IoT and Edge Connectivity in Hazardous Areas: The Complete Guide to Ex Zones, Sensors and Wireless

IoT In Hazardous Areas
Field Resource

IoT and Edge Connectivity in Hazardous Areas

A working guide to deploying sensors, wireless networks and edge computing where an explosive atmosphere can form. What the Ex zones actually mean, which connectivity technologies survive them, and how to lay out an architecture that keeps a refinery, silo or chemical plant both instrumented and safe.

The short version. A hazardous area is anywhere a flammable gas, vapour, mist or dust can mix with air in ignitable quantities. You cannot drop a standard sensor or gateway into one. Every device has to carry an explosion-protection certification matched to the zone, the gas or dust group and a maximum surface temperature. For low-power IoT the dominant protection concept is intrinsic safety (Ex ia/ib/ic), and the practical pattern is simple: certified field devices in the zone, the compute and the backhaul pushed out to a gateway at the edge of it.

What counts as a hazardous area

A hazardous area is a location in which an explosive atmosphere is present, or can reasonably be expected to be present, in quantities that demand special precautions for the construction, installation and use of equipment. An explosive atmosphere is a mixture with air, under normal atmospheric conditions, of flammable substances as gas, vapour, mist or dust, in which combustion spreads through the whole mixture once it is ignited. Wherever electrical or even non-electrical equipment operates in or near that mixture, there is a standing risk of fire or explosion. This framing follows the classification model set out by explosion-protection specialists such as Bartec, which we have extended here into the IoT and connectivity domain.

Typical hazardous environments include oil and gas facilities, chemical and petrochemical plants, pharmaceutical production, energy and hydrogen infrastructure, and manufacturing or logistics sites that handle combustible dusts. These are exactly the sites now under pressure to instrument everything: remote condition monitoring, emissions and leak detection, tank-level telemetry, predictive maintenance on rotating equipment. The tension the whole industry is working through is that the places with the strongest business case for IoT are also the places with the hardest constraints on the hardware.

Two regulatory regimes dominate. Most of the world uses the Zone system under the IEC 60079 series of standards, localised as ATEX in Europe and UKEX in Great Britain, with IECEx as the international certification scheme. The United States and Canada historically use the Class/Division system under the National Electrical Code, though the Zone system is now permitted there too. If you are specifying hardware for a global asset base, you will meet both.

How hazardous areas are classified

Classification is about probability and duration. It answers one question for every point in a plant: how often, and for how long, is an ignitable atmosphere actually present here? The answer sets the zone, and the zone sets what equipment is allowed. Gases and vapours use Zones 0, 1 and 2. Combustible dusts use Zones 20, 21 and 22. In both cases the lower number is the more dangerous, because the atmosphere is present more of the time.

Safe (non-hazardous) area ZONE 0 vapour space ZONE 1 around the vent, occasional release ZONE 2 unlikely, brief if it occurs at all Zone 0 / 20 – continuous Zone 1 / 21 – occasional Zone 2 / 22 – rare / brief

Zones are nested by probability. The inside of the vessel is Zone 0; the space around a vent where releases occur in normal operation is Zone 1; the wider envelope where a release is unlikely and short-lived is Zone 2. Dust zones (20, 21, 22) follow the same logic for clouds of combustible dust.

Once a plant has been zoned, the classification is tied to an Equipment Protection Level (EPL) and an ATEX equipment category. The EPL is what you will actually read off a device label. The table below maps the whole chain for both gas and dust.

SubstancePresence of the atmosphereZoneATEX category (Group II)Protection levelEPL
Gas, vapour, mistContinuous or long periods, or frequentZone 01GVery highGa
Gas, vapour, mistOccasional in normal operationZone 12GHighGb
Gas, vapour, mistUnlikely, and brief if it occursZone 23GNormalGc
DustContinuous or long periods, or frequentZone 201DVery highDa
DustOccasional in normal operationZone 212DHighDb
DustUnlikely, and brief if it occursZone 223DNormalDc

The zone is only half of the specification. The other half describes what could ignite and how hot the equipment is allowed to get. Gases are split into groups by how easily they ignite and how much energy an explosion releases; dusts are grouped by conductivity; and every device carries a temperature class capping its maximum surface temperature below the auto-ignition point of the surrounding material.

