For a Thailand factory, OPC UA 1.05 migration does not mean replacing every machine in 2026. In September 2026, the OPC Foundation said support for certification of OPC UA 1.03 will end at the end of 2026 and advised vendors to target 1.05. It did not say installed 1.03 devices would stop working, existing certifications would automatically expire, or plants must replace every device by that date. The practical decision is what to require when buying a new machine, gateway or client, how to assess existing assets, and what evidence to demand before acceptance. This guide turns that decision into an RFP, factory acceptance test (FAT), site acceptance test (SAT) and operations handover for a Thailand plant and its Japanese headquarters.
What the 2026 certification announcement actually changes
The September 2026 Compliance Corner explicitly addresses certification support for 1.03, recommends that vendors target 1.05, and notes that OPC UA 1.05.00 was released in 2021. Specifications, SDKs, toolkits and a 1.05 Compliance Test Tool (CTT) are available. Keep five different things apart: the specification version, a vendor’s implemented version, the version and configuration covered by a product certification, compatibility of a plant’s actual client/server combination, and the expiry of operational certificates. The same version number on two documents does not make those claims equivalent.
The Foundation’s CTT page still lists 1.05, 1.04 and 1.03 tool releases dated 20 April 2026. Listing a test tool for an older version does not contradict a later plan to end certification support for that version. A vendor’s CTT self-test is also not a Foundation certification. The certification process describes testing of exposed functions, profiles, interoperability, robustness and lab preparation. Ask which exact product build was tested, by whom, against which functions, and when.
Define two procurement paths. For new equipment and gateways, decide where 1.05 is a required delivery condition. For installed 1.03 systems, decide which assets need an upgrade now and which can remain under documented support and risk controls. Applying a single year-end deadline to both paths can cause unnecessary shutdowns while leaving real interface defects untested.
Certification support is different from plant operation
An OPC UA specification, a product certification and a working factory integration describe different levels of evidence. An embedded server may implement 1.03. The supplier may have a certification for a different product build. The plant may still need its MES client to interpret values correctly. A certification logo in a catalogue does not prove that the quoted model, firmware, licence, profile and role match the certified configuration. Equally, an installed 1.03 device does not become unusable simply because certification support for 1.03 is scheduled to end.
Assess each asset’s installed version, support contract, security update path, downtime window, warranty and future procurement need. A moulding machine’s embedded server may be hard to change without affecting the machine warranty. A new 1.05-capable gateway that has been tested with that server may be a sensible option. But a gateway cannot repair unknown source semantics: units, quality, timestamps, asset IDs and reset rules still need an owner. Obtain the equipment maker’s permission and clarify safety and change responsibilities before touching a running line.
“Supports 1.05” is not a complete acceptance criterion. Specify server/client roles, relevant profiles, required services, information model, certificate handling, data quality and reconnection behaviour. Use the OPC UA online reference to identify the applicable part and edition, then obtain the supplier’s implementation statement rather than inferring functionality from the version label.
Build an asset and interface register before the RFP
Start with observed assets, not a shopping list. Record equipment and plant asset IDs, local Thai names, machine maker, product model, firmware, server/client role, endpoint, current specification version, exposed nodes, certificates, connected systems, maintenance owner, change approver and warranty constraints. Mark unknown facts as “to verify” with an owner and date; do not fill blanks with assumptions from a catalogue.
Map the data route as well. Does a value travel from PLC to embedded server or through an external gateway? Which switch, network zone and client are involved? Does MES receive a raw tag or a transformed business event? Where is the timestamp assigned? Who issues, renews and revokes trust certificates? This register shows when a licence update, time synchronisation, data model correction or extra test is preferable to replacing a functioning machine.

The boundary in Figure 1 separates existing assets from new scope. Put identifiers on the drawing that match the register. This makes it harder for the machine builder, Thai system integrator, MES vendor and Japanese headquarters to classify the same interface as “the other party’s work”. Identical tag names are insufficient when their units, quality or reset conditions differ.
