Overseas Site IoT Implementation 2026: Thailand Factory RFP, 90-Day PoC and Operations
An overseas site IoT implementation succeeds only when the company decides, before choosing sensors or dashboards, who will use the data at the Thai factory, how far the Japan team may intervene remotely, and who makes operating decisions during a communications or cyber incident. This guide translates those questions into practical requirements for an RFP, an illustrative 90-day proof of concept, production transition, daily operations, OT security, backup and recovery. Ninety days and any thresholds discussed below are contracting examples, not statutory values or universal industry benchmarks.
Executive conclusion: procure a locally operable decision system, not a visualization project
Sending machine data to the cloud does not complete a factory IoT project. Management, the Japan headquarters, Thai production, maintenance, quality, IT, OT and suppliers use the same data for different decisions. If meaning, time, units, quality and ownership are unclear, teams return to calls and spreadsheets during an exception, while unmaintainable gateways remain on the plant network.
Make these six items RFP gates:
- Define the equipment, business decision, users and required evidence for each use case.
- Define responsibility boundaries among PLCs, sensors, gateways, plant networks and cloud services.
- Separate remote viewing from any authority to change a plant asset.
- Test missing data, clock drift, duplicates, delay and replay as acceptance scenarios.
- Include asset inventory, vulnerability handling, identities, certificates, backup and recovery exercises in operations.
- Define PoC success as evidence that a decision and support process can move to production, not merely that data appeared.
For commercial scoping, see IoT cost planning for a Thailand factory. For the plant wireless layer, see factory wireless LAN design in Thailand.
Why overseas factory IoT is harder than a single-country rollout
An overseas site combines generations of machinery, suppliers, protocols, maintenance documents, languages, shifts, vendor contracts and corporate IT rules. A tag that appears simple from Japan may be blocked because the original PLC program is missing, the machine warranty limits connections, the cabinet lacks power and space, or the local process name does not match the corporate master.
Remote monitoring is also an operating-model issue. When Japan sees an alarm, who contacts the local shift? Whose decision has priority? Is the machine stopped, or is data stale? May a specialist change a parameter remotely? If an RFP only says “monitor the Thailand factory from Japan,” bidders will assume different scopes, making price and acceptance incomparable.
The first deliverable should therefore be a use-case register, not a hardware list. For every row, record the user, decision, required data, freshness, acceptable gaps, notification route, local response, retention and audit evidence. Reviewing compressor energy intensity in a daily meeting is fundamentally different from detecting a hazardous state in seconds and stopping equipment. The latter must not depend on a general-purpose cloud notification.
Assign management, plant and IT/OT responsibility before issuing the RFP
IoT projects often fail because no one owns the source of truth. Include the plant manager, production, maintenance, quality, EHS, local IT, Japan business owner and corporate IT/security in the preparation team. The buyer should settle these decisions before asking a supplier to design the solution.
| Subject | Likely owner | Decision to fix in the RFP |
|---|---|---|
| Production condition and safety | Thai production and EHS | Whether IoT advises or participates in control |
| Equipment and tag semantics | Maintenance and engineering | Asset ID, unit, normal range and approval |
| Quality disposition | Quality | Reference data or data used for product release |
| OT network | Plant OT and maintenance | Zones, permitted flows and shutdown procedure |
| Identity and cloud | IT and security | Authentication, logs, data location and suppliers |
| Remote monitoring | Joint Thai and Japan team | Notification, first response and escalation |
| Data use and retention | Information owner | Reuse, export, deletion and contract exit |
Do not stop at a RACI chart. Test the allocation with an exception: the VPN drops on night shift, the gateway is buffering, and the Japan dashboard shows an old last value. Can the interface flag staleness, can the local team verify the process, and does everyone know who restores the connection?
Select Thailand factory IoT scope from closed-loop use cases
A larger PoC does not always produce better learning. Select a small scope that closes the loop from sensing to a local decision and follow-up. Candidates include energy monitoring, run/stop reasons, condition-based maintenance, process-condition records, utility anomalies, or linking a lot with machine conditions.
