden Costs of an Unmonitored Solar Farm<a href="https://eziwan.com/en/blog/solar-farm-monitoring#the-hidden-costs-of-an-unmonitored-solar-farm" class="hash-link" aria-label="Direct link to The Hidden Costs of an Unmonitored Solar Farm" title="Direct link to The Hidden Costs of an Unmonitored Solar Farm" translate="no">​</a></h2>
<p>Failing to monitor a solar farm isn't a cost savings—it's a cost deferral with interest.</p>
<p><strong>Undetected Production Losses</strong>: A partially shaded or soiled cell in a string can reduce that string’s output by 20 to 60 percent, depending on the module technology (with or without power optimizers). In a 500 kWp installation, a faulty string represents a loss of 5,000 to 15,000 kWh per year depending on sunlight exposure, or €600 to €1,800 in lost revenue (at the feed-in tariff or the EPEX spot price).</p>
<p><strong>Undetected Accelerated Degradation</strong>: Photovoltaic modules degrade by an average of 0.5% per year. Certain defects accelerate this degradation: hot spots, delamination, and microcracks caused by hail. If detected early through thermography or IV curve analysis, these defects cost €200–500 per module to repair. If detected late, after 2 or 3 years, they require complete replacement.</p>
<p><strong>Voiding of Manufacturer Warranties</strong>: Most performance warranties for modules (25 years) and inverters (5–10 years) require monitoring of operating conditions. Without time-stamped monitoring data, it is difficult to support a warranty claim.</p>
<p><strong>ENEDIS Non-Compliance</strong>: Energy producers connected to the public grid are subject to metering and reporting requirements. A facility that lacks production data may have its feed-in tariff rights challenged during audits.</p>
<p><strong>Representative figures</strong>: A European study (2023) covering 400 solar farms ranging from 10 kWp to 10 MWp showed that farms without monitoring systems exhibited performance discrepancies of 3 to 8% compared to monitored farms with equivalent characteristics. For a 1 MWp plant producing 1,200 MWh/year, this represents a loss of 36 to 96 MWh, or €3,600 to €14,400 per year, depending on the price of electricity.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="iot-architecture-for-monitoring-a-solar-farm">IoT Architecture for Monitoring a Solar Farm<a href="https://eziwan.com/en/blog/solar-farm-monitoring#iot-architecture-for-monitoring-a-solar-farm" class="hash-link" aria-label="Direct link to IoT Architecture for Monitoring a Solar Farm" title="Direct link to IoT Architecture for Monitoring a Solar Farm" translate="no">​</a></h2>
<p>An effective photovoltaic monitoring architecture is organized into three layers.</p>
<p><strong>Field Layer (Sensors and Equipment)</strong>:</p>
<ul>
<li class="">Inverters: central inverters or micro-inverters, depending on the installation</li>
<li class="">String combiners with per-string measurement</li>
<li class="">Weather station: global horizontal irradiance (GHI), irradiance in the plane of the modules (POA), ambient temperature, module temperature, wind speed and direction</li>
<li class="">ENEDIS production meter (Linky PRO or approved B2B meter)</li>
<li class="">Temperature sensors on DC cables and circuit breaker panels</li>
</ul>
<p><strong>Communication Layer (IoT Gateway)</strong>:</p>
<ul>
<li class="">Local industrial gateway with Modbus RS-485, Modbus TCP, and/or SunSpec interfaces</li>
<li class="">4G LTE connectivity for remote sites or as a backup to fiber</li>
<li class="">Local data storage in the event of a connectivity outage (store-and-forward)</li>
<li class="">Local data preprocessing (aggregation, calculation of performance metrics)</li>
</ul>
<p><strong>Cloud Layer (Monitoring and Analytics)</strong>:</p>
<ul>
<li class="">Real-time monitoring dashboard</li>
<li class="">Historical production and performance data</li>
<li class="">Alert and notification engine</li>
<li class="">Production reports for operators and investors</li>
<li class="">API for exporting data to accounting systems or energy aggregators</li>
</ul>
<p>For an industrial rooftop installation of less than 36 kWp, the system architecture can be simplified: a single inverter with a built-in communication interface, a 4G gateway with Modbus RTU, and a SaaS monitoring platform.</p>
<p>For a 1 MWp ground-mounted solar farm, the complexity increases: multiple distribution boxes, a dedicated weather station, a separate ENEDIS meter, and potentially an industrial Ethernet subnetwork between the gateway and the equipment.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="communication-protocols-modbus-sunspec-the-solar-industry-standard">Communication Protocols: Modbus SunSpec, the solar industry standard<a href="https://eziwan.com/en/blog/solar-farm-monitoring#communication-protocols-modbus-sunspec-the-solar-industry-standard" class="hash-link" aria-label="Direct link to Communication Protocols: Modbus SunSpec, the solar industry standard" title="Direct link to Communication Protocols: Modbus SunSpec, the solar industry standard" translate="no">​</a></h2>
<p>The photovoltaic industry has adopted the <strong>SunSpec Alliance</strong> as its interoperability standard. SunSpec defines standardized data models implemented over Modbus TCP (port 502) or Modbus RTU (RS-485).</p>
<p><strong>Why SunSpec Is Important</strong>: Before SunSpec, each inverter manufacturer had its own proprietary Modbus registry. Integrating SMA, Huawei, SolarEdge, Fronius, and Sungrow inverters into a single monitoring system required as many drivers as there were brands. SunSpec standardizes the addresses and format of essential data.</p>
<p><strong>The main SunSpec models</strong>:</p>
<ul>
<li class="">Model 1: Common (equipment identification, firmware version)</li>
<li class="">Model 101/102/103: Single/Split/Three-Phase Inverter (AC power, voltage, current, frequency, energy generated, alarms)</li>
<li class="">Model 160: Multiple MPPT Extension (data per MPPT tracker)</li>
<li class="">Model 307/308: Weather Station (irradiance, temperature)</li>
<li class="">Model 801–810: String Combiner (voltage, current, power per string)</li>
</ul>
<p>In practice, SunSpec implementation varies by manufacturer and firmware version. Always check the list of supported SunSpec models in the inverter documentation, and test register reads before deployment.</p>
