PlantAtlas
Industrial architecture explorer

Common core vs industry-specific

Each row is one module of our platforms and each column an industry. A module that is essential everywhere belongs to the product's common core; one that matters only in some industries belongs in that industry's pack.

Module
101
Essential in every industry
33
Matters in some industries only
25

Advanced Process Control (APC) Platform

ModuleScopeOur releaseRefineryPetrochemicalIron & SteelCopper
Plant connectivity and signal conditioning
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Important
Important
Safe operation and fallback
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Important
Cross-industryv1
Important
Important
Useful
Useful
Base-layer audit and PID tuning
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryv1
Essential
Essential
Important
Important
Cross-industryv2
Important
Important
Useful
Important
Plant testing and model identification
Cross-industryMVP
Essential
Essential
Important
Important
Cross-industryv1
Essential
Essential
Important
Important
Cross-industryMVP
Essential
Essential
Important
Important
Cross-industryMVP
Essential
Essential
Important
Useful
Cross-industryv1
Important
Essential
Important
Important
Inferentials and state estimation
Cross-industryMVP
Essential
Essential
Important
Important
Cross-industryMVP
Essential
Essential
Important
Important
Cross-industryMVP
Essential
Essential
Essential
Essential
Multivariable control engine
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Important
Industry-specificLater
Rare
Important
Rare
Rare
Rule-based, fuzzy and adaptive control
Mixedv1
Useful
Useful
Essential
Essential
Mixedv1
Rare
Rare
Important
Important
Mixedv2
Rare
Rare
Useful
Important
Economic optimisation and coordination
Cross-industryv1
Essential
Essential
Important
Important
Cross-industryv1
Important
Important
Useful
Rare
Cross-industryv2
Important
Important
Useful
Useful
Cross-industryLater
Useful
Useful
Useful
Useful
Controller design, configuration and simulation
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Important
Important
Cross-industryMVP
Essential
Essential
Essential
Important
Cross-industryv1
Important
Important
Important
Important
Operation and commissioning
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Important
Important
Cross-industryMVP
Essential
Essential
Essential
Essential
Performance, model health and benefits
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryv1
Essential
Essential
Important
Important
Cross-industryv1
Essential
Essential
Important
Important
Cross-industryv2
Useful
Useful
Useful
Useful
Lifecycle, versioning and security
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryv1
Essential
Essential
Important
Important
Industry application templates
Industry-specificv1
Essential
Rare
Rare
Rare
Industry-specificv2
Rare
Essential
Rare
Rare
Industry-specificv1
Rare
Rare
Essential
Rare
Industry-specificv2
Rare
Rare
Useful
Essential

Industrial Data Platform

ModuleScopeOur releaseRefineryPetrochemicalIron & SteelCopper
Acquisition and connectivity
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Important
Important
Mixedv2
Useful
Useful
Essential
Important
Cross-industryv1
Important
Important
Important
Important
Cross-industryv1
Essential
Essential
Important
Important
Storage and history
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryv1
Essential
Essential
Essential
Important
Cross-industryv1
Important
Important
Essential
Important
Cross-industryv2
Important
Important
Useful
Useful
Context and semantic model
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Important
Essential
Mixedv1
Useful
Important
Essential
Important
Cross-industryv1
Essential
Essential
Important
Important
Data quality, validation and reconciliation
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryv1
Important
Important
Important
Essential
Cross-industryv2
Essential
Important
Important
Essential
Mixedv2
Essential
Important
Important
Essential
Calculation and event processing
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryv1
Important
Essential
Essential
Important
Cross-industryv1
Useful
Important
Important
Important
Access and data services
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryv1
Important
Important
Important
Important
Cross-industryv1
Important
Important
Important
Important
Cross-industryv2
Important
Important
Important
Important
Cross-industryLater
Useful
Important
Useful
Useful
Enterprise and control integration
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryv1
Important
Important
Essential
Important
Cross-industryv1
Essential
Essential
Important
Important
Cross-industryMVP
Essential
Essential
Important
Important
Cross-industryv2
Important
Important
Useful
Useful
Cross-industryv2
Important
Important
Useful
Useful
Applications and visualisation
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryv1
Essential
Essential
Essential
Essential
Cross-industryv1
Essential
Essential
Important
Important
Cross-industryv2
Important
Important
Important
Important
Cross-industryv2
Essential
Essential
Useful
Useful
Industry packs
Cross-industryv1
Essential
Essential
Essential
Essential
Industry-specificv1
Essential
Useful
Rare
Rare
Industry-specificv1
Useful
Essential
Rare
Rare
Industry-specificv1
Rare
Rare
Essential
Useful
Industry-specificv2
Rare
Rare
Useful
Essential
Security and governance
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Essential
Essential
Cross-industryMVP
Essential
Essential
Important
Essential
Cross-industryv1
Important
Important
Important
Important
Platform operations
Cross-industryv1
Important
Important
Important
Essential
Cross-industryv1
Essential
Essential
Important
Important
Cross-industryMVP
Essential
Essential
Essential
Essential

