Modbus CRC and LRC calculator

Calculate or check the CRC-16 of a Modbus RTU frame, or the LRC of a Modbus ASCII frame, and read every field the bytes carry.

Modbus and serial Updated Free, no sign-up

CRC-16, RTU

Append 8C D4 to send this frame. A frame pasted with its CRC is checked instead.

Read Holding Registers, request

BytesFieldValueMeaning
01Unit address1The server this frame is for or from
03Function0x03Read Holding Registers
2E E0Starting address12000Holding register 412001, protocol address 0x2EE0
00 01Quantity11 holding register; the reply carries 2 data bytes
8C D4CRC-160xD48CLow byte first

The complete frame

  • Spaced01 03 2E E0 00 01 8C D4
  • C array0x01, 0x03, 0x2E, 0xE0, 0x00, 0x01, 0x8C, 0xD4
  • Run together01032EE000018CD4
  • Modbus ASCII, then CR LF:01032EE00001ED
The CRC byte by byte

The register starts at 0xFFFF. Each byte is XORed into its low byte, then it is shifted right eight times, XORed with 0xA001 whenever a 1 falls out.

ByteValueRegister after it
1010x807E
2030x2140
32E0xECA0
4E00xF0ED
5000x4D30
6010xD48C

The register ends at 0xD48C and is sent low byte first: 8C D4.

Check
Check
Frame

Examples

From the unit address on. Paste it with its CRC to check it

CRC bytes, as sent

8C D4

Read Holding Registers request to unit 1.

CRC value
0xD48C
Complete frame
01 03 2E E0 00 01 8C D4
Frame length with CRC
8 bytes

Modbus sends the low byte of the CRC first.

How it’s calculated
  1. CRC = CRC-16/MODBUS(frame), start 0xFFFF, polynomial 0xA001=01 03 2E E0 00 01=0xD48C
  2. Sent low byte first=0xD48C → 8C D4

Choose the gateway connection for this Modbus line.

Build a system

The Modbus CRC-16 of 01 03 2E E0 00 01 is 0xD48C, sent low byte first as 8C D4.

Tip: Paste a frame straight from a serial capture, CRC and all. If the function code sizes the frame, its last bytes are checked and the verdict says whether it arrived intact.

How to calculate a Modbus CRC-16

Every Modbus RTU frame ends with a 16-bit CRC over all the bytes before it, sent low byte first. A device that works out a different CRC discards the frame without replying, which is why a bad CRC shows up as a timeout rather than an error. Modbus ASCII uses a simpler one-byte LRC instead. The calculator works out both and shows the frame byte by byte.

CRC-16 (Modbus RTU)

start 0xFFFF; for each byte: XOR, then 8 × (shift right; if a 1 fell out, XOR 0xA001)

Start with 0xFFFF. XOR the first byte into the low byte of the register, then shift right eight times, XOR-ing 0xA001 after every shift that pushes out a 1. Repeat for every byte from the unit address to the last data byte.

Byte order on the wire

CRC 0x8776 → sent 76 87

The CRC is the only field in a Modbus frame sent low byte first. Everything else, addresses and register values included, goes high byte first.

LRC (Modbus ASCII)

LRC = (0x100 − (sum of bytes mod 0x100)) mod 0x100

Add the address, function and data bytes, drop any carry past 8 bits, and take the two’s complement. It is sent as two hex characters after the data and before CR LF.

Modbus CRC examples

Read three holding registers from unit 17

Unit 0x11 (17), function 03, starting at address 0x006B, three registers: the request from the Modbus serial line guide. Its CRC is 0x8776, sent as 76 87, so the complete frame is 11 03 00 6B 00 03 76 87.

CRC bytes, as sent 76 87 Open in the calculator

The same request in Modbus ASCII

0x11 + 0x03 + 0x00 + 0x6B + 0x00 + 0x03 = 0x82. Its two’s complement is 0x7E, so the LRC is 7E and the line reads :1103006B00037E, then CR LF.

LRC byte 7E Open in the calculator

Checking a captured frame

A serial capture shows 01 03 00 00 00 0A C5 CD. Enter the first six bytes: the CRC comes out as C5 CD, the same as the last two bytes captured, so the frame’s check value matches its preceding bytes. If they differ, look at wiring, termination and noise before the device.

CRC bytes, as sent C5 CD Open in the calculator

CRC and LRC for common Modbus requests

Requests from unit 1 and unit 17, with the CRC in the order it is sent and the Modbus ASCII LRC.

Frame (hex)CRC-16, as sentLRC
01 03 00 00 00 0184 0AFB
01 03 00 00 00 0AC5 CDF2
01 04 00 00 00 0271 CBF9
01 06 00 01 00 0398 0BF5
11 03 00 6B 00 0376 877E
11 10 00 01 00 02 04 00 0A 01 02C6 F0CB

Download this table (CSV)

Questions about Modbus CRC

Why is the Modbus CRC sent low byte first?

It falls out of how the CRC is computed, shifting right from the least significant bit. The Modbus serial line specification fixes the order: low byte, then high byte. Tools that show 0x8776 and frames that end 76 87 are both right.

What happens when the CRC is wrong?

The device discards the frame and does not answer, so the master sees a timeout. It never sends an exception for a bad CRC. Repeated CRC errors usually point at termination, biasing, grounding or cable routing.

Does Modbus TCP use a CRC?

No. Modbus TCP relies on TCP’s own error checking and replaces the CRC with the MBAP header. A gateway between TCP and RTU adds and removes the CRC.

Which CRC variant is Modbus?

CRC-16/MODBUS: polynomial 0x8005 used in reflected form (0xA001), initial value 0xFFFF, no final XOR.

Limits of this result

  • A matching CRC proves only that the entered bytes reproduce the checksum; it does not validate the function, address, quantity or device response.
  • Modbus TCP frames carry no checksum; the MBAP header is not built here.

Read Modbus devices on the Gateway

A ZMB builds and checks the RTU frames itself. It polls the Modbus device locally over RS-485 and sends the data to the Gateway over the wireless mesh.

Related guides

Sources

  1. MODBUS over Serial Line Specification and Implementation Guide V1.02 (opens in a new tab) (PDF) Modbus Organization, 2006-12-20
  2. SCADAPack E Modbus frame diagnostics example (opens in a new tab) Schneider Electric, modified 2025-08-18