Modbus Basics: Registers, Addressing & Data Types
A practical introduction to Modbus for controls technicians, PLC programmers, BAS technicians, integrators, and instrumentation engineers.
What Is Modbus?
Modbus is a communications protocol commonly used to exchange data between industrial controllers, instruments, meters, drives, PLCs, HMIs, SCADA systems, and building automation equipment.
One reason Modbus remains common in controls is its relative simplicity. A device exposes data points, and another device reads or writes those data points using defined Modbus functions.
Modbus can operate over several physical communication methods. Two common implementations encountered in controls are Modbus RTU over RS-485 and Modbus TCP over Ethernet.
Modbus Client and Server
Modern Modbus terminology generally uses client and server.
The client initiates a request, while the server responds with the requested data or acknowledges a write operation.
Older documentation often uses the terms master and slave. You will still encounter those terms frequently in existing PLC, gateway, instrument, and BAS documentation.
PLC or BAS controller = Modbus client
Energy meter = Modbus server
The controller requests a register from the meter, and the meter returns the requested data.
Modbus Data Types
Modbus data is commonly organized into four logical categories.
| Type | Typical Description | Access |
|---|---|---|
| Coils | Single-bit digital outputs | Read / Write |
| Discrete Inputs | Single-bit digital inputs | Read Only |
| Input Registers | 16-bit register values | Read Only |
| Holding Registers | 16-bit register values | Read / Write |
These categories describe the standard Modbus data model. A specific device may use its register map in ways that require additional interpretation.
Understanding Modbus Registers
A standard Modbus register contains 16 bits of data. That means a single register can represent a range of values depending on how the device interprets those bits.
For example, an unsigned 16-bit register can represent:
A signed 16-bit integer uses one bit for the sign and therefore has a different range:
The important point is that the register itself is simply binary data. The device documentation tells you how that data should be interpreted.
Modbus Addressing
Modbus addressing is one of the most common sources of confusion when integrating equipment.
Device documentation may describe a register using terminology such as:
- Register 0
- Register 1
- Holding Register 40001
- Holding Register 40010
- Offset 9
These descriptions do not necessarily mean that the number entered into a particular PLC or gateway configuration should be identical.
The 40001 Problem
A register documented as 40001 is often intended to indicate a holding register, but the actual address used by a driver may be 0, 1, or another offset depending on its addressing scheme.
If every other setting appears correct but the data is coming from the wrong register, addressing convention should be one of the first things to verify.
Register Scaling
The number contained in a Modbus register is not necessarily the engineering value displayed by the device.
A manufacturer may scale a measurement before storing it in a register.
A temperature register contains: 725
The device documentation says the value is temperature in tenths of a degree Fahrenheit.
Therefore:
Another device might provide a raw value from 0–1000 that represents 0–100 PSI. In that case, linear scaling is required.
The important rule is: do not assume the scaling. Find it in the device register map.
Signed and Unsigned Values
A 16-bit register can be interpreted as either an unsigned integer or a signed integer.
If a register contains a value that appears unexpectedly large or negative, verify the data type specified by the device manufacturer.
This is particularly important for values such as temperature, pressure, position, and other measurements that can cross zero.
32-Bit Values
A standard Modbus register is 16 bits, but many devices need more than 16 bits to represent a value.
A 32-bit value therefore occupies two consecutive 16-bit registers.
The device documentation should specify how those two registers are arranged and interpreted.
IEEE-754 Floating-Point Values
Many instruments and controllers use IEEE-754 single-precision floating point to transmit measurements such as temperature, pressure, flow, or electrical values.
A 32-bit floating-point value occupies two 16-bit Modbus registers.
The raw register values must be combined correctly before the IEEE-754 representation can be decoded.
This is where word order and byte order become particularly important.
IEEE-754 Floating Point Converter → Convert hexadecimal, binary, and IEEE-754 floating-point values when troubleshooting register data.Byte Order and Word Order
Multi-register data can be confusing because devices may use different byte and word arrangements.
Consider a 32-bit value stored in two registers:
Register B = remaining 16 bits
One device may place the high word first while another may place the low word first. Individual bytes within a word can also be arranged differently depending on the implementation.
For gateway and PLC integrations, terms such as ABCD, CDAB, BADC, and DCBA may be used to describe byte or word arrangements.
Practical Modbus Example
Imagine an energy meter with the following register documentation:
Address: 40101
Data type: Unsigned 16-bit
Scaling: Divide by 10
Description: Voltage
The controller reads a raw value of:
Applying the documented scaling:
If the controller instead displays 480 V, the communication may be working perfectly—the scaling configuration is simply wrong.
Modbus Troubleshooting Workflow
When a Modbus point is not behaving as expected, work from the communication layer toward the data interpretation layer.
1. Verify Physical Communication
- Check wiring and connections.
- Verify RS-485 polarity where applicable.
- Check Ethernet connectivity for Modbus TCP.
- Verify termination and biasing where required.
2. Verify Communication Settings
- Slave/server address
- Baud rate
- Parity
- Stop bits
- Communication mode
3. Verify the Modbus Function
Make sure the client is requesting the correct data type and function for the point being accessed.
4. Verify the Register Address
Check the manufacturer's register map and determine whether the software expects zero-based or one-based addressing.
5. Verify the Data Type
Determine whether the value is an unsigned integer, signed integer, 32-bit value, floating point, or another format.
6. Verify Scaling
Check for multiplication factors, divisors, offsets, or engineering-unit conversions.
7. Verify Byte and Word Order
This is especially important for 32-bit integers and floating-point values.
Modbus Tools
ControlsCalc includes several tools that can help when interpreting Modbus and PLC data.
Modbus Register Converter → Convert raw Modbus register values into engineering units using configurable ranges and scaling. IEEE-754 Floating Point Converter → Decode floating-point values when a device uses two registers to represent a measurement. PLC Raw Counts → Engineering Units → Convert PLC analog input counts into engineering units using configurable ranges.