Industrial IoT promises a single pane of glass over assets, energy and production. In practice, the projects that succeed share a boring trait: they did the readiness work first. This checklist is the same one our integration team uses on the opening site visit — distilled from rollouts across mining, manufacturing, water and commercial buildings.
Most stalled IIoT projects fail at the cable, not the cloud. Segregate OT from IT, profile every device, and design for deterministic latency before adding a single sensor.
- Plant network segmented into Purdue-style zones with documented conduits between Levels 2, 3 and 3.5.
- Industrial DMZ (iDMZ) terminating every north-south flow — no direct PLC-to-cloud connections.
- Wireless coverage surveyed for 2.4 GHz / 5 GHz / private LTE blind spots in process areas.
- Failure-mode tested: what happens to control loops when the uplink drops for 60 seconds?
An IIoT rollout doubles your attack surface overnight. Treat IEC 62443 as the baseline, not the ceiling, and make sure incident response covers the production network too.
- Asset inventory complete for PLCs, RTUs, HMIs, drives and gateways — including firmware versions.
- Role-based access on engineering workstations; no shared admin credentials on the plant floor.
- Patch and backup cadence agreed with operations — including offline golden images of every PLC.
- IR runbook explicitly names OT containment steps (isolate, freeze, fall back to manual control).
Data without context is noise. Standardise tag naming, units and metadata at the source — before the first dashboard goes live — or you will rebuild the historian twice.
- Tag naming convention published (ISA-95 / ISA-88 aligned) and enforced in engineering reviews.
- Unified Namespace (UNS) or equivalent semantic model agreed with process and reliability teams.
- Time synchronisation via NTP/PTP across PLCs, gateways and historian — drift under 100 ms.
- Retention policy defined per tag class: high-resolution, aggregated, and cold archival.
The edge is where physics meets software. Choose protocols that survive intermittent links and gateways that can be remotely managed, updated, and observed.
- MQTT Sparkplug B (or equivalent) for store-and-forward telemetry with birth/death certificates.
- OPC UA for richer asset models where legacy DCS / PLC vendors support it natively.
- Edge gateways provisioned via zero-touch enrolment with signed firmware updates.
- Local buffering proven for at least 24 hours of disconnected operation.
Telemetry only creates value when it lands in the systems that drive decisions — CMMS for maintenance, ERP for production, EMS for energy. Plan the integration before procurement.
- CMMS (e.g. SAP PM, Maximo) integration scoped for work-order generation from condition alerts.
- ERP touchpoints identified for OEE, batch genealogy and material consumption.
- Energy management system fed sub-metered loads for ISO 50001 and Section 12L reporting.
- Event bus or middleware (Kafka, MQTT broker, iPaaS) chosen — not bespoke point-to-point.
Value cases & success metrics11
Pilots die when nobody can defend their ROI. Pick two or three use cases with hard baselines and a named operations sponsor before any sensor is procured.
- Top three use cases prioritised by annualised value (downtime, yield, energy, safety).
- Pre-rollout baseline measured for at least 90 days on the target asset or line.
- Success metrics agreed with finance — measured in rand, not dashboard views.
- Stage-gate plan defines what triggers scale-up from pilot to plant-wide rollout.
People, skills & governance12
Technology is the easy part. Without a control owner, a data steward and an empowered reliability engineer, the platform decays within twelve months.
- Named platform owner sitting between IT, OT and operations — with budget authority.
- Reliability and process engineers trained on the analytics tools, not just the dashboards.
- Change management process covers tag additions, model retraining and dashboard publishing.
- Vendor lock-in risks reviewed: data export, model portability, contractual exit clauses.
28 checks across 7 dimensions.
Count every box your site can defend with evidence today. Under 14: pause and remediate. 14 – 22: pilot ready, with named gaps to close in parallel. Above 22: scale with confidence.
Start the self-assessmentSign-in required · results saved to your account
References & further reading
Standards, regulators and industry research referenced above.
- [1]ISA-99 / IEC 62443-3-2 — Security risk assessment for system design
- [2]NIST SP 800-82 Rev. 3 — Guide to Operational Technology Security
- [3]IEC 62443-2-1 — Security program requirements for IACS asset owners
- [4]CISA — Cybersecurity best practices for industrial control systems
- [5]ISA-95 — Enterprise-control system integration
- [6]ISA-88 — Batch control models and terminology
- [7]Eclipse Sparkplug Specification v3.0 (MQTT for industrial data)
- [8]OPC Foundation — OPC UA Specifications
- [9]ISO 50001:2018 — Energy management systems
- [10]South African Income Tax Act, Section 12L — Energy efficiency savings allowance
- [11]McKinsey — Unlocking the industrial potential of robotics and IoT (2024)
- [12]World Economic Forum — Global Lighthouse Network insights
Related services
System Integration & IIoT
Edge gateways, MQTT/OPC UA, unified namespace and historian build-outs.
Instrumentation & Control
Field instrumentation, PLC/SCADA upgrades and IEC 62443-aligned design.
Advisory
Readiness audits, business cases and digital transformation roadmaps.
More from the field
Engineering writing on SCADA, edge, energy and safety systems.
