OPC UA

OPC UA Explained: Address Space, Subscriptions and Security for Engineers

What OPC UA actually is, how its address space and subscriptions work, why connections fail on certificates, and when to choose it over Modbus or MQTT.

By EDWartens engineering team 20 January 2026 Updated 5 October 2026 6 min
OPC UA Explained: Address Space, Subscriptions and Security for Engineers

OPC UA (Open Platform Communications Unified Architecture) is a vendor-neutral, platform-independent standard for sharing industrial data. A server exposes named, typed and structured data that clients can browse, read, write and subscribe to, with encryption and authentication built in. It is the usual bridge between PLCs, SCADA, MES and software. Below is OPC UA explained for working engineers, from the address space to a first connection.

“The ABCs of OPC UA: Everything You Need to Understand” by RealPars, 10 min. Played from the creator's own YouTube channel; the video belongs to them.

In this lesson by RealPars, the basics of OPC UA are introduced for people who have not used it before. Watch it, then use the sections below to go a step deeper and to make your first connection.

Where OPC UA came from

The original OPC standards, now called OPC Classic, let Windows software read PLC data through Microsoft's COM/DCOM technology. They worked, but they tied you to Windows and DCOM was notoriously hard to configure across networks. The OPC Foundation says OPC UA, released in 2008, integrates all the functionality of the Classic specifications into one extensible, platform-independent framework. It runs on PCs, servers, PLCs and embedded devices, on Windows, Linux and other operating systems. The specifications are also published as the international standard IEC 62541, in parts such as IEC 62541-4, which defines the services clients and servers use.

OPC UA explained: the address space

Modbus gives you register 40108 and a manual. OPC UA gives you a browsable tree of nodes. Each node has a NodeId (a namespace index plus an identifier), a browse name, a data type and attributes. The main node classes you will work with are:

  • Objects, such as a pump, a mixer or a line, which organise other nodes
  • Variables, which hold values such as Speed or Temperature
  • Methods, which a client can call, such as StartBatch
  • Types, which define what a kind of object contains, so every pump looks the same

Nodes are joined by references, such as "has component" or "has property". That structure is what the OPC Foundation means by turning data into information: a client can discover what a server contains and understand it without a separate document.

Industry groups publish companion specifications that define standard object types for their equipment, so a client can understand machines from different makers the same way.

Reading data: polling versus subscriptions

A client can simply read a value whenever it wants. More often it creates a subscription and adds monitored items to it. The server samples each item at the requested sampling interval and sends only changes, grouped at the publishing interval. A deadband can suppress small changes. This is far more efficient than polling hundreds of values, and it is how SCADA and data platforms usually use OPC UA.

The OPC Foundation also defines PubSub, an alternative publish and subscribe mechanism for many-to-many data distribution, which can run over transports such as UDP or MQTT.

Security, and why your first connection fails

OPC UA builds security in rather than bolting it on. The OPC Foundation lists encryption, authentication and auditing, with X.509 certificates, message signing and user controls. In practice there are three layers to get right:

  1. Security mode: None, Sign, or Sign and Encrypt. Use Sign and Encrypt in production.
  2. Application certificates: the client and server each have a certificate, and each must trust the other. A new client is usually rejected until someone moves its certificate into the server's trusted list.
  3. User authentication: anonymous, username and password, or a user certificate.

Nine times out of ten, a first connection that fails is a certificate that has not been trusted yet. Look in both trust lists before you look anywhere else.

Your first connection

Your first OPC UA connection
Your first OPC UA connection

You do not need a PLC. Start a server on your laptop: an OPC UA simulation server, or a few lines of Python with the asyncua library, which provides both a client and a server. Connect a generic OPC UA client to the endpoint URL (opc.tcp is the binary protocol; port 4840 is the registered default), accept the certificates, and browse to a variable. Read it once, then subscribe to it and change the value on the server. Watching the change arrive without asking for it is the moment subscriptions make sense.

On real equipment, many current PLCs include an OPC UA server that you enable in the engineering software; check which licence your vendor requires. SCADA and HMI packages, historians and edge gateways commonly act as clients, servers or both.

OPC UA, Modbus or MQTT?

OPC UA, Modbus and MQTT compared
OPC UA, Modbus and MQTT compared

They are not really rivals. A typical modern plant uses Modbus to reach meters and drives, OPC UA from the PLC to SCADA and MES, and MQTT to spread data to many consumers or the cloud, often with Sparkplug B for MQTT to give the data a standard shape. Our IIoT training guide follows the data along that whole path, from PLC to dashboard. Choose OPC UA when data needs structure, meaning and security between systems. See our Modbus tutorial for the other end of the scale, and Industry 4.0 for engineers for how the pieces fit together.

A worked example: modelling a mixer

Suppose you want to expose a mixer to SCADA and MES. In Modbus you would publish a register map and hope everyone reads it the same way. In OPC UA you design the address space instead.

Create an object type called MixerType. Give it three variables: Speed (a Double in rpm, writable by operators), Temperature (a Double in degrees Celsius, read-only) and State (an enumeration such as Idle, Running, Fault). Add a method, StartBatch, that takes a recipe number as an input argument and returns whether the batch was accepted. Attach engineering units and ranges as properties, so a client knows what the numbers mean.

Now create Mixer1 and Mixer2 as instances of MixerType. A client that understands one understands both, and a third mixer added next year needs no new documentation. The PLC logic still decides whether StartBatch is allowed; OPC UA only carries the request.

This is the habit that makes OPC UA worth the effort: decide the structure once, as a type, and reuse it everywhere.

Good practice

  • Expose only what is needed, and make most of it read-only.
  • Model once. Build an object type for each kind of equipment and reuse it. Well-modelled data is also what data engineering for industrial AI depends on.
  • Mind the load. Hundreds of fast subscriptions can load a PLC's communication processor; choose sensible sampling intervals.
  • Keep it inside the right zone. OPC UA security is strong, but it does not remove the need for network segmentation under ISA/IEC 62443.

Learn OPC UA free

Industrial Communication introduces OPC UA alongside Modbus and PROFINET. Industrial Data with Python builds OPC UA servers and subscribing clients with asyncua, including username and password security. Node-RED for Industrial IoT connects an S7-1500 over OPC UA, and OT and ICS Cybersecurity covers the zones it should live in. Learning is free in full. If you pass a course's final assessment, the optional EDWartens Certificate of Completion is a small one-off fee, US$8.99 for a beginner course. Anyone can check it at edwartens.com/verification; it is not an OPC Foundation or vendor certification.

Take the free course

Questions

What is OPC UA in simple terms?

A vendor-neutral way for industrial software and devices to share data. A server exposes named, typed data in a browsable structure, and clients read it, write it or subscribe to changes, with security built in.

Is OPC UA a replacement for Modbus?

Not on simple field devices, where Modbus stays common. OPC UA is stronger higher up, between PLCs, SCADA, MES and software, where structured data, meaning and security matter.

What is the difference between OPC UA and OPC DA?

OPC DA is part of OPC Classic, which relied on Microsoft COM/DCOM and therefore Windows. OPC UA, released in 2008, integrates the Classic functions into one platform-independent framework with its own security.

Why does my OPC UA client fail to connect?

Most often because of certificates: the server has not trusted the client's certificate, or the client has not trusted the server's. Check both trust lists, the endpoint's security policy and the user authentication method.

Is OPC UA an international standard?

Yes. The OPC Foundation's OPC UA specifications are also published as the IEC 62541 series.

Sources

Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.