Specify OPC UA 1.05 in an RFP that suppliers can price
A single line reading “OPC UA 1.05 compliant” lets bidders price different scopes. State whether you need a server, a client or a gateway with both roles. Request the quoted model, hardware and software revisions, firmware, optional licences, support in Thailand and any prerequisites. Put “implemented and available now” in a separate column from a future roadmap promise.
Use profiles to express the required functional scope. OPC UA Part 7 relates profiles, conformance units and test cases. Select what the business needs rather than requiring every optional feature: Data Access, events, history, methods or PubSub, for example. If an industry Companion Specification matters, request its edition and delivered nodes. Publication of a Companion Specification alone says nothing about an individual machine’s implementation.
| RFP field | Supplier response | Buyer evidence |
|---|---|---|
| Delivered build | Model, HW/FW/SW, licence, interface role | Quote, datasheet and test-unit match |
| OPC UA scope | Edition, profile, conformance units, options | Implementation matrix and test record |
| Endpoint and security | URL, port, policies, authentication | Configuration export and FAT screen |
| Information model | Namespace, NodeId policy, type, unit, quality and time | NodeSet/export and tag dictionary |
| Failure behaviour | Disconnect, restart, gap, retry and duplicate handling | Fault-injection record |
| Maintenance | Certificate lifecycle, upgrade, backup, recovery and access | Procedure, owner and training record |
This matrix makes quotations comparable; it does not replace the technical specification. Require limits, extra charges and the production configuration behind every “yes”. Decide whether Foundation certification is mandatory for this purchase according to use and risk. This article does not claim a general legal requirement for every plant purchase to be certified. Even without making certification a contractual condition, the buyer can demand concrete FAT and SAT evidence.
Compare the whole migration scope, not a protocol checkbox
Quotes differ because one may include the server licence and certificate interface while another prices a communication card, gateway, integration labour or Thai-language handover separately. Compare firmware and vulnerability support, spare-unit restoration, onsite response, remote support, operational training and the maintenance term alongside hardware cost. For the delivery build, record the exact versions. If a supplier upgrades the FAT unit but delivers older spare stock, the FAT result no longer proves the delivered build. Treat a changed NodeId, enum, name or exposed field as an interface change requiring impact assessment and retest.
If the supplier promises compatibility with an installed 1.03 endpoint, provide a representative source configuration and ask which actual asset will be used for verification. Check the endpoint’s security policy, certificate authority, necessary nodes, number of clients, load and machine warranty. Simulate an unavailable plant asset at FAT and confirm the real connection during SAT. “Both speak OPC UA” does not allocate interface responsibility.
Freeze the FAT build and test both normal and fault cases
Before the supplier FAT, freeze the test machine model, serial, firmware, software, licence, OPC UA version, profiles, settings and client/server pairs. A demonstration on a related model is not proof for the contracted product. Capture this identity, date, test operators, result and evidence path on the first page of every test record.
Normal tests must cover the nodes the plant actually needs, with datatype, engineering unit, range, StatusCode, SourceTimestamp, ServerTimestamp, update interval and event order. Check whether a counter includes rejected parts, when it resets and whether a stale last value is shown as a live reading. Confirm that a read-only MES interface has no wider write privilege. A convenient demo tag is not a substitute for the production node list.
Fault tests should include cable loss, server and client restart, certificate expiry, untrusted certificates, clock skew, Bad or Uncertain value quality and a temporarily missing node. There is no universal acceptable reconnection time or data-loss threshold; the buyer must set values per use case. Record what is lost or duplicated, who is alerted, and how plant staff reconcile the result after recovery. “Reconnected successfully” alone is not a business acceptance result.

The Foundation’s 2026 European interoperability workshop describes testing clients and servers from different vendors, debugging failures and recording results. That is a useful testing pattern for a local FAT. Participation in that event is neither a requirement for a Thailand plant nor a product certification. Test the combination that the plant will actually receive.
