Blog

2026.09.07

Thailand MES 2026: RFP, 90-Day PoC and Acceptance Guide

Thailand MES 2026: RFP, 90-Day PoC and Acceptance Guide

Thailand MES 2026: RFP, 90-Day PoC and Acceptance Guide

When selecting a Thailand MES, the first comparison should not be a long feature matrix. The decisive question is whether the project can turn factory constraints, quality records, ERP boundaries, data ownership and local support into evidence strong enough for an investment decision. This guide gives factory managers and regional IT/OT leaders a practical 2026 route from readiness and BOI screening through a 100-point RFP, a 90-day PoC, FAT/SAT/UAT and the operating model after rollout.

Conclusion: select a Thailand MES by designing evidence, not watching demos

The reliable sequence is to limit the line and loss to address; define the ERP, MES/MOM and SCADA/PLC boundary with ISA-95; and turn interfaces and data ownership into contractual requirements. Score vendors with a weighted RFP, then test normal operation, outages, replay, exceptions, recovery and access control in a 90-day PoC. Make the decision from observable FAT, SAT and UAT evidence.

BOI measures may affect the investment case, but buying MES does not automatically qualify a project. Screen the investment, timing, equipment and software scope, and domestic automation linkage against current BOI conditions. The 50% and 100% figures are caps on the amount of the three-year corporate income tax (CIT) exemption, not subsidy rates. Likewise, ISA-95, OPC UA, NIST SP 800-82 and IEC 62443 are useful design references; a label on a product is not a guarantee of interoperability or security.

TOMAS TECH can support a Thailand factory while it is still assessing readiness, drafting an RFP or planning a PoC. If equipment downtime is constrained, the ERP boundary is unclear or multi-site rollout conditions need definition, contact TOMAS TECH at the planning stage.

Why MES selection matters for Thailand factories in 2026

Thailand BOI’s Smart and Sustainable Industry measure supports efficiency improvement and the transition toward smart and sustainable industry. Its current page describes a minimum efficiency-enhancement investment of THB 1 million, excluding land and working capital; machinery import-duty exemption; and a three-year corporate income tax exemption capped at 50% of qualifying upgrade investment. The page states that this three-year CIT exemption cap rises to 100% when machinery that connects to or supports Thailand’s domestic automation industry represents at least 30% of the total value of machinery, automation systems and robots used or improved under the project. The 50% and 100% figures are CIT-exemption caps, not subsidy rates. This is an eligibility screen, not tax advice. Confirm the latest rules and the eligibility of the specific project before applying.

In a 2026 release, BOI reports 1,397 applications/projects and more than THB 146 billion in investment from the measure’s start in 2023 through the first half of 2026. It also describes a Thai electronics manufacturer combining AGV, image processing and IIoT, with MES connecting production-line machinery to ERP. These are BOI-reported totals, not independent market statistics. They nevertheless show why connected execution data, rather than isolated automation, belongs in the investment discussion.

Purchasing too early exposes unresolved issues later: unavailable signals, inconsistent shop-floor codes, mismatch between ERP material/orders and actual production, and shutdown risk on legacy assets. Readiness therefore precedes a software demo. NSTDA’s Sustainable Manufacturing Center presents the Thailand i4.0 Index as an industrial-readiness assessment context connected to DX roadmaps and implementation involving IoT, AI and automation. Do not invent a required score or certification. Use readiness work to ask what can be measured, who can operate it and which failure conditions the factory can tolerate.

Thailand factory MES readiness: 12 questions before the RFP

Factory management, production, quality, maintenance, IT, OT and planning/finance should answer these questions. “Undecided” is acceptable because exposing an undecided responsibility is the point.

