PURDUE MODEL LEVELS
Purdue Model for ICS Security: The Levels Explained
The Purdue model explained level by level, from the physical process at Level 0 to the enterprise at Level 5, with the Level 3.5 DMZ, how it maps to ISA-95 and ISA/IEC 62443 zones and conduits, IT vs OT, and where cloud and IIoT break it.

The Purdue model is a reference architecture that divides an industrial organisation into levels, from the physical process at Level 0 up to the corporate enterprise at Level 5. In ICS security it is used to decide where to segment networks: Levels 0 to 3 are operational technology (OT), Levels 4 and 5 are IT, and an industrial demilitarised zone, often called Level 3.5, sits between them so that no traffic passes directly from business to plant. It is a way to organise trust and data flow, not a security standard in itself.
Checked on 11 October 2026 against the sources listed under this post.
What is the Purdue model?
The Purdue model is the short name for the Purdue Reference Model for Computer Integrated Manufacturing (CIM), a hierarchy that places people, equipment and systems at numbered levels according to the job they do. According to PERA.net, it was developed by Theodore J. Williams and members of the Industry-Purdue University Consortium for CIM. Williams was director of the Purdue Laboratory for Applied Industrial Control at Purdue University from 1965 to 1994 and guided and edited the original development of both the reference model and the Purdue Enterprise Reference Architecture (PERA).
NIST SP 800-82 Rev. 3 (September 2023) cites the reference model as published by the Instrument Society of America, now ISA, in 1989, and notes that the ISA-95 standard grew from PERA, first published by ISA in 1992. The model was built to describe manufacturing integration; the security community later adopted its levels as a map for network segmentation.
In this nine-minute video, Instrumentation Tools explains the Purdue model for industrial control systems. It is one of the lessons in our free ICS Security Foundations course. It is a good place to start because seeing the levels drawn as a stack makes the rest of this guide, and every OT security diagram you meet later, much easier to read.
What are the Purdue model levels?
PERA.net notes that although five levels is most common, larger organisations may define more. The usual security version has six levels plus the DMZ:
| Level | What it does | Examples |
|---|---|---|
| Level 5: Enterprise network | Corporate-level services | Email, corporate IT, internet access, cloud business applications |
| Level 4: Business logistics | Business planning and logistics for the site | ERP, scheduling, site IT servers |
| Level 3.5: OT DMZ | Brokers every exchange between IT and OT | Replicated historian, patch server, remote access jump host |
| Level 3: Manufacturing operations | Manages production workflow across the site | MES, plant historian, OT domain and backup servers |
| Level 2: Supervisory control | Supervises, monitors and controls the process | SCADA servers, HMIs, engineering workstations |
| Level 1: Basic control | Senses and manipulates the process | PLCs, DCS controllers, RTUs, safety controllers |
| Level 0: Physical process | The equipment that makes the product | Sensors, valves, motors, drives, transmitters |

