security ISO/IEC 27001ISO/IEC 27001 ISO/IEC 27001:2022 (with Amd 1:2024)ISO/IEC 27001:2022 (with Amd 1:2024) ISO/IEC 27001 is the international requirements standard for an information security management system (ISMS), certified for an organisation and the scope it declares, not for a product. ISO/IEC 27017ISO/IEC 27017 ISO/IEC 27017:2026 (replaces ISO/IEC 27017:2015)ISO/IEC 27017:2026 (replaces ISO/IEC 27017:2015) ISO/IEC 27017 adds cloud-specific guidance and controls to the ISO/IEC 27002 control set, for both cloud service providers and their customers. ISO/IEC 27701ISO/IEC 27701 ISO/IEC 27701:2025ISO/IEC 27701:2025 ISO/IEC 27701 specifies a management system for organisations that control or process personally identifiable information, and since 2025 can be certified on its own. ISO/IEC 29147ISO/IEC 29147 ISO/IEC 29147:2018ISO/IEC 29147:2018 ISO/IEC 29147 tells a product vendor how to receive vulnerability reports from outside and how to publish remediation information to users. ISO/IEC 30111ISO/IEC 30111 ISO/IEC 30111:2019ISO/IEC 30111:2019 ISO/IEC 30111 specifies how a vendor investigates, prioritises, fixes and verifies a reported vulnerability in its product or service. SPDXSPDX ISO/IEC 5962:2021 (SPDX 2.2.1)ISO/IEC 5962:2021 (SPDX 2.2.1) ISO/IEC 5962 standardises SPDX, a machine-readable format for describing the components, versions, suppliers and licences inside a software package — the basis of a software bill of materials (SBOM). IEC 62351IEC 62351 IEC 62351 series (e.g. IEC 62351-5, IEC 62351-6)IEC 62351 series (e.g. IEC 62351-5, IEC 62351-6) IEC 62351 is the IEC series that adds authentication, integrity and encryption to the power-system protocols IEC 60870-5-104, IEC 61850 and DNP3. EU CRAEU CRA Emerging Regulation (EU) 2024/2847Regulation (EU) 2024/2847 The Cyber Resilience Act is an EU regulation that makes security by design, vulnerability handling, an SBOM, a stated support period and CE marking legal conditions for selling any software or connected product in the EU. NIS2NIS2 Directive (EU) 2022/2555Directive (EU) 2022/2555 NIS2 is the EU directive that obliges medium and large operators in critical sectors, including oil refining and chemicals, to manage cybersecurity risk — explicitly including the security of their suppliers. IEC 62443IEC 62443 ISA/IEC 62443 seriesISA/IEC 62443 series ISA/IEC 62443 is the series of standards for cybersecurity of industrial automation and control systems, covering asset-owner programmes, system design with zones and conduits, and secure products.
safety ISA-TR84.00.09ISA-TR84.00.09 ISA-TR84.00.09-2024 Part 1 (replaces ISA-TR84.00.09-2017)ISA-TR84.00.09-2024 Part 1 (replaces ISA-TR84.00.09-2017) ISA-TR84.00.09 is an ISA technical report that shows how to build cybersecurity into every phase of the IEC 61511 safety lifecycle, so that a safety instrumented system is protected against attack as well as against random failure. IEC 61511IEC 61511 IEC 61511-1:2016 (ANSI/ISA-61511)IEC 61511-1:2016 (ANSI/ISA-61511) IEC 61511 is the process-industry standard for the whole life of safety instrumented systems, from hazard analysis and SIL targets to design, operation, proof testing and change management. IEC 61508IEC 61508 IEC 61508-1 to -7:2010IEC 61508-1 to -7:2010 IEC 61508 is the umbrella functional-safety standard for electrical, electronic and programmable electronic safety systems, against which safety PLCs, transmitters and valves are certified to a SIL.
