Quick answer: An IEC 60870-5-104 ASDU starts with a type ID that says what the data is (for example 13 = M_ME_NC_1 short float), a variable structure qualifier, a two-octet cause of transmission that says why it was sent (3 = spontaneous, 6 = activation, 7 = confirmation, 20 = general interrogation), a two-octet common address and one or more information objects, each with a three-octet IOA.

Every IEC 60870-5-101 and -104 message that carries data is an ASDU (application service data unit). Knowing its few header fields makes traffic logs readable and explains most negative confirmations.

What is inside an IEC 104 ASDU?

FieldSize in IEC 104Meaning
Type identification1 octetWhat the data is, e.g. 13 = M_ME_NC_1 short float
Variable structure qualifier (VSQ)1 octetSQ bit + number of information objects (0-127)
Cause of transmission (COT)2 octetsWhy it is sent (6 bits), P/N and T bits, originator address
Common address (CA)2 octetsStation address; 65535 = broadcast
Information object(s)variableIOA (3 octets) + value + quality (+ time tag)

In IEC 104 the ASDU follows a 6-octet APCI (start byte 0x68, length, four control octets). An APDU is at most 253 octets, which leaves at most 249 octets for the ASDU. With the 6-octet data unit identifier, 243 octets remain for information objects. That limits how many objects fit in one ASDU, for example 30 short floats without time tag (8 octets each: IOA 3 + value 4 + quality 1) but only 16 with a CP56Time2a time tag (15 octets each).

The SQ bit of the variable structure qualifier selects the layout: SQ = 0 means every object carries its own IOA; SQ = 1 means one IOA followed by consecutive elements, which saves space for contiguous address blocks. The number of objects field is 7 bits, so an ASDU holds at most 127 objects.

Which type IDs are used most?

Type IDNameDescription
1M_SP_NA_1Single-point information
3M_DP_NA_1Double-point information
5M_ST_NA_1Step position information
7M_BO_NA_1Bitstring of 32 bits
9M_ME_NA_1Measured value, normalized
11M_ME_NB_1Measured value, scaled
13M_ME_NC_1Measured value, short floating point
15M_IT_NA_1Integrated totals (counters)
30M_SP_TB_1Single point with CP56Time2a
31M_DP_TB_1Double point with CP56Time2a
34 / 35 / 36M_ME_TD_1 / TE_1 / TF_1Normalized / scaled / short float with CP56Time2a
37M_IT_TB_1Integrated totals with CP56Time2a
45C_SC_NA_1Single command
46C_DC_NA_1Double command
47C_RC_NA_1Regulating step command
48 / 49 / 50C_SE_NA_1 / NB_1 / NC_1Set-point: normalized / scaled / short float
58-64C_SC_TA_1 … C_BO_TA_1Commands with CP56Time2a (IEC 104)
70M_EI_NA_1End of initialization
100C_IC_NA_1Interrogation command
101C_CI_NA_1Counter interrogation command
102C_RD_NA_1Read command
103C_CS_NA_1Clock synchronization command
105C_RP_NA_1Reset process command
107C_TS_TA_1Test command with CP56Time2a

IEC 104 does not use the CP24Time2a time-tagged types of IEC 101 (for example type 2 M_SP_TA_1 or type 4 M_DP_TA_1). It uses their CP56Time2a counterparts (types 30 to 40) and adds commands with time tag (types 58 to 64).

What does the cause of transmission (COT) mean?

The COT tells the receiver why an ASDU was sent. In IEC 104 the COT field is two octets: the first carries the 6-bit cause plus the P/N bit (1 = negative confirmation) and the T (test) bit; the second is the originator address, which identifies the master that caused the response.

COTNameUsed for
1periodic, cyclicValues sent at a fixed interval
2background scanLow-priority refresh of the database
3spontaneousA value or quality changed
4initializedEnd of initialization (M_EI_NA_1)
5requestAnswer to a read command
6activationCommand or interrogation from the master
7activation confirmationOutstation accepts (or with P/N rejects) the activation
8deactivationMaster cancels a selected command
9deactivation confirmationOutstation confirms the cancel
10activation terminationCommand or interrogation finished
11 / 12return info, remote / localState change caused by a remote or local command
20interrogated by station interrogationData answering a general interrogation
21-36interrogated by group 1-16Data answering a group interrogation
37requested by general counter requestCounters answering C_CI_NA_1
38-41requested by group 1-4 counter requestCounters answering a group counter request
44unknown type identificationNegative confirmation
45unknown cause of transmissionNegative confirmation
46unknown common address of ASDUNegative confirmation
47unknown information object addressNegative confirmation

What do typical message sequences look like?

General interrogation

  1. Master: C_IC_NA_1, COT 6 (activation), IOA 0, QOI 20 (station interrogation).
  2. Outstation: C_IC_NA_1, COT 7 (activation confirmation).
  3. Outstation: all monitored points with COT 20 (interrogated by station interrogation).
  4. Outstation: C_IC_NA_1, COT 10 (activation termination).

Select-before-operate command

  1. Master: C_SC_NA_1 with S/E = 1 (select), COT 6. Outstation confirms with COT 7.
  2. Master: the same command with S/E = 0 (execute), COT 6. Outstation operates and confirms with COT 7.
  3. Outstation: COT 10 (activation termination) when the command has been completed.

A master can cancel a selected command with COT 8 (deactivation); the outstation answers COT 9. Any step can instead be answered with the P/N bit set, which is a negative confirmation: the command was not accepted.

Spontaneous data

When a value or its quality changes, the outstation sends it with COT 3 (spontaneous) without being asked. Cyclic transmission (COT 1) is used for values that are sent at a fixed interval regardless of change.

Which quality bits can a value carry?

BitNameMeaning
IVinvalidThe value is not valid, e.g. the source device does not respond
NTnot topicalThe value was not updated successfully within the expected time
SBsubstitutedThe value was entered by an operator or an automatic source, not measured
BLblockedThe value is blocked for transmission, e.g. by a local function
OVoverflowMeasured values only: the value is outside the representable range
EIelapsed time invalidProtection events only

Why does an outstation answer with COT 44 to 47?

These causes are always sent with the P/N bit set, echoing the rejected ASDU:

  • 44 unknown type ID: the outstation does not support that command type, for example a time-tagged command sent to a device that only accepts C_SC_NA_1.
  • 45 unknown cause of transmission: for example a command sent with COT 3 instead of 6.
  • 46 unknown common address: the master uses a different CA from the outstation.
  • 47 unknown IOA: no command object is configured at that address.

In a gateway, 46 and 47 almost always mean the signal list in the SCADA system and the gateway mapping differ.

Frequently asked questions

Is the COT always two octets?

In IEC 104, yes: cause plus originator address. In IEC 101 it can be one or two octets, set per project.

What is the difference between COT 3 and COT 20?

COT 3 means the outstation sent the value on its own because it changed. COT 20 means the value is part of the answer to a general (station) interrogation, whether or not it changed.

Try it with Max IEC Gateway. The gateway polls Modbus TCP and RTU devices and serves the values as an IEC 60870-5-104 server or IEC 60870-5-101 outstation, with a traffic monitor that shows every exchange.

Download the free 30-day trial See all features