OPC UA VS MQTT

OPC UA vs MQTT: Which Protocol and When to Use It

OPC UA and MQTT are not rivals so much as layers: one describes and secures plant data, the other moves it through a broker. How each works, how they differ on security and data modelling, where Modbus and Sparkplug fit, and how to choose.

By EDWartens engineering team 11 October 2026 10 min
OPC UA vs MQTT: Which Protocol and When to Use It

OPC UA and MQTT solve different problems, so the real answer to "OPC UA vs MQTT" is usually "both, at different levels". OPC UA is an industrial interoperability standard (IEC 62541) that describes data with a typed information model, secures every connection itself, and works as client/server or publish/subscribe. MQTT is a lightweight publish/subscribe transport that moves any payload through a broker and leaves data meaning and most security to you. Use OPC UA where PLCs, SCADA and MES must read, write and understand each other's data; use MQTT, often with Sparkplug, to fan that data out across a site or to the cloud.

Checked on 11 October 2026 against the sources listed under this post.

What is the difference between OPC UA and MQTT?

OPC UA is a platform-independent, service-oriented architecture from the OPC Foundation, first released in 2008, that combines data access, alarms, history and methods in one framework with built-in security. The OPC Foundation's overview says it is meant to run on anything from an embedded microcontroller to cloud infrastructure, and calls information modelling a fundamental element of the architecture. It is published internationally as the IEC 62541 series; the IEC Webstore shows the Part 1 overview was replaced by a full standard, IEC 62541-1:2025.

MQTT is "a Client Server publish/subscribe messaging transport protocol" that is light weight, open and simple, in the words of the OASIS MQTT 5.0 standard (7 March 2019). The same abstract says it is agnostic to the content of the payload. Version 3.1.1 became an OASIS Standard on 29 October 2014 and is still widely deployed.

The short version: OPC UA is about what the data means and who may touch it; MQTT is about getting messages from many publishers to many subscribers efficiently.

QuestionOPC UAMQTT
What does it define?Data model, services, security and transportsA message transport only
How do clients talk?Client/server sessions, or PubSub (Part 14)Every client talks to a broker
Is there a data model?Yes: objects, variables, types, methodsNo: the payload is opaque bytes
Can a client browse what exists?Yes, through the server's address spaceNo, unless a layer such as Sparkplug adds it
Who handles security?The protocol: certificates, signing, encryptionThe implementer: TLS, credentials, broker ACLs
Can it write to a device?Yes, with reads, writes and method callsOnly by convention, through a command topic
OPC UA and MQTT at a glance
OPC UA and MQTT at a glance
“What is MQTT Protocol ? How it works ? | 2022” by IT and Automation Academy, 7 min. Played from the creator's own YouTube channel; the video belongs to them.

In this seven-minute video, IT and Automation Academy explains what the MQTT protocol is and how it works. It is one of the lessons in our free Industrial Communication course, and it also appears in Industrial Data with Python. It is worth watching before the rest of this guide, because the broker model is the part that feels least familiar to engineers who have only used PLC-to-HMI protocols.

How does OPC UA work?

Client/server: the classic plant connection

A client such as a SCADA or MES application opens a secure session to a server, often built into the PLC or running on a gateway. It can browse the address space, read and write current and historical values, call methods and subscribe to data changes and events, which the OPC Foundation describes as delivered to a single client with guaranteed delivery. That makes OPC UA the natural choice where the client must also send setpoints and commands.

The information model

In OPC UA a value never travels alone: a temperature arrives as a typed variable inside an object, with its engineering unit, range and relationships to other nodes. Other organisations extend the core models for their industries, so two vendors' machines can expose the same structure. MQTT has nothing equivalent built in.

OPC UA PubSub (Part 14)

OPC UA also has a publish/subscribe model, defined in OPC 10000-14, Part 14: PubSub (release 1.05.06, 22 October 2025). The OPC Foundation describes it as optimised for many-to-many configurations: publishers send to message-oriented middleware without knowing who, if anyone, is subscribed. Part 14 defines two message encodings, binary UADP and JSON, and two kinds of middleware:

  • Brokerless, over OPC UA UDP or raw Ethernet, where the network delivers messages directly with no software intermediary. The specification notes that with OPC UA UDP there is no guarantee of timeliness, delivery, ordering or duplicate protection.
  • Broker-based, where a broker routes messages, so publishers and subscribers never address each other directly. Part 14 names MQTT as such a protocol and defines a full mapping for it; AMQP is covered in an informative annex.

