Insights · Digital Transformation · Featured

From SCADA to edge, without the rip-and-replace.

A seven-phase migration path that takes a legacy SCADA estate to a modern edge-and-UNS architecture — in parallel, by line, with the old stack still authoritative until the new one earns trust.

← All insightsPublished 09 May 2025 · 9 min read

Every operator we work with eventually asks the same question: how do we move on from this SCADA without breaking the plant?The honest answer is that you don't move on — you migrate around it. This is the phased path our integration team uses, refined across brownfield mines, water utilities and food & beverage sites.

Phase 01

Discover what you actually have1,2

Most SCADA estates are older, deeper and more entangled than the documentation suggests. Before any migration plan, map the truth: every PLC, every screen, every protocol and every analog cable that keeps the plant running.

  • Asset inventory: PLCs, RTUs, HMIs, drives, gateways — with firmware versions and end-of-life dates.
  • Protocol survey: Modbus, Profibus/Profinet, EtherNet/IP, DNP3, OPC Classic — including non-routable links.
  • Tag census: how many points are actively scanned, how many are stale, how many are duplicated across servers.
  • Operator interview round: which screens are used hourly, which are decorative, which are silently broken.
Phase 02

Model the plant before you move it3,4,5

A modern edge architecture lives or dies on its data model. Standardise an ISA-95 hierarchy and a unified namespace (UNS) on paper first — migrating tags into a clean model is far cheaper than migrating them twice.

  • Adopt an ISA-95 site → area → line → cell → asset hierarchy as the canonical topology.
  • Define a Unified Namespace that exposes context, not just raw tags (e.g. site/area/line/asset/metric).
  • Pick a semantic model — OPC UA Companion Specs, Sparkplug, or vendor-neutral JSON — and enforce it.
  • Agree units, engineering ranges and quality flags as part of the tag contract, not as comments in code.
Phase 03

Introduce the edge layer in parallel6,7

The lowest-risk migration runs the new edge alongside the existing SCADA, not in place of it. Edge gateways subscribe to the same PLCs, publish into the new UNS, and prove themselves for months before any control hand-over.

  • Deploy edge gateways (Ignition Edge, HiveMQ Edge, Litmus, AWS Greengrass or equivalent) read-only first.
  • Bridge legacy PLCs via OPC UA where available; fall back to native Modbus/EtherNet/IP drivers otherwise.
  • Publish to an MQTT broker using Sparkplug B for store-and-forward, birth/death and quality semantics.
  • Run the edge for at least one full production cycle before any downstream system depends on it.
Phase 04

Coexist — don't cut over8

A big-bang SCADA replacement is the textbook way to bring a plant to its knees. Run old and new in parallel, migrate one area or line at a time, and keep the legacy HMI authoritative until the new stack has earned trust.

  • Choose one non-critical line as the pilot — ideally with a recent control upgrade and good documentation.
  • Mirror critical screens on the new HMI/visualisation layer; operators decide when to switch primary view.
  • Keep historian dual-feed during transition so reports remain comparable across the cutover window.
  • Define explicit rollback criteria: latency, packet loss, alarm parity, operator confidence score.
Phase 05

Unlock analytics & integration9,10

Once the UNS is the source of truth, the value cases your old SCADA could never serve become straightforward: condition monitoring, OEE, energy attribution, batch genealogy and ML-driven anomaly detection.

  • Stream UNS topics into a time-series store (InfluxDB, TimescaleDB, Snowflake, Fabric) with retention tiers.
  • Push events to CMMS (SAP PM, Maximo) and ERP via an event bus rather than point-to-point integrations.
  • Stand up condition-monitoring and OEE dashboards on the new layer — leave the legacy SCADA for control.
  • Treat ML models as first-class deployable artefacts with versioning, rollback and drift monitoring.
Phase 06

Harden as you go, not at the end11,12

Edge gateways, MQTT brokers and cloud bridges materially expand the attack surface. IEC 62443 zones and conduits, signed firmware and least-privilege access have to be designed in — bolting them on after go-live is a project of its own.

  • Define IEC 62443 zones across Levels 2–3.5 with documented conduits and protocol whitelists.
  • Terminate every north-south flow at an industrial DMZ; no direct PLC-to-cloud connections.
  • Use mTLS and per-device certificates for MQTT clients; rotate via an internal PKI, not shared secrets.
  • Mirror OT events into the corporate SIEM — Splunk, Sentinel, Elastic — with OT-aware detections.
Phase 07

Operate the platform like a product13

The migration ends not when the old SCADA is decommissioned, but when an empowered platform team owns the new stack: roadmap, SLAs, change control, training and a clear backlog of value cases.

  • Named platform owner sitting across IT, OT and operations — with budget authority and a backlog.
  • Observability across edge gateways, brokers and historians: uptime, lag, message loss, queue depth.
  • Change control covers tag additions, dashboard publishing and ML model promotion — not just PLC code.
  • Training plan for control engineers, reliability and operations — analytics tools, not just dashboards.
Where to start

One pilot line. Ninety days. Read-only edge.

The cheapest way to de-risk a SCADA migration is to put an edge layer alongside the existing stack on a single non-critical line, prove the UNS for a quarter, then plan the rest of the rollout from real telemetry — not vendor slides.

Talk to our integration team

References & further reading

Standards, vendor references and industry research cited above.

  1. [1]NIST SP 800-82 Rev. 3 — Guide to Operational Technology Security
  2. [2]ARC Advisory — Asset inventory and OT visibility benchmarks
  3. [3]ISA-95 — Enterprise-control system integration
  4. [4]Unified Namespace — Walker Reynolds, 4.0 Solutions reference architecture
  5. [5]OPC Foundation — OPC UA Companion Specifications
  6. [6]Eclipse Sparkplug Specification v3.0
  7. [7]HiveMQ — MQTT and Sparkplug for industrial IoT
  8. [8]ISA-101 — Human-machine interface design
  9. [9]ISO 22400 — KPIs for manufacturing operations management (OEE)
  10. [10]ISA-88 — Batch control models and terminology
  11. [11]ISA-99 / IEC 62443 series — Security for industrial automation and control systems
  12. [12]CISA — Cybersecurity best practices for industrial control systems
  13. [13]World Economic Forum — Global Lighthouse Network insights

Related services & reading

Let's build

Have a project in mind? Let's scope it together.

Tell us about your site, your constraints and your timeline. We'll respond with a practical engineering perspective — not a sales pitch.

View projects