  1. Where do the product, process and line scope start and end?
  2. Is the target loss downtime, changeover, scrap, traceability, WIP, progress visibility or recording labor?
  3. Who measured the baseline, under what definition and during which period?
  4. Which PLC, machine, inspection and measurement signals are available or unavailable?
  5. Where will manual entry remain, who owns it and how much delay is acceptable?
  6. Do ERP material, BOM, routing, work-order and inventory-unit masters match the floor?
  7. At what granularity must material, lot/serial, operator, equipment and process values be linked?
  8. During network or server failure, must production continue, degrade or stop safely?
  9. Which system is authoritative, and who owns correction, approval and audit history?
  10. Which languages—Thai, English, Japanese or others—are needed for UI, reports and training?
  11. Who triages night or holiday incidents, and when are they escalated?
  12. After one-line success, what becomes a site standard and what remains a local variation?

The output should be seven concrete artifacts: scope diagram, current data flow, connection inventory, code-mapping table, outage/recovery policy, responsibility matrix, and baseline/measurement definition. For the general introduction sequence, see the Thailand MES implementation guide.

Use ISA-95 to define ERP, MES/MOM and SCADA/PLC boundaries

In the common ISA-95 model, Level 4 covers business planning and logistics, including ERP, while Level 3 covers manufacturing operations management, where MES/MOM typically sits. PLCs and DCS are typically Level 2 control systems. Depending on implementation scope, SCADA may sit at Level 2 or extend toward Level 3 and the Level 2/3 boundary through supervisory, historian and operations-coordination functions. ISA-95 Parts 2–5 address interface objects, activity models, operations-management integration objects and transactions between business and manufacturing.

LayerPrimary responsibilityTypical dataAmbiguity to prevent
ERP / Level 4Demand, purchasing, inventory accounting, master planning, costingMaterial, BOM, work order, planned quantity, inventory unitERP and MES both independently correcting orders or stock
MES/MOM / Level 3Dispatch, execution, WIP, quality, traceability, aggregationStart/finish, genealogy, defects, downtime, consumptionNo named owner for exceptions or history correction
SCADA / Level 2–3 boundarySupervision, history and operational coordination according to scopeState, alarms, history and aggregated tagsAssigning a level or source of truth from the product name alone
PLC/DCS / typically Level 2Sequence, interlock and real-time controlTags, I/O, cycles and process valuesMES or SCADA being used as an unsafe substitute for control
Thailand MES 2026: RFP, 90-Day PoC and Acceptance Guide - figure 1

Product boundaries vary. SCADA may include history or production functions; MES may include planning; ERP may expose shop-floor screens. Resolve names by assigning, for every business event, one source of instruction, one source of actuals, one duplicate-replay rule and one correction authority.

OPC UA supports information exchange from industrial devices and control systems through MES and ERP with common information, message, communication and conformance models. A common protocol does not make tag meaning, units, quality flags, timestamps or equipment-state definitions identical. OPC UA is one connection condition; a data contract and site-specific security design remain necessary.

MES requirements: freeze scope, ownership and exceptions

A strong MES specification says more about abnormal conditions than about screens in normal operation. Bound the scope by product, process, equipment, user, shift, report and interface, and state exclusions. A one-line PoC might include work-order dispatch, material-lot verification, completion, key defects and downtime reasons while excluding advanced scheduling, full maintenance and enterprise BI.

Assign ownership item by item:

  • Who creates material, BOM, routing and work orders, and when are they sent to MES?
  • Where are actual production, WIP, consumption, completion, defect, scrap and rework authoritative?
  • Who approves genealogy creation, split, merge and cancellation?
  • Who owns tag name, unit, scale, quality and timestamp?
  • How are unknown lots, duplicate messages, reversed order and clock drift handled?
  • How long are original value, changed value, reason, approver and time retained?
  • At contract exit, in which documented format can data, configuration, history and attachments be exported?

“An API is available” is not a requirement. For every interface, document source, destination, event, mandatory fields, key, unit, time base, frequency, maximum delay, retry, deduplication, error notification and recovery owner. MES–ERP integration especially needs idempotency when the same order is replayed, reprocessing after partial failure, post-close corrections and buffering during outages.

A 100-point MES RFP scorecard

Set weights and mandatory gates before receiving proposals so presentation quality does not determine the winner.

DimensionWeightEvidence requested
Production, quality and traceability fit25Factory scenario, exceptions, genealogy and audit history
Integration and data ownership20ERP/equipment interface, API, dictionary, export and deduplication
Operational resilience and offline recovery15Outage, buffer, replay, redundancy, RTO/RPO test
OT cybersecurity15Asset/account control, segmentation, encryption, logs, vulnerability/update process
Rollout and local support15Thailand coverage, languages, training, site template and SLA
Lifecycle, TCO and exit10Five-year cost, upgrade, licensing, migration and exit
Total100

Create pass/fail gates as well: MES must not replace safety control; privileged work must not use a shared account; audit history cannot be silently deleted; data must be returned in a documented format at exit; and outage recovery must be demonstrated in the PoC. A proposal failing a gate is held even with a high score.

Production, quality, maintenance, IT/OT, management and procurement should score independently and record why they differ. Distinguish standard function, configuration, customization, external product and unsupported requirements. For customization, evaluate schedule, test and maintenance ownership. Require proof through a screen, log, configuration, design record, comparable reference or PoC result—not a sales assertion.

The 90-day MES PoC in five stages

A PoC is not a showroom. It is a test capable of disproving the investment hypothesis. A single line and limited interfaces are appropriate, but exceptions and recovery must remain in scope.

Days 0–15: baseline and scope

Freeze product, process, equipment and shifts. Measure downtime, recording delay, traceability search time and re-entry count under consistent definitions. Assign stakeholders, decision maker and data owners in a RACI. Document exclusions and change control. “Cannot measure yet” is a valid discovery.

Days 16–30: interfaces and data contracts

Define events for ERP orders, material, BOM, machine tags, quality results and completion. Agree keys, units, clocks, mandatory/optional fields, retries, duplicates, reversed sequence and error codes—not only happy-path sample messages. If production assets cannot be changed safely, use a read-only connection or edge buffer in the test architecture.

Days 31–60: one-line PoC

Execute order receipt, start, material verification, completion, quality record, finished-good posting and ERP return. Observe whether operators can use the needed Thai or other language, hand over between shifts, recover from scan errors and work with acceptable terminal response. Treat every return to paper or a spreadsheet as a defect to understand.

Thailand MES 2026: RFP, 90-Day PoC and Acceptance Guide - figure 2

Days 61–75: exception, recovery and cyber tests

Test network loss, ERP downtime, MES restart, duplicate orders, unknown lots, wrong scans, equipment clock drift and unauthorized actions. Confirm continue/stop criteria with the safety owner. Capture buffer order, replay, prevention of double counting, alert, audit log and backup restoration as evidence.

Days 76–90: shadow operation, UAT and decision

Run MES beside the current record and reconcile daily. Sign UAT when conditions pass; for gaps, retain severity, workaround, owner and due date. Decide Go, conditional Go, repeat PoC or No-Go using the RFP score, acceptance results, operating load, five-year TCO and status of BOI eligibility review.

For multiple plants, separate the common template from Thailand-specific variations. The ASEAN multi-site factory IoT rollout guide expands on standardization and local variation.

Observable acceptance tests for FAT, SAT and UAT

FAT normally verifies the specification in the supplier environment; SAT adds the actual site network, terminals, equipment and surrounding systems; UAT is acceptance by business users in their operating scenarios. Contract names can differ, but identify who tests what, where, with which data and evidence.

TestActionPass conditionRequired evidence
Order idempotencySend the same keyed order three timesOne valid order; duplicates logged and alertedMessage log, screen and record count
Wrong material preventionScan a lot not valid for the orderWork blocked or routed to controlled approvalScan history, warning and approval log
Complete genealogySearch material-to-product and product-to-materialParent/child and process history reproduced for scopeQuery result and source reconciliation
Outage recoveryDisconnect, generate events, reconnectAgreed continue/stop behavior; no loss or duplicateTimes, buffer, replay and count reconciliation
Clock driftMove edge time outside toleranceAlarm raised; event not finalized in a false orderAlert, synchronization log and held record
AuthorizationOperator attempts master changeDenied and attempt auditedRole matrix, denial and audit log
Record correctionCorrect a quality value with reasonOriginal/new value, reason, requester, approver and time retainedChange and approval history
Backup restoreRun the agreed restore procedureConsistent recovery within agreed RTO/RPOTiming, restore log and record reconciliation
Shadow reconciliationCompare legacy and MES records dailyWithin agreed tolerance; every difference explainedDaily sheet and discrepancy ticket

Do not copy a universal RTO, RPO, response time or tolerance; derive it from production, safety and quality needs. Preserve test input, software/configuration version, executor, time, log location, differences and retest. For more detail on interface and evidence design, see the Thailand manufacturing data collection PoC/RFP guide.

An illustrative investment calculation without an ROI promise

The following is a fictional illustration of arithmetic, not a claimed result or universal ROI.

Assume one line spends 120 minutes per shift on recording and reconciliation, two shifts per day and 25 days per month. The baseline is 120 × 2 × 25 = 6,000 minutes, or 100 hours/month. A hypothesis of 40% reduction gives 40 candidate hours/month. At an illustrative THB 500/hour, that is THB 20,000/month or THB 240,000/year.

If the PoC measures only 20%, the annual candidate benefit is THB 120,000. If administration adds eight hours/month at the same illustrative rate, annual operating cost is THB 48,000 and the net candidate benefit is THB 72,000. Include master maintenance, monitoring, backup, terminal replacement, training and change testing. When valuing downtime or quality, separate occurrence probability and evidence and prevent double counting.

Five-year TCO should include initial licenses, implementation, customization, machine connection, infrastructure, cybersecurity, training, annual support, cloud use, upgrades, additional staff, site rollout and contract-exit export. Until eligibility and approval are confirmed, do not treat a BOI incentive as certain income in the base case.

Turn OT cybersecurity references into MES requirements

NIST SP 800-82 Rev. 3 was finalized in September 2023 and addresses OT security while preserving performance, reliability and safety requirements. NIST’s OT publications page also lists 2026 pre-draft work for Rev. 4; Rev. 4 is not final at the time of this article. State the referenced version in the RFP and ask how later revisions will be assessed.

IEC 62443-2-1:2024 specifies security-program policy and procedure requirements for IACS asset owners. It recognizes long IACS lifecycles and the use of compensating measures for legacy systems. Convert that context into asset-owner responsibility, vendor maintenance, account control, backup, incident response and change management—not just a product checkbox.

At minimum, the RFP and PoC should require:

  • inventory of OT assets and paths, allowing only necessary zones and flows;
  • individual accounts, role-based access, an MFA scope and governed emergency access;
  • requested, time-bound, approved, recorded and closed vendor remote maintenance;
  • ownership for encryption, certificates, keys and secret storage/rotation;
  • vulnerability intelligence, patch validation, outage coordination and exception approval for OS, database, edge and app;
  • synchronized clocks and tamper-resistant centralized logs across MES, ERP, edge and identity services;
  • a tested restore from an isolated backup, not merely the presence of a backup;
  • safe and quality-preserving degraded operation during communication or security-device failure.
Thailand MES 2026: RFP, 90-Day PoC and Acceptance Guide - figure 3

OPC UA’s integrated security mechanisms help, but defaults, certificates, trust lists, old endpoints, segmentation and monitoring still need site-specific engineering. Neither “OPC UA” nor “IEC 62443 aligned” is sufficient evidence by itself. References structure responsibilities and tests.

Put BOI eligibility screening on the project schedule

Do not wait until product selection is complete. Early in concept design, document the investing entity, plant, equipment/software/service scope, planned order/import/start dates, improvement from current capability and the proportion of qualifying domestic-linked automation or robotics. Confirm timing-sensitive rules, including what may be ordered before an application, against current official guidance.

