Common core vs industry-specific
Each row is one module of our platforms and each column an industry. A module that is essential everywhere belongs to the product's common core; one that matters only in some industries belongs in that industry's pack.
Module
101
Essential in every industry
33
Matters in some industries only
25
Advanced Process Control (APC) Platform
| Module | Scope | Our release | Refinery | Petrochemical | Iron & Steel | Copper |
|---|---|---|---|---|---|---|
| Plant connectivity and signal conditioning | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Important | Important | |
| Safe operation and fallback | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Important | |
| Cross-industry | v1 | Important | Important | Useful | Useful | |
| Base-layer audit and PID tuning | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Cross-industry | v2 | Important | Important | Useful | Important | |
| Plant testing and model identification | ||||||
| Cross-industry | MVP | Essential | Essential | Important | Important | |
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Cross-industry | MVP | Essential | Essential | Important | Important | |
| Cross-industry | MVP | Essential | Essential | Important | Useful | |
| Cross-industry | v1 | Important | Essential | Important | Important | |
| Inferentials and state estimation | ||||||
| Cross-industry | MVP | Essential | Essential | Important | Important | |
| Cross-industry | MVP | Essential | Essential | Important | Important | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Multivariable control engine | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Important | |
| Industry-specific | Later | Rare | Important | Rare | Rare | |
| Rule-based, fuzzy and adaptive control | ||||||
| Mixed | v1 | Useful | Useful | Essential | Essential | |
| Mixed | v1 | Rare | Rare | Important | Important | |
| Mixed | v2 | Rare | Rare | Useful | Important | |
| Economic optimisation and coordination | ||||||
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Cross-industry | v1 | Important | Important | Useful | Rare | |
| Cross-industry | v2 | Important | Important | Useful | Useful | |
| Cross-industry | Later | Useful | Useful | Useful | Useful | |
| Controller design, configuration and simulation | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Important | Important | |
| Cross-industry | MVP | Essential | Essential | Essential | Important | |
| Cross-industry | v1 | Important | Important | Important | Important | |
| Operation and commissioning | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Important | Important | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Performance, model health and benefits | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Cross-industry | v2 | Useful | Useful | Useful | Useful | |
| Lifecycle, versioning and security | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Industry application templates | ||||||
| Industry-specific | v1 | Essential | Rare | Rare | Rare | |
| Industry-specific | v2 | Rare | Essential | Rare | Rare | |
| Industry-specific | v1 | Rare | Rare | Essential | Rare | |
| Industry-specific | v2 | Rare | Rare | Useful | Essential | |
Industrial Data Platform
| Module | Scope | Our release | Refinery | Petrochemical | Iron & Steel | Copper |
|---|---|---|---|---|---|---|
| Acquisition and connectivity | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Important | Important | |
| Mixed | v2 | Useful | Useful | Essential | Important | |
| Cross-industry | v1 | Important | Important | Important | Important | |
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Storage and history | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | v1 | Essential | Essential | Essential | Important | |
| Cross-industry | v1 | Important | Important | Essential | Important | |
| Cross-industry | v2 | Important | Important | Useful | Useful | |
| Context and semantic model | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Important | Essential | |
| Mixed | v1 | Useful | Important | Essential | Important | |
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Data quality, validation and reconciliation | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | v1 | Important | Important | Important | Essential | |
| Cross-industry | v2 | Essential | Important | Important | Essential | |
| Mixed | v2 | Essential | Important | Important | Essential | |
| Calculation and event processing | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | v1 | Important | Essential | Essential | Important | |
| Cross-industry | v1 | Useful | Important | Important | Important | |
| Access and data services | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | v1 | Important | Important | Important | Important | |
| Cross-industry | v1 | Important | Important | Important | Important | |
| Cross-industry | v2 | Important | Important | Important | Important | |
| Cross-industry | Later | Useful | Important | Useful | Useful | |
| Enterprise and control integration | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | v1 | Important | Important | Essential | Important | |
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Cross-industry | MVP | Essential | Essential | Important | Important | |
| Cross-industry | v2 | Important | Important | Useful | Useful | |
| Cross-industry | v2 | Important | Important | Useful | Useful | |
| Applications and visualisation | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | v1 | Essential | Essential | Essential | Essential | |
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Cross-industry | v2 | Important | Important | Important | Important | |
| Cross-industry | v2 | Essential | Essential | Useful | Useful | |
| Industry packs | ||||||
| Cross-industry | v1 | Essential | Essential | Essential | Essential | |
| Industry-specific | v1 | Essential | Useful | Rare | Rare | |
| Industry-specific | v1 | Useful | Essential | Rare | Rare | |
| Industry-specific | v1 | Rare | Rare | Essential | Useful | |
| Industry-specific | v2 | Rare | Rare | Useful | Essential | |
| Security and governance | ||||||
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
| Cross-industry | MVP | Essential | Essential | Important | Essential | |
| Cross-industry | v1 | Important | Important | Important | Important | |
| Platform operations | ||||||
| Cross-industry | v1 | Important | Important | Important | Essential | |
| Cross-industry | v1 | Essential | Essential | Important | Important | |
| Cross-industry | MVP | Essential | Essential | Essential | Essential | |
Standards our products must meet
Each row is one requirement a standard places on our products. The badge says how binding it is; click a row to see what it demands, what it means for the architecture and which modules it governs.