<p><strong>Alternatives</strong>: For inverters that do not support SunSpec, proprietary protocols are available via RS-485 or through manufacturer apps (SMA Sunny Portal, Huawei FusionSolar, SolarEdge Monitoring). These solutions are functional but create a dependency on the manufacturer’s cloud, which can be problematic for data sovereignty and service continuity.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="key-data-to-collect-strings-inverters-weather-meters">Key Data to Collect (strings, inverters, weather, meters)<a href="https://eziwan.com/en/blog/solar-farm-monitoring#key-data-to-collect-strings-inverters-weather-meters" class="hash-link" aria-label="Direct link to Key Data to Collect (strings, inverters, weather, meters)" title="Direct link to Key Data to Collect (strings, inverters, weather, meters)" translate="no">​</a></h2>
<p>A monitoring system must collect data at levels of detail and frequencies appropriate for each use case.</p>
<p><strong>Inverter Data (every 1 to 5 minutes)</strong>:</p>
<ul>
<li class="">Instantaneous AC power (W or kW)</li>
<li class="">Energy generated: daily / monthly / total (kWh)</li>
<li class="">DC voltage and current per MPPT</li>
<li class="">AC voltage and current per phase</li>
<li class="">Grid frequency</li>
<li class="">Internal inverter temperature</li>
<li class="">Status code and active alarm codes</li>
</ul>
<p><strong>String data (every 5 to 15 minutes)</strong>:</p>
<ul>
<li class="">DC voltage and current per string</li>
<li class="">Calculated power per string</li>
<li class="">Ratio relative to the reference string (anomaly score)</li>
</ul>
<p><strong>Weather Station (every 1 to 5 minutes)</strong>:</p>
<ul>
<li class="">Irradiance in the plane of the modules (W/m²) — POA pyranometer sensor</li>
<li class="">Ambient temperature (°C)</li>
<li class="">Module temperature (°C) — Pt100 or NTC sensor on reference cell</li>
<li class="">Wind speed (m/s) — for estimating cooling effects and detecting snow</li>
</ul>
<p><strong>Generation Meter (every 15 minutes)</strong>:</p>
<ul>
<li class="">Active energy fed into the grid (kWh) — ENEDIS billing reading</li>
<li class="">Instantaneous active power (kW)</li>
<li class="">Power factor (for power ratings &gt; 3 kWp connected to a three-phase system)</li>
</ul>
<p><strong>Calculated Metrics (Performance Ratio, PR)</strong>:
The Performance Ratio is the fundamental KPI for a PV plant. It is calculated as the ratio of the energy actually generated to the energy that could theoretically be generated under the same irradiance conditions. A PR of 80% is typical for a well-maintained installation in France. A PR below 75% should prompt an investigation.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="predictive-alerts-detecting-clogging-and-deterioration-before-loss-occurs">Predictive Alerts: Detecting Clogging and Deterioration Before Loss Occurs<a href="https://eziwan.com/en/blog/solar-farm-monitoring#predictive-alerts-detecting-clogging-and-deterioration-before-loss-occurs" class="hash-link" aria-label="Direct link to Predictive Alerts: Detecting Clogging and Deterioration Before Loss Occurs" title="Direct link to Predictive Alerts: Detecting Clogging and Deterioration Before Loss Occurs" translate="no">​</a></h2>
<p>Real-time alerts flag failures that have already occurred. Predictive alerts allow for intervention before production losses become significant.</p>
<p><strong>Soiling Detection</strong></p>
<p>Gradual soiling of the modules is often the primary cause of underperformance in solar farms located in agricultural areas, near roads, or in semi-arid regions. Detection is based on monitoring the <strong>Soiling Index</strong>:</p>
<p><em>Soiling Index = Measured PR / Reference PR for Clean Modules</em></p>
<p>When the Soiling Index falls below 0.97 (a 3% loss), cleaning is economically justified in most scenarios. For a 1 MWp installation, a 3% loss represents approximately 36 MWh/year, or €3,600 to €7,200 depending on the price of electricity—the cost of professional cleaning is generally €0.01 to €0.02/Wp.</p>
<p><strong>String-Based Anomaly Detection</strong></p>
<p>Comparing strings with the same orientation, tilt, and number of modules makes it possible to detect anomalies:</p>
<ul>
<li class="">A string with a voltage 15% below the median of similar strings warrants investigation (partial shading, loose connection, faulty module)</li>
<li class="">A string at 0 V and 0 A indicates an open circuit (fuse, connector, cable)</li>
<li class="">A string with normal voltage but low current suggests an open cell or an activated bypass diode</li>
</ul>
<p><strong>Detection of Gradual Drift</strong></p>
<p>A 30- or 90-day trend analysis normalized by irradiance can detect a gradual decline of 1 to 2 percent below the normal annual rate, which is an indicator of accelerated aging (hot spots, microcracks).</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="4g-lte-connectivity-for-off-grid-solar-farms">4G LTE Connectivity for Off-Grid Solar Farms<a href="https://eziwan.com/en/blog/solar-farm-monitoring#4g-lte-connectivity-for-off-grid-solar-farms" class="hash-link" aria-label="Direct link to 4G LTE Connectivity for Off-Grid Solar Farms" title="Direct link to 4G LTE Connectivity for Off-Grid Solar Farms" translate="no">​</a></h2>
<p>The vast majority of ground-mounted solar farms are located in rural areas or on the plains, far from urbanized areas. Wired connectivity (fiber, ADSL) is often unavailable or not economically feasible for the small amount of daily data generated by a modest-sized solar farm.</p>
<p><strong>4G LTE connectivity</strong> is the standard solution for the vast majority of installations:</p>
<p><strong>Advantages</strong>:</p>
<ul>
<li class="">Nationwide coverage of over 98% in France (Orange, SFR, Bouygues)</li>
<li class="">Deployment requires no civil engineering work</li>
<li class="">Low monthly cost (€5 to €30 for an M2M SIM with low data usage)</li>
<li class="">Failover possible with a secondary SIM from another carrier</li>
</ul>
<p><strong>Recommended Architecture</strong>:</p>
<ul>
<li class="">Industrial gateway housed in an on-site communications cabinet, powered by the facility’s AC grid (or via battery + dedicated solar panels if an independent power supply is desired)</li>
<li class="">External LTE antenna with low cable loss (LMR-240 cable or equivalent, max. 3 m between antenna and gateway)</li>
