Level 3 vs Level 4: The ISA-95 Boundary Vendors Keep Asking You to Forget

Layered industrial control room representing manufacturing execution and enterprise system boundaries

Every few years the industry rediscovers that MES and ERP should talk to each other, packages it as news, and sells it back to you as a platform decision. This year it’s arrived as a wave: Rockwell’s continued integration of Plex, SAP folding generative assistants like Joule into its manufacturing story, GE Vernova’s software push, Critical Manufacturing’s expanding scope. Each pitch, in its own way, asks you to stop thinking about where MES ends and ERP begins. That’s exactly the wrong moment to stop thinking about it.

The ISA-95 Level 3/4 boundary isn’t bureaucratic trivia. It’s the thing that tells you which system owns a piece of data, which system you should trust when two systems disagree, and which system you’re paying twice for if you’re not careful. Convergence pitches don’t eliminate that boundary — they move it, hide it, or quietly duplicate it. Your job is to find out which.

What ISA-95 actually says, in plain terms

ISA-95 is the standard (formally ANSI/ISA-95, aligned with IEC 62264) that defines how enterprise systems and control systems exchange information. It organizes a manufacturing operation into a hierarchy of levels:

  • Level 0-1: the physical process and the sensors/actuators that touch it — the actual machine, the actual measurement.
  • Level 2: supervisory control — SCADA, PLCs, HMI — the systems that run a line or a cell in near real time.
  • Level 3: manufacturing operations management — this is where MES lives. Production scheduling execution, work order dispatch, in-process quality, genealogy, WIP tracking, labor and equipment data collection at the shop-floor level.
  • Level 4: business planning and logistics — this is ERP. Master production scheduling, materials planning, order management, financials, procurement, long-horizon capacity planning.

The standard’s real contribution isn’t the pyramid diagram everyone’s seen in a slide deck. It’s the object models — B2MML schemas for things like production schedules, production performance, and equipment capability — that define what information crosses the boundary and in what shape. ISA-95 was never trying to say “buy two systems.” It was trying to say: here is where the nature of the decision changes, so here is where the interface needs to be explicit.

The boundary is functional, not architectural

This is where practitioners get tripped up, and where vendors have every incentive to let the confusion ride. Level 3 and Level 4 are not defined by which product you bought. They’re defined by three things: time horizon, data ownership, and transaction authority.

Time horizon

ERP plans in days, weeks, and months. It answers “what should we make this month, with what materials, against what demand.” MES operates in seconds, minutes, and shifts. It answers “what is this machine doing right now, and what should the operator do next.” A system that can’t tell you what happened on the line in the last ninety seconds isn’t doing Level 3 work, no matter what the license says.

Data ownership

ERP owns the master data that defines the business: the item master, the standard BOM, the customer order, the cost structure, the plan. MES owns the master data that defines execution reality: the as-built genealogy, the actual routing followed, real-time equipment status, in-process quality results, actual labor and downtime. These aren’t competing copies of the same truth — they’re genuinely different records that happen to reference each other.

Transaction authority

This is the sharpest test. Who has the authority to create a given transaction, versus who merely consumes or reports it? ERP creates the production order. MES creates the record of how that order was actually executed — the confirmations, the scrap, the actual times, the genealogy. When a convergence platform lets either layer “author” the same transaction, you’ve collapsed the boundary, and you need to know exactly what that trade-off costs you in auditability and system-of-record clarity.

The decision test: three questions for any convergence pitch

When a vendor tells you their platform “unifies” MES and ERP, or that an AI layer now spans both, don’t ask what it does. Ask these three questions about the specific data object in front of you — a work order, a quality result, a genealogy record, whatever’s on the table:

  1. Who owns the transaction? Which system is the system of record that creates and timestamps the actual event — the scan, the confirmation, the deviation? If the answer is “either, depending on configuration,” that’s not a feature, that’s an unresolved architecture decision being handed to you.
  2. Who owns the master record? Is the item master, routing, or spec being maintained in one place and referenced everywhere else, or is there a second copy living in the “unified” layer that now needs its own reconciliation logic? Duplicated master data is the single most common source of MES/ERP integration failure, and convergence platforms don’t repeal that risk — they just make it less visible.
  3. What’s the update cadence? Is this data updated in near-real-time against the process (Level 3 behavior) or on a planning cycle (Level 4 behavior)? A platform that stores both in the same database doesn’t change the fact that one is a live operational stream and the other is a periodic plan. If the vendor can’t clearly answer which cadence governs a given screen, they haven’t actually converged anything — they’ve just skinned two systems to look like one.

Run every “unified” screen, every AI copilot answer, every cross-layer dashboard through those three questions. Most of the time you’ll find the underlying systems still have distinct ownership — the convergence is in the user experience and the integration layer, not in the actual data model. That’s often a perfectly reasonable thing to buy. It’s just not the same thing as eliminating the Level 3/4 boundary, and you should price and contract it accordingly.

Why this matters more during a renewal cycle

The risk isn’t that convergence platforms are bad architecture. Tighter integration between MES and ERP, done well, genuinely reduces double-entry and reconciliation lag — that’s been a legitimate goal since long before this year’s product announcements. The risk is evaluating a renewal or a new platform on the vendor’s language instead of on your own data model. If you can’t say, in plain terms, which system will own the genealogy record six months after go-live, you haven’t finished the evaluation — you’ve just read the brochure.

The ISA-95 boundary was never about keeping two products on two servers. It was about making sure someone, somewhere, could point to a transaction and say with certainty who created it, who owns its master definition, and how fast it needs to move. Any platform — converged, unified, AI-assisted, or otherwise — still has to answer that question. Make them answer it before you sign, not after you’ve gone live and discovered you’re reconciling two “single sources of truth.”


This article was written with the assistance of artificial intelligence. While we aim for accuracy, the information may be incomplete, out of date, or incorrect, and should be independently verified before you rely on it for any decision. It is provided for general information only and does not constitute professional advice.

Related posts