Classification axisCategoryRepresentative material / limit
Gas group (Group II)IIAPropane – least onerous
IIBEthylene
IICHydrogen and acetylene – most onerous
Dust group (Group III)IIIACombustible flyings
IIIBNon-conductive dust
IIICConductive dust (for example metal dust)
Temperature classT1Max surface temperature 450 °C
T2300 °C
T3200 °C
T4135 °C – common target for electronics
T5100 °C
T685 °C – most demanding

Read together, these produce the marking string you will see on a compliant device, for example Ex ia IIC T4 Ga. That reads as: intrinsically safe, suitable for the hydrogen and acetylene gas group, surface temperature never above 135 °C, and rated to the highest equipment protection level so it can sit in Zone 0. A device certified only to Ex ic IIA T4 Gc is a completely different animal and belongs in Zone 2 with the easiest gases.

Do not confuse the two systems. A US Class/Division label is not interchangeable with a Zone label. Class I covers gases and vapours, Class II combustible dusts, Class III ignitable fibres and flyings, and Division 1 or 2 describes how often the material is present. If your estate spans both regimes, specify equipment carrying dual approval rather than trying to translate a certificate after the fact.

What “Ex-certified” actually means for an IoT device

Explosion protection is not one technique but a family of them, each defined in a part of IEC 60079. A device can combine several. The concept you choose decides which zones the device can enter, how it is built and how much it costs. For battery-powered sensors and radios, one concept dominates because it is the only one that makes a small, cheap, low-power device economic in the most dangerous zones.

ConceptMarkingHow it worksTypical zoneIoT relevance
Intrinsic safetyEx ia / ib / icLimits electrical and thermal energy in the circuit below what can ignite the atmosphere, even under faultia: Zone 0/20
ib: Zone 1/21
ic: Zone 2/22
The default for sensors, transmitters and low-power radios. Low energy budget suits IoT
FlameproofEx dContains any internal explosion inside a robust enclosure so it cannot propagate outZone 1/2Used for higher-power gateways, cameras and cellular routers that cannot meet the IS energy limit
Increased safetyEx eExtra measures against arcs, sparks and hot surfaces in normal operationZone 1/2Terminal boxes, junctions, antenna feedthroughs
EncapsulationEx mIgnition-capable parts sealed in compoundZone 0/1/2 by subdivisionSealed sensor modules and small electronics
PressurisationEx pPositive internal pressure keeps the atmosphere outZone 1/2Larger edge enclosures, HMI panels, analysers
Non-sparking / restrictedEx ec / nAReduced likelihood of ignition in normal operation onlyZone 2Cost-effective route for Zone 2 gateways and I/O

Why intrinsic safety is the IoT concept. An intrinsically safe circuit is engineered so that neither a spark nor a hot component can ever deliver enough energy to ignite the atmosphere, even with two independent faults present for Ex ia. Because the protection lives in the energy budget rather than in a heavy enclosure, an Ex ia sensor can be small, sealed and battery-driven, which is precisely the IoT device profile. The cost is a hard ceiling on power, current and stored energy, which ripples all the way through your choice of radio, duty cycle and battery.

The sensing layer: what you actually measure

The reason to accept all this constraint is data. The sensing workloads that justify hazardous-area IoT cluster into a handful of families, each with mature Ex-certified hardware on the market:

  • Gas and leak detection. Fixed and wireless detectors for methane, H2S, oxygen depletion, VOCs and hydrogen. Increasingly the highest-value IoT use case because a networked detector is also an emissions and compliance instrument.
  • Condition monitoring. Vibration and temperature on pumps, motors, compressors and agitators for predictive maintenance. Small, high-duty-cycle, and the classic case for edge analytics because raw vibration data is expensive to backhaul.
  • Level, pressure and flow. Tank and silo telemetry, wellhead and pipeline monitoring, often in remote spots where the connectivity question dominates.
  • Temperature. Process, bearing and trace-heating measurement, frequently the input to a safety function.
  • Corrosion and integrity. Wall-thickness and cathodic-protection sensing on pipwork and vessels, typically very low data rate but very long-lived.

