An open protocol BMS is a building management system whose devices communicate using a published, vendor-neutral standard — most commonly BACnet (ANSI/ASHRAE 135, published in the UK as BS EN ISO 16484-5) — so controllers, sensors and meters from different manufacturers can exchange data without a proprietary gateway. It reduces vendor lock-in, but it does not eliminate it.
The phrase "open protocol" gets written into just about every BMS specification we price, and it almost never means what the person writing it thinks it means. We have walked into buildings with BACnet on every datasheet in the O&M folder and still been unable to get a single point out of the system, because the supervisor licence sat with a contractor who had gone quiet. Open at the field layer, shut at the top. That gap — between what the protocol allows and what the building actually owns — is what this guide is about.
If your immediate concern is commercial rather than technical, our companion guide on BMS vendor lock-in and who actually owns your building's controls covers the handover checklist. This page covers the engineering: what the protocols are, how the layers fit together, and where open systems genuinely fall over on site.
An open protocol BMS is one where the communication rules between devices are published by a standards body rather than owned by a manufacturer. Any vendor can implement them, any competent integrator can read them, and no single company controls who gets to connect. BACnet is the dominant example — it is maintained by ASHRAE as Standard 135 and adopted internationally as ISO 16484-5, which is the reference a UK specification should be citing rather than a brand name.
The opposite is a closed or proprietary protocol, where the manufacturer publishes nothing and integration requires their own gateway, their own tools, or their own engineers. Those systems still exist and still get installed. The practical test is not what the brochure says: it is whether a second contractor, with no relationship to the first, can arrive with a laptop, discover the devices on the network, read the point list and take the site on. If the answer is no, the system is not open in any way that matters to the building owner, whatever the datasheet claims.
Worth separating out early, because it causes more confusion than anything else in this subject: Tridium Niagara is not a protocol. Neither is Trend IQVISION or Distech EC-Net. Those are supervisory frameworks — software platforms that speak several protocols at once and normalise them into one interface. A building can run a Niagara-based supervisor over an entirely open BACnet field layer, or over a completely proprietary one. Our guide to EC-Net, Niagara N4 and Distech explained unpicks that distinction properly.
It works in four layers, and knowing which layer a problem sits in saves an enormous amount of wasted time on site.
The field layer is the physical equipment: temperature sensors, damper and valve actuators, pressure switches, flow meters. Most of these speak no protocol at all — they are analogue or digital signals on a pair of wires, 0–10V or 4–20mA or a volt-free contact, hard-wired back to a controller terminal. Protocol conversations start above them. Our breakdown of BMS field devices and field equipment covers that layer device by device.
The automation layer is the controllers — a Trend IQ4, a Distech ECLYPSE, a Siemens or Schneider unit — reading those signals, running the control strategy, and talking to each other. This is where the fieldbus lives: BACnet MS/TP over RS-485, or BACnet/IP over Ethernet, or Modbus RTU on its own RS-485 trunk.
The management layer is the supervisor: graphics, alarms, trend logs, scheduling. It gathers data from every controller below it and presents one view of the building.
The integration layer sits above or beside all of that, and it is where most modern projects actually get interesting — energy dashboards, analytics platforms, and third-party sensor systems pulling data out via BACnet, an API or an IoT gateway. Products such as Wattsense exist specifically to bridge mixed legacy plant into a single normalised data stream when the original BMS will not.
Openness is not a single property of the whole system. It is a property of each boundary between those layers, and a building can be open at one and welded shut at the next.
Five or six matter in UK commercial buildings, and they are not interchangeable. This is the practical shape of it:
| Protocol | Standard | Typically used for | Openness in practice |
|---|---|---|---|
| BACnet (MS/TP and /IP) | ANSI/ASHRAE 135; ISO 16484-5 | Main BMS backbone, controllers, plant | Genuinely open; self-describing device and object model |
| Modbus (RTU and TCP) | Modbus Organization specification | Meters, inverters, chillers, packaged plant | Open and universal, but no self-description — you need the register map |
| LonWorks / LonTalk | ISO/IEC 14908 | Legacy installations, some VAV and lighting | Open standard, shrinking support base |
| KNX | EN 50090, EN 13321-1, ISO/IEC 14543-3 | Lighting, blinds, room control | Open; strong in Europe, more common on lighting than plant here |
| M-Bus / Wireless M-Bus | EN 13757-2 and -3; wireless EN 13757-4 | Heat, water and gas meters | Open, purpose-built for metering |
| MQTT / OPC UA | ISO/IEC 20922; IEC 62541 | Cloud analytics, IoT integration | Open, but sits above the BMS rather than inside it |
The one that catches people out is Modbus. It is completely open and it is on almost every meter and inverter you will ever meet, but it carries no description of itself. A BACnet device tells the network what it is and what its objects mean; a Modbus device hands over a number from register 40001 and leaves you to find out from the manufacturer's documentation whether that is kilowatt-hours, and whether it needs scaling by ten. Lose the register map and an open device becomes effectively unreadable. Our full comparison of BACnet vs Modbus goes through where each one belongs.