Keep CTT records and formal certification in separate columns
The CTT is useful for testing client and server conformance. A screenshot or self-test report, however, must not be presented as “certified”. The Foundation’s How to Certify describes a separate lab process. Maintain separate evidence for supplier self-tests, cross-vendor interoperability tests and Foundation certification. Verify product name, revision, role, profile and any excluded features before relying on a certificate for the quoted build.
Avoid demanding redistribution of the CTT itself in the RFP; its access and licensing conditions are governed by the Foundation. Ask for test configuration, results, gaps and reproducible steps. A certified generic server still does not define this plant’s downtime codes, lot associations or MES mappings. Product compliance and process data correctness need separate acceptance.
Use SAT to accept the real Thai plant and its operating team
At site acceptance, compare installed hardware, firmware, settings, cabling and network zones with the FAT baseline. Schedule Thai maintenance and operations staff and name who can authorise a test interruption. For hazardous fault scenarios, follow machine-safety procedures and maker approval; simulate safely or use a non-production window where required.
Correlate MES records, machine display and PLC/device log over the same period. Does a stop signal mean machine fault or material wait? Is the counter good pieces or all cycles? Can a stale value be mistaken for the present one? Are buffered events replayed twice after a long outage? Does missing data become a false zero-production record? Specify pass criteria and manual reconciliation before testing. These questions cannot be settled by a generic OPC UA certificate.

At handover, receive as-built diagrams, backed-up configurations, account and certificate procedures, log locations, spare-unit versions, support contacts and recovery instructions. Have a Thai maintenance owner rehearse reconnection and certificate renewal. Neither a headquarters-only secret nor an undocumented local change is a sustainable operation. Store credentials under the plant’s IT/OT policy, with appropriate access controls.
Treat security, quality and networking as operating requirements
A version change does not repair an over-broad trust list or privileges. Assign owners for network segmentation, permitted flows, user and application certificates, read/write rights, audit logs and renewal monitoring. Do not leave “trust everything” or unencrypted test settings in production. Keep safety control outside an MES data collection design.
Maintain a versioned tag dictionary with asset ID, datatype, unit, source, timestamp, quality, normal range and change owner. A replacement machine can retain a familiar NodeId while altering scale, enum or reset semantics. Review all reports, alarms, quality rules and traceability searches affected by a change.
For LAN zones and physical connectivity, see our industrial network construction guide. OPC UA FX/TSN deployment is a separate field-level decision; it is not a synonym for a client/server version migration. For northbound designs, see the OPC UA cloud reference solution. This article concentrates on purchasing, testing and operating a specific 1.05-capable interface.
Sequence the migration around procurement and downtime
First update specifications for new purchases and require evidence for the delivered build. Then prioritise installed assets with expiring support, unpatchable security issues, frequent failures or missing required data. A stable, supported 1.03 asset may remain under monitored change control while the plant tests its connection to a new 1.05 client or gateway. Make this an explicit asset decision, not an assumption based on a version label.
Use a test bench, compare old and new paths in parallel where feasible, and retain quality and timestamp differences rather than checking only numerical equality. Before cutover, prove the rollback, backup restoration, spare version and support contact. Coordinate the Thailand plant’s permissible stop window with Japanese support hours. Put evidence gates at RFP comparison, FAT and SAT. FAT alone cannot prove the real plant network and data semantics; SAT alone is a costly place to discover a fundamental unsupported feature.
RFP clause you can adapt
The supplier shall identify the delivered product model, HW/FW/SW revision, required licences, OPC UA Client/Server role, supported specification edition, profiles, information model and limitations. Where OPC UA 1.05 support is offered, the supplier shall provide evidence for the quoted delivery build. Any claim of OPC Foundation certification shall identify the product, revision and profile to which it applies. The supplier shall conduct FAT and SAT against the buyer’s specified installed peers, nodes, units, timestamps, quality, certificate and permission rules, and disconnection/recovery scenarios, recording open defects and corrective actions.