<li class="">M2M SIM on a private APN to isolate the park’s traffic from the public network</li>
</ul>
<p><strong>Bandwidth Sizing</strong>: For a 1 MWp solar farm with 20 inverters and a weather station, data collected every 5 minutes amounts to approximately 200–500 MB per month, which is easily covered by a 1 GB/month M2M plan.</p>
<p><strong>Store and forward</strong>: The gateway must store data locally in the event of a loss of connectivity (carrier network maintenance, weather-related incident) and automatically transmit it when connectivity is restored. A local history of at least 72 hours is recommended.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="enedis-compliance-and-generation-metering">ENEDIS Compliance and Generation Metering<a href="https://eziwan.com/en/blog/solar-farm-monitoring#enedis-compliance-and-generation-metering" class="hash-link" aria-label="Direct link to ENEDIS Compliance and Generation Metering" title="Direct link to ENEDIS Compliance and Generation Metering" translate="no">​</a></h2>
<p>Facilities connected to the French public grid are subject to the metering requirements defined by ENEDIS in its <em>Technical Connection Specifications</em> (PTR).</p>
<p><strong>Generation Meter</strong>:</p>
<ul>
<li class="">For single-phase or three-phase installations ≤ 36 kVA: a Linky meter or approved equivalent, read by ENEDIS.</li>
<li class="">For installations &gt; 36 kVA: an approved remote-reading meter with a communication interface (IEC 62056, Modbus TCP, or M-Bus, depending on the version), read by ENEDIS or via self-reported readings.</li>
</ul>
<p><strong>Load Curve</strong>:
Producers subject to the purchase obligation with a capacity greater than 36 kVA must provide ENEDIS with load curves at 10-minute intervals. This requirement necessitates a local metering system with data storage and automatic transmission.</p>
<p><strong>ENEDIS Interface for Self-Consumption</strong>:
For self-consumption systems that sell surplus energy, the ENEDIS meter simultaneously measures both feed-in and consumption. The IoT monitoring system can retrieve this data via the ENEDIS API (Metering Data Access Feed) to integrate it into the dashboard.</p>
<p><strong>Purchase Agreement</strong>:
Production data is generally self-reported or recorded by the operator, depending on the type of agreement. Monitoring data with a time-stamped history serves as supporting documentation in the event of a dispute over production volumes.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="typical-roi-for-a-solar-monitoring-system">Typical ROI for a Solar Monitoring System<a href="https://eziwan.com/en/blog/solar-farm-monitoring#typical-roi-for-a-solar-monitoring-system" class="hash-link" aria-label="Direct link to Typical ROI for a Solar Monitoring System" title="Direct link to Typical ROI for a Solar Monitoring System" translate="no">​</a></h2>
<p>Investing in a monitoring system is justified for installed capacity of approximately 10 kWp or more, depending on the value of the energy and the type of sales contract.</p>
<p><strong>Typical Costs of a Monitoring System (2026)</strong>:</p>
<ul>
<li class="">Lightweight SaaS solution for installations ≤ 100 kWp: €300–800 installation fee + €15–50/month subscription fee</li>
<li class="">Professional solution for a 100 kWp–1 MWp array: €1,500–5,000 installation fee + €50–200/month</li>
<li class="">Operator solution for installations &gt; 1 MWp with a dedicated weather station: €5,000–20,000 installation fee + €200–800/month</li>
</ul>
<p><strong>Quantifiable Benefits</strong>:</p>
<ul>
<li class="">Early detection of anomalies: 1.5% to 3% increase in production (conservative range based on available studies)</li>
<li class="">Reduction in unnecessary preventive maintenance interventions (scheduling based on actual performance rather than a fixed schedule)</li>
<li class="">Optimization of cleaning schedules: 0.5 to 1% additional production</li>
<li class="">Reasonably documented total gain: <strong>2 to 4% of annual production</strong></li>
</ul>
<p><strong>Simplified calculation for a 200 kWp system</strong>:</p>
<ul>
<li class="">Typical annual production: 200 kWp × 1,100 h/year = 220,000 kWh</li>
<li class="">Monitoring benefit: 2.5%: 5,500 kWh × 0.10 €/kWh = <strong>550 €/year</strong></li>
<li class="">Monitoring cost for 200 kWp: ~100 €/month = 1,200 €/year</li>
<li class="">Result: neutral in terms of direct savings, but offset by the value of preserved warranties, ENEDIS compliance, and a reduction in emergency service calls.</li>
</ul>
<p><strong>For a 1 MWp plant</strong>, the calculation clearly shows a positive result: monitoring savings of 2.5% × 1,100 MWh = 27.5 MWh, or €2,750 to €5,500 depending on the price of electricity, for an annual monitoring cost of €2,400 to €9,600. The ROI is achieved in 1 to 2 years for most projects.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="example-of-an-eziwan-architecture-for-a-solar-farm">Example of an Eziwan architecture for a solar farm<a href="https://eziwan.com/en/blog/solar-farm-monitoring#example-of-an-eziwan-architecture-for-a-solar-farm" class="hash-link" aria-label="Direct link to Example of an Eziwan architecture for a solar farm" title="Direct link to Example of an Eziwan architecture for a solar farm" translate="no">​</a></h2>
<p>The typical architecture of a solar monitoring system covers the entire chain, from the string to the dashboard:</p>
<p><strong>Inverters and trackers (Modbus SunSpec, RS-485) + energy meter + weather station → Eziwan industrial 4G gateway → multi-carrier M2M SIM card → outbound VPN tunnel → Eziwan cloud → performance ratio, low-output alerts, and remote access to inverters.</strong></p>
<p>In a ground-mounted solar farm, the gateway is powered by the auxiliary network at the delivery substation and operates completely autonomously: no telecom infrastructure needs to be installed, and no network intervention is required on the operator’s end. Remote access allows O&amp;M teams to diagnose a faulty inverter before dispatching a field crew—often the difference between a 2-hour and a 2-day loss of production.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="checklist-for-implementing-supervision-of-an-existing-fleet">Checklist for Implementing Supervision of an Existing Fleet<a href="https://eziwan.com/en/blog/solar-farm-monitoring#checklist-for-implementing-supervision-of-an-existing-fleet" class="hash-link" aria-label="Direct link to Checklist for Implementing Supervision of an Existing Fleet" title="Direct link to Checklist for Implementing Supervision of an Existing Fleet" translate="no">​</a></h2>