Rank candidates by pain, data accessibility, local ability to act, connection risk and repeatability. A sensor adds little if the plant has neither parts nor personnel to respond. Conversely, an existing PLC source combined with a daily review process can test operational capability even on a limited machine set.
For every use case, state the current decision process, who changes what after seeing the data, equipment and signals, event and sampling logic, operation during a gap, normal and exception acceptance tests, and the decision to retire, continue or scale after the PoC.
Use ISA-95 to align headquarters, ERP, MES and equipment boundaries
ISA-95 is a series for enterprise-control system integration. Its technology-neutral activity and information-exchange models, including the 2025 Part 1, are useful for assigning sources of truth and update direction. Do not use the familiar levels as decorative architecture.
Orders, purchasing, finance and official material master data may belong in ERP; detailed execution and equipment assignment in MES; instantaneous control in PLC or DCS; cross-site analytics in an IoT platform. These are candidates, not automatic rules. If the IoT layer invents asset identifiers that differ from ERP and MES, Japan cannot join analytics to production orders or lots.
An interface matrix should name sender, receiver, owner, key, unit, timestamps, create/change/cancel events, retry, out-of-order handling, duplicate protection and error quarantine. “API available” or “supports OPC UA” is not an acceptance specification.

Choose among OPC UA, MQTT and existing PLC interfaces
The OPC Foundation’s 2026 material describes OPC UA as the IEC 62541 industrial information-exchange standard designed for manufacturer- and platform-independent interoperability. It covers horizontal machine communication and vertical device-to-cloud exchange, supports client/server and PubSub patterns, and provides information models. OPC UA over MQTT is also addressed.
A protocol label alone does not prove interoperability. Specify profiles, information model, namespace and node rules, certificates, encryption settings, endpoints, source timestamps, status codes, history, events, reconnect behavior and server load. State where proprietary tags become a governed shared vocabulary.
MQTT can suit low-bandwidth publish/subscribe flows, but the RFP must define topic hierarchy, payload schema, QoS, retained messages, sessions, duplicates, order, certificate renewal and broker outage behavior. A QoS number does not by itself guarantee business-level exactly-once processing; require an event identifier and idempotent consumption.
If a legacy PLC cannot tolerate direct polling, use an approved SCADA, historian or gateway layer. Never expose a legacy industrial protocol directly to the internet. Place conversion inside a maintained security boundary with an explicit owner.
Architecture requirements for overseas factory remote monitoring
Separate outbound monitoring from remote actuation. For analytics, favor flows from the plant to a controlled boundary service and then to the approved cloud; do not create arbitrary internet-to-PLC access. Japan users should reach the dashboard through governed identity, multifactor authentication, roles, device conditions and session logging.
Where remote maintenance is necessary, avoid shared permanent VPN accounts. Require request and approval, a limited window and asset scope, a controlled jump environment, MFA, command logging, recording where justified, emergency termination and revocation at contract exit. Local staff must be able to see and terminate a remote session.
NIST SP 1800-45 became final on 24 June 2026 and presents three representative secure OT remote-access architectures built with commercially available technologies. It can inform RFP scenarios for authentication, authorization and protected communication. However, it is an implementation example for water and wastewater utilities of different capacities in the United States, not a standard that automatically applies to manufacturing. A Thailand factory must evaluate each pattern against its own asset risk, network and local procedures.
NIST SP 800-82 Rev.3 provides guidance for securing OT while accounting for performance, reliability and safety. As of August 2026, Rev.4 is a pre-draft and Rev.3 remains the published final baseline used here. Apply controls through risk assessment, maintenance windows, equipment constraints and plant safety procedures, rather than copying an IT configuration that could stop production.
Convert Secure by Demand into supplier evaluation
The CISA-led Secure by Demand guide for OT owners and operators helps purchasers ask vendors for secure products. Replace the vague requirement “the system shall be secure” with verifiable questions:
- Is the product secure by default, with unnecessary services and default accounts removable?
- Which MFA, role separation and centralized identity options are standard?
- What are the vulnerability-disclosure policy, notification route, fix-support period and end-of-support date?
- Can the supplier disclose software components and validate signed updates?
