Quick answer: An IEC 60870-5-104 ASDU starts with a type ID that says what the data is (for example 13 = M_ME_NC_1 short float), a variable structure qualifier, a two-octet cause of transmission that says why it was sent (3 = spontaneous, 6 = activation, 7 = confirmation, 20 = general interrogation), a two-octet common address and one or more information objects, each with a three-octet IOA.
Every IEC 60870-5-101 and -104 message that carries data is an ASDU (application service data unit). Knowing its few header fields makes traffic logs readable and explains most negative confirmations.
What is inside an IEC 104 ASDU?
| Field | Size in IEC 104 | Meaning |
|---|---|---|
| Type identification | 1 octet | What the data is, e.g. 13 = M_ME_NC_1 short float |
| Variable structure qualifier (VSQ) | 1 octet | SQ bit + number of information objects (0-127) |
| Cause of transmission (COT) | 2 octets | Why it is sent (6 bits), P/N and T bits, originator address |
| Common address (CA) | 2 octets | Station address; 65535 = broadcast |
| Information object(s) | variable | IOA (3 octets) + value + quality (+ time tag) |
In IEC 104 the ASDU follows a 6-octet APCI (start byte 0x68, length, four control octets). An APDU is at most 253 octets, which leaves at most 249 octets for the ASDU. With the 6-octet data unit identifier, 243 octets remain for information objects. That limits how many objects fit in one ASDU, for example 30 short floats without time tag (8 octets each: IOA 3 + value 4 + quality 1) but only 16 with a CP56Time2a time tag (15 octets each).
The SQ bit of the variable structure qualifier selects the layout: SQ = 0 means every object carries its own IOA; SQ = 1 means one IOA followed by consecutive elements, which saves space for contiguous address blocks. The number of objects field is 7 bits, so an ASDU holds at most 127 objects.
Which type IDs are used most?
| Type ID | Name | Description |
|---|---|---|
| 1 | M_SP_NA_1 | Single-point information |
| 3 | M_DP_NA_1 | Double-point information |
| 5 | M_ST_NA_1 | Step position information |
| 7 | M_BO_NA_1 | Bitstring of 32 bits |
| 9 | M_ME_NA_1 | Measured value, normalized |
| 11 | M_ME_NB_1 | Measured value, scaled |
| 13 | M_ME_NC_1 | Measured value, short floating point |
| 15 | M_IT_NA_1 | Integrated totals (counters) |
| 30 | M_SP_TB_1 | Single point with CP56Time2a |
| 31 | M_DP_TB_1 | Double point with CP56Time2a |
| 34 / 35 / 36 | M_ME_TD_1 / TE_1 / TF_1 | Normalized / scaled / short float with CP56Time2a |
| 37 | M_IT_TB_1 | Integrated totals with CP56Time2a |
| 45 | C_SC_NA_1 | Single command |
| 46 | C_DC_NA_1 | Double command |
| 47 | C_RC_NA_1 | Regulating step command |
| 48 / 49 / 50 | C_SE_NA_1 / NB_1 / NC_1 | Set-point: normalized / scaled / short float |
| 58-64 | C_SC_TA_1 … C_BO_TA_1 | Commands with CP56Time2a (IEC 104) |
| 70 | M_EI_NA_1 | End of initialization |
| 100 | C_IC_NA_1 | Interrogation command |
| 101 | C_CI_NA_1 | Counter interrogation command |
| 102 | C_RD_NA_1 | Read command |
| 103 | C_CS_NA_1 | Clock synchronization command |
| 105 | C_RP_NA_1 | Reset process command |
| 107 | C_TS_TA_1 | Test command with CP56Time2a |
IEC 104 does not use the CP24Time2a time-tagged types of IEC 101 (for example type 2 M_SP_TA_1 or type 4 M_DP_TA_1). It uses their CP56Time2a counterparts (types 30 to 40) and adds commands with time tag (types 58 to 64).
What does the cause of transmission (COT) mean?