<ol>
<li class=""><strong>Inventory of inverters</strong>: brands, models, firmware versions, and availability of the SunSpec Modbus profile.</li>
<li class=""><strong>Audit of the existing RS-485 bus</strong>: topology, length, terminations—the number one cause of missing data.</li>
<li class=""><strong>Connectivity selection</strong>: multi-carrier M2M SIM (fleets are almost always in rural areas), outdoor antenna if the delivery station is made of metal.</li>
<li class=""><strong>Definition of KPIs</strong>: expected performance ratio per string, under-production alert thresholds, inverter availability.</li>
<li class=""><strong>Metering connection</strong>: consistency between production measured at the inverters and energy metered at the delivery point.</li>
<li class=""><strong>Alerts and O&amp;M on-call duty</strong>: Routing of critical alarms (inverter failure, loss of communication) to the operations team.</li>
</ol>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/solar-farm-monitoring#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>Can Enphase, SMA, Fronius, and ABB inverters be monitored using a single gateway?</strong>
Yes, provided that the inverters expose their data via Modbus TCP or SunSpec. SMA (SunSpec Modbus), ABB (Modbus TCP), Fronius (Modbus TCP SunSpec), and certain Enphase models via their local gateway are compatible. Eziwan offers preconfigured profiles for common brands, reducing the initial setup time to just a few hours.</p>
<p><strong>Does the gateway work on a non-fiber network—4G only?</strong>
This is the most common deployment scenario for ground-based stations or industrial rooftops located far from urban centers: the built-in 4G LTE gateway connects directly via the mobile network. For solar farms in rural areas, the Dual SIM ensures uninterrupted data transmission even if one carrier’s service goes down.</p>
<p><strong>What is the minimum data collection frequency required to detect a failure in real time?</strong>
For rapid detection of a string with no power: every 5 minutes is sufficient. For calculating the Performance Ratio: every 15 minutes. For ENEDIS compliance (10-minute production curves): every 10 minutes. The Eziwan gateway allows you to configure different sampling frequencies for each variable based on its importance.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/solar-farm-monitoring#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/grafana-industrial-monitoring-modbus">Blog: Grafana for Modbus Industrial Monitoring — Dashboards and Alerts</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/predictive-maintenance-iot-field-sensors">Blog: IIoT Predictive Maintenance — From Sensor Data to Alerts</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/industrial-iot-roi-calculation">Blog: ROI of Industrial IoT — Calculation and Optimization</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/modbus-mqtt-opcua-industrial-protocols">Blog: Modbus, MQTT, OPC-UA — Comparison of Industrial Protocols</a></li>
</ul>
<hr>
<p><strong>Want to learn more?</strong> Eziwan offers IoT monitoring solutions for solar farms, from small industrial rooftops to large ground-mounted plants. <a class="" href="https://eziwan.com/en/supervision-energetique">Discover our energy monitoring solutions</a> or <a class="" href="https://eziwan.com/en/telereleve-compteurs">contact us for a quote tailored to your installation</a>.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/solar-farm-monitoring#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/supervision-photovoltaique-iot">IoT Solar Monitoring</a> — real-time monitoring of solar power generation</li>
<li class=""><a class="" href="https://eziwan.com/en/solution-energie-renouvelable">Renewable Energy Solution</a> — IoT monitoring of renewable energy installations</li>
<li class=""><a class="" href="https://eziwan.com/en/supervision-energetique">Energy Monitoring</a> — dashboard for monitoring energy consumption and production</li>
<li class=""><a class="" href="https://eziwan.com/en/generator-monitoring">Generator Monitoring</a> — remote monitoring of backup generators</li>
<li class=""><a class="" href="https://eziwan.com/en/solution-energie-infrastructures">Energy &amp; Infrastructure Solution</a> — monitoring of critical energy infrastructure</li>
</ul>]]></content:encoded>
            <category>renewable-energy</category>
            <category>supervision</category>
            <category>iot</category>
            <category>photovoltaic</category>
        </item>
        <item>
            <title><![CDATA[Private 5G in Factories by 2026: When Is It Really Worth the Cost?]]></title>
            <link>https://eziwan.com/en/blog/5g-private-network-factory</link>
            <guid>https://eziwan.com/en/blog/5g-private-network-factory</guid>
            <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Private 5G Networks in Factories: Use Cases, Actual Costs, Deployment Timelines, and When to Stick with 4G LTE. 2026 Guide.]]></description>
            <content:encoded><![CDATA[<p>Industrial 5G has been the subject of extensive discussion since 2020: ultra-low latency, revolutionary data rates, the connection of millions of sensors, and the digital transformation of factories. In 2026, the reality is more nuanced. Yes, 5G delivers on its technical promises when deployed correctly. No, it does not replace 4G LTE for the majority of current industrial use cases. And no, a private 5G network cannot be deployed for 50,000 euros.</p>
<p>This guide provides an honest assessment of what 5G will actually bring to the industry in 2026, in which cases it is justified, and how to determine whether your project is one that can benefit from it.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="industrial-5g-the-real-promise-latency--5-ms-data-rate-10-gbps-1-million-deviceskm">Industrial 5G: The Real Promise (latency &lt; 5 ms, data rate 10 Gbps, 1 million devices/km²)<a href="https://eziwan.com/en/blog/5g-private-network-factory#industrial-5g-the-real-promise-latency--5-ms-data-rate-10-gbps-1-million-deviceskm" class="hash-link" aria-label="Direct link to Industrial 5G: The Real Promise (latency < 5 ms, data rate 10 Gbps, 1 million devices/km²)" title="Direct link to Industrial 5G: The Real Promise (latency < 5 ms, data rate 10 Gbps, 1 million devices/km²)" translate="no">​</a></h2>
