What is CANopen?
CANopen is an open application-layer communication protocol that runs on top of the CAN bus and defines how sensors, I/O modules, drives and controllers in machines and embedded systems exchange data, are configured and are monitored. Classic CAN itself only governs how messages of up to 8 bytes travel across two wires; CANopen adds addressing, network management, a standardised object dictionary and device profiles. The protocol is maintained by the user and manufacturer association CAN in Automation (CiA) and has also been European standard EN 50325-4 since December 2002.
🕰️ How did CANopen come about?
Bosch developed CAN for the automotive industry in the 1980s. In the early 1990s machine builders discovered the robust, low-cost bus, but every vendor layered its own proprietary protocol on top of it. That fragmentation created demand for an open standard.
| Year | Milestone |
|---|---|
| 1992 | Six companies and two individuals found the non-profit association CAN in Automation (CiA) in Germany |
| 1993 | The European Esprit project ASPIC, led by Bosch, works out the CANopen concept |
| 1994 | CiA publishes the first version of CiA 301, the application layer and communication profile |
| 1995 | First CANopen demonstrator shown at Hannover Messe |
| 2001 | CiA 304 (CANopen Safety) is released, later standardised as EN 50325-5 |
| 2002 | CANopen becomes European standard EN 50325-4 |
| 2017 | CiA 1301 (CANopen FD) is published |
CiA now has more than 700 member companies and, besides CANopen, also maintains the specifications for CAN FD and CAN XL.
🧠 How does CANopen work?
At the heart of every CANopen device is the object dictionary: a table holding all parameters and process data, addressed by a 16-bit index and an 8-bit sub-index.
| Index range | Contents |
|---|---|
| 1000h–1FFFh | Communication parameters (identity, PDO mapping, heartbeat time) |
| 2000h–5FFFh | Manufacturer-specific parameters |
| 6000h–9FFFh | Standardised profile parameters, for example from CiA 401 or CiA 402 |
On top of that, CiA 301 defines a small set of communication services:
- PDO (Process Data Object) — fast, cyclic or event-driven process data without protocol overhead; up to 8 bytes per message in classic CANopen
- SDO (Service Data Object) — confirmed access to any object in the dictionary, used for configuration and diagnostics; expedited, segmented or block transfer
- NMT (Network Management) — an NMT master switches nodes between the initialisation, pre-operational, operational and stopped states
- Heartbeat and node guarding — checks whether each device is still alive; heartbeat (the device announces itself periodically) has largely replaced the older node guarding (the master actively polls)
- SYNC, EMCY and TIME — a synchronisation pulse for simultaneous sampling, high-priority error messages and time distribution
A network holds at most 127 nodes (node ID 1–127). Device descriptions are supplied as an EDS file (CiA 306), which lets configuration tools and PLC engineering environments recognise the device.
🔄 What is the difference between PDO and SDO?
| Characteristic | PDO | SDO |
|---|---|---|
| Purpose | Real-time process data | Configuration and diagnostics |
| Communication model | Producer/consumer, one-to-many | Client/server, one-to-one |
| Acknowledgement | No | Yes, every request gets a response |
| Data size | Up to 8 bytes (CANopen FD: 64 bytes) | Any length via segmented or block transfer |
| Content | Fixed in advance through PDO mapping | Any object via index and sub-index |
| Typical use | Setpoint and actual position of a servo motor | Setting acceleration ramps or reading fault codes |
A PDO carries raw data only; which objects it contains is configured once through SDOs. That keeps CANopen economical with bandwidth and well suited to real-time applications.
🧩 Which device profiles does CANopen define?
Profiles ensure that devices from different vendors behave in the same way:
- CiA 401 — generic digital and analogue I/O modules
- CiA 402 — drives and motion control: servo drives, variable frequency drives and stepper motor controllers, with a fixed state machine and modes such as profile position and cyclic synchronous position; standardised internationally as IEC 61800-7-201
- CiA 406 — encoders
- CiA 417 — lift control systems (CANopen Lift)
- CiA 412 and CiA 425 — medical equipment, such as contrast-agent injectors for CT and MRI scanners
- CiA 447 — add-on devices in special-purpose vehicles such as police cars and taxis
For shipping, CiA 307 (2004) described a redundant two-cable CANopen network; that redundancy concept now lives in CiA 302-6.
🔧 What bit rates and bus lengths are typical?
CiA 301 specifies bit rates from 10 kbit/s to 1 Mbit/s. Because each bit has to reach the far end of the bus within one bit time, the maximum length shrinks as speed increases:
| Bit rate | Indicative maximum bus length |
|---|---|
| 1 Mbit/s | 25 m |
| 500 kbit/s | 100 m |
| 250 kbit/s | 250 m |
| 125 kbit/s | 500 m |
| 50 kbit/s | 1,000 m |
| 10 kbit/s | 5,000 m |
In practice 250 and 500 kbit/s are the most common choices. A step-by-step approach for a new network:
- Choose the bit rate and topology — a line bus with short stubs and a 120 Ω termination resistor at both ends
- Assign unique node IDs — via rotary switches, software or LSS (CiA 305)
- Import the EDS files into the configuration tool or PLC environment
- Define the PDO mapping — which objects, at which cycle time or SYNC ratio
- Configure heartbeat times so the master detects a failed node within a few cycles
- Test the bus load — as a rule of thumb keep it below roughly 70% to leave headroom for error messages and SDO traffic
🚀 What is CANopen FD?