Levels 0 to 2: the cell and area
Levels 0, 1 and 2 are where control actually happens, and where an attack can have physical effects. NIST makes a specific point about Level 0: many sensors, actuators and field protocols cannot be authenticated, so data can be replayed, modified or spoofed. That is why critical processes may need extra measures such as separate field I/O monitoring.
Level 3: site operations
Level 3 holds the systems that run the whole site rather than one machine. The IEC 62264-1:2013 abstract, the international edition of ISA-95, calls this the manufacturing operations management domain (Level 3) and defines its interface with the enterprise domain at Level 4. The ISA95 committee page says that standard is based on the Purdue Reference Model and that the interface it first considered is the one between levels 3 and 4.
Levels 4 and 5: business and enterprise
Levels 4 and 5 are ordinary IT: business systems, email and internet access. They face the outside world, which is exactly why they must never have a direct route down to a controller.
What is Level 3.5 in the Purdue model?
Level 3.5 is the informal name for the industrial demilitarised zone (OT DMZ) between Level 3 and Level 4. Nothing in the original reference model is numbered 3.5; the label came from security practice. The idea is simple: IT and OT never connect directly. Each exchange terminates on a server in the DMZ, such as a replicated historian that business users query instead of the plant historian.
The US guidance agrees on where this boundary goes. The EPA's segmentation guidance describes Levels 0 to 3 as OT assets and Levels 4 and 5 as the IT enterprise network, with segmentation primarily between Levels 3 and 4 and a DMZ as a buffer, denying IT-to-OT connections by default unless explicitly allowed by IP address and port. NIST SP 800-82 Rev. 3 adds that any communication between the enterprise level and operations management should go through services in the DMZ, and that those DMZ services must be monitored because an attacker who compromises them can pivot into OT. In May 2025, CISA, the FBI, EPA and DOE listed segmenting IT and OT, with a DMZ for passing control data to enterprise logistics, among five primary mitigations for OT.
How does the Purdue model relate to ISA/IEC 62443 zones and conduits?
The Purdue model tells you what level an asset belongs to. ISA/IEC 62443, the series developed by ISA's ISA99 committee (founded 2002) in cooperation with IEC TC 65 WG 10, tells you how to secure the groups you form.
- A zone is a group of physical or logical assets that share common security requirements, with clearly defined physical or logical borders (as INCIBE-CERT quotes IEC 62443).
- A conduit is a "logical grouping of communication channels that share common security requirements connecting two or more zones", in the definition in ANSI/ISA-62443-3-2-2020.
Part 3-2 sets requirements for defining the system under consideration, partitioning it into zones and conduits, assessing risk for each, and setting a target security level (SL-T) for each zone and conduit. A Purdue level is a sensible first cut for zones, but it is rarely the last: one Level 1 may hold a packaging line and a safety system that deserve separate zones. Our guide to free IEC 62443 training goes deeper into the series.
IT vs OT: what is different?
The Purdue boundary exists because IT and OT protect different things. IT security is chiefly about the confidentiality and integrity of data. OT security is chiefly about safety and keeping a physical process running. NIST SP 800-82 Rev. 3 sets out the differences:
| Concern | IT network | OT network |
|---|---|---|
| Top priority | Confidentiality and integrity of data | Safety, availability, the physical process |
| Timing | High throughput, tolerates some delay | Time-critical, often deterministic responses |
| Restarts | Rebooting is a routine fix | Outages planned days or weeks ahead |
| Patching | Timely and often automated | Tested by vendor and owner first, may need revalidation |
| Component lifetime | About three to five years | Often 10 to 15 years or longer |
| Who manages it | IT staff | Usually control engineers |
NIST adds that any security measure that impairs safety is unacceptable in OT. That is why NIST advises testing tools that use active scanning on offline systems before they touch a production OT network, and why the IT vs OT network split sits at Level 3.5.
Is the Purdue model still relevant?
It is still the most common shared vocabulary, but it has real limits, and NIST SP 800-82 Rev. 3 treats it as one option rather than a rule. NIST suggests organising OT segmentation with the Purdue model, ISA-95 levels, the three-tier IIoT architecture, or a combination.
- IIoT and cloud cross levels. NIST notes that IIoT can increase connectivity with enterprise and cloud systems and may require altering boundaries or exposing more interfaces. A sensor that sends data straight to a cloud platform skips every level between 0 and 5.
- Perimeters are blurring. NIST's zero trust section observes that boundary devices between zones do not stop lateral movement inside a zone, and that cloud, wireless and cellular links make perimeters less defined.
- Not every device can join a zero trust design. NIST suggests applying zero trust first at the higher levels (Purdue Levels 3, 4 and 5 and the OT DMZ), because many PLCs and HMIs cannot support it.
- Remote access cuts through. CISA notes that many operators, and contractors working for them, make risk-based trade-offs on remote access to OT, and asks for private connections, VPNs with strong passwords and phishing-resistant MFA instead.
The fix is not to abandon the model but to draw these flows on it deliberately and route them through monitored conduits.
How to apply the Purdue model to your plant
- Inventory first. List every asset and every data flow, including vendor remote access and any cloud link.
- Assign levels, then zones. Place each asset at a Purdue level, then group assets with the same security needs into ISA/IEC 62443 zones.
- Build the OT DMZ. Put a firewall pair or firewall with a DMZ between Level 3 and Level 4 and move shared services into it.
- Allow only adjacent levels. NIST's example is that Level 4 devices should not communicate directly with Levels 2, 1 or 0, and outbound rules from OT should be as strict as inbound rules.
- Consider one-way paths. Where data only needs to leave OT, NIST notes a unidirectional gateway (data diode) can protect lower levels from a compromise above.
- Secure remote access through the DMZ with least privilege and MFA, and disable dormant accounts.
- Monitor and log every conduit, and keep the ability to run the process manually if the network fails, as CISA recommends.