- Can logs be exported securely while retaining time and asset identity?
- Can configuration and data be exported in usable formats at contract exit?
- Can the plant remain in a safe state when the product is disconnected?
Classify every response as standard, configuration, custom, third-party dependency or roadmap, and require evidence in a demo or FAT. Do not score a roadmap item as a current capability.
Procure meaning, quality and time—not only a tag list
Each signal needs a global asset ID, local label, data type, unit, scale, source, source time, receive time, quality code, normal range, calibration context, owner and change history. Thai, Japanese and English labels should resolve to the same governed identifier.
Time is critical. Mixing a PLC clock, gateway clock and cloud receive time can reverse the apparent order of events. Define time source, UTC storage, local display, timezone, clock-drift flags and behavior after a clock jump. Thailand does not use daylight saving time, but a multi-site platform still needs explicit display rules.
Quality must distinguish missing, disconnected, out-of-range, under maintenance, manual, estimated and late-arriving values. If a dashboard holds the last value, show its age and status prominently. Presenting a stale value as current can drive a worse decision than showing no value.
Design the 90-day PoC as a small production system
The 90-day period is illustrative. Plant shutdowns, procurement, network works and production cycles may require another duration. The principle is to include real users, assets, shifts, communications failures and maintenance rather than a temporary demonstration.
Before Day 1: baseline and safety approval
Agree KPI definitions, baseline collection, connection approval, management of change, work permits, rollback, network drawing and asset register. Do not invent an improvement percentage; compare values gathered under the same definition. Route any potential safety-control impact through the plant’s formal risk and approval process.
Days 1–30: connectivity and data quality
Connect the selected tags and verify unit, time, status, gaps, retry, buffering and PLC load. Evidence the full path and every transformation. Deliberately interrupt the network, restart the gateway and simulate certificate failure, then inspect duplicates and order after recovery.
Days 31–60: operating process and exceptions
Thai users perform daily reviews, maintenance decisions and alarm response. Japan participates within its agreed remit and does not bypass local authority. Review alarm fatigue, shift handover, language, holidays, absence and false positives, then improve rules and training.
Days 61–90: security, recovery and scale decision
Exercise account review, privilege validation, log review, vulnerability response, backup restore, incident communications and contract-exit data return. Measure the work to add an asset, reusable data-model templates, local spares, licensing and communications cost.

Define a PoC acceptance scorecard
Do not decide with one efficiency percentage. Score business fit, data quality, OT safety, security, operability, scalability and total cost separately, with weights based on plant risk.
Evidence can include:
- records that intended users made the target decision in the agreed routine;
- detection and explanation of gaps, late values and duplicates in dashboards and logs;
- continued safe local operation during a communications loss and controlled resynchronization;
- proof that an unauthorized role cannot reach assets, settings or restricted data;
- local execution of gateway replacement, certificate renewal and account revocation;
- a measured restore of configuration and required data from backup;
- an agreed list of production gaps, costs, owners and dates.
If a requirement uses a number such as “99% data acquisition,” define the denominator, planned downtime, bad quality, late arrivals, tag population and measurement window. This guide does not recommend a universal threshold. Safety or control functions need separate, stricter engineering criteria.
Include OT backup and recovery in the IoT scope
NIST SP 1339, published in June 2026, identifies OT backup as vital to recovery from reliability and cyber incidents. It emphasizes integrating backups with change management, creating them regularly, testing them and reviewing them during recovery exercises. An IoT scope should cover gateway configuration, certificates, connections, tag transformations, relevant PLC/HMI configurations, dashboards, alarm rules, network settings and procedures—not only cloud history.
Ask what is backed up and on which change or schedule; who owns, encrypts and isolates it; whether replacement is possible without identical hardware; who performs restore tests; how restored configuration is reconciled to the plant; and how ransomware, cloud outage, certificate loss or vendor exit is exercised.
A successful backup-job log is not proof of recoverability. Restore to an isolated environment during the PoC or SAT and verify connections, roles, data, alarms and the documented procedure.