How does MQTT work?

Every MQTT client connects to a broker. A publisher sends a message to a topic, a text path such as site1/line2/filler/temperature, and the broker forwards it to every client subscribed to a matching topic filter. Three features matter most on a plant:

  • Quality of Service. QoS 0 is "at most once" (loss can occur), QoS 1 is "at least once" (duplicates can occur) and QoS 2 is "exactly once".
  • Retained messages. When a message is published with the RETAIN flag, the broker stores it and hands it to future subscribers, so a new dashboard sees the last value immediately.
  • Will messages. A client registers a will message that the broker publishes if the connection closes abnormally, which is how other clients learn that a device has gone offline.

The MQTT 5.0 standard notes that TCP ports 8883 and 1883 are registered with IANA for MQTT over TLS and without TLS respectively. Version 5.0 added, among other things, reason codes on every acknowledgement, message expiry, a formal request/response pattern and shared subscriptions for load-balanced consumers.

How do OPC UA and MQTT compare on security?

This is the biggest practical difference. OPC UA builds security into the protocol. According to the OPC Foundation, it identifies every client and server with an X.509 certificate, signs messages to prove sender and integrity, encrypts sessions, sequences packets against replay, authenticates users by credentials, certificates or tokens, and keeps audit logs.

MQTT deliberately does not. Chapter 5 of the MQTT 5.0 standard is non-normative and says the exact security technologies are context specific, so it is the implementer's responsibility to include them. It strongly recommends that servers offering TLS use port 8883. In practice, MQTT security is TLS plus whatever your broker provides: credentials or client certificates, and access control on topics.

When you run OPC UA over MQTT, the two models meet. The Part 14 MQTT mapping points out that TLS only protects each hop and depends on trusting the broker. For end-to-end protection the publisher must use UADP binary messages, because message-level security is only defined for UADP; JSON payloads rely on MQTT and broker security alone.

MQTT broker security checklist
MQTT broker security checklist

What is Sparkplug, and is it OPC UA's real rival?

Plain MQTT says nothing about topic names or payloads, so two systems on the same broker can still be unable to understand each other. As the Eclipse Foundation announcement puts it, by design the MQTT specification does not dictate a topic namespace or any payload encoding. Sparkplug fills that gap: it defines an OT-centric topic namespace, a payload optimised for process variables, and the session state management that SCADA needs. Its birth and death certificates tell subscribers when an edge node's data is valid. Sparkplug 3.0 was published as the international standard ISO/IEC 20237, announced on 7 November 2023.

So the honest comparison for a new unified namespace project is often Sparkplug B over MQTT vs OPC UA PubSub over MQTT: both put structure on the same broker. Sparkplug is simpler and built around edge nodes and devices; OPC UA PubSub carries the richer OPC UA model and its message security. Our explainer on MQTT Sparkplug B covers the topic structure and birth/death sequence in detail.

OPC UA vs MQTT vs Modbus

Modbus still sits under many of these systems. The Modbus Organization describes it as a messaging structure developed by Modicon in 1979 for client-server communication between intelligent devices, with Modbus TCP/IP on well-known port 502. It moves raw register values; what register 40001 means lives in the device manual, not in the protocol.

Modbus TCPOPC UAMQTT
PatternClient polls serverClient/server or PubSubPublish/subscribe via broker
Data meaningRegister map in a manualSelf-describing modelWhatever the payload says
Built-in securityNone in classic Modbus TCPYesNo, use TLS and the broker
Typical roleDrives, meters, simple I/OController and supervisory linksPlant-wide and cloud distribution

A common pattern is Modbus at the device, OPC UA at the controller or gateway, and MQTT above. Our Modbus TCP register walkthrough shows the first step in practice.

Is OPC UA or MQTT faster?