<p>The 5G NR (New Radio) specifications define three usage profiles that address distinct needs:</p>
<p><strong>eMBB (Enhanced Mobile Broadband)</strong>: Theoretical speeds of up to 10 Gbps, typically 1 to 4 Gbps under real-world conditions with a properly sized private network. Useful for real-time HD video, augmented reality applications, and massive firmware updates.</p>
<p><strong>URLLC (Ultra-Reliable Low-Latency Communications)</strong>: Guaranteed latency of less than 1 ms for critical real-time control applications (cobot control, closed-loop control). This is the most difficult feature to deploy—it requires a 5G SA (Standalone) architecture and a dense radio infrastructure.</p>
<p><strong>mMTC (Massive Machine Type Communications)</strong>: up to 1 million connections per km², suitable for large-scale sensor deployments. In industrial practice, factories that approach these densities are rare.</p>
<p>We need to distinguish between two architectures:</p>
<ul>
<li class=""><strong>5G NSA (Non-Standalone)</strong>: Relys on the existing 4G core network with a 5G radio layer. Primarily improves data throughput but does not deliver URLLC-level latency. This is what Orange, SFR, and Bouygues are currently deploying on their public networks.</li>
<li class=""><strong>5G SA (Standalone)</strong>: Native 5G core network (5GC), essential for network slices, sub-millisecond latency, and MEC (Multi-access Edge Computing) functions. This is the architecture used for private industrial networks.</li>
</ul>
<p>In 2026, 5G SA deployments in French industry remain concentrated in a limited number of pilot sites and large-scale installations. The equipment ecosystem (industrial 5G terminals, sensors, and controllers) is still maturing.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="use-cases-that-truly-justify-5g">Use Cases That Truly Justify 5G<a href="https://eziwan.com/en/blog/5g-private-network-factory#use-cases-that-truly-justify-5g" class="hash-link" aria-label="Direct link to Use Cases That Truly Justify 5G" title="Direct link to Use Cases That Truly Justify 5G" translate="no">​</a></h2>
<p>5G is justified when at least one of these three factors is present: critical real-time latency, extreme connection density, or very high mobile data rates.</p>
<p><strong>Autonomous Guided Vehicles (AGVs / AMRs)</strong>: Dense fleets of AGVs require real-time coordination and seamless coverage across the entire factory floor. 5G offers seamless handover (&lt; 1 ms), which Wi-Fi cannot guarantee during rapid movement. A fleet of 50+ AGVs is a strong use case for 5G.</p>
<p><strong>Cobots and Collaborative Robotics</strong>: A cobot’s closed-loop control systems (emergency stop, collision detection) require latencies of less than 5 ms. This requirement can be met with 5G SA URLLC, but not with 4G (typical latency: 10–30 ms).</p>
<p><strong>Augmented Reality and Remote Technical Support</strong>: AR headsets (Microsoft HoloLens, Magic Leap) or smart glasses (RealWear) used for maintenance support or training require high symmetrical throughput (&gt;100 Mbps) and low latency to provide an acceptable user experience. 5G eMBB meets this need.</p>
<p><strong>Real-time machine vision</strong>: quality inspection using high-resolution cameras with on-edge MEC processing. The uplink bandwidth required for multi-camera 4K video streams exceeds the effective capacity of 4G LTE Cat 16.</p>
<p><strong>Remote Control of Hazardous Machinery</strong>: Remote operation of construction equipment, robots in ATEX zones, or cutting machines with video feedback. 5G reduces perceived latency to a level that makes operation intuitive.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="why-4g-lte-will-still-meet-80-of-industrial-needs-in-2026">Why 4G LTE Will Still Meet 80% of Industrial Needs in 2026<a href="https://eziwan.com/en/blog/5g-private-network-factory#why-4g-lte-will-still-meet-80-of-industrial-needs-in-2026" class="hash-link" aria-label="Direct link to Why 4G LTE Will Still Meet 80% of Industrial Needs in 2026" title="Direct link to Why 4G LTE Will Still Meet 80% of Industrial Needs in 2026" translate="no">​</a></h2>
<p>Despite the enthusiasm surrounding 5G, the reality of industrial projects in France in 2026 is that 4G LTE remains the standard technology for the vast majority of deployments.</p>
<p>The reasons are technical and economic:</p>
<p><strong>Traditional remote monitoring doesn't need anything more</strong>: Retrieving Modbus readings every 5 seconds from about ten sensors results in an average data rate of 1 to 5 kbps. 4G LTE Cat 1 (10 Mbps downlink) is overkill for this need. 5G is unnecessary.</p>
<p><strong>4G latencies are sufficient for 90% of SCADA applications</strong>: monitoring a pumping station, remotely managing an electrical distribution network, or monitoring a photovoltaic system all work perfectly with 4G latencies (10–50 ms). An alarm that is transmitted in 50 ms versus 5 ms has no operational impact.</p>
<p><strong>The industrial 4G ecosystem is mature and robust</strong>: hundreds of models of industrial 4G routers, gateways, and modems are available, backed by years of real-world experience. The industrial 5G ecosystem is still in its early years of mass production.</p>
<p><strong>The cost-benefit ratio does not shift in the other direction unless there are very specific requirements</strong>: as long as you do not have latency constraints below 10 ms, high-density mobility, or data rates exceeding 150 Mbps, 4G LTE is the best investment.</p>
<p>The right approach in 2026 is to pinpoint the few processes that actually require 5G, and to stick with 4G for everything else.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="private-5g-networks-architecture-equipment-and-partner-operators-in-france">Private 5G Networks: Architecture, Equipment, and Partner Operators in France<a href="https://eziwan.com/en/blog/5g-private-network-factory#private-5g-networks-architecture-equipment-and-partner-operators-in-france" class="hash-link" aria-label="Direct link to Private 5G Networks: Architecture, Equipment, and Partner Operators in France" title="Direct link to Private 5G Networks: Architecture, Equipment, and Partner Operators in France" translate="no">​</a></h2>