We'll assess your controls and provide a detailed quotation with energy savings estimates.
Yes — BACnet is an open, non-proprietary standard published by ASHRAE as Standard 135 and adopted as ISO 16484-5. No manufacturer owns it, no licence fee is payable to speak it, and the specification is publicly available. That is what makes it the correct thing to name in a specification.
The qualifier that matters is conformance. "Supports BACnet" is a marketing claim; BACnet Testing Laboratories (BTL) listing is an independently tested one, and the two are not the same thing. A device can implement a thin subset of the standard, expose a handful of read-only objects, and still put BACnet on the front page of the datasheet. This is precisely the complaint that comes up again and again from working integrators — that vendors follow the same standard differently enough that every new manufacturer means a fresh round of discovery. Specify the BTL listing and the BACnet Interoperability Building Blocks (BIBBs) you need, not just the word.
The competitive one is the strongest and it is commercial, not technical. When the field layer is genuinely open and the documentation exists, a maintenance contract can go out to three firms and get three real prices back. Over the life of a control system that is worth more than any single feature, because it applies to every renewal rather than once at handover.
Second, you can buy the right equipment rather than the equipment your BMS vendor happens to sell. Actuators from Belimo, sensors from Sontay, meters from whoever is MID-approved and available — all onto one system, without a gateway per manufacturer. Gateways are not just an equipment cost; each one is another device to power, configure, document and eventually fail.
Third, phased replacement becomes possible. A closed system tends to fail as a unit: when the supervisor goes end-of-life, the whole estate goes with it. On an open field layer you can replace a supervisor and keep the controllers, or replace controllers floor by floor and keep the supervisor, spreading a large capital cost across several budget years. That is exactly the argument in our guide to legacy BMS upgrade: retrofit or replace.
Fourth, your data is reachable. Energy reporting, MEES evidence, analytics, net-zero measurement — all of it depends on getting trend data out of the BMS in a usable form. Open protocols make that a configuration job rather than a negotiation.
Open costs more to engineer. Integrating three manufacturers means three sets of documentation, three commissioning behaviours and three technical support routes, and every one of those is time. A single-vendor system where everything is pre-mapped genuinely is faster to commission, and on a tight programme that difference is real money. Pretending otherwise is how projects end up under-priced and rushed.
Open does not mean plug-and-play. Different manufacturers interpret the same standard differently — priority arrays handled inconsistently, COV subscriptions that quietly stop, object naming that bears no relation to the points schedule. Two BTL-listed devices will still need proper integration testing before you can claim they work together.
Support gets diffuse. When a multi-vendor system misbehaves at three in the morning, there is no single number to ring, and every manufacturer's first instinct is to point at the other one's kit. Somebody has to own the integration contractually, or nobody does.
Open networks widen the attack surface. More IP-connected devices, more remote access routes, more third-party platforms with credentials into your building. BACnet/SC (Secure Connect), defined in ASHRAE Addendum bj to Standard 135 and carried into the 135-2020 edition, adds TLS encryption and certificate-based authentication and is a genuine improvement — but it is not a substitute for network segmentation, and certificate ownership needs settling at handover rather than afterwards. The NCSC treats operational technology as needing a tailored approach rather than standard corporate IT controls; our guide to BMS cybersecurity covers what that means for a building.
And the big one: an open protocol does not stop a contractor locking you out. This is the single most common misunderstanding in the whole subject. The protocol governs how devices talk on the wire. It says nothing about who holds the engineering password, who holds the supervisor licence, who holds the strategy source files, or who holds the graphics project. Every one of those can be withheld on a fully BACnet system, and routinely is — not usually out of malice, but because nobody wrote them into the specification and nobody chased them at practical completion.
The pattern repeats. Integration gets specified as one line in the BMS scope, no points schedule agreed between the parties, and the two contractors meet for the first time on the commissioning programme with three days left. The BMS engineer wants values in engineering units; the chiller supplier's Modbus map returns raw integers needing a scaling factor nobody documented.
RS-485 is the other recurring one, and it is nearly always the same three faults. Termination belongs at each of the two physical ends of a segment — 120Ω, twice, and only twice. Polarization or bias — a pull-up and pull-down pair, given as 450–650Ω in the Modbus over Serial Line specification — is a different job: it holds the idle line in a defined state and belongs at one designated point on the bus, typically the master. Fitting bias at every device, or terminating in the middle of a run, produces exactly the intermittent comms faults that get blamed on "the protocol".
Star topology is the third. A star has no single pair of ends, so termination cannot be applied correctly and reflections happen regardless. It is a reason to avoid star wiring on RS-485, not a case where you can safely leave termination off — and where a star already exists, the fix is to re-route to a proper trunk or use a manufacturer-approved repeater, keeping stubs short.