| Standards & protocols | What it demands | Data Platform | APC | Standards & compliance | ||
|---|---|---|---|---|---|---|
| Security | ||||||
| As a product supplier we must run a documented secure development lifecycle for every release of both platforms, including maintenance and end of life, covering eight practices — security management, specification of security requirements, secure by design, secure implementation, security verification and validation testing, management of security-related issues, security update management and security guidelines for users. | Certify | |||||
| Every Data Platform component installed inside or at the boundary of a control zone must provide the technical security capabilities of IEC 62443-4-2 — identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events and resource availability — at the capability security level (SL-C) that the site's zone requires. | — | Certify | ||||
| The APC runtime writes setpoints into the DCS every cycle, so its servers and services are control-zone components and must meet IEC 62443-4-2 at the capability security level of the zone in which they are installed. | — | Certify | ||||
| The asset owner partitions the plant into zones and conduits on the basis of a security risk assessment and gives each zone a target security level (SL-T). Our products do not perform this assessment, but every deployment has to fit into it. | Shapes design | |||||
| The system built from our products and the customer's infrastructure must meet the system requirements of IEC 62443-3-3 at each zone's target level. The integrator demonstrates this, but can only do so if the products provide the capabilities. | Mandatory | |||||
| Service providers that integrate or maintain automation systems must run a security programme for the work they do at the plant — secure engineering and commissioning, remote access, protection of customer data and credentials, and patching and backup during the service. | Certify | |||||
| OPC UA has its own security model — application-instance certificates, signed or signed-and-encrypted secure channels and user authentication — but it also allows the security mode None; choosing a secure mode is left to the installation. | Shapes design | |||||
| Power-system protocols were designed without security; IEC 62351 adds authentication, integrity and encryption to the IEC 60870-5 protocols such as IEC 60870-5-104 (part 5) and to IEC 61850 (part 6), and covers DNP3 as well. | — | Shapes design | ||||
| A vendor must offer a public way to report vulnerabilities, acknowledge and coordinate with reporters, other vendors and national CERTs, and publish advisories that tell users which versions are affected and what to do. | Shapes design | |||||
| A vendor must investigate each reported vulnerability, assess and prioritise it, develop and test a fix, release it and verify that it works, under a documented process. | Shapes design | |||||
| Each release must come with a software bill of materials that lists every third-party and open-source component in a standard machine-readable format such as SPDX (ISO/IEC 5962) or CycloneDX. | Shapes design | |||||
| To sell software in the EU, the manufacturer must meet essential cybersecurity requirements by design, handle vulnerabilities over a declared support period of at least five years, draw up an SBOM, report actively exploited vulnerabilities to ENISA (early warning within 24 hours, from 11 September 2026) and affix CE marking after a conformity assessment (main obligations from 11 December 2027). | Mandatory | |||||
| EU operators of refineries and chemical plants must manage the cybersecurity of their supply chain, including the secure development practices and vulnerability handling of their suppliers. | Reference | |||||
| The company needs an information security management system with a risk assessment, a statement of applicability and audited controls over its people, offices, development systems, cloud accounts and support processes. | Certify | |||||
| A cloud service must document which security responsibilities lie with the provider and which with the customer, separate customers' environments, control administrative operations, let customers monitor activity, and return or delete customer data at contract end. | Reference | |||||
| NE 177 separates core process control from monitoring and optimisation (on and off premises) and requires a NOA security gateway that lets data flow out of core process control without any feedback path, with protection profiles NOA Basic and NOA Extended derived from IEC 62443-3-3. | — | Shapes design | ||||
| Any value that comes back from the monitoring and optimisation domain into core process control must pass Verification of Request — authentication and authorisation, verification, mapping, acceptance and mapping verification — with status feedback that reveals nothing about the control system's internals. | Shapes design | |||||