Use gates for initial eligibility screen, confirmation with BOI or qualified advisers, separation of eligible cost items, and alignment of application/approval with procurement. Version-control the system design, equipment list, data flow, baseline and quotation breakdown so they can support both engineering and application review. If incentives are necessary to make the case, show management a sensitivity case without incentives.

Production rollout and operating model after the PoC

PoC acceptance is not the finish. Plan line-stop windows, master migration, training, cutover decision, rollback, hypercare and change freeze. Divide support among L1 operations, L2 plant IT/OT, L3 integration partner and product vendor. Define Thailand night/holiday contacts, response targets and handover information.

Monitor more than system uptime: unsent events, replay counts, manual-entry rate, unknown lots, master mismatches, corrections, paper fallback, aged alarms, restore tests and training completion. Compare benefit KPIs with the same baseline definitions and annotate changes in product mix or volume.

For site rollout, version a template. Standardize data model, interface principles, access, audit, acceptance tests and operating KPIs. Keep equipment protocols, product rules, languages, shifts and local legal/customer requirements as governed variation. Unlimited variation becomes unmaintainable; forced uniformity creates workarounds. Define exception approval and a route to improve the template.

RFP attachment templates

An RFP alone allows bidders to price different assumptions. Supply common attachments and mark unknowns explicitly so differences reflect product and delivery method, not hidden scope.

1. Business scenarios

For each scenario, state trigger, actor, input, expected result, exception and evidence. A material-verification case could start after ERP order receipt, use an operator lot scan, expect a mismatch block, and include substitute material, rework, split lot, damaged label and network loss as exceptions. Link the scenario to screen history and audit log. The same list later becomes the FAT/SAT/UAT foundation.

2. Equipment and connection inventory

Record maker, model, age, PLC/controller, confirmed protocols, existing connection, signal count, time synchronization, available stop window, maintenance owner and availability of drawings/backups. Do not mark an unknown legacy device as “OPC-ready.” Compare read-only gateway, external sensor, existing SCADA and governed manual input by accuracy, latency, shutdown risk and maintainability.

3. Data dictionary and code mapping

Map ERP material code, floor name, customer part, unit, field length, leading zeros and character rules. For machine states, define running, changeover, planned stop, failure, material wait and quality wait, including priority. A PLC “run” signal does not by itself decide whether product under quality hold counts as output. Document the transformation from raw signal to KPI and its owner.

4. Non-functional and operating requirements

Cover response, concurrent users, event volume, retention, backup, RTO/RPO, monitoring, maintenance window, languages, terminals and reports. If a target is unknown, define it as a PoC hypothesis, not a vendor choice. For intermittent plant-to-cloud links, specify offline duration, local buffer, replay order and central visibility.

5. Responsibility and assumptions

Assign design, configuration, wiring, PLC change, test data, training, migration, go-live attendance and incident triage among the buyer, MES vendor, integrator, equipment supplier, ERP team and network team. Replace the phrase “customer preparation” with named deliverables. Define the change quotation, rates and approval route if assumptions prove false.

Turn vendor demos into verification sessions

Give every bidder the same factory data and exception sequence. If something cannot be demonstrated, require it to be classified as standard, configuration, customization, future function or unsupported. Ask which key prevents duplicate ERP orders; how wrong material enters controlled approval; what terminals, edge and central views show during a 30-minute outage; how 10,000 buffered events replay without double counting; where BOM/tag changes are tested; whether a Thai dictionary survives upgrades; where administrator actions are audited; and how a complete exit export is proven.

Map answers to RFP and PoC test numbers rather than leaving them in meeting notes. A salesperson’s “possible” remains unverified until the product and delivery owners confirm implementation, license, cost, version and deployment-mode constraints.

The Go/No-Go decision package

Day 90 should compare each original hypothesis with measured results, not show only successful screens. Include a one-page executive summary, scope/exclusions, RFP score and gates, acceptance results, open risks, operating model, five-year TCO, measured benefits, BOI review status and rollout roadmap.