Embed Japan-to-Thailand monitoring in daily work
A remote center creates little value if Thailand and Japan chase the same alarm independently. Classify events as information, verification, local action or management escalation. Local approved safety and control procedures remain authoritative for emergency stops and actions.
Each alarm should carry asset ID, event time, data quality, current state, recommended check, local owner and escalation deadline. A Japanese explanation is insufficient if it does not map to Thai work instructions and machine labels. Record cause, action, part and downtime, then review recurring alarms monthly.
Japan is well placed to compare sites, provide specialist support, track unresolved issues and support investment decisions. It should not silently change a PLC around local approval. If emergency access is justified, use two-person approval, time and asset limits, command recording, emergency cutoff and post-event review.
Operate assets, accounts, certificates, patches and changes together
Gateways proliferate after deployment. The asset register should capture ID, model, serial, location, IP, firmware, OS, software, owner, maintainer, warranty, support end, certificate expiry, backup and permitted destinations. Promote every retained PoC device into formal production inventory.
Patching is neither uncontrolled automation nor indefinite deferral. Receive notices, assess impact, test, schedule in a maintenance window and preserve rollback. For OT equipment that cannot be patched promptly, assign compensating restrictions, monitoring and a deadline.
Certificates and service accounts do not trigger HR offboarding, so they are easily forgotten. Track issuer, purpose, private-key custody, expiry, renewal owner, revocation and replacement testing. Avoid shared identities. Include revocation of every vendor account, API key, VPN route and certificate in contract-exit acceptance.
Treat Thailand Smart and Sustainable Industry incentives carefully
The current Thailand BOI Smart and Sustainable Industry page states a minimum investment of THB 1 million, excluding land cost and working capital. For an existing project, it describes a three-year corporate income tax exemption capped at 50% of the investment. Where machinery connected with Thailand’s domestic automation industry accounts for at least 30% of the eligible machinery value, it describes a three-year exemption capped at 100% of the investment. Implementation must be completed within three years after the investment-promotion certificate is issued.
These are a summary of the published measure, not a promise that an IoT purchase qualifies automatically. Evaluate technical fit separately from incentive eligibility. Before ordering, confirm the eligible activity, value calculation, filing timing and evidence with BOI, NSTDA and other relevant bodies. Retain asset lists, improvement scope, investment records, invoices and commissioning evidence. This article is not tax, legal or investment-promotion advice.
Use common vendor-demo, FAT and SAT scenarios
Give every bidder the same input, network conditions, users and expected output.
Scenario A—normal collection and review: correlate equipment value, state, energy and production order; confirm that Thai and Japanese screens refer to the same asset, time and unit.
Scenario B—communications loss and replay: disconnect plant-to-cloud, observe local operation, buffering and stale-value indication, then inspect duplicates, order and gaps after recovery.
Scenario C—sensor fault: inject out-of-range, stuck and calibration-expired states and distinguish process abnormality from data-quality abnormality.
Scenario D—remote maintenance: allow a vendor into one asset for an approved period, retain activity evidence and prove access fails after expiry.
Scenario E—restore: recover configuration, certificates and mappings to a replacement gateway or isolated environment and ensure that only approved communication returns.
FAT evidences normal and exception flows in the configured environment. SAT uses actual Thai-factory PLCs, cabinets, power, network, time, language, shifts and security boundaries. Keep PoC approval separate from production acceptance; link gaps, workaround, owner and date to contractual milestones.

RFP question checklist
Business and data
- Are use case, user, decision, KPI and data owner clear?
- Can asset, tag, unit, time, quality and history be exported together?
- Do Thai and Japanese labels resolve to one master?
- Can missing, delayed, duplicate and estimated data be distinguished?
OT connectivity and availability
- Who evaluates PLC load and machine-warranty impact?
- How does the plant run during power, WAN or cloud loss?
- Can gateway replacement, offline buffering and resynchronization be tested?
- Is the boundary between safety control and IoT analytics documented?
Security and supplier
- Can the supplier diagram zones, allowed flows, remote access and logging?
- Are MFA, least privilege, certificate renewal and vulnerability notices standard?
- Are support end, third-party components, signed update and incident contact contractual?