Standards our products must meet

Each row is one requirement a standard places on our products. The badge says how binding it is; click a row to see what it demands, what it means for the architecture and which modules it governs.

Standards & protocolsWhat it demandsData PlatformAPCStandards & compliance
Security
As a product supplier we must run a documented secure development lifecycle for every release of both platforms, including maintenance and end of life, covering eight practices — security management, specification of security requirements, secure by design, secure implementation, security verification and validation testing, management of security-related issues, security update management and security guidelines for users.Certify
Every Data Platform component installed inside or at the boundary of a control zone must provide the technical security capabilities of IEC 62443-4-2 — identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events and resource availability — at the capability security level (SL-C) that the site's zone requires.—Certify
The APC runtime writes setpoints into the DCS every cycle, so its servers and services are control-zone components and must meet IEC 62443-4-2 at the capability security level of the zone in which they are installed.—Certify
The asset owner partitions the plant into zones and conduits on the basis of a security risk assessment and gives each zone a target security level (SL-T). Our products do not perform this assessment, but every deployment has to fit into it.Shapes design
The system built from our products and the customer's infrastructure must meet the system requirements of IEC 62443-3-3 at each zone's target level. The integrator demonstrates this, but can only do so if the products provide the capabilities.Mandatory
Service providers that integrate or maintain automation systems must run a security programme for the work they do at the plant — secure engineering and commissioning, remote access, protection of customer data and credentials, and patching and backup during the service.Certify
OPC UA has its own security model — application-instance certificates, signed or signed-and-encrypted secure channels and user authentication — but it also allows the security mode None; choosing a secure mode is left to the installation.Shapes design
Power-system protocols were designed without security; IEC 62351 adds authentication, integrity and encryption to the IEC 60870-5 protocols such as IEC 60870-5-104 (part 5) and to IEC 61850 (part 6), and covers DNP3 as well.—Shapes design
A vendor must offer a public way to report vulnerabilities, acknowledge and coordinate with reporters, other vendors and national CERTs, and publish advisories that tell users which versions are affected and what to do.Shapes design
A vendor must investigate each reported vulnerability, assess and prioritise it, develop and test a fix, release it and verify that it works, under a documented process.Shapes design
Each release must come with a software bill of materials that lists every third-party and open-source component in a standard machine-readable format such as SPDX (ISO/IEC 5962) or CycloneDX.Shapes design
To sell software in the EU, the manufacturer must meet essential cybersecurity requirements by design, handle vulnerabilities over a declared support period of at least five years, draw up an SBOM, report actively exploited vulnerabilities to ENISA (early warning within 24 hours, from 11 September 2026) and affix CE marking after a conformity assessment (main obligations from 11 December 2027).Mandatory
EU operators of refineries and chemical plants must manage the cybersecurity of their supply chain, including the secure development practices and vulnerability handling of their suppliers.Reference
The company needs an information security management system with a risk assessment, a statement of applicability and audited controls over its people, offices, development systems, cloud accounts and support processes.Certify
A cloud service must document which security responsibilities lie with the provider and which with the customer, separate customers' environments, control administrative operations, let customers monitor activity, and return or delete customer data at contract end.Reference
NE 177 separates core process control from monitoring and optimisation (on and off premises) and requires a NOA security gateway that lets data flow out of core process control without any feedback path, with protection profiles NOA Basic and NOA Extended derived from IEC 62443-3-3.—Shapes design