CANopen FD (CiA 1301, 2017) brings CANopen to CAN FD, with a data phase of several Mbit/s and frames of up to 64 bytes. PDOs can therefore carry 64 bytes, and the classic SDO has been replaced by the USDO (universal SDO), which also supports broadcast and routing across network segments. CANopen FD is not directly compatible with classic CANopen devices on the same bus; migration usually happens machine by machine or through a gateway.
🔄 How does CANopen compare with DeviceNet, EtherCAT and PROFINET?
| Characteristic | CANopen | DeviceNet | EtherCAT | ProfiNET |
|---|---|---|---|---|
| Physical layer | CAN | CAN | Ethernet | Ethernet |
| Governing body | CiA | ODVA | EtherCAT Technology Group | PROFIBUS & PROFINET International |
| Application model | Object dictionary | CIP | CoE: CANopen dictionary | Own I/O model |
| Max. nodes | 127 | 64 | 65,535 | Practically unlimited |
| Typical domain | Machines, embedded, mobile | Factory automation (US) | High-speed motion control | Factory automation (Europe) |
DeviceNet, introduced by Allen-Bradley in 1994, uses the same CAN layer but a different application protocol, so the two are not interchangeable. EtherCAT, by contrast, adopted the CANopen model: with CoE (CANopen over EtherCAT) the same object dictionary and the same CiA 402 profile run over industrial Ethernet. Many drives therefore support both. See also the overview of fieldbuses.
🏭 Where is CANopen used?
- Machine building — packaging, printing and textile machines with distributed I/O and drives
- Mobile machinery — cranes, aerial work platforms, agricultural and construction machines, often alongside SAE J1939
- Medical technology — CT scanners, X-ray systems and injectors
- Lifts — shaft information, doors and call panels through CiA 417
- Maritime — ship automation and engine control
- Embedded systems — robotics, laboratory equipment, battery and energy storage systems
🔐 How secure is CANopen?
Classic CAN, CAN FD and CANopen (CiA 301 and CiA 1301) offer no authentication and no encryption. Every device on the bus can read and send every message; anyone able to issue an SDO write or an NMT command can change parameters or stop a drive. The security model therefore relies on physical access: the bus sits inside the machine, behind a cabinet door.
Risks arise mainly where the bus connects to the outside world:
- Gateways to Ethernet — CAN-to-Ethernet gateways and remote maintenance make the bus reachable over the network; place them behind network segmentation in line with IEC 62443
- Diagnostic ports — an exposed CAN connector on a machine or vehicle is a direct way in
- Inventory — record in your asset inventory which machines contain CANopen gateways
- Product regulation — the Cyber Resilience Act and the Machinery Regulation set requirements for protecting controls against tampering and unauthorised access
CiA is working on an authentication option for CANopen messages, and for CAN XL there is already CANsec (CiA 613-2), a security layer providing authentication, integrity and optional encryption.
❓ Frequently asked questions
Is CANopen the same as CAN?
No, CAN is the underlying bus that covers the physical and data link layers, defined in ISO 11898. CANopen is an application-layer protocol running on top of it that adds addressing, network management and device profiles. A CANopen device is therefore always a CAN device, but not the other way round.
How many devices can a CANopen network have?
A CANopen network supports up to 127 nodes with node IDs 1 to 127. In practice, bus load, cable length and the electrical characteristics of the transceivers often limit the number to a few dozen. Larger systems link several CANopen networks through a PLC or gateway.
What is an EDS file in CANopen?
An EDS file (Electronic Data Sheet, CiA 306) describes the object dictionary of a CANopen device in text form. Configuration tools and PLC environments import the EDS file to learn which objects, PDOs and parameters a device offers. The XML variant is called XDD (CiA 311).
What is CiA 402 in CANopen?
CiA 402 is the CANopen device profile for drives and motion control, such as servo drives, frequency converters and stepper motor controllers. It defines a fixed state machine and operating modes, so drives from different brands are controlled in the same way. The same profile is used on EtherCAT via CoE and is standardised in IEC 61800-7-201.
Is CANopen being replaced by Ethernet?
For high-speed motion control and large installations many machine builders are moving to EtherCAT or PROFINET, often keeping the CANopen object model through CoE. Inside compact machines, mobile machinery, medical equipment and embedded systems, CANopen remains popular because of its low cost and robustness. CANopen FD and CAN XL also keep the technology developing.
Is CANopen secure against cyberattacks?
CANopen has no built-in authentication or encryption, so any device on the bus can send messages and change parameters. The security of CANopen therefore depends on physical protection and on well-secured gateways to Ethernet and remote networks. For CAN XL, a security layer is available in the form of CANsec.
📌 In summary
CANopen is the open application protocol on top of CAN that uses an object dictionary, PDOs, SDOs and device profiles such as CiA 401 and CiA 402 to make machine components from different vendors work together. It is robust and inexpensive but has no built-in security; protect the bus physically and secure every gateway to Ethernet.