| Safety boundary | ||||||
| Safety instrumented functions must be independent of the basic process control system (BPCS). Because the BPCS is not designed to IEC 61511, the risk reduction claimed for it is strictly limited — at most two BPCS protection layers with a total risk reduction of 100. | Mandatory | |||||
| The end user must carry out a security risk assessment of the SIS that covers the SIS itself, the BPCS and any other device connected to it, identifies threats, consequences and likelihood, and defines the measures that reduce the risk. | Mandatory | |||||
| IEC 61508 governs electrical, electronic and programmable systems that perform safety functions, including the development of their software to a safety integrity level (SIL). | Reference | |||||
| Cybersecurity should be built into every phase of the safety lifecycle — from hazard and risk analysis through design, operation and management of change — so that safety instrumented systems and other safety controls, alarms and interlocks are protected against attack as well as random failure. | Reference | |||||
| ISO/IEC 25010:2023 treats safety as a product quality: the product keeps within operational constraints, identifies risks, fails safe, warns of hazards and integrates safely with the systems around it. | Shapes design | |||||
| Data | ||||||
| Data quality is described by a fixed set of characteristics — such as accuracy, completeness, consistency, credibility and currentness — each with defined ways of measuring it. | Shapes design | |||||
| Master data should meet stated data requirements, carry its provenance and be maintained by defined data-quality management processes, so that its quality is measured and improved rather than assumed. | — | Shapes design | ||||
| Data used to train analytics and machine-learning models must have its quality measured and managed across its life cycle — including representativeness, label quality and provenance — under defined governance. | Shapes design | |||||
| Reconciliation must combine redundant measurements and balance equations using each measurement's uncertainty, produce reconciled values with reconciled uncertainties, and test statistically whether measurements and model agree. | — | Shapes design | ||||
| Metal accounting should rest on a check-in/check-out balance of measured mass and assays, a documented procedure, authorised and audited use of provisional or replacement data, target accuracies at every accounting measurement point, regular stockpile surveys, and the identification and removal of bias. | — | Shapes design | ||||
| Interoperability | ||||||
| OPC UA products can be certified by OPC Foundation accredited test labs for compliance with the profiles they claim, interoperability, robustness, usability and efficient use of resources. | Certify | |||||
| ISA-95 (IEC 62264) defines the equipment hierarchy — enterprise, site, area, work centre, work unit — and the object models used to exchange production information between control and business systems. | — | Shapes design | ||||
| ISA-88 (IEC 61512) defines the models of batch control and the structure of batch records — procedure, unit procedure, operation, phase — and how they relate to equipment. | — | Shapes design | ||||
| The Asset Administration Shell (IEC 63278 and the IDTA specifications) is the standard digital representation of an asset, organised in submodels such as nameplate, technical data, documentation and time series. | — | Shapes design | ||||
| DEXPI is the process industry's exchange format for P&IDs, carrying equipment, instruments, piping and their connections as data rather than drawings. | — | Shapes design | ||||
| ISO 15926 provides a data model and a reference data library of standard classes for process-plant equipment, instruments and properties. | — | Reference | ||||
| ISO 23247 sets out a framework and reference architecture for digital twins of manufacturing elements — how the twin is fed from the physical element, how it is represented and how it exchanges information with its users. | Reference | |||||
| ISO/IEC 30141 describes IoT systems through common characteristics, architecture views and patterns, with emphasis on trustworthiness — reliability, safety, security, privacy and resilience. | — | Reference | ||||
| AI | ||||||
| An organisation that develops or provides AI systems needs an AI management system: AI policy, roles, AI risk and impact assessments, data governance, monitoring of AI performance and continual improvement. | Certify | |||||
| AI-specific risks — unreliable output outside the training data, drift, misuse, opacity — must be identified, analysed, evaluated, treated, monitored and recorded as part of normal risk management. | Shapes design | |||||
| AI systems need life-cycle processes beyond classic software: data acquisition and preparation, model building and verification, deployment, continuous validation in operation, re-training and retirement. | Shapes design | |||||