<p>A private 5G network in a factory is a cellular infrastructure deployed on-site and dedicated to a single organization. There are two main models:</p>
<p><strong>Dedicated private 5G network</strong>: dedicated radio spectrum (3.4–3.8 GHz band, allocated by ANFR), RAN equipment (base stations), and core network installed on-site. The company operates its own network. This is the most efficient—and most expensive—model.</p>
<p><strong>Operator 5G Network Slice</strong>: An operator’s public network (Orange, SFR, Bouygues) is segmented to create a dedicated slice for the enterprise, with a guaranteed SLA. Lower initial investment, but dependence on the operator’s coverage and slightly higher latency than a dedicated network.</p>
<p>RAN (Radio Access Network) equipment for private 5G networks is primarily supplied by:</p>
<ul>
<li class=""><strong>Ericsson</strong> (Private 5G / CBRS solution)</li>
<li class=""><strong>Nokia</strong> (Digital Automation Cloud)</li>
<li class=""><strong>Atos / Bull</strong> (partnerships with operators in France)</li>
<li class=""><strong>CBRS vendors</strong>: for deployments on shared spectrum (less relevant in Europe than in the United States)</li>
</ul>
<p>In France, operators offer private 5G network solutions:</p>
<ul>
<li class=""><strong>Orange Business</strong>: Campus Networks, deployments in partnership with Ericsson or Nokia</li>
<li class=""><strong>SFR Business</strong>: private 5G offering with integrated MEC</li>
<li class=""><strong>Bouygues Telecom Entreprises</strong>: specific industry partnerships</li>
</ul>
<p>Deploying a dedicated private network requires submitting an application to ANFR for authorization to use frequencies in the 3.4–3.8 GHz band. Specific frequency bands have been reserved for private networks since ARCEP’s decision in 2020.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="actual-cost-of-a-private-5g-deployment-2026-budget-ranges">Actual Cost of a Private 5G Deployment (2026 Budget Ranges)<a href="https://eziwan.com/en/blog/5g-private-network-factory#actual-cost-of-a-private-5g-deployment-2026-budget-ranges" class="hash-link" aria-label="Direct link to Actual Cost of a Private 5G Deployment (2026 Budget Ranges)" title="Direct link to Actual Cost of a Private 5G Deployment (2026 Budget Ranges)" translate="no">​</a></h2>
<p>Cost is often the deciding factor. Here are some realistic cost ranges for 2026, based on actual deployments in Europe:</p>
<p><strong>Private 5G (Standalone) Network for a 10,000 m² Factory</strong></p>
<ul>
<li class="">RAN equipment (4 to 8 indoor antennas): €150,000 – €300,000</li>
<li class="">5G core network (edge or cloud): €80,000 – €200,000</li>
<li class="">Integration, installation, and commissioning: €50,000 – €150,000</li>
<li class=""><strong>Total initial investment: 280,000 – 650,000 €</strong></li>
<li class="">Annual maintenance (software, support): 40,000 – 80,000 €/year</li>
</ul>
<p><strong>Private 5G SA Network for a Large Factory (50,000 m²)</strong></p>
<ul>
<li class="">RAN equipment (20 to 40 antennas): €500,000 – €1,200,000</li>
<li class="">5G core network: €150,000 – €400,000</li>
<li class="">Integration and engineering: €200,000 – €500,000</li>
<li class=""><strong>Total initial investment: €850,000 – €2,100,000</strong></li>
</ul>
<p><strong>5G Network Slicing (Carrier)</strong></p>
<ul>
<li class="">Monthly contract: 5,000–25,000 €/month depending on the SLA and guaranteed bandwidth</li>
<li class="">CPE (Customer Premises Equipment): €10,000 – €50,000</li>
<li class=""><strong>Total over 5 years: €350,000 – €1,550,000</strong></li>
</ul>
<p>These figures explain why the market for private 5G networks in Europe is still concentrated among large industrial companies (automotive, chemical, and energy) with large-scale sites and use cases that have demonstrated a high ROI.</p>
<p>For a 5,000 m² manufacturing facility with standard monitoring requirements, 4G LTE remains the rational choice in 2026 in the vast majority of cases.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="5g-vs-wi-fi-6e-in-the-factory-the-right-choice-depending-on-the-use-case">5G vs. Wi-Fi 6E in the Factory: The Right Choice Depending on the Use Case<a href="https://eziwan.com/en/blog/5g-private-network-factory#5g-vs-wi-fi-6e-in-the-factory-the-right-choice-depending-on-the-use-case" class="hash-link" aria-label="Direct link to 5G vs. Wi-Fi 6E in the Factory: The Right Choice Depending on the Use Case" title="Direct link to 5G vs. Wi-Fi 6E in the Factory: The Right Choice Depending on the Use Case" translate="no">​</a></h2>
<p>Before comparing 5G and Wi-Fi 6E, it’s important to recognize that these are two complementary technologies—not necessarily competitors in every case.</p>
<table><thead><tr><th>Criterion</th><th>Private 5G SA</th><th>Wi-Fi 6E</th></tr></thead><tbody><tr><td>Latency</td><td>&lt; 1 ms (URLLC)</td><td>2–5 ms</td></tr><tr><td>Actual maximum data rate</td><td>2–4 Gbps</td><td>1–2 Gbps</td></tr><tr><td>Mobile coverage</td><td>Excellent (seamless handover)</td><td>Challenging beyond the cell</td></tr><tr><td>Connection density</td><td>1 M/km²</td><td>~500 devices/AP in practice</td></tr><tr><td>Infrastructure cost</td><td>Very high (300 K€+)</td><td>Low (10 K€ for an average factory)</td></tr><tr><td>Interference with existing networks</td><td>None (dedicated spectrum)</td><td>Risk (6 GHz coexistence)</td></tr><tr><td>Native security</td><td>SIM-based, L1 encryption</td><td>WPA3, depends on configuration</td></tr><tr><td>Available devices</td><td>Ecosystem under development</td><td>Very broad (tablets, laptops, sensors)</td></tr></tbody></table>
<p><strong>Choose Wi-Fi 6E</strong> for applications where devices move slowly or not at all (field service tablets, warehouse picking terminals), where Wi-Fi devices are widely available, and where the infrastructure budget is limited.</p>
<p><strong>Choose 5G</strong> for high-speed AGVs, collaborative robotics, URLLC applications, and deployments where SIM-based security is a requirement.</p>
<p><strong>Combine the two</strong> in large factories: 5G for critical robotic cells, Wi-Fi 6E for connected tools and operator terminals.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="decision-tree-4g-lte-wi-fi-6e-or-private-5g">Decision Tree: 4G LTE, Wi-Fi 6E, or Private 5G?<a href="https://eziwan.com/en/blog/5g-private-network-factory#decision-tree-4g-lte-wi-fi-6e-or-private-5g" class="hash-link" aria-label="Direct link to Decision Tree: 4G LTE, Wi-Fi 6E, or Private 5G?" title="Direct link to Decision Tree: 4G LTE, Wi-Fi 6E, or Private 5G?" translate="no">​</a></h2>
