What is NAMUR Open Architecture?

NAMUR Open Architecture (NOA) is a reference architecture from the German user association NAMUR that makes data from field devices and the control system available for monitoring and optimisation through a second, one-way channel, without changing or endangering the existing process control. NOA leaves the classic automation pyramid intact and adds a parallel data path alongside it. This allows chemical and pharmaceutical companies to apply predictive maintenance, device monitoring and process optimisation to existing plants (brownfield) as well as new builds (greenfield).


🧠 What is NAMUR and which recommendations are well known?

NAMUR was founded on 3 November 1949 in Leverkusen by instrumentation and control engineers from companies including Bayer, BASF and HΓΌls. The name originally stood for Normenarbeitsgemeinschaft fΓΌr Mess- und Regeltechnik in der chemischen Industrie, a standards working group for measurement and control in the chemical industry. Today it is the User Association of Automation Technology in Process Industries, with more than 180 member companies, mostly end users from the process sector.

NAMUR publishes its work as NAMUR Recommendations (NE) and worksheets (NA). They are not formally binding, but vendors follow them widely and they are often fed into IEC and DIN standardisation. Some well-known examples:

Recommendation Subject Essence
NE 43 Failure signalling by transmitters Valid signal 3.8–20.5 mA on a 4-20 mA loop; ≀ 3.6 mA or β‰₯ 21 mA indicates a fault
NE 107 Self-monitoring and diagnostics of field devices Four status signals: Failure, Function check, Out of specification, Maintenance required (revised July 2025)
NE 148 Modularisation of process plants Requirements that laid the foundation for Module Type Package
NE 175–178 NAMUR Open Architecture Concept, information model, security and write-back

NOA builds on these earlier recommendations. The diagnostic information that NE 107 makes available in a smart field device often goes unused in practice, because the control system only reads the measured value. NOA sets out to unlock that information.


🎯 What problem does NOA solve?

In the classic pyramid, and in the Purdue Model, all data travels upwards through the DCS. That works well for control, but poorly for Industry 4.0 applications:

  • Stranded data β€” modern transmitters hold dozens of parameters and diagnostic values, yet the DCS typically reads only the process variable.
  • Risk of change β€” every additional connection to the DCS needs validation and can affect availability or safety.
  • Slow innovation β€” a control system stays in service for twenty years or more, while analytics software and cloud applications change within months.

NOA therefore separates two worlds: stable, validated core process control and a flexible environment for analytics and optimisation. NOA was first presented at the NAMUR general assembly in November 2016 and was worked out in NAMUR working group 2.8 (Automation Architectures).


πŸ”§ How does the NOA second channel work?

NOA distinguishes two domains:

Domain Role Requirements
Core Process Control (CPC) Field devices, DCS, safety systems and operation Deterministic, highly available, validated, rarely changed
Monitoring + Optimization (M+O) Device management, condition monitoring, analytics, optimisation Flexible, quick to change, on-premises or in the cloud

The second channel takes data directly from the CPC world, for example via HART multiplexers, WirelessHART gateways or an edge device that listens in, and delivers it to M+O. NE 175 defines four building blocks:

  • NOA information model β€” a uniform data model based on OPC UA, so that M+O applications understand devices without custom engineering
  • NOA diode β€” the function that guarantees data flows only from CPC to M+O
  • NOA Verification of Request β€” a controlled route for change requests back into CPC
  • NOA Aggregating Server β€” optional bundling of several data streams into a single interface for M+O

πŸ“š Which NAMUR recommendations describe NOA?

NE Title Published Content
NE 175 NOA Concept July 2020 Architecture, domains and building blocks
NE 176 NOA Information Model June 2021 OPC UA model with device-independent and device-specific parameters
NE 177 NOA Security Zones and Security Gateway April 2021 Three security zones and protection profiles based on IEC 62443-3-3
NE 178 NOA Verification of Request March 2025 Steps for safely passing requests from M+O to CPC
NE 179 NOA Aggregating Server not yet published Aggregation of NOA data streams

The information model is closely aligned with PA-DIM (Process Automation Device Information Model), a protocol-independent OPC UA model for process instruments that is jointly maintained by organisations including NAMUR, FieldComm Group, the OPC Foundation and PROFIBUS & PROFINET International.


πŸ” How does NOA protect core process control?

