Aug 25, 2026

Your machine isn't obsolete. Your PLC might be.

Siemens is phasing out the S7-300 and S7-1200 G1, NIS2 and the Cyber Resilience Act are coming. Why the next generation of machine control can be open and vendor-neutral.

Your machine isn't obsolete. Your PLC might be.

There is something strange about industrial automation. A production machine runs reliably for twenty, thirty years. The mechanics are maintained. Motors get replaced, bearings get replaced, sensors get upgraded. But one day someone opens the electrical cabinet and discovers that the PLC has become the hardest component of the whole machine to replace.

And suddenly a perfectly good machine is an automation project.

That is the problem we want to solve. Not by replacing the machine, and not by trading one closed controller for the next.

The PLC has become a dependency

For decades, closed PLC ecosystems were a logical choice. Siemens, Rockwell, Mitsubishi, Schneider and others built impressive ecosystems around their hardware and engineering environments: reliable, well documented, available anywhere in the world.

The price was dependency. Once a machine has been engineered around one PLC ecosystem, changing controller manufacturers also means changing the programming environment, hardware, I/O, fieldbus, diagnostics, engineering workflow, spare parts and the knowledge of your own people.

So the cost is not the PLC. It is the ecosystem around it. And in the end that ecosystem decides when your machine is "obsolete", not the machine itself.

The migration clock is ticking

This is now becoming very concrete. Siemens states that the S7-300 and ET 200M left the portfolio on 1 October 2025. And on 1 November 2026, Siemens starts the gradual phase-out of the first generation S7-1200 (G1). Siemens' own migration material describes the challenge exactly as the factory floor feels it: spare parts, support, modernization and long-term operational stability.

The obvious answer is: move to the next Siemens generation. And for many machines, that is simply the right answer. But there is another question worth asking:

If we are going to redesign the controller anyway, why rebuild the same vendor dependency?

What if the PLC became a commodity?

Imagine the machine application is independent of the controller manufacturer. The PLC program follows IEC 61131-3, the standard with the languages every automation engineer already knows: structured text, ladder, function blocks. The fieldbus is an open industrial standard such as EtherCAT. The I/O can come from multiple manufacturers. The controller is an industrial PC or an embedded controller. The operating system is standard Linux, with real-time extensions where needed. And upward, the machine talks over OPC UA, MQTT or another standard interface.

Open control architecture: machine, I/O and drives over EtherCAT, above that an open PLC runtime on IEC 61131-3, an edge layer for monitoring and updates, and over MQTT or OPC UA the cloud and IT systems. Every layer can be replaced on its own.

Suddenly the architecture looks like this: machine logic, below it an open PLC runtime, below that standard interfaces, below that replaceable hardware. That is a very different proposition from what hangs in most cabinets today: vendor engineering environment, vendor PLC, vendor I/O, vendor ecosystem.

The important thing in that picture is not any single technology. It is the separation of concerns. The machine logic should not be permanently married to the controller vendor.

Open source doesn't mean hobbyist

This distinction matters. When people hear "open source PLC", they tend to picture a Raspberry Pi running a hobby project. That is not the proposition.

An industrial control platform still needs everything a classic PLC needs: deterministic execution, industrial hardware, a sound electrical design, fieldbus support, diagnostics, lifecycle management, cybersecurity, testing, documentation and functional safety where required. None of those requirements change.

Open source is about ownership and transparency, not about lowering engineering standards. Linux is open source. That does not make the trains, network equipment and medical systems running on it toys.

To be fair: this is engineering, not a product out of a box. Safety (SIL/PL) and complex motion control are separate tracks with their own certification, and not every machine is a candidate. That belongs on the table at the start of every conversation about this.

The cybersecurity argument

There is another reason this discussion is becoming urgent: the factory floor is no longer isolated. The PLC now sits inside an ecosystem of HMIs, drives, engineering laptops, MES, ERP, remote access, cloud, monitoring and external suppliers. Each of those connections was once an exception. Now they are the norm.

That changes the security model. In our earlier article on NIS2 we looked at exactly this problem: the OT environment is often the blind spot, with old PLCs, HMIs, gateways and remote access sitting outside the asset register. A controller designed in 2008 for a machine behind a closed door now hangs on the same network as the vendor's laptop.

NIS2 changes the conversation

NIS2 is not simply an "IT cybersecurity problem". For organizations in scope, the requirements extend into the systems that support production. That means manufacturers increasingly need answers to questions such as:

  • Which PLCs exactly are installed?
  • Which firmware versions are running on them?
  • Who can access them, and which suppliers have remote access?
  • Which networks can reach the controller?
  • What happens if a controller fails?
  • How is the software backed up, and can the machine be restored?
  • How are vulnerabilities handled?

