Obsolete PLC: Repair, Replace or Retrofit?
Updated · Written by HAM International Trade Team
Repair fits a bounded fault when the original system remains recoverable. Like-for-like replacement can restore service when the exact unit, backups, tools, configuration, and condition are controlled. Retrofit fits wider support, network, software, safety, skills, or reliability problems—but it needs defined scope, test, cutover, and rollback.
Diagnose the failure before choosing the intervention
Obsolete is a lifecycle condition, not a fault diagnosis. A stopped machine may have power, I/O, network, field-device, wiring, program, battery, memory, or process causes rather than a failed CPU. Preserve alarms, indicators, programs, parameters, network data, and removed hardware before swapping components. A replacement that restarts the machine can hide the original cause.
Inventory CPU, racks, power, I/O, special modules, networks, HMI, drives, safety, remote stations, software and versions, licences, cables, backups, controlled passwords, drawings, spare condition, and available skills. The choice concerns this system, not only the PLC model.
Repair, like-for-like replacement and retrofit
Compare the complete intervention and residual risk.
| Option | Best fit | Residual risk |
|---|---|---|
| Repair | Bounded failure, repairable original, controlled configuration and credible test | Other ageing components, weak backups and shrinking skills remain |
| Like-for-like replacement | Exact identity, known-good backup and tool, urgent recovery, controlled condition | Stock authenticity, ageing, revision differences and lifecycle remain |
| Retrofit | Support, reliability, network, software, safety, capacity or skills justify change | Scope growth, conversion gaps, commissioning downtime and new failure modes |
Repair must return evidence, not only a working unit
A repair proposal should state incoming fault, diagnosis, work, replaced parts, configuration or memory handling, functional test, untested functions, warranty and failure response. Decide whether the original serialised unit must return and how data is protected. A bench pass may not exercise networks, field loads, timing, safety interaction, or intermittent faults.
Use repair as a bounded recovery. Set the remaining-life assumption, spare coverage, next failure trigger, and date for retrofit review. Repeated repair without a lifecycle trigger can consume budget while drawings, tools and experienced people disappear.
Choose the intervention with explicit triggers
The fastest physical swap is not always the fastest verified recovery.
- 01
Confirm recoverability
Secure backups, tools, licences, passwords, cables, identity and safe access.
OUTPUTRecovery readiness
- 02
Bound the fault
Separate hardware from power, I/O, network, field, software and process causes.
OUTPUTFailure evidence
- 03
Compare options
Estimate downtime, engineering, tests, spares, support, skills, lifecycle and rollback.
OUTPUTDecision comparison
- 04
Authorise bounded action
Define hardware, work, acceptance, owner, stops and contingency.
OUTPUTExecutable intervention
- 05
Set lifecycle trigger
Use failures, stock, support date, risk or asset plan to force reassessment.
OUTPUTFuture decision point
A retrofit is a project boundary, not a CPU purchase
Define whether the project replaces CPU only or also racks, I/O, network, HMI, drives, safety, panels, wiring, data and documentation. Conversion tools may assist while leaving instructions, timing, mapping, communications, diagnostics or operator behaviour to resolve. Manufacturer renewal examples are family-specific evidence, not a universal promise.
Plan offline review, simulation or bench work, panel changes, backups, site tests, production trial, acceptance, training, spares, security review where relevant, and rollback. Name who approves control behaviour and safety. A schedule with no time for discrepancy correction is not a validation plan.
Intervention decision file
Do not approve from hardware price alone.
- Failure mode and system boundary are evidence-backed
- Program, parameters, HMI, network and drive data are backed up and readable
- Software, licences, passwords, cables, tools and skills are available
- Repair tests, replacement condition or retrofit differences are itemised
- Downtime includes conversion, installation, test, correction and restart
- Safety, quality, data and regulatory effects have reviewers
- Acceptance, rollback and contingency are written
- A future migration or retirement trigger is recorded
Connect emergency recovery and asset strategy
A repaired PLC can be right for this shutdown and wrong for the next three years. A retrofit can be strategically sound and unsafe to rush into the current outage. Record both horizons: the authorised immediate intervention and the dated lifecycle action it enables.
HAM can investigate Japan-side component or service options after the controls owner sets the intervention. Diagnosis, control design, safety, conversion, commissioning and acceptance remain with qualified owners.
Frequently asked questions
- Is like-for-like replacement risk-free?
- No. Exact code, revision, condition, firmware, backups, tools, battery or memory state, networks and configuration still need control.
- When should retrofit be selected?
- When support, reliability, stock, skills, networks, safety, capacity or asset-life evidence makes continued recovery less viable than controlled migration.
- Can a conversion tool prove the program is correct?
- No. Incomplete logic, timing, mapping, communications, diagnostics and machine behaviour require engineering review and validation.