- Can the buyer retrieve data and configuration and fully revoke supplier access?
Deployment, operations and cost
- Does the quote include survey, cabinet work, downtime, training and spares?
- Are license, cloud, network, support, update and export costs comparable over one term?
- What Thai first-line and Japan escalation hours are covered?
- Can PoC assets and data be governed and reused in production?
Common failure patterns
Calling a dashboard a successful PoC
The screen proves only a normal case. Include network loss, sensor fault, expired privileges, restore and night-shift response.
Letting Japan operate around the local plant
This overlooks local safety responsibility and actual equipment condition. Separate viewing from actuation and require approval, limits and evidence.
Collecting every tag first
Data without meaning and a user increases cost and attack surface. Start from use-case signals and govern additions.
Turning a temporary PoC into production unchanged
Shared accounts, unmanaged endpoints and temporary links survive. Add a production gate for inventory, configuration baseline, backup and support.
Promising an improvement percentage before measurement
Different definitions of downtime, missing data, shifts and product mix make the result invalid. Gather baseline and PoC results under one definition and disclose the window and exclusions.
FAQ on overseas site IoT implementation
How many machines should a Thailand factory IoT PoC include?
There is no universal number. Choose enough scope to test the full loop from data to local action and evidence. Include the template needed to repeat it on the next asset.
Can overseas factory remote monitoring be cloud-only?
Cloud aggregation and analytics are useful, but they do not replace local safety, control or operation during an outage. The design must include plant boundaries, buffering, identity, recovery and local procedures.
Should Japan be allowed to control a Thai PLC remotely?
Separate monitoring from control by default. If remote action is justified, require risk assessment, local approval, MFA, jump access, time and asset limits, command evidence, emergency cutoff and review.
Does OPC UA support guarantee plug-and-play integration?
No. Both sides must align profiles, models, certificates, security settings, nodes, units, time, quality and events, then prove them in FAT and SAT.
Is 90 days an industry-standard PoC duration?
No. It is an illustrative contracting period here. Choose a duration that covers works, maintenance windows and production cycles, and prioritize evidence of normal, exception, recovery and operation.
Does an IoT investment automatically qualify for BOI incentives?
No. Confirm current activity, investment excluding land and working capital, eligible machinery value and completion deadline with BOI, NSTDA and relevant bodies before commitment. Technical fit and incentive eligibility are separate decisions.
Summary: connect RFP, PoC and operations as one evidence chain
An overseas site IoT implementation should procure one operating model for Thai decisions and Japan support, not disconnected sensors, networks, clouds and dashboards. Use ISA-95 to clarify boundaries and ownership. Specify OPC UA or MQTT down to information models and failure behavior. Use NIST SP 800-82 Rev.3 as the current final OT security baseline, Secure by Demand for supplier evaluation, and NIST SP 1339 for change-integrated backup and recovery exercises.
Treat the 90-day PoC as a small production system that tests data quality, communications loss, remote access, local work and restore. Agree measurement definitions and avoid inflated promises. The final result is local operability and a repeatable pattern for the next asset.
If you need to turn a Thailand factory concept into an RFP, connectivity survey, 90-day PoC and operating model, contact TOMAS TECH even before the equipment list or architecture is fixed. We can structure a phased approach around the existing PLC and ERP without interrupting local production.
Primary references
- NIST, SP 1339 OT Backup Quick Start Guide
- NIST, SP 800-82 Rev.3 Guide to Operational Technology Security
- NIST, Operational Technology Security Publications
- NIST, SP 1800-45 Cybersecurity for the Water and Wastewater Sector: OT Remote Access
- CISA et al., Secure by Demand Priority Considerations for OT Owners and Operators
- OPC Foundation, OPC UA Interoperability for Industrie 4.0 and IoT 2026
- International Society of Automation, ISA-95 Standard
- Thailand Board of Investment, Smart and Sustainable Industry
Primary sources were checked on 27 August 2026. Standards and guides do not replace equipment-specific safety assessment or Thai legal and tax advice. Recheck official scheme conditions, product versions and support status immediately before procurement or application.