The Purdue model - short for the Purdue Enterprise Reference Architecture - is the layered blueprint that most industrial networks are still designed around today. It divides an operation into numbered levels, from the physical process at the bottom to business systems at the top, with a buffer zone in between. It is the mental map engineers use when they say a device belongs "at Level 2" or that traffic must pass through "the DMZ."
Purdue Model in one line: The Purdue model (Purdue Enterprise Reference Architecture) is a reference architecture that segments an industrial control environment into hierarchical levels - from field instrumentation up to enterprise IT - to organize network design, data flow, and security boundaries.
The Purdue model runs from Level 0 to Level 5. Level 0 is the process - the physical equipment being controlled. Level 1 holds basic control: PLCs, RTUs, and controllers. Level 2 is area supervisory control, including HMIs and local SCADA. Level 3 is site operations - historians, production management, and engineering workstations. Above that sits Level 4 (site business systems) and Level 5 (enterprise IT), which together form the corporate IT domain.
A defining feature is the industrial demilitarized zone (IDMZ) placed between Levels 3 and 4. It acts as a controlled buffer so that OT systems below never talk directly to IT systems above. Data crossing that boundary is brokered through the DMZ, which is why historians, patch servers, and remote-access jump hosts often live there.
The model was created for discrete manufacturing decades ago, and modern realities - cloud services, IIoT sensors, and remote monitoring - do not always map cleanly onto its rigid layers. Cloud SCADA, for example, deliberately moves some functions off-site, which challenges the assumption that Level 3 lives on-premise. Many teams now treat Purdue as a conceptual guide rather than a strict wiring diagram.
Even so, its core principle endures: segment the network, control every boundary crossing, and never let enterprise traffic reach controllers directly. That discipline underpins most OT security programs. A cloud platform that respects these boundaries typically collects data through an edge gateway or DMZ broker rather than exposing controllers, which is how Merobix connects to field devices while keeping the control layer isolated.
Yes, though it is applied more flexibly. Cloud SCADA and IIoT sensors bend the strict level boundaries, so many organizations use Purdue as a conceptual framework for segmentation and boundary control rather than a literal network topology. The underlying goal of isolating control from enterprise traffic remains.
The industrial demilitarized zone sits between Level 3 (site operations) and Level 4 (business systems). It is a buffer network where data is brokered so OT and IT never connect directly - hosting things like replicated historians, patch servers, and remote-access jump hosts.
They complement each other. Purdue supplies the layered network architecture; ISA-95 aligns functional models and enterprise-control interfaces to comparable levels. Engineers commonly reference both when designing how the plant floor connects upward.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.