<p>Before committing to a 5G budget, review this decision tree:</p>
<div class="language-text codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_QJqH"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar" style="color:#393A34;background-color:#f6f8fa"><code class="codeBlockLines_e6Vv"><div class="token-line" style="color:#393A34"><span class="token plain">Do you have AGVs or mobile robots that require uniform coverage while in motion?</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">├── YES → 5G (or Wi-Fi 6E with roaming) is relevant</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│   ├── Vitesse &gt; 10 km/h ou latence &lt; 5 ms requise → 5G SA URLLC</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">│   └── Vitesse &lt; 10 km/h et latence 5–15 ms suffisante → Wi-Fi 6E</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">└── NON</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    ├── Do you have any devices that require more than 100 Mbps while on the go?</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    │   ├── YES → 5G eMBB or Wi-Fi 6E if mobility is low</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    │   └── NON</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    │       ├── Avez-vous des contraintes de latence &lt; 10 ms critiques (cobots, arrêts d'urgence) ?</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    │       │   ├── OUI → 5G SA URLLC obligatoire</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    │       │   └── NON</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    │       │       ├── Do you have more than 500 IoT sensors in a single 1,000 m² area?</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    │       │       │   ├── OUI → 5G mMTC (rare en pratique industrielle)</span><br></div><div class="token-line" style="color:#393A34"><span class="token plain">    │       │       │   └── NO → 4G LTE meets your needs. Stay on 4G.</span><br></div></code></pre></div></div>
<p><strong>The vast majority of factories fall into the "NO" category for each question</strong> — and the conclusion is consistently "4G LTE is sufficient." This is a fact that 5G salespeople often fail to mention.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="guaranteed-slas-what-private-5g-contracts-mention-and-what-they-leave-out">Guaranteed SLAs: What Private 5G Contracts Mention (and What They Leave Out)<a href="https://eziwan.com/en/blog/5g-private-network-factory#guaranteed-slas-what-private-5g-contracts-mention-and-what-they-leave-out" class="hash-link" aria-label="Direct link to Guaranteed SLAs: What Private 5G Contracts Mention (and What They Leave Out)" title="Direct link to Guaranteed SLAs: What Private 5G Contracts Mention (and What They Leave Out)" translate="no">​</a></h2>
<p>Private 5G network contracts typically include SLAs (Service Level Agreements) based on the following metrics. Here’s what these guarantees are really worth:</p>
<table><thead><tr><th>SLA Metric</th><th>What Is Guaranteed</th><th>What Is Not Guaranteed</th></tr></thead><tbody><tr><td><strong>Network Availability</strong></td><td>99.9% (87 min/year downtime)</td><td>End-user device availability</td></tr><tr><td><strong>Latency</strong></td><td>"Optimized for URLLC" (&lt; 5 ms in areas with high radio density)</td><td>End-to-end application latency</td></tr><tr><td><strong>Throughput</strong></td><td>"Up to X Gbps" (peak throughput, not guaranteed)</td><td>Minimum throughput guaranteed per terminal</td></tr><tr><td><strong>Recovery time</strong></td><td>4–8 hours (network incidents)</td><td>Impact on your production</td></tr><tr><td><strong>Penalties</strong></td><td>Credits on monthly invoice</td><td>Compensation for your production loss</td></tr></tbody></table>
<p><strong>What is often missing from contracts</strong>: The URLLC latency guarantee (&lt; 1 ms) is contingent on a full 5G SA architecture with dense radio infrastructure. On a 5G NSA network or one with insufficient radio infrastructure, this latency cannot be achieved.</p>
<p>Before signing, make sure to specify: the guaranteed distance between antennas on your property, the minimum number of UEs supported simultaneously, and the termination conditions if the SLAs are not met after 3 months.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="how-to-prepare-your-infrastructure-for-5g-today">How to Prepare Your Infrastructure for 5G Today<a href="https://eziwan.com/en/blog/5g-private-network-factory#how-to-prepare-your-infrastructure-for-5g-today" class="hash-link" aria-label="Direct link to How to Prepare Your Infrastructure for 5G Today" title="Direct link to How to Prepare Your Infrastructure for 5G Today" translate="no">​</a></h2>
<p>Even if your 5G project is 2 or 3 years away, the architectural decisions made today will determine how easy and how costly the migration will be.</p>
<p><strong>Adopt an edge architecture now</strong>: A local industrial gateway capable of hosting applications could support 5G MEC (Multi-access Edge Computing) in the future. Deploy edge-capable devices rather than simple, transparent 4G modems.</p>
<p><strong>Standardize on open protocols</strong>: MQTT, OPC-UA, and REST are transport-network-agnostic. A system built on these standards can migrate to 5G without requiring application rewrites.</p>
<p><strong>Plan for Your CBRS/ANFR Application</strong>: If you are considering a dedicated private 5G network, start the spectrum reservation process early. ANFR procedures take several months.</p>
<p><strong>Assess your real-world use cases</strong>: Document the latency currently observed in your critical processes, the data rates in use, and connection densities. This assessment forms the basis for a rational 5G decision rather than one driven by marketing.</p>
<p><strong>Train your teams</strong>: 5G SA skills (core network, RAN, slicing) differ from Wi-Fi and 4G skills. The skills gap is currently one of the main obstacles to private 5G deployments in France.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="4g-or-5g-what-does-the-sim-card-actually-change">4G or 5G: What Does the SIM Card Actually Change?<a href="https://eziwan.com/en/blog/5g-private-network-factory#4g-or-5g-what-does-the-sim-card-actually-change" class="hash-link" aria-label="Direct link to 4G or 5G: What Does the SIM Card Actually Change?" title="Direct link to 4G or 5G: What Does the SIM Card Actually Change?" translate="no">​</a></h2>