| An automated AI system must keep its state observable and support a controlled transfer of control to a person or another system, including under uncertainty, and this ability must be verified. | — | Shapes design | ||||
| AI systems intended as safety components in the management and operation of critical infrastructure, such as the supply of gas, heating or electricity, are high-risk and carry heavy obligations. | Reference | |||||
| Quality | ||||||
| A certified quality management system that controls design and development, delivery, support and improvement of both products. | Certify | |||||
| Product requirements should cover every quality characteristic explicitly — functional suitability, performance efficiency, compatibility, interaction capability, reliability, security, maintainability, flexibility and safety — with measurable acceptance criteria. | Shapes design | |||||
| Software life-cycle processes run from agreement and planning through development, verification, transition, operation and maintenance to disposal. | Reference | |||||
| Operations | ||||||
| Every alarm presented to an operator through the control system must follow the site's alarm philosophy: identified, rationalised (cause, consequence, operator response, time to respond, priority), documented in the master alarm database, implemented and monitored. | — | Mandatory | ||||
| An alarm is an indication to the operator that requires a response, and the alarm standard covers every alarm presented through the control system; information that does not require an operator response must not be presented as an alarm. | Shapes design | |||||
| The alarm management lifecycle includes monitoring and assessing alarm-system performance with defined metrics — alarm rates per operator position, floods, frequent, chattering and stale alarms — and periodic audit. | — | Shapes design | ||||
| EEMUA 191 gives practical guidance on alarm-system design and management and widely quoted benchmarks for acceptable alarm load and flood conditions. | — | Reference | ||||
| ISA-101 sets out an HMI lifecycle — philosophy, style guide, display hierarchy — and the principles of high-performance displays that make abnormal situations obvious and avoid decoration. | Shapes design | |||||
| IEC 61131-3 defines the programming languages and program units, such as function blocks, of PLCs and of most DCS control languages. | Shapes design | |||||
| An organisation must analyse business impact, set recovery objectives, and maintain and exercise continuity plans for the services others depend on. | Reference | |||||
| A service provider needs a managed system for service levels, incidents, problems, changes, releases and continual improvement. | Reference | |||||
| Privacy | ||||||
| Personal data must be identified, minimised, protected, kept only as long as needed and handled according to the rights of the people it describes, under a privacy management system for controllers and processors. | Reference | |||||
| Industry | ||||||
| ISO 14224 defines the equipment taxonomy and boundaries and the codes for failure modes, mechanisms and causes used to collect reliability and maintenance data in the petroleum, petrochemical and natural gas industries. | — | Shapes design | ||||
| Condition-monitoring software is organised as a chain from data acquisition and manipulation through state detection, health assessment and prognostics to advisory generation, with open interfaces between the blocks. | — | Shapes design | ||||
| A condition-monitoring programme starts from an equipment audit and criticality, identifies failure modes, selects measurements and techniques, sets alert criteria and reviews the results. | — | Reference | ||||
| The 2024 edition of ISO 55001 strengthens the requirements on managing asset data and knowledge, and ISO 55013:2024 gives guidance on managing data for asset management. | — | Reference | ||||
| Energy performance indicators and energy baselines should be defined with their relevant variables, normalised, and compared over defined periods to demonstrate energy performance improvement under ISO 50001. | Shapes design | |||||
| An organisation's greenhouse-gas inventory is quantified from activity data and emission factors with documented methods and uncertainty, and must be verifiable. | — | Reference | ||||
| A steel plant with DRI and EAF facilities calculates its annual CO₂ emissions and CO₂ intensity within a defined boundary, from defined material and energy flows and emission factors, with stated treatment of upstream and credit flows. | — | Shapes design | ||||
| ISO 22400 defines manufacturing-operations KPIs — their formulas, elements, units and timing — such as availability, effectiveness and quality ratio. | Shapes design | |||||
APC applications by industry
Refinery
Petrochemical
Iron & Steel
Copper