Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 30141

Internet of Things - Reference Architecture

Technology & Innovation Published: 2024

ISO 30141:2024 at a glance

Current edition
ISO/IEC 30141:2024 - Internet of Things (IoT) — Reference architecture
Published
2024
Status
Published
Type of standard
Guidance
Certifiable
No — used for reference and implementation, not certification
Previous edition
ISO/IEC 30141:2018
Official ISO page
View ISO 30141:2024 on iso.org
Last verified

Overview

Reference architecture for Internet of Things systems, providing a conceptual model, architectural views and design patterns; second edition published 2024

ISO/IEC 30141:2024 provides a standardized IoT reference architecture using a common vocabulary, reusable designs and industry best practice. The second edition was published in August 2024 by ISO/IEC JTC 1/SC 41 and replaces ISO/IEC 30141:2018, which is withdrawn. It is an architectural reference, not a requirements standard, so systems and organizations are not certified against it.

The document takes a top-down approach. It begins by collecting the characteristics of IoT systems — such as the coupling of physical and digital entities, heterogeneity of devices and networks, real-time and event-driven behaviour, large scale, long device lifetimes, constrained resources, and the trustworthiness concerns of safety, security, privacy, reliability and resilience. These characteristics are then abstracted into a conceptual model and a reference model, from which the architectural views are derived.

Several architectural views are provided, describing an IoT system from complementary angles: the functional view (what capabilities exist and how they decompose), the system view (how components are deployed and arranged), the communication or networking view (how entities interconnect across constrained and unconstrained networks), the information view (how data is represented and flows), and the usage view (how actors use the system). The second edition adds a construction view with architecture and design patterns for building IoT systems, which is the most practically useful addition for implementation teams.

Core entities in the model include the physical entity being sensed or actuated, IoT devices (sensors and actuators), gateways, networks, IoT services and applications, operations and management functions, access management, and the users — human and digital — that interact with the system.

The 2024 edition brings the document into conformance with ISO/IEC/IEEE 42010:2022, the standard for architecture description, improves usability, and strengthens support for implementation patterns. That conformance means IoT architecture documentation can be produced in the same form as other enterprise architecture work.

Trustworthiness runs through the architecture as a cross-cutting concern rather than a separate section: security of devices and communications, protection of personal data collected by sensing, safety where actuation affects the physical world, and resilience where connectivity is intermittent. For depth on those topics, the related documents are ISO/IEC 27400 (IoT security and privacy guidelines), ISO/IEC 30147 (methodology for trustworthiness of IoT systems and services), the ISO/IEC 21823 series (IoT interoperability) and ISO/IEC 29100 (privacy framework).

Typical uses are structuring the architecture of large IoT deployments, writing platform-neutral procurement specifications, assessing vendor proposals against a consistent model, and giving multi-disciplinary teams — operational technology, IT, networking and data — a shared description of the same system.

Purpose

To provide a common, vendor-neutral reference architecture for IoT systems — characteristics, conceptual and reference models, architectural views and design patterns — so that IoT solutions can be described, designed, compared and integrated consistently.

Key Benefits

  • Gives a vendor-neutral architectural model for describing and comparing IoT systems
  • Provides multiple complementary views so different disciplines can describe the same system coherently
  • Adds a construction view with reusable architecture and design patterns in the 2024 edition
  • Conforms to ISO/IEC/IEEE 42010:2022, aligning IoT documentation with general architecture practice
  • Establishes a common vocabulary across OT, IT, networking and data teams
  • Treats trustworthiness — security, privacy, safety, reliability, resilience — as a cross-cutting concern
  • Supports platform-neutral procurement specifications and vendor evaluation
  • Scales from single-site deployments to large distributed systems such as smart cities and utilities
  • Helps identify interoperability and integration points early in design
  • Provides continuity for organizations that adopted the 2018 first edition

Key Requirements

  • Note: ISO/IEC 30141 is a reference architecture — it is applied as design guidance and is not certified against
  • Identify the characteristics of the IoT system being designed, including scale, heterogeneity and real-time behaviour
  • Use the conceptual model and reference model as the basis for system description
  • Describe the system using the architectural views, including functional, system, communication, information and usage views
  • Apply the construction view patterns when designing implementations
  • Identify the core entities: physical entities, sensors and actuators, devices, gateways, networks, services and applications
  • Define operations, management and monitoring functions for deployed devices
  • Define identity, authentication and access management for devices, services and users
  • Address data collection, representation, flow, storage and analytics in the information view
  • Address security across devices, networks, platforms and applications
  • Address privacy where sensing collects personally identifiable information
  • Address safety and resilience where actuation affects the physical world or connectivity is intermittent
  • Consider interoperability with other systems and reference the ISO/IEC 21823 series where relevant
  • Document the architecture in a manner consistent with ISO/IEC/IEEE 42010:2022

Who Needs This Standard?

Architects and engineering teams designing IoT platforms and deployments, industrial and manufacturing organizations building connected operations, smart city and utility programmes, healthcare and building management technology teams, and procurement functions specifying or evaluating IoT solutions.

Where to get ISO 30141

The full text of ISO 30141 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 30141 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Our AI Risk Assessment Workbook is a set of blank, printable templates for running an AI risk process: an AI system inventory, a risk register with worked example rows, a likelihood and impact scoring matrix, a treatment plan and a monitoring log. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Related Standards