Any value that comes back from the monitoring and optimisation domain into core process control must pass Verification of Request — authentication and authorisation, verification, mapping, acceptance and mapping verification — with status feedback that reveals nothing about the control system's internals.Shapes design
Safety boundary
Safety instrumented functions must be independent of the basic process control system (BPCS). Because the BPCS is not designed to IEC 61511, the risk reduction claimed for it is strictly limited — at most two BPCS protection layers with a total risk reduction of 100.Mandatory
The end user must carry out a security risk assessment of the SIS that covers the SIS itself, the BPCS and any other device connected to it, identifies threats, consequences and likelihood, and defines the measures that reduce the risk.Mandatory
IEC 61508 governs electrical, electronic and programmable systems that perform safety functions, including the development of their software to a safety integrity level (SIL).Reference
Cybersecurity should be built into every phase of the safety lifecycle — from hazard and risk analysis through design, operation and management of change — so that safety instrumented systems and other safety controls, alarms and interlocks are protected against attack as well as random failure.Reference
ISO/IEC 25010:2023 treats safety as a product quality: the product keeps within operational constraints, identifies risks, fails safe, warns of hazards and integrates safely with the systems around it.Shapes design
Data
Data quality is described by a fixed set of characteristics — such as accuracy, completeness, consistency, credibility and currentness — each with defined ways of measuring it.Shapes design
Master data should meet stated data requirements, carry its provenance and be maintained by defined data-quality management processes, so that its quality is measured and improved rather than assumed.—Shapes design
Data used to train analytics and machine-learning models must have its quality measured and managed across its life cycle — including representativeness, label quality and provenance — under defined governance.Shapes design
Reconciliation must combine redundant measurements and balance equations using each measurement's uncertainty, produce reconciled values with reconciled uncertainties, and test statistically whether measurements and model agree.—Shapes design
Metal accounting should rest on a check-in/check-out balance of measured mass and assays, a documented procedure, authorised and audited use of provisional or replacement data, target accuracies at every accounting measurement point, regular stockpile surveys, and the identification and removal of bias.—Shapes design
Interoperability
OPC UA products can be certified by OPC Foundation accredited test labs for compliance with the profiles they claim, interoperability, robustness, usability and efficient use of resources.Certify
ISA-95 (IEC 62264) defines the equipment hierarchy — enterprise, site, area, work centre, work unit — and the object models used to exchange production information between control and business systems.—Shapes design
ISA-88 (IEC 61512) defines the models of batch control and the structure of batch records — procedure, unit procedure, operation, phase — and how they relate to equipment.—Shapes design
The Asset Administration Shell (IEC 63278 and the IDTA specifications) is the standard digital representation of an asset, organised in submodels such as nameplate, technical data, documentation and time series.—Shapes design
DEXPI is the process industry's exchange format for P&IDs, carrying equipment, instruments, piping and their connections as data rather than drawings.—Shapes design
ISO 15926 provides a data model and a reference data library of standard classes for process-plant equipment, instruments and properties.—Reference
ISO 23247 sets out a framework and reference architecture for digital twins of manufacturing elements — how the twin is fed from the physical element, how it is represented and how it exchanges information with its users.Reference
ISO/IEC 30141 describes IoT systems through common characteristics, architecture views and patterns, with emphasis on trustworthiness — reliability, safety, security, privacy and resilience.—Reference
AI
An organisation that develops or provides AI systems needs an AI management system: AI policy, roles, AI risk and impact assessments, data governance, monitoring of AI performance and continual improvement.Certify
AI-specific risks — unreliable output outside the training data, drift, misuse, opacity — must be identified, analysed, evaluated, treated, monitored and recorded as part of normal risk management.Shapes design
