Modbus RTU frames explained
Dinesh Kumar G · 1 min read · 4 October 2026
What is inside a Modbus RTU request and response, how the CRC-16 is calculated, and the mistakes that stop a slave from answering.
The frame
Every Modbus RTU message is: slave ID (1 byte) → function code (1 byte) → data → CRC (2 bytes). Frames are separated by at least 3.5 character times of silence on the line.
Common function codes
| Code | Meaning |
|---|---|
| 01 | Read coils |
| 02 | Read discrete inputs |
| 03 | Read holding registers |
| 04 | Read input registers |
| 05 | Write single coil |
| 06 | Write single register |
| 15 | Write multiple coils |
| 16 | Write multiple registers |
A worked example
Read 10 holding registers starting at address 0 from slave 1:
01 03 00 00 00 0A C5 CD
01 slave, 03 function, 00 00 start address, 00 0A quantity, C5 CD CRC. Build your own in the Modbus RTU frame builder.
The CRC-16
Start with 0xFFFF. For each byte, XOR it into the low byte of the CRC, then shift right eight times; after each shift, if the bit shifted out was 1, XOR with 0xA001. Send the result low byte first — the one field that is not high byte first.
Why a slave doesn't answer
- CRC bytes swapped.
- Address off by one: register 40001 in a manual is address 0 on the wire.
- Function 03 used for a value the device keeps as an input register (04).
- Baud rate, parity or stop bits different from the slave.
- Two masters on one RS-485 line, or no termination on a long run.