Protocols About 2 min read

OPC Unified Architecture

OPC UA provides information models, services and security policies. Check which ones the server implements and how client identities are authorised.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Inherited check dated 13 September 2026. Supporting evidence for this inherited check has not been independently confirmed.

Recorded scope: OPC Foundation reference pages for Parts 4, 6, 8, 12, 13, 17 and 26 were checked at release 1.05.07, published 15 April 2026. Other Parts and product conformance remain independently versioned.

Companion specifications, product profiles, namespace versions, and the applicable OPC Foundation conformance units are required for a concrete integration.

Verification and testing

Overview#

OPC UA is a platform independent architecture for typed information models, discovery, client/server services, subscriptions, methods, events, and Publish Subscribe communication. It is a versioned multi part family, not a monolithic “1.05.06” specification. At this review, Part 1 (Overview and Concepts), Part 2 (Security Model), and several other parts are 1.05.06, while Parts 4, 6, 8, 12, 13, 17, and 26 are 1.05.07; other parts retain still different patch levels.12 Record each required Part and companion specification independently.

Model before transport#

A durable client binds to namespace URI plus NodeId and validates the node class, DataType, ValueRank, engineering units, access level, modelling rule, and companion specification version. Namespace indexes are server session assignments and can change; never persist an index as global identity. Browse/display names are human facing and not stable identifiers.

Every value should preserve StatusCode and source/server timestamps. Don't convert Bad, Uncertain, stale, or missing data into a normal value. For subscriptions, define sampling interval, publishing interval, queue size, discard policy, lifetime, keepalive, reconnect transfer/recreation behaviour, and how data gaps are surfaced.

Methods and writes are commands. Validate argument types and semantic preconditions, apply least privilege, use idempotency/correlation where the model supports it, and obtain completion state from the authoritative node/event rather than the transport result alone.

Security layers#

OPC UA separates SecureChannel protection, application instance identity, Session, and user identity/authorisation. Select an approved endpoint, MessageSecurityMode, SecurityPolicy, application certificate, and user token policy as a coherent set. None modes/policies are for explicitly isolated commissioning or diagnostics, not an acceptable production default when protected profiles are available.3

  • Maintain a deliberate application trust list; don't auto trust every certificate returned by discovery.
  • Validate chains, identity/application URI rules, key usage, validity, revocation policy, and algorithm strength as required by the selected profile.
  • Map users/service identities to roles and authorise nodes, attributes, methods, and subscriptions; an authenticated application isn't automatically an authorised operator.
  • Separate discovery from trust, and expose only intended endpoints and profiles.
  • Plan certificate renewal and trust list rollover without disabling validation or sharing private keys.

PubSub#

OPC UA PubSub has its own publisher/writer and subscriber/reader configuration, transport mappings, message security, key distribution, dataset metadata, sequencing, and discovery considerations.4 Don't apply client/server Session assumptions to PubSub. Bind publisher identity, DataSetWriterId, schema/configuration version, field types, security group, key lifetime, and stale/sequence rules explicitly.

Safety boundary#

An OPC UA server may front PLC, BMS, access control, or energy controls. Discovery and browsing can expose a rich operational model; broad subscriptions can exhaust server resources. Use product capability statements, companion specifications, and an authorised non production validation environment before integrating a live endpoint.

Primary sources#

Section overview · Wiki home

  1. OPC Foundation, OPC UA Online Reference ↩

  2. OPC Foundation, OPC 10000-1 v1.05.06 ↩

  3. OPC Foundation, OPC UA Part 2, security model ↩

  4. OPC Foundation, OPC UA Part 14, PubSub ↩