Set certification as required or optional only after evaluating the use case and supplier market. Attach a detailed node list, threshold table and responsibility matrix. In multilingual contracts, keep “supports”, “self-tested” and “certified” in separate evidence columns so translation cannot blur them.
Resolve FAT/SAT failures with a controlled retest
Finding a defect during acceptance is useful; leaving it as an undefined “adjustment in progress” is not. For each failed case, record the expected and observed results, reproducible steps, equipment and configuration revisions, business impact, temporary operation, corrective owner and due date. If a production event arrives twice after reconnection, reconnecting successfully does not pass the case until MES double counting is addressed. A display-order difference with no effect on decisions may be handled as an agreed change request, but the buyer should record why it is acceptable.
After a correction, rerun the failed case and related normal and fault cases. A trust-list fix calls for normal connection, rejection of untrusted certificates and reconnection after renewal. A NodeId or unit correction may affect history, reports, alarms and traceability search as well as the screen. Capture firmware and configuration versions at retest so the FAT-to-SAT difference can be explained.
Name the person who may hold acceptance or grant conditional acceptance before testing. The supplier alone should not classify a defect as minor. If quality decisions, safety, lot tracking or data completeness are involved, the Thailand plant owner needs to understand the temporary procedure and residual risk. Any conditional go-live should have a monitoring rule, deadline, retest date and final approver. Use the same test IDs and equipment IDs in Japanese, Thai and English records, linking raw data, screenshots, logs, timestamps and signatures so local staff can repeat the scenario later.
Frequently asked questions
Will installed OPC UA 1.03 devices stop working at the end of 2026?
The Foundation’s September announcement concerns the end of 1.03 certification support, not automatic device shutdown or automatic revocation of existing certification. Decide continued use from the specific supplier’s support, security, compatibility and plant risk. Target 1.05 for new procurement and verify the quoted build.
Is OPC UA 1.05 support the same as Foundation certification?
No. A vendor’s implementation claim, a CTT self-test, a cross-vendor interoperability result and formal certification are different evidence. Check the covered product build and profile. FAT and SAT are still needed for factory-specific data meaning and failure behaviour.
What determines migration cost?
The scope of firmware, licences, gateways, installed-machine changes, test equipment, information-model mapping, certificates, installation windows, training and support. A universal price without an asset register and RFP responses would be misleading.
Can SAT repeat the FAT script and stop there?
Retain common normal tests, but FAT checks a reproducible supplier build and SAT checks installed equipment, network, time, permissions, real data semantics and local recovery. A FAT pass is not a reason to omit SAT.
Must OPC UA FX or cloud integration be bought at the same time?
No. Field-level communication, plant-to-MES integration and cloud aggregation are related but separate scopes. Specify each against a use case and its own evidence.
Conclusion
The planned end of 1.03 certification support is a clear prompt to review new purchases, not a blanket shutdown deadline for installed machines. Build the asset register, state 1.05 profiles and product identity in the RFP, verify the quoted build at FAT, verify plant meaning and operations at SAT, and hand over certificates, backups, time and quality rules to named owners.
TOMAS TECH can help Thailand factories prepare an installed-interface register, RFP requirement matrix and FAT/SAT evidence plan while the project is still being scoped. If your machine list or current connection problems are not yet complete, contact us to discuss the starting point.
Sources
- OPC Foundation, Compliance Corner – September 2026 — certification-support statement.
- OPC Foundation, OPC UA Compliance Test Tool — tool purpose and version listings.
- OPC Foundation, How to Certify — formal certification process.
- OPC Foundation, OPC Interoperability Workshop 2026 Europe — cross-vendor testing pattern.
- OPC Foundation, OPC UA Part 7: Profiles — profile, conformance unit and test-case structure.
- OPC Foundation, OPC UA Online Reference — specification index.