The connectivity layer: wireless in an explosive atmosphere

There are two myths worth clearing first. The first is that a radio is dangerous because it emits RF. At the transmit powers used across IoT, from tens of milliwatts up to around a watt, the radiated RF energy sits well below the ignition thresholds that IEC 60079 concerns itself with for the common gas groups. The real constraint is not the transmission, it is the device: its electronics, its battery and its enclosure all still need an appropriate protection concept. The second myth is that you must run cables everywhere. You do not, but the wireless standard you pick has to co-exist with the energy limits of intrinsic safety and, more often, with a plant that is already running a purpose-built industrial wireless network.

Range → Data rate → short (metres) long (kilometres) BLE ZigbeeThread WirelessHART / ISA100 Wi-FiHaLow 5G /RedCap NB-IoT LTE-M LoRaWAN Bubble colour is only for legibility, not a rating

Rough positioning of the main options. There is no single winner: LPWAN technologies trade data rate for range and battery life, HaLow and cellular buy throughput back at a power cost, and the industrial mesh standards win on determinism and their installed base in process plants.

LoRaWAN

Sub-GHz, unlicensed, very long range and very low power, at the price of a low data rate and no hard real-time guarantee. It is the natural fit for sparse, battery-first telemetry across a large site: tank levels, cathodic protection, remote wellheads. Ex-certified LoRaWAN transmitters are readily available, and the tiny energy budget sits comfortably inside intrinsic safety.

NB-IoT and LTE-M

The 3GPP low-power wide-area pair, licensed and carrier-operated, which removes the need to own gateways. NB-IoT excels at deep-indoor and below-grade penetration for static, low-rate assets; LTE-M adds throughput, mobility and voice for mobile workers and lone-worker safety devices. Both benefit directly from eSIM and remote SIM provisioning for fleets that are hard to reach once installed.

Wi-Fi HaLow (802.11ah)

Sub-GHz Wi-Fi built for IoT: roughly a kilometre of range with far higher throughput than the LPWAN options, and a native IP stack that makes it easy to carry richer payloads such as imaging, acoustic monitoring or higher-rate vibration. It costs more power than LoRaWAN, so it suits mains or larger-battery field devices and Zone 2 assets rather than the deepest zones. It is the bridge technology when you have outgrown LPWAN data rates but do not want a cellular subscription per device.

Zigbee, Thread and 802.15.4

Short-range, low-power mesh at 2.4 GHz. Useful for dense clusters of sensors around a single skid or process unit where a self-healing mesh removes cabling, though 2.4 GHz range and penetration in a steel-heavy plant is a real limitation.

WirelessHART and ISA100.11a

These are the incumbents, and any hazardous-area connectivity guide that ignores them is incomplete. Both are 2.4 GHz, 802.15.4-based industrial mesh standards, standardised as IEC 62591 and IEC 62734 respectively, and purpose-built for process automation with the determinism, security and Ex-certified field-device ecosystem that refineries and chemical plants already trust. In many brownfield sites the right connectivity answer is not a new IoT network at all, it is another node on the WirelessHART mesh that is already there.

Bluetooth Low Energy

Short range, but valuable for commissioning, asset tags, and pairing portable gas detectors or personnel devices to a nearby gateway. Ex-certified BLE beacons and wearables are common in mobile-worker deployments.

Private 5G and cellular RedCap

Where the workload is high bandwidth or latency-sensitive – video analytics, automated guided vehicles, dense real-time telemetry – private cellular earns its place. The emerging middle tier is RedCap (reduced-capability 5G), which trims cost and power to sit between LPWAN and full 5G, a good match for cameras and mid-rate industrial sensors that LPWAN cannot serve.

The wired backbone: Ethernet-APL and 2-WISE

Not everything should be wireless. Ethernet-APL brings 10 Mbit/s Ethernet (10BASE-T1L, IEEE 802.3cg) over a single twisted pair for up to a kilometre, loop-powered, all the way to the field device. Its intrinsically safe variant, 2-WISE (2-Wire Intrinsically Safe Ethernet, specified in IEC TS 60079-47:2021 and built on IEC 60079-11 and -25), defines universal intrinsic-safety port parameters so an APL spur can reach Ex ia and therefore Zone 0 and 20. For dense, high-rate instrumentation on a new-build process unit, APL gives you a deterministic, IP-native trunk that a mesh of battery radios cannot match, and it removes the per-loop intrinsic-safety calculation that made fieldbus commissioning painful.

TechnologyRangeData ratePowerSpectrumTypical Ex fit
LoRaWANLong (km)Very lowVery lowUnlicensed sub-GHzEx ia sensors, remote telemetry
NB-IoTLongLowLowLicensedDeep-indoor static assets
LTE-MLongLow-mediumLow-mediumLicensedMobile and worker safety
Wi-Fi HaLowMedium (~1 km)Medium-highMediumUnlicensed sub-GHzZone 2 rich-payload sensors
Zigbee / ThreadShortLowLow2.4 GHzDense skid-level mesh
WirelessHART / ISA100Short-medium (mesh)LowLow2.4 GHzProcess automation, large Ex ecosystem
5G / RedCapMediumHighMedium-highLicensed / privateVideo, AGVs, Ex d enclosures
Ethernet-APL (2-WISE)Wired, to 1 kmVery high (10 Mbit/s)Loop-poweredn/aEx ia trunk to Zone 0/20

The edge layer: computing at the boundary of the plant

Hazardous-area sites are where edge computing stops being a buzzword and becomes structural. Four forces push processing out to a gateway rather than the cloud. Bandwidth: raw vibration or acoustic data is far too heavy to stream continuously over an LPWAN or a metered cellular link, so it has to be reduced to features and alarms locally. Latency: a safety-relevant response, such as shutting a valve on a gas alarm, cannot wait for a round trip to a data centre. Autonomy: remote terminals and offshore assets need to keep functioning through backhaul outages. And security: the fewer raw streams that leave the plant boundary, the smaller the attack surface.

The practical pattern almost always looks the same. Certified field devices live in the zone. An Ex-rated gateway – flameproof (Ex d) if it is a powerful cellular or compute unit, or increased-safety and non-sparking (Ex e / Ex ec) if it can sit in Zone 2 – aggregates them, runs the edge analytics, and holds the backhaul radio. Wherever a low-energy field circuit has to cross from a safe area into Zone 0 or 1, an intrinsic-safety barrier or isolator, or a 2-WISE APL port, sits on the boundary and enforces the energy limit. The compute and the expensive, power-hungry radio are kept out of the worst zone; only the certified, energy-limited endpoints go in.

A reference architecture

To make this concrete, picture a fuel storage terminal. Vapour spaces inside the tanks are Zone 0; the vents and manifolds are Zone 1; the surrounding bunded area is Zone 2; the control room is a safe area. Here is how the layers stack up.

ZONE 0 / 1 BOUNDARY ZONE 2 SAFE AREA / CLOUD Ex ia level / gas Ex ia vibration WirelessHART node IS barrier/ 2-WISE Ex d gatewayedge computeanalytics + alarmsRedCap / satellite backhaul Platform / SCADAdashboards, historian emissions / compliancereporting

Certified, energy-limited endpoints go into the zone. The intrinsic-safety boundary sits at the zone edge. Compute and the power-hungry backhaul radio live in the Ex d gateway just outside the worst zone, sending only features, alarms and compliance data onward.

Reading left to right: Ex ia level, gas and vibration sensors sit in Zone 0 and 1, energy-limited by design. At the boundary, an intrinsic-safety barrier or a 2-WISE APL port lets their signals cross into the less hazardous area without carrying enough energy to ignite anything. A flameproof Ex d gateway in Zone 2 aggregates everything, runs the condition-monitoring and gas-alarm logic locally so a leak triggers action in milliseconds, and only then backhauls a compact stream over RedCap or satellite to the platform in the safe area. The heavy compute and the strongest radio never enter Zone 0. That separation is the whole game.

How to select and specify: a checklist

Before you buy a single device, work through the specification in this order. Skipping a step is how a project ends up with hardware that cannot legally be installed.

  1. Zone. Get the hazardous-area classification drawing and confirm the zone for the exact mounting point, not the general area.
  2. Gas or dust group. Identify the material – IIA, IIB or IIC for gas; IIIA to IIIC for dust.
  3. Temperature class. Confirm the required T-rating against the material’s auto-ignition temperature and the ambient.
  4. Protection concept. Choose Ex ia/ib/ic, Ex d, Ex e and so on to match the zone and the device’s power budget.
  5. Certification scheme. ATEX, UKEX or IECEx, and dual approval if the asset base is global. Check the certificate covers the specific model and firmware.
  6. Ingress and environment. IP rating, corrosion, vibration and temperature range for the real installation.
  7. Power and battery. An intrinsically safe device has a certified maximum stored energy; confirm the battery pack is part of the certification.
  8. Connectivity. Match the radio to range, data rate and the networks already on site before defaulting to something new.
  9. Gateway placement. Push compute and backhaul to the least hazardous zone that still gives coverage.
  10. Documentation. Maintain the Ex register, verification dossier and inspection regime; certification is a lifecycle obligation, not a one-off.

Frequently asked questions

Can I put a normal IoT sensor in a hazardous area if I seal it in a box?

No. A general-purpose enclosure does not make a device compliant. The device itself has to be certified to an explosion-protection concept appropriate to the zone, gas or dust group and temperature class. Sealing an uncertified device changes nothing about its internal ignition risk.

Does a wireless transmitter’s RF energy risk igniting the atmosphere?

At the transmit powers used across IoT, the radiated RF is generally well below the ignition thresholds in IEC 60079 for the common gas groups. The certification concern is the device’s own electronics, battery and enclosure, not the transmission itself.

Which connectivity technology is best for hazardous areas?

There is no single best. LoRaWAN and NB-IoT suit sparse, low-rate, battery-first telemetry; Wi-Fi HaLow and RedCap carry richer payloads at a power cost; and WirelessHART or ISA100.11a are often the right answer on a brownfield process plant because the mesh and its certified devices are already installed.

What is intrinsic safety and why does it matter for IoT?

Intrinsic safety (Ex ia/ib/ic) limits the electrical and thermal energy in a circuit below what can ignite the atmosphere, even under fault. Because the protection is in the energy budget rather than a heavy enclosure, it is the only concept that lets a small, sealed, battery-powered device operate in the most dangerous zones, which is exactly the IoT device profile.

Where should the gateway and edge compute sit?

In the least hazardous zone that still provides coverage, usually Zone 2 or a safe area. The compute and the power-hungry backhaul radio are the parts hardest to make intrinsically safe, so you keep them out of Zone 0 and 1 and let energy-limited endpoints reach in.

Sources and further reading: hazardous-area classification framing adapted from Bartec; standards references to the IEC 60079 series, ATEX Directives 2014/34/EU and 1999/92/EC, IECEx, IEC TS 60079-47:2021 (2-WISE), IEC 62591 (WirelessHART) and IEC 62734 (ISA100.11a). This guide is educational and is not a substitute for a formal DSEAR, ATEX or IECEx assessment. Always classify areas and certify equipment through a competent authority for your specific installation.