AI systems need life-cycle processes beyond classic software: data acquisition and preparation, model building and verification, deployment, continuous validation in operation, re-training and retirement.Shapes design
An automated AI system must keep its state observable and support a controlled transfer of control to a person or another system, including under uncertainty, and this ability must be verified.—Shapes design
AI systems intended as safety components in the management and operation of critical infrastructure, such as the supply of gas, heating or electricity, are high-risk and carry heavy obligations.Reference
Quality
A certified quality management system that controls design and development, delivery, support and improvement of both products.Certify
Product requirements should cover every quality characteristic explicitly — functional suitability, performance efficiency, compatibility, interaction capability, reliability, security, maintainability, flexibility and safety — with measurable acceptance criteria.Shapes design
Software life-cycle processes run from agreement and planning through development, verification, transition, operation and maintenance to disposal.Reference
Operations
Every alarm presented to an operator through the control system must follow the site's alarm philosophy: identified, rationalised (cause, consequence, operator response, time to respond, priority), documented in the master alarm database, implemented and monitored.—Mandatory
An alarm is an indication to the operator that requires a response, and the alarm standard covers every alarm presented through the control system; information that does not require an operator response must not be presented as an alarm.Shapes design
The alarm management lifecycle includes monitoring and assessing alarm-system performance with defined metrics — alarm rates per operator position, floods, frequent, chattering and stale alarms — and periodic audit.—Shapes design
EEMUA 191 gives practical guidance on alarm-system design and management and widely quoted benchmarks for acceptable alarm load and flood conditions.—Reference
ISA-101 sets out an HMI lifecycle — philosophy, style guide, display hierarchy — and the principles of high-performance displays that make abnormal situations obvious and avoid decoration.Shapes design
IEC 61131-3 defines the programming languages and program units, such as function blocks, of PLCs and of most DCS control languages.Shapes design
An organisation must analyse business impact, set recovery objectives, and maintain and exercise continuity plans for the services others depend on.Reference
A service provider needs a managed system for service levels, incidents, problems, changes, releases and continual improvement.Reference
Privacy
Personal data must be identified, minimised, protected, kept only as long as needed and handled according to the rights of the people it describes, under a privacy management system for controllers and processors.Reference
Industry
ISO 14224 defines the equipment taxonomy and boundaries and the codes for failure modes, mechanisms and causes used to collect reliability and maintenance data in the petroleum, petrochemical and natural gas industries.—Shapes design
Condition-monitoring software is organised as a chain from data acquisition and manipulation through state detection, health assessment and prognostics to advisory generation, with open interfaces between the blocks.—Shapes design
A condition-monitoring programme starts from an equipment audit and criticality, identifies failure modes, selects measurements and techniques, sets alert criteria and reviews the results.—Reference
The 2024 edition of ISO 55001 strengthens the requirements on managing asset data and knowledge, and ISO 55013:2024 gives guidance on managing data for asset management.—Reference
Energy performance indicators and energy baselines should be defined with their relevant variables, normalised, and compared over defined periods to demonstrate energy performance improvement under ISO 50001.Shapes design
An organisation's greenhouse-gas inventory is quantified from activity data and emission factors with documented methods and uncertainty, and must be verifiable.—Reference
A steel plant with DRI and EAF facilities calculates its annual CO₂ emissions and CO₂ intensity within a defined boundary, from defined material and energy flows and emission factors, with stated treatment of upstream and credit flows.—Shapes design
ISO 22400 defines manufacturing-operations KPIs — their formulas, elements, units and timing — such as availability, effectiveness and quality ratio.Shapes design

APC applications by industry

Refinery
Petrochemical
Iron & Steel
Copper