The guiding principle of NOA is that M+O must never affect the availability or safety of CPC. NE 177 translates this into the language of IEC 62443:

  • Three zones β€” Core Process Control, M+O on-premises and M+O off-premises, in line with the zones and conduits model
  • Two protection profiles β€” NOA Basic and NOA Extended, which achieve different security levels from IEC 62443-3-3
  • NOA Security Gateway β€” enforces one-way traffic from CPC to M+O, with no feedback path

The NOA diode is a functional requirement, not a product name. For the basic profile a software solution is often sufficient, such as an OPC UA server that only grants read access. Where requirements are higher, you choose a physical data diode that makes return traffic impossible in hardware.

Writing into CPC never happens directly. Through Verification of Request (NE 178), every request, for example a new setpoint from an optimisation algorithm, is first checked for origin, plausibility and process context. It is then executed by an authorised party within CPC. The requester does not need to know the automation details of the plant.


πŸ”„ How does NOA relate to Purdue, MTP and OPA?

  • Purdue Model β€” NOA does not replace Purdue but adds a controlled side route. Data no longer has to climb level by level through the DCS and historian.
  • Module Type Package β€” MTP standardises the integration of process modules into the control system, so it lives inside CPC. NOA governs how data is used outside it. Both come from the NAMUR community and complement each other.
  • Open Process Automation β€” OPA redesigns the control system itself as an open, vendor-neutral system. NOA deliberately leaves the existing control system untouched.
  • Asset Administration Shell β€” the Industry 4.0 digital twin can carry device data from the NOA channel. Researchers at Otto von Guericke University Magdeburg have already modelled the NE 178 Verification of Request with proactive AAS.
  • Ethernet-APL β€” two-wire Ethernet all the way to the field makes the second channel simpler, because device data no longer has to pass through HART multiplexers.

🧭 How do you implement NOA step by step?

  1. Choose a concrete use case β€” for example pump monitoring, heat exchanger fouling or valve condition. Start small and measurable.
  2. Inventory the data sources β€” which field devices provide NE 107 diagnostics, which protocols are present (HART, PROFIBUS PA, Foundation Fieldbus) and what data is missing?
  3. Define zones and profile β€” carry out a risk assessment in line with IEC 62443-3-2 and choose NOA Basic or NOA Extended.
  4. Implement the NOA diode β€” using a read-only edge gateway, an OPC UA server or a hardware data diode towards M+O.
  5. Map to the information model β€” use NE 176 and PA-DIM so that applications recognise devices consistently.
  6. Organise operations β€” define who manages the gateway, how patching works and who may add M+O applications.
  7. Only then introduce write-back β€” exclusively through a Verification of Request process with clear approval.

For chemical and pharmaceutical companies in the EU that fall under NIS2, NOA helps unlock data without opening new attack paths into the control system.


❓ Frequently asked questions

What does NOA stand for?

NOA stands for NAMUR Open Architecture. It is an architecture concept from the process industry association NAMUR that makes process data available for monitoring and optimisation through a second channel. Core process control remains unchanged.

Is NAMUR Open Architecture a standard?

NAMUR Open Architecture is defined in NAMUR Recommendations (NE 175 to NE 178), not in an IEC or ISO standard. These recommendations are not legally binding, but they are widely followed in the process industry. For security, NOA does refer to the international standard IEC 62443-3-3.

What is the NOA diode?

The NOA diode is the building block of NAMUR Open Architecture that ensures data flows only from core process control to the monitoring and optimisation domain. Depending on the protection profile, this is done in software, for example with a read-only OPC UA server, or with a hardware data diode.

Can NOA write to the control system?

NAMUR Open Architecture does not allow M+O applications to write directly to the control system. Changes go through the Verification of Request concept from NE 178, in which every request is checked and then executed within core process control. This keeps the control system protected.

Does NOA work in existing plants?

NAMUR Open Architecture is explicitly intended for existing plants as well as new ones. Because NOA does not modify the DCS, the second channel can be built alongside the existing control system using HART multiplexers, WirelessHART gateways or edge devices. In greenfield projects, NOA can be included in the design from the start.

What is the difference between NE 43 and NE 107?

NE 43 defines which current values on a 4-20 mA loop indicate a fault: 3.6 mA or lower, or 21 mA or higher. NE 107 describes the four standardised status signals a field device uses to report its health. NAMUR Open Architecture mainly makes that NE 107 diagnostic data far more usable.


πŸ“Œ In summary

NAMUR Open Architecture adds a second, one-way channel alongside existing process control, through which field and process data flow securely to monitoring and optimisation. With NE 175 to NE 178, an OPC UA information model, security zones based on IEC 62443 and controlled write-back, NOA brings Industry 4.0 to the process industry without touching the control system itself.