One Trend-specific trap worth naming, because engineers waste hours on it: a traditional Trend IQ site Lan runs as a current loop, which does not use 120Ω impedance termination at all. Hunting for a termination resistor across an older Trend Lan is looking for something that was never fitted. What does get terminated is the BACnet MS/TP fieldbus — an IQ4NC provides an integral 120Ω terminator switched in at one end, with a 120Ω resistor across the MS/TP terminals at the far end (Trend IQ4NC data sheet TA201285). Bias on a Trend MS/TP trunk follows the manufacturer's rules rather than the Modbus one above: the IQ4NC applies its own 470Ω network bias, and the same data sheet caps the network at two biasing devices — on the IQ4NC/00 and /12 variants bias is permanently applied and cannot be switched out. Check the variant before adding bias anywhere else.
BS EN ISO 16484-5 is the data communication protocol standard for building automation and control systems — the international adoption of BACnet, and the correct citation for a UK specification. Naming the standard rather than the brand keeps a specification enforceable and vendor-neutral. BS EN ISO 16484-6 covers data communication conformance testing, which is the mechanism behind independent BTL certification: the reason you specify a BTL listing rather than accepting a vendor's own claim.
CIBSE Guide H (2009), section 3.1.3.1, specifies that a sensor accuracy of 0.6 K over the 15–25°C range is suitable for zone air temperature measurement — a concrete, checkable figure for the field layer that no protocol choice will rescue you from. Openness is worthless if the measurement underneath it is wrong. CIBSE and BSRIA both publish commissioning guidance that carries more weight in a dispute than any manufacturer's method statement.
For the metering side, EN 13757-2 and -3 define wired M-Bus (with wireless in EN 13757-4), and EN 1434 sets the requirements for heat meters including accuracy classes — the standards that decide whether your sub-metering data is good enough to bill from or only good enough to look at.
On our 16-floor fan coil upgrade at Pinsent Masons, the control layer was Trend, and the occupancy data came from LightFi — a completely separate manufacturer with its own wireless sensor estate. On a closed system that is a gateway project with a licence attached. Because the integration boundary was handled properly, the occupancy data landed alongside the FCU control data and both were usable together.
The constraint that shaped the job was access: a live legal practice, so the work ran weekends only. That is the argument for open systems that never appears in a brochure. When you can only touch the building for two days at a time, a floor-by-floor phased approach is the only approach, and a phased approach is only possible if the layer you are not touching this weekend keeps talking to the layer you replaced last weekend. Closed systems tend to demand a single switchover. Buildings in use rarely have room for one.
A specification that actually delivers an open system names four things. First, the standard, not the brand: BS EN ISO 16484-5, with BTL listing required and the specific BIBBs stated. Second, a points schedule agreed between all parties before commissioning starts, in engineering units, with scaling factors documented — this single document prevents more integration failures than anything else. Third, the handover deliverables written as contract items: engineering-level passwords, supervisor licence registered to the building owner, strategy and graphics source files, network topology drawing, and every Modbus register map. Fourth, named responsibility for integration — one party who owns the boundary when two manufacturers disagree.
Then verify it before the retention is released. Ask a second contractor to attend, connect to the network, discover the devices and read the points. If they can, the system is open. If they cannot, you have a closed system with an open protocol on the datasheet, and the time to find that out is while somebody still owes you money.
Three trigger points. If your supervisor is approaching end-of-life — and if you are running Trend IQ3 or a 963 front end, that decision is already live — you are about to commit to a platform for the rest of that system's life either way, so it is worth doing it deliberately. If a maintenance re-tender has just come back with fewer bidders than you sent out, that is lock-in showing itself and it will not improve on its own. And if you are writing a specification for new work, this is the cheapest moment there will ever be to get it right: an open-protocol clause and a handover schedule cost nothing at tender stage and are close to unrecoverable afterwards.
Open protocols are the right default. BACnet at the field and automation layers, Modbus where the plant dictates it, M-Bus for metering, and a supervisor chosen on merit rather than because it is the only thing that will talk to your controllers. But openness is a property of the whole delivery — protocol, documentation, credentials and licences together — and only the first of those four is technical. Get all four written into the specification and you own your building's controls. Get one of them and you own a cabinet.
Alpha Controls installs, commissions and takes over multi-vendor BMS across London, Kent and the South East, on Trend, Distech, Niagara-based supervisors and open BACnet field layers. If you have inherited a system nobody can get into, or you are specifying one and want the open-protocol clauses to actually hold, talk to us or request a quote.
Specialist BMS installation, commissioning, and maintenance across London and the South East. SafeContractor Approved, BCIA Member.
Our team of building automation specialists is ready to help you optimise your building's performance and efficiency.
Get in Touch