MOFF runs on a single Windows machine in your DMZ, at Purdue level 3.5. It polls downward into the OT network and delivers upward into IT. Data crosses the boundary in one direction only.
The DMZ is the common case, not the only one. Where MOFF sits is a question of where your network boundary is and who needs the data.
The levels on the diagram are the ones your architects already use. MOFF polls equipment at levels 0 to 2, runs at the boundary most sites call level 3.5, and delivers to business and analytics systems at levels 4 and 5. If a network drawing already places a DMZ between OT and IT, MOFF goes where that drawing says.
On the security side the same logic applies. A read-only path out of the OT zone with no inbound route is what a zone and conduit model asks for, and MOFF is designed that way. No IEC 62443 certification is claimed, because none has been carried out.
Want to see it running against your own protocols?