For a PLC that has sat in a cabinet for fifteen years, those questions are hard to answer. A modern control platform makes them a lot easier: the inventory, the versions, the accounts and the logging are built in. To be clear: NIS2 does not require anyone to replace old PLCs. What NIS2 does is increase the importance of knowing, securing and managing OT assets throughout their lifecycle. And that is exactly where a legacy controller struggles.

Then comes the Cyber Resilience Act

The EU Cyber Resilience Act pushes in the same direction from another angle. The CRA introduces cybersecurity requirements for products with digital elements placed on the European market: secure-by-design development, risk assessment, vulnerability handling and support across the lifecycle. According to the European Commission's implementation timeline, the reporting obligations apply from 11 September 2026 and the main obligations from 11 December 2027.

A nuance applies here too: the CRA does not make old PLCs illegal. Its obligations target manufacturers placing products with digital elements on the market. But the direction is clear. Industrial automation is becoming software, and once industrial equipment is software, its cybersecurity lifecycle matters.

So the question is no longer only: "Does the PLC control the machine?" The question becomes: "Can we securely maintain the software that controls the machine for the next fifteen years?"

Three trends are converging

What makes this moment special is that three developments are now touching each other:

  1. PLC obsolescence. Legacy controllers are reaching the end of their supported lifecycle, with hard dates from the manufacturer itself.
  2. Industrial cybersecurity. Factories need visibility, access control, segmentation, monitoring and lifecycle management, and have to be able to demonstrate it.
  3. Open digital infrastructure. Manufacturers expect machines to take part in MES, analytics, AI, energy management and cloud platforms, as we described earlier for the Unified Namespace.

Those three trends point at the same architecture: open, observable, software-defined control.

We don't think the answer is "replace Siemens"

This matters. Siemens makes excellent automation equipment, and for many applications Siemens will remain the best choice. The point is not to replace one brand with another. The point is that the manufacturer of the product has a choice.

If an industrial controller can be replaced without redesigning the entire machine, the customer has more control over cost, lifecycle, cybersecurity, maintenance, engineering, data and future technology. That is the real value of open automation. Not cheaper than Siemens. But yours.

From PLC migration to machine modernization

This is where we see the bigger opportunity. A PLC migration can be the entry point. But once the controller is modernized, the machine can become part of the factory's digital infrastructure. The same platform then delivers machine data, OEE, energy data, alarms, remote diagnostics, software version management, cybersecurity monitoring, data pipelines for AI and the MES connection. The same data layer that MeshOS uses for a live view of your production gains a machine that tells exactly what it is doing.

The PLC stops being an isolated black box. It becomes part of the digital factory.

The bigger idea

Industry spent decades building incredibly reliable machines. Now we need to give those machines a software architecture that survives the next twenty years. Not by replacing every machine. Not by pushing every manufacturer into another closed ecosystem. But by modernizing the control layer around open standards.

Your machine should not become obsolete because its PLC did.

And: the answer to vendor lock-in should not be another vendor lock-in.

Frequently asked questions

Do I have to replace my S7-300 right now?

No. An S7-300 that runs today will run tomorrow. What changes is that new modules can no longer be ordered and that support and security updates stop. So the question is not whether, but when and how: planned, with a fallback, or unplanned, the moment a CPU fails and the last spare has already been used.

Is an open PLC the same as a soft PLC?

Almost. A soft PLC is a runtime that runs on a PC or embedded controller instead of dedicated PLC hardware. An open PLC adds the requirement that the program is written in standard languages (IEC 61131-3), the fieldbus and interfaces are open and the runtime is not tied to one manufacturer. A soft PLC from a major vendor can still be completely closed.

What happens to safety and motion in such a migration?

They are handled separately. Safety functions (SIL/PL) need certified components and their own validation, and sometimes a certified safety PLC remains the best choice for them. Motion control can run over EtherCAT and open drives, but synchronized motion we assess per machine. An honest inventory up front prevents surprises afterwards.

Does an open controller make my factory NIS2 or CRA compliant?

No, not by itself. Compliance is about your organization, your processes and your ability to demonstrate them, not about one controller. What a modern, observable control architecture does do is make the controls that regulation expects easier to implement and demonstrate. This article is not legal advice.

Have a legacy PLC that deserves a second life?

Meshnex helps manufacturers assess and modernize legacy control systems, keeping the existing machine wherever possible. What that project looks like, from inventory to switch-over, is on our page about open PLC modernization. Rather talk about your machine right away? Contact us.

Back to Blog