The Purdue model is the most widely used reference for thinking about industrial network architecture. It organizes a plant into levels, from the physical process at the bottom to enterprise IT at the top, and gives teams a shared vocabulary for where systems sit and how they should connect.
This article explains the levels in plain terms, focuses on the IT/OT boundary where most security decisions live, and is honest about where the model strains under modern, cloud-connected operations.
01Key takeaways
- 01
The Purdue model organizes industrial systems into levels from the physical process up to enterprise IT.
- 02
The IT/OT boundary, often implemented as a DMZ at level 3.5, is where the most important security controls live.
- 03
The model maps naturally onto IEC 62443 zones and conduits, giving structure to segmentation.
- 04
Modern connectivity, cloud analytics and remote access strain the strict hierarchy and require deliberate boundary controls.
- 05
Used as a map rather than a mandate, the model still guides where to reduce reachability and enforce direction.
02What the Purdue model is
The Purdue model, derived from the Purdue Enterprise Reference Architecture, divides an industrial environment into functional levels. Each level represents a layer of the operation, from sensors and actuators touching the physical process up to the business systems that run the enterprise.
Its value is shared understanding. When everyone agrees what level a system belongs to, conversations about segmentation, data flow and risk become concrete instead of abstract.
The Purdue model is a map of the plant: it says where systems belong and which neighbors they should talk to.
03The levels, 0 to 5
- Level 0 - Process
- The physical equipment: sensors, actuators and the process itself.
- Level 1 - Basic control
- Controllers such as PLCs and RTUs that directly drive the process.
- Level 2 - Area supervision
- SCADA, HMIs and supervisory systems that operators use to run an area.
- Level 3 - Site operations
- Manufacturing operations systems, historians and site-wide production management.
- Level 3.5 - IT/OT DMZ
- The demilitarized zone that brokers traffic between OT and IT, where data is exchanged without direct connections across the boundary.
- Levels 4-5 - Enterprise
- Business logistics and corporate IT, including ERP, email and the wider enterprise network.
04The IT/OT DMZ at level 3.5
The most important security idea in the model is that OT and IT should not connect directly. Instead, they meet in a DMZ at level 3.5, where intermediary systems broker data so that no host on one side reaches straight through to the other.
This is where data diodes, unidirectional gateways and brokered services typically live. The DMZ is the single most consequential boundary in an industrial network, because it is the path an attacker on the enterprise side must cross to reach operations.
05How it maps to IEC 62443 zones
The Purdue levels translate cleanly into IEC 62443 zones and conduits. Levels become zones grouped by trust and consequence, and the connections between them become conduits to be deliberately controlled.
Using the two together is powerful: the Purdue model tells you where systems sit, and the zone-and-conduit model tells you how to enforce the boundaries between them. One provides the map, the other the control discipline.
06Where the model strains
The strict hierarchy assumes data moves level by level. Modern operations break that assumption: cloud analytics wants data from level 3 directly, remote vendors want access deep in the plant, and IIoT devices talk to the internet from low levels.
- Cloud connectivity that bypasses the orderly climb through each level.
- Remote and vendor access that reaches deep into OT for support.
- IIoT sensors that communicate outward without respecting the hierarchy.
- Flat networks where the levels exist on paper but not in the wiring.
These pressures do not make the model useless; they make its boundaries more important. The question becomes how to allow the new flows without dissolving the separation the model was protecting.
07Applying controls per level
The model is most useful when it drives decisions about reachability. Each boundary between levels is a place to ask what must cross, in which direction, and how often.
For boundaries that should be one-way or connected only intermittently, an AIRGAPNET controlled connectivity pattern can enforce the separation the model intends, keeping data flowing upward while preventing reach back down. The model identifies the boundary; the control makes it real.
08Closing thought
The Purdue model endures because it gives industrial teams a common map. Even as cloud and remote access complicate the picture, the levels still tell you where the consequential boundaries are and what separation you are trying to preserve.
Treat it as a guide, not a cage. Use the levels to locate your boundaries, map them to zones and conduits, and enforce the most important ones, especially the IT/OT DMZ, with controls that match the data flow.
FAQFrequently asked questions
What is the Purdue model?
The Purdue model is a reference architecture that organizes an industrial environment into functional levels, from the physical process at level 0 up to enterprise IT at levels 4 and 5. It gives OT teams a shared vocabulary for where systems sit and how they connect.
What are the levels of the Purdue model?
Level 0 is the physical process, level 1 basic control such as PLCs, level 2 area supervision such as SCADA and HMIs, level 3 site operations and historians, level 3.5 the IT/OT DMZ, and levels 4 and 5 enterprise business and corporate IT.
What is the IT/OT DMZ at level 3.5?
It is a demilitarized zone where OT and IT exchange data through intermediary systems rather than direct connections. It is where data diodes, unidirectional gateways and brokered services typically sit, and the most consequential boundary in the network.
How does the Purdue model relate to IEC 62443?
Purdue levels map cleanly onto IEC 62443 zones and conduits. The Purdue model tells you where systems sit, and the zone-and-conduit model tells you how to enforce the boundaries between them.
Is the Purdue model still relevant with cloud and IIoT?
Yes, though modern connectivity strains its strict hierarchy. Cloud analytics, remote access and IIoT bypass the level-by-level flow, which makes the model's boundaries more important to enforce deliberately rather than less.
SRCSources of record
From map to enforced boundary
Find your boundaries, then make them real.
Use the Purdue levels to locate your most consequential boundaries, then enforce the IT/OT DMZ and one-way flows with controls that match each data flow.