Classify open items by safety/regulatory/customer quality, production interruption, data integrity, operating load and usability. Do not approve a safety or customer-quality defect through an informal workaround. A conditional Go needs an owner, date, retest and stop condition in the contract and plan.

A No-Go is not necessarily failure. Evidence of missing signals, inconsistent masters or unowned operations can prevent a larger loss. A repeat PoC should test only unresolved hypotheses. Data contracts, scenarios and acceptance tests remain reusable if the product changes.

Contract safeguards for change, data and exit

MES changes after go-live as products, equipment, ERP and security requirements evolve. A change request should cover purpose, impact, data migration, stop time, rollback, tests, documentation and training. Avoid direct production edits and track configuration differences across development, validation and production.

Data clauses should name the owner, permitted vendor processing, location and cross-border transfer, subcontractors, retention, deletion, backup and incident notification. A cloud service should provide periodic machine-readable exports with documented fields and relationships; screen PDFs are not a migration-capable return.

The exit plan should include notice, export, transfer of configuration/scripts/interface specifications, knowledge handover, parallel run, shutdown, revocation of accounts/certificates and evidence of backup deletion. Proprietary capability can be valuable, but its benefit and switching cost belong in the RFP’s lifecycle/TCO score.

Training and adoption for local Thailand operations

One operator briefing is insufficient. Operators learn normal and safe exception handling; supervisors learn approval and discrepancy handling; quality learns genealogy and correction; maintenance learns connection triage; IT/OT learns monitoring, accounts, backup and restore. UAT should confirm that Thai procedures match UI terminology and night-shift staff receive equivalent support.

Measure competence by scenario execution, not attendance. When facing an unknown lot, outage or printer failure, users should follow the defined continue/stop route and retain evidence instead of silently returning to paper. Review adoption at 30, 60 and 90 days: investigate duplicate spreadsheets, night-shift delays and exception bypass by root cause—training, UI, master quality, terminal placement or access design. Feed accountable improvements into the multi-site template and prevent knowledge of settings, incidents and recovery from remaining with one individual.

Frequently asked questions

Is Thailand MES only for large factories?

No. The decision depends on traceability, product variety, exceptions, recording burden and gaps between ERP and equipment. A one-line start can be sensible, but data ownership and future rollout should still be decided.

How much does MES cost?

There is no universal range: equipment, users, functions, interfaces, customization, availability, deployment and support vary widely. Use one five-year TCO form covering initial, recurring, expansion and exit costs.

Is normal operation enough for an MES PoC?

No. Production loss often comes from outage, duplicates, incorrect entry, master mismatch, clock drift, excessive privilege or failed recovery. Test these on days 61–75 and retain logs and reconciled counts.

Does an ISA-95 product guarantee ERP integration?

No. ISA-95 is a framework for roles, models and interfaces. Product implementation, semantics, API/version, exception mapping and site testing remain necessary.

Does MES alone qualify for BOI incentives?

Not automatically. Current thresholds and benefits are useful screening inputs, but eligibility depends on the specific project, items, timing and design. Confirm current conditions.

Can a factory with legacy PLCs implement MES?

Potentially. Compare read-only gateways, edge buffering, existing SCADA and governed manual input. Test safety, stop windows and maintainability. Long-lived IACS may require compensating measures.

Summary: use 90 days to evidence a Thailand MES decision

Start with readiness, scope and a measurable baseline. Use ISA-95 to define the ERP–MES/MOM–SCADA/PLC boundary and turn data ownership and exceptions into an RFP. Apply a 100-point score across fit, integration, resilience, OT cybersecurity, local support and TCO. Use a 90-day PoC to test normal and failed states. Prove FAT, SAT and UAT with logs, screens and reconciliations. Screen BOI conditions in parallel, without treating incentives or standards as guarantees.

Sources

Information current as checked in September 2026. This is general technical and planning information, not tax, legal or certification advice. Confirm changing BOI and standards conditions with the relevant authority.