The COT tells the receiver why an ASDU was sent. In IEC 104 the COT field is two octets: the first carries the 6-bit cause plus the P/N bit (1 = negative confirmation) and the T (test) bit; the second is the originator address, which identifies the master that caused the response.
| COT | Name | Used for |
|---|---|---|
| 1 | periodic, cyclic | Values sent at a fixed interval |
| 2 | background scan | Low-priority refresh of the database |
| 3 | spontaneous | A value or quality changed |
| 4 | initialized | End of initialization (M_EI_NA_1) |
| 5 | request | Answer to a read command |
| 6 | activation | Command or interrogation from the master |
| 7 | activation confirmation | Outstation accepts (or with P/N rejects) the activation |
| 8 | deactivation | Master cancels a selected command |
| 9 | deactivation confirmation | Outstation confirms the cancel |
| 10 | activation termination | Command or interrogation finished |
| 11 / 12 | return info, remote / local | State change caused by a remote or local command |
| 20 | interrogated by station interrogation | Data answering a general interrogation |
| 21-36 | interrogated by group 1-16 | Data answering a group interrogation |
| 37 | requested by general counter request | Counters answering C_CI_NA_1 |
| 38-41 | requested by group 1-4 counter request | Counters answering a group counter request |
| 44 | unknown type identification | Negative confirmation |
| 45 | unknown cause of transmission | Negative confirmation |
| 46 | unknown common address of ASDU | Negative confirmation |
| 47 | unknown information object address | Negative confirmation |
What do typical message sequences look like?
General interrogation
- Master: C_IC_NA_1, COT 6 (activation), IOA 0, QOI 20 (station interrogation).
- Outstation: C_IC_NA_1, COT 7 (activation confirmation).
- Outstation: all monitored points with COT 20 (interrogated by station interrogation).
- Outstation: C_IC_NA_1, COT 10 (activation termination).
Select-before-operate command
- Master: C_SC_NA_1 with S/E = 1 (select), COT 6. Outstation confirms with COT 7.
- Master: the same command with S/E = 0 (execute), COT 6. Outstation operates and confirms with COT 7.
- Outstation: COT 10 (activation termination) when the command has been completed.
A master can cancel a selected command with COT 8 (deactivation); the outstation answers COT 9. Any step can instead be answered with the P/N bit set, which is a negative confirmation: the command was not accepted.
Spontaneous data
When a value or its quality changes, the outstation sends it with COT 3 (spontaneous) without being asked. Cyclic transmission (COT 1) is used for values that are sent at a fixed interval regardless of change.
Which quality bits can a value carry?
| Bit | Name | Meaning |
|---|---|---|
| IV | invalid | The value is not valid, e.g. the source device does not respond |
| NT | not topical | The value was not updated successfully within the expected time |
| SB | substituted | The value was entered by an operator or an automatic source, not measured |
| BL | blocked | The value is blocked for transmission, e.g. by a local function |
| OV | overflow | Measured values only: the value is outside the representable range |
| EI | elapsed time invalid | Protection events only |
Why does an outstation answer with COT 44 to 47?
These causes are always sent with the P/N bit set, echoing the rejected ASDU:
- 44 unknown type ID: the outstation does not support that command type, for example a time-tagged command sent to a device that only accepts C_SC_NA_1.
- 45 unknown cause of transmission: for example a command sent with COT 3 instead of 6.
- 46 unknown common address: the master uses a different CA from the outstation.
- 47 unknown IOA: no command object is configured at that address.
In a gateway, 46 and 47 almost always mean the signal list in the SCADA system and the gateway mapping differ.
Frequently asked questions
Is the COT always two octets?
In IEC 104, yes: cause plus originator address. In IEC 101 it can be one or two octets, set per project.
What is the difference between COT 3 and COT 20?
COT 3 means the outstation sent the value on its own because it changed. COT 20 means the value is part of the answer to a general (station) interrogation, whether or not it changed.
Try it with Max IEC Gateway. The gateway polls Modbus TCP and RTU devices and serves the values as an IEC 60870-5-104 server or IEC 60870-5-101 outstation, with a traffic monitor that shows every exchange.
Related guides
Modbus basics on the ModbusBB site: register addressing, function codes, Modbus timeouts.