Automation Glossary • ISA-95 vs Purdue

ISA-95 vs Purdue Model: Same Levels, Different Job

Merobix Engineering • • 4 min read

People use ISA-95 and the Purdue model as if they were the same thing because they share a level diagram, but they answer different questions. This page compares them: what each was built to do, why their levels line up, and when you should reach for one rather than the other. It is written for the engineer or architect who needs to be precise about whether a level statement is about integration or about security.

Back to Blog

ISA-95 vs Purdue in one line: ISA-95 vs the Purdue model is a case of shared levels serving different jobs. The Purdue model is a reference architecture that uses numbered levels to organize how an operational-technology network is segmented and secured. ISA-95 uses the same levels to define how information is exchanged between control systems and business systems. Purdue answers where the security boundaries go; ISA-95 answers how integration is structured. They overlap because they describe the same plant hierarchy with the same numbered levels.

The Decision in One Paragraph

Reach for the Purdue model when the question is about network architecture and security: which zones exist, where the boundaries and conduits between them belong, and how to keep a compromise at one level from reaching another. Reach for ISA-95 when the question is about information exchange and integration: how a production request from the business system becomes a plant-floor instruction, and how plant data flows back up. The two use the same level numbers, so the vocabulary is shared, but the purpose is not.

In practice both come up in the same project and rarely conflict, because one is describing the security zoning and the other the data flow across the same hierarchy. The mistake is using them interchangeably in a way that hides which concern you are addressing. When you say Level 3, be clear whether you mean the operations-management functions ISA-95 places there or the security zone the Purdue model draws there, because the audience and the implications differ.

Why the Levels Line Up

The levels line up because both describe the same plant hierarchy: the numbered levels originate in the earlier Purdue reference architecture, and ISA-95 built on that same hierarchy when it defined its integration models. The table shows the correspondence and the differing emphasis.

LevelISA-95 emphasisPurdue emphasis
0-1Process and sensing/actuatingField zone to protect
2Supervisory control (SCADA)Control-system security zone
3Operations management (MES)Operations DMZ boundary area
4Business planning (ERP)Enterprise network zone

Because the numbers match, the ISA-95 model and the Purdue model can be read off the same diagram, which is exactly why they get conflated.

The most consequential Purdue-specific idea that ISA-95 does not emphasize is the boundary between operations and enterprise, often implemented as a demilitarized zone. Purdue treats that boundary as a security control point where traffic between the plant and the business is inspected and constrained. ISA-95 cares about the same interface but as an information-exchange interface, not primarily a security one. Recognizing which concern you are addressing at that boundary keeps a networking conversation and an integration conversation from talking past each other.

When Each Wins

The Purdue model wins any conversation about security architecture. When you are segmenting an OT network, deciding where firewalls and conduits go, or arguing about how far a threat could propagate, Purdue's zone-and-boundary framing is the right tool, and it maps onto the levels a security team already thinks in. If the deliverable is a network segmentation design, start from Purdue.

ISA-95 wins any conversation about integration and information. When you are defining how a production order flows from ERP to the plant, or how operations data rolls up to the business, ISA-95's models and interfaces are the right tool. If the deliverable is a data-exchange design between control and enterprise systems, start from ISA-95, and note that its badge is properly written as ISA-95-aligned rather than as any compliance certification, since no such certification scheme exists.

Frequently Asked Questions

Are ISA-95 and the Purdue model the same?

No. They share the same numbered levels, which is why they get confused, but they serve different jobs. The Purdue model is a reference architecture for network segmentation and security. ISA-95 defines how information is exchanged between control and business systems. Purdue answers where the security boundaries go; ISA-95 answers how integration is structured.

Why do they use the same levels?

Because both describe the same plant hierarchy. The numbered levels originate in the earlier Purdue reference architecture, and ISA-95 built on that same hierarchy, so Level 0 through Level 4 mean the same physical scope in both and a single diagram can carry both readings. The difference is emphasis: ISA-95 reads a level as a set of functions to integrate, and the Purdue model reads it as a security zone to protect.

Which should I use for network security design?

The Purdue model. Its zone-and-boundary framing, including the operations-to-enterprise DMZ, is built for deciding where firewalls and conduits belong and how far a threat could spread. ISA-95 is the better tool when the deliverable is an information-exchange design between control and business systems rather than a network segmentation plan.

More in Manufacturing & Machine Controls
ISA-88 batch model elements  •  ISA-95 hierarchy model  •  ISA-88 phase state model  •  ISA-88 physical model  •  ISA-88 procedural control model  •  All Manufacturing & Machine Controls →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →