Operational guide / Updated August 2026 / 7 min read

Does connecting to a DCS void the OEM warranty?

Engineering leader with experience at GE, Mitsubishi and Alstom, specialising in advanced controls, industrial process and multi-physics modelling, with R&D and patent-pending work behind the Yunify engine.

The answer depends on the executed agreement, and the agreement is usually clearer on this than people expect. Reading through an interface the OEM supplied and supports normally sits outside the exclusions; changing the controller programme normally does not. Written confirmation of the specific path, obtained before a pilot, settles the question far more cheaply than a dispute does.

WarrantyOT integrationProcurementControls

Why the answer is contractual rather than technical

Search this and you get forum threads, a vendor help file and a lot of hedging. The reason is that a definitive answer would be wrong: warranty scope is set by an executed supply contract, and contracts differ. Nobody wants to publish a statement a plant might rely on and then discover their own agreement says something else.

That is a fair concern and it has produced an unhelpful outcome, which is that a question every prospect must resolve before signing has no useful public treatment at all. The answerable version is narrower: what these exclusions usually say, which connection paths typically sit inside them, and how to convert the uncertainty into a written position before it costs anything.

None of this is legal advice, and the executed contract governs in every case.

What the exclusion usually says

The clause that matters is normally an exclusion rather than a prohibition. It says the supplier is not liable for faults arising from unauthorised modification of the equipment or its configuration, sometimes extended to unapproved additions to the system.

Two words in that do the work. Modification, which is about changing what the equipment does. And unauthorised, which is about whether the supplier agreed. A change the supplier approved in writing is not unauthorised, whatever else it is, which is why the written confirmation below matters more than the technical argument.

Note also what the exclusion does not usually say. It rarely prohibits reading. It rarely mentions network connections at all, because most of these contract templates predate the question. The absence of a clause about your specific case is a large part of why the answer feels uncertain, and it usually works in the plant's favour rather than against it.

Paths that typically sit outside the exclusions

Reading from a plant historian. The historian is downstream of control, already collecting, and reading it usually adds no load to the process network. It is the lowest-risk path in every sense and the one to propose first.

Reading through an OPC server the supplier provided and supports. Using a supplied interface for its intended purpose is difficult to characterise as modification, particularly where the supplier sold it as an option and documented it.

Placing acquisition hardware on a network segment the plant controls, separated from the control network by a firewall the plant owns. The equipment is untouched and the boundary is the plant's, not the supplier's.

Each of those describes a data path rather than a change to equipment, and that framing is the one to use when putting the question.

Paths that typically sit inside them

Modifying the controller programme. This includes adding logic purely to expose tags, which people underestimate because it feels harmless. It is a change to the programme the supplier warranted.

Changing scan time or controller loading in a way that affects deterministic behaviour. A controller that now completes its cycle differently is behaving differently, and where timing matters this is squarely inside the exclusion.

Placing an unapproved device directly on the control network. This is usually the cyber objection and the warranty objection at the same time, and it is the one most likely to be refused.

Changing configuration inside the supplier's scope of supply, including adding an interface that does not already exist. Adding an OPC server where there was none is a change to the control system and needs the same approval as any other, even though the end state looks like the low-risk path.

Management of change is a separate gate

Clearing the warranty question does not clear the site's own procedure. Most operating plants have a management-of-change process that covers modifications to control and safety systems, and it exists to protect the safety case rather than the commercial position.

The two gates ask different questions. The supplier asks whether their equipment was altered. The site asks whether the documented basis of safe operation still holds. A path can pass the first and fail the second, particularly where the safety case was assessed against a specific configuration.

Where a safety instrumented system is anywhere near the proposal, the answer narrows further. IEC 61511 requires the safety instrumented system to be independent of the basic process control system to the extent that its integrity is not compromised, and no analytics function should sit where a safety function would come to depend on it. That boundary takes precedence over any technical convenience, and the detail is in reading plant data without modifying the control system.

The email that removes the question

The uncertainty is cheap to resolve and expensive to leave. Write to the supplier describing the exact path, the direction of data flow and what enforces the direction, and ask them to confirm in writing that it falls outside the warranty exclusions.

A usable version reads roughly: we intend to read the following tags from the existing historian, over a one-way path, with no connection to the control network and no change to controller programme, scan time or configuration. Please confirm this does not fall within the exclusions in clause X.

Specificity is what gets it answered. A general enquiry about connecting analytics invites a general refusal. A named path with a named enforcement mechanism invites an engineer to check it against the contract and say yes.

Doing this before a pilot costs an email. Doing it after a fault, when the supplier is looking for reasons the exclusion applies, costs considerably more. It is also the single most effective way to remove the objection permanently, because the answer is reusable across every later phase of the project.

Questions teams ask

Frequently asked questions

Does connecting to a DCS void the OEM warranty?

It depends on the supply contract, but reading through an interface the supplier provided does not usually fall within the exclusions. Modifying the controller programme, changing scan time or adding an unapproved device to the control network more often does. Ask the supplier to confirm the specific path in writing before a pilot.

Is reading from a historian safe from a warranty point of view?

It is the lowest-risk path. A historian sits downstream of control and is already collecting, so reading it usually adds no load to the process network and does not alter any equipment the supplier warranted. It is the path to propose first, subject to whether its resolution and retention meet the need.

Does adding an OPC server count as a modification?

Usually yes. Reading through an OPC server that already exists is using a supplied interface. Adding one where there is none is a change to the control system and needs the same approval as any other change, even though the resulting data path looks identical.

What should the letter to the OEM say?

Name the exact path, the tags, the direction of data flow, what enforces that direction, and confirm that no controller programme, scan time or configuration is being changed. Then ask for written confirmation that it falls outside the stated exclusions. A general enquiry invites a general refusal.

Is the warranty the only approval needed?

No. The site's management-of-change procedure is a separate gate and asks a different question: whether the documented basis of safe operation still holds. A path can satisfy the supplier and still require a site change assessment, particularly where a safety system is anywhere nearby.

What if the contract says nothing about connections?

That is common, because many of these templates predate the question, and it usually works in the plant's favour. An exclusion covering unauthorised modification does not obviously cover reading through a supplied interface, which is why a specific written confirmation is worth obtaining rather than an argument about interpretation.