<p>The transition to 5G does not change the fundamentals of industrial connectivity: you still need a suitable M2M SIM card, a well-managed access point, and consumption monitoring. Three specific points to keep in mind:</p>
<ul>
<li class=""><strong>Plan Compatibility</strong>: Most current M2M SIM cards are 4G/5G NSA; 5G SA (which provides true latency guarantees) requires specific carrier plans, which are still rare in 2026.</li>
<li class=""><strong>Multi-carrier remains king</strong>: A well-received 4G multi-carrier SIM is better than a single-carrier 5G SIM on the edge of coverage—industrial 5G is currently concentrated in dense areas and private campuses.</li>
<li class=""><strong>Data consumption remains unchanged</strong>: Modbus or MQTT telemetry consumes the same amount of data on both 4G and 5G; only video and massive edge use cases justify higher data plans.</li>
</ul>
<p>In other words: for a network of traditional remote management sites, there is no rush to migrate to 5G—the right SIM card and the right 4G router remain the most sensible investment.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="example-of-a-4g5g-hybrid-architecture">Example of a 4G/5G Hybrid Architecture<a href="https://eziwan.com/en/blog/5g-private-network-factory#example-of-a-4g5g-hybrid-architecture" class="hash-link" aria-label="Direct link to Example of a 4G/5G Hybrid Architecture" title="Direct link to Example of a 4G/5G Hybrid Architecture" translate="no">​</a></h2>
<p>A pragmatic approach is to deploy the same architecture regardless of the radio access method:</p>
<p><strong>Production equipment (Modbus, OPC-UA, Profinet) → Eziwan industrial gateway (4G modem today, interchangeable 5G module tomorrow) → multi-carrier M2M SIM → outbound VPN tunnel → Eziwan cloud → monitoring and remote access.</strong></p>
<p>When a use case justifies 5G (AGVs, machine vision), only the radio module changes: safety, monitoring, fleet management, and integrations remain the same. This provides the best protection for your investment in the face of a standard that is still evolving.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="faq">FAQ<a href="https://eziwan.com/en/blog/5g-private-network-factory#faq" class="hash-link" aria-label="Direct link to FAQ" title="Direct link to FAQ" translate="no">​</a></h2>
<p><strong>Is private 5G available to French industrial SMEs today?</strong>
Private 5G networks have been deployed in France since 2022–2023, primarily in large factories and ports (PSA, Airbus, Port of Marseille). For SMEs, private 5G remains expensive (€300,000 to over €1 million for radio infrastructure). Public 5G (from carriers) with network slicing is more accessible, but industrial coverage will remain limited to urban and suburban areas in 2026.</p>
<p><strong>What industrial use cases truly justify 5G over 4G LTE?</strong>
Use cases that justify 5G: AGVs (autonomous guided vehicles) requiring latency &lt; 5 ms, real-time machine vision (4K cameras for quality control), augmented reality for maintenance technicians (high bandwidth + low latency), and extremely high connection densities (1,000+ sensors per m²). For SCADA monitoring, predictive maintenance, and remote access—4G LTE is more than sufficient.</p>
<p><strong>Can operators’ public 5G networks replace a private 5G network in a factory?</strong>
For most factories: yes, thanks to 5G network slicing, which allows you to reserve a dedicated network slice. The guaranteed latency SLAs are less stringent than those of a private network, but sufficient for 95% of industrial applications. A private 5G network is justified only if you have ultra-strict latency requirements (&lt; 1 ms) or require absolute data confidentiality.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="further-reading">Further Reading<a href="https://eziwan.com/en/blog/5g-private-network-factory#further-reading" class="hash-link" aria-label="Direct link to Further Reading" title="Direct link to Further Reading" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/blog/lora-zigbee-4g-wifi-industrial-iot-protocol">Blog: LoRa, Zigbee, 4G, or Wi-Fi—Which IoT Protocol Should You Choose?</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/industrial-lte-router">Blog: Industrial 4G LTE Router—Migrating from ADSL Before the End of Copper</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/edge-computing-vs-cloud-industry">Blog: Edge Computing vs. Industrial Cloud — When to Use Which?</a></li>
<li class=""><a class="" href="https://eziwan.com/en/blog/m2m-iot-sim-french-carriers-comparison">Blog: M2M IoT SIM Cards — Comparison of French Operators in 2026</a></li>
</ul>
<hr>
<p><strong>Need an analysis for your project?</strong> The Eziwan team helps manufacturers assess their connectivity needs and choose between 4G LTE, private 5G, and Wi-Fi. <a class="" href="https://eziwan.com/en/telegestion-industrielle">Contact us for a case study</a> tailored to your site’s specific requirements.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-resources">Additional Resources<a href="https://eziwan.com/en/blog/5g-private-network-factory#additional-resources" class="hash-link" aria-label="Direct link to Additional Resources" title="Direct link to Additional Resources" translate="no">​</a></h2>
<ul>
<li class=""><a class="" href="https://eziwan.com/en/routeur-5g-industriel">Industrial 5G Router</a> — 5G equipment for factories and industrial sites</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-4g-vs-5g-router">Comparison of Industrial 4G vs. 5G Routers</a> — When should you switch to 5G?</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-routers">Industrial Routers</a> — complete catalog of connectivity equipment</li>
<li class=""><a class="" href="https://eziwan.com/en/industrial-connectivity">Industrial Connectivity</a> — overview of 4G, 5G, and alternative technologies</li>
</ul>]]></content:encoded>
            <category>5g</category>
            <category>industry-40</category>
            <category>iiot</category>
            <category>connectivity</category>
        </item>
    </channel>
</rss>