Getting the addressing right is part of the job: our walkthrough on subnetting for PLC and OT networks shows how to plan subnets that match your zones. For why this matters, see our overview of cybersecurity in industrial automation and our report on Iran-linked PLC attacks.
Where to learn OT network security for free
Start with ICS Security Foundations, which contains the video above, then OT and ICS Cybersecurity with ISA/IEC 62443 for zones, conduits and security levels. Controls engineers should add Cybersecurity for PLC Programmers, and OT Security Assessment covers testing a running plant safely. All are free; the optional EDWartens Certificate of Completion is not an ISA or IEC certification and is not accredited, and anyone can check one at edwartens.com/verification.
Take the free course
FreeCybersecurity · Beginner · Free
ICS Security Foundations: Control Systems, Defence in Depth and the 62443 Requirements
FreeCybersecurity · Intermediate · Free
OT and ICS Cybersecurity with ISA/IEC 62443
FreeCybersecurity · Intermediate · Free
Cybersecurity for PLC Programmers: Hardening Siemens and Rockwell Controllers
FreeCybersecurity · Intermediate · Free
OT Security Assessment: Testing a Plant Without Stopping It
Questions
What are the levels of the Purdue model?
Level 0 is the physical process (sensors, actuators), Level 1 the devices that sense and manipulate it (PLCs, controllers), Level 2 supervisory control (SCADA, HMI), Level 3 site manufacturing operations (MES, historians), Level 4 business logistics (ERP) and Level 5 the enterprise network. Security architectures add an OT DMZ between Levels 3 and 4, often called Level 3.5.
What is Level 3.5 in the Purdue model?
Level 3.5 is the informal name for the industrial demilitarised zone (OT DMZ) between the plant's operations network at Level 3 and the business network at Level 4. Data passes into and out of OT through services in the DMZ, such as a replicated historian or a jump host, rather than through direct connections. CISA and NIST both recommend a DMZ between IT and OT.
Who created the Purdue model?
It grew out of the Purdue Reference Model for Computer Integrated Manufacturing, whose development was guided and edited by Theodore J. Williams of the Purdue Laboratory for Applied Industrial Control at Purdue University. NIST cites it as published by the Instrument Society of America in 1989, and the related Purdue Enterprise Reference Architecture was published by ISA in 1992.
Is the Purdue model a security standard?
No. It began as a reference model for manufacturing integration, not a security standard. Security guidance such as NIST SP 800-82 Rev. 3 uses it as one way to organise network segmentation, alongside ISA-95 levels and ISA/IEC 62443 zones and conduits, which is the standard that sets security requirements.
What is the difference between IT and OT security?
IT security puts confidentiality and integrity of data first, while OT security puts safety, availability and control of a physical process first. NIST SP 800-82 Rev. 3 notes that OT often cannot be rebooted or patched on short notice, uses components with lifetimes of 10 to 15 years or more, and may run protocols with no authentication.
Is the Purdue model still relevant with cloud and IIoT?
Yes as a way to think about trust and data flow, but not as a strict rule that only adjacent levels ever talk. IIoT devices and cloud services create connections that cross levels, so NIST advises mapping those flows explicitly, routing them through the DMZ where possible, and applying zero trust principles at the higher levels where devices support it.
Sources
- NIST: SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security (September 2023)
- PERA.net: What is the Purdue Model?, read 11 October 2026
- PERA.net: Biographical sketch of Theodore J. Williams, read 11 October 2026
- ISA: ISA95, Enterprise-Control System Integration committee page, read 11 October 2026
- IEC Webstore: IEC 62264-1:2013 Enterprise-control system integration, Part 1: Models and terminology
- ISA: ISA/IEC 62443 Series of Standards, read 11 October 2026
- ISA: ANSI/ISA-62443-3-2-2020 preview (scope and definitions)
- CISA, FBI, EPA, DOE: Primary Mitigations to Reduce Cyber Threats to Operational Technology (6 May 2025)
- US EPA: Protect 2.F, Network Segmentation (water sector guidance, July 2024)
- INCIBE-CERT: Zones and conduits, protecting our industrial network (21 June 2018)
Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.

Cyber Resilience Act Reporting Obligations: What Machine Builders and OEMs Must Do Now

Controls Engineer Certifications: CAP, CCST and More

PLC Programmer Salary by Country (2026): A Free Salary Estimator

Node-RED PLC Dashboard: Read Live Data and Build an Operator Page (Video)

IIoT Training: How Plant Data Gets From a PLC to a Dashboard, and How to Learn It Free

OPC UA Explained: Address Space, Subscriptions and Security for Engineers