There is no single performance figure you can trust outside your own network, because tag counts, update rates and security settings differ on every plant. What actually decides throughput and latency:

  • Encoding. Binary UADP or OPC UA binary is more compact than JSON, whichever transport carries it.
  • The broker hop. MQTT adds a broker between publisher and subscriber, but one publish reaches any number of subscribers without extra load on the PLC.
  • Connections. Each OPC UA client/server session uses resources on the server, and a server embedded in a PLC has limited resources, so the number of direct clients matters.
  • QoS and security. QoS 2 and per-message signing add round trips and processing.
  • Report by exception. Both OPC UA subscriptions and MQTT publishing can send only changes, which usually matters more than the protocol.

When should you use OPC UA, MQTT or both?

SituationBest fitWhy
SCADA or HMI reading and writing PLC tagsOPC UA client/serverWrites, browsing and per-session security
Machine builder exposing a standard interfaceOPC UA with a companion modelSame structure across vendors
Many consumers need the same plant dataMQTT brokerOne publish, many subscribers
Edge devices on cellular or satellite linksMQTTLight, outbound-only connections
Unified namespace across sitesMQTT with Sparkplug or OPC UA PubSubStructure on a shared broker
Plant to cloud analyticsMQTT, often fed from OPC UAOutbound links through one broker

How to choose for a new project

  1. List every consumer of plant data and whether it only reads or must also write.
  2. Use OPC UA client/server for anything that writes setpoints, browses tags or needs per-user security.
  3. Put an edge gateway beside the controllers that reads them over OPC UA or Modbus.
  4. Publish from the gateway to an MQTT broker with one agreed topic scheme.
  5. Choose Sparkplug B or OPC UA PubSub JSON so every subscriber decodes payloads the same way.
  6. Secure both layers: OPC UA certificates, TLS on port 8883 and topic-level access control on the broker.
  7. Test latency and broker load with realistic tag counts before you roll out.
Designing a plant data architecture with both
Designing a plant data architecture with both

How to learn OPC UA and MQTT for free

Start with the free Industrial Communication course, which runs from serial and fieldbus networks to Modbus, PROFINET and OPC UA, then read our guide to the OPC UA protocol. For hands-on MQTT, Node-RED for Industrial IoT lets you run a broker and flows on a laptop, and our Node-RED PLC dashboard walkthrough shows the plant side. Industrial Data with Python covers collecting and analysing the data once it arrives. All are free, and the optional EDWartens Certificate of Completion, which is not a vendor or accredited credential, can be checked by anyone at edwartens.com/verification.

Take the free course

Questions

Is OPC UA better than MQTT?

Neither is better in general, because they do different jobs. OPC UA describes data with a typed information model and secures each connection itself, which suits PLC, SCADA and MES integration. MQTT is a lightweight broker-based transport that moves any payload to many subscribers, which suits plant-wide and cloud data distribution. Many plants use OPC UA at the machine and MQTT above it.

Can OPC UA run over MQTT?

Yes. OPC UA Part 14 (PubSub) defines an MQTT transport mapping for MQTT 3.1.1 and 5.0, with message bodies encoded either as binary UADP or as JSON. The default topic structure starts with the prefix opcua, and MQTT QoS 0, 1 and 2 map to the OPC UA delivery guarantees.

What is the difference between OPC UA PubSub and MQTT?

OPC UA PubSub is a messaging model from the OPC UA specification that defines what is published (DataSets with metadata) and how it is encoded. MQTT is one of the transports PubSub can use, alongside brokerless UDP and Ethernet. So OPC UA PubSub over MQTT is OPC UA content carried by an MQTT broker.

What is Sparkplug B and how does it relate to MQTT?

Sparkplug is an Eclipse Foundation specification that runs on top of MQTT. MQTT itself does not dictate a topic namespace or payload encoding, so Sparkplug defines both, plus session state management with birth and death certificates. Sparkplug 3.0 was published as the international standard ISO/IEC 20237 in 2023.

Is MQTT secure for industrial use?

It can be, but security is the implementer's job. The MQTT 5.0 specification leaves the choice of privacy, authentication and authorisation technologies to the implementer and strongly recommends TLS on TCP port 8883. A secure deployment adds per-client credentials or certificates, topic-level access control and a well-placed, monitored broker.

Which is faster, OPC UA or MQTT?

There is no single answer, because the result depends on encoding, network, broker, QoS level and how many clients are connected. A binary OPC UA encoding is usually more compact than JSON, while MQTT adds a broker hop but scales to many subscribers cheaply. Test both with your own tag counts and update rates before you decide.

Sources

Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.