architecture ISO/IEC 42001ISO/IEC 42001 Emerging ISO/IEC 42001:2023ISO/IEC 42001:2023 ISO/IEC 42001 is the first certifiable management-system standard for organisations that develop, provide or use AI systems. ISO/IEC 23894ISO/IEC 23894 ISO/IEC 23894:2023ISO/IEC 23894:2023 ISO/IEC 23894 adapts general risk-management practice to the specific risks of AI systems, for organisations that develop, deploy or use them. ISO/IEC 5338ISO/IEC 5338 ISO/IEC 5338:2023ISO/IEC 5338:2023 ISO/IEC 5338 extends the classic system and software life-cycle processes with the processes that machine-learning systems need, such as data acquisition, model training, continuous validation and retirement. EU AI ActEU AI Act Emerging Regulation (EU) 2024/1689Regulation (EU) 2024/1689 The EU AI Act regulates AI systems by risk class; AI used as a safety component in the supply of gas, heating, electricity or water is high-risk. ISO/IEC 25010ISO/IEC 25010 ISO/IEC 25010:2023ISO/IEC 25010:2023 ISO/IEC 25010 defines the nine quality characteristics — from functional suitability and reliability to security and safety — against which software and ICT products are specified and evaluated. ISO 12207ISO 12207 ISO/IEC/IEEE 12207:2026ISO/IEC/IEEE 12207:2026 ISO/IEC/IEEE 12207 is the reference set of processes for acquiring, developing, operating, maintaining and retiring software. ISO 9001ISO 9001 ISO 9001:2026 (replaces ISO 9001:2015)ISO 9001:2026 (replaces ISO 9001:2015) ISO 9001 is the most widely used management-system standard; a certificate shows customers that a supplier plans, delivers and improves its products and services under a controlled quality system. ISO 23247ISO 23247 ISO 23247-1 to -4:2021ISO 23247-1 to -4:2021 ISO 23247 defines a framework and reference architecture for building digital twins of manufacturing elements and exchanging information with them. ISO/IEC 30141ISO/IEC 30141 ISO/IEC 30141:2024ISO/IEC 30141:2024 ISO/IEC 30141 is the international reference architecture for IoT systems, with a common vocabulary, architecture views and design patterns for trustworthy systems. UNSUNS Emerging A Unified Namespace is an architecture pattern, not a standard, in which every plant and business system publishes its current state into one shared, hierarchically named event hub — usually an MQTT broker — instead of being wired point to point. ISA-95ISA-95 ANSI/ISA-95 (Parts 1–8); IEC 62264ANSI/ISA-95 (Parts 1–8); IEC 62264 ISA-95 (IEC 62264) is the standard that defines the levels of a manufacturing enterprise, the activities of manufacturing operations management, and the information exchanged between the plant and the business systems. NOANOA Emerging NAMUR NE 175, NE 176, NE 177, NE 178NAMUR NE 175, NE 176, NE 177, NE 178 NAMUR Open Architecture is a reference concept that adds a second, secure channel to take data out of the core control system for monitoring and optimisation, without touching the control system itself. O-PASO-PAS Emerging O-PAS StandardO-PAS Standard O-PAS is a "standard of standards" from The Open Group's Open Process Automation Forum that defines an open, interoperable and secure architecture for process control, so that control hardware and software from different vendors can be combined and replaced independently. Purdue modelPurdue model Purdue Enterprise Reference Architecture (PERA)Purdue Enterprise Reference Architecture (PERA) The Purdue model is the layered reference model — Level 0 process up to Level 4 business — that ISA-95 uses for functions and IEC 62443 practice uses for network zones; it is the shared map of where each plant system sits.
semantic ISO/IEC 22989ISO/IEC 22989 ISO/IEC 22989:2022ISO/IEC 22989:2022 ISO/IEC 22989 fixes the vocabulary and core concepts of AI — machine learning, training data, AI agents, trustworthiness — that the other AI standards build on. ISO/IEC 5259ISO/IEC 5259 Emerging ISO/IEC 5259-1 to -5 (2024–2025)ISO/IEC 5259-1 to -5 (2024–2025) ISO/IEC 5259 is a five-part series on measuring, managing and governing the quality of data used to train and run analytics and machine-learning models. ISO 8000ISO 8000 ISO 8000 series (e.g. ISO 8000-1:2022, ISO 8000-8:2015, ISO 8000-61:2016)ISO 8000 series (e.g. ISO 8000-1:2022, ISO 8000-8:2015, ISO 8000-61:2016) ISO 8000 is the international series on data quality, focused on master data and on the processes an organisation needs to keep data fit for use. ISO/IEC 25012ISO/IEC 25012 ISO/IEC 25012:2008; ISO/IEC 25024:2015ISO/IEC 25012:2008; ISO/IEC 25024:2015 ISO/IEC 25012 defines fifteen characteristics of data quality, and its companion ISO/IEC 25024 defines how to measure each one. VDI 2048VDI 2048 VDI 2048 Blatt 1:2017-09 (and further Blätter)VDI 2048 Blatt 1:2017-09 (and further Blätter) VDI 2048 is the German engineering guideline for improving process measurements and their uncertainties by reconciliation against mass and energy balances, used for operation and acceptance tests. AMIRA P754AMIRA P754 AMIRA P754 Code of Practice and Guidelines, Release 3 (2007)AMIRA P754 Code of Practice and Guidelines, Release 3 (2007) AMIRA P754 is an industry code of practice — not an ISO standard and not mandatory — for producing auditable metal balances in concentrators, smelters and refineries. ISO 15926ISO 15926 ISO 15926 series (e.g. ISO/TS 15926-4:2019)ISO 15926 series (e.g. ISO/TS 15926-4:2019) ISO 15926 is a multi-part standard for integrating and exchanging the engineering and life-cycle data of process plants, including oil and gas facilities, through a common data model and reference data library. B2MMLB2MML B2MML / BatchML (XML implementation of ANSI/ISA-95 and ISA-88)B2MML / BatchML (XML implementation of ANSI/ISA-95 and ISA-88) B2MML is the set of XML schemas that implement the ISA-95 data models, so that ERP and MES can exchange production schedules, performance, materials and equipment in an agreed format. ISA-5.1ISA-5.1 ANSI/ISA-5.1-2024ANSI/ISA-5.1-2024 ISA-5.1 is the standard that defines instrument tag letters (such as TIC = temperature indicating controller) and the symbols used for instruments and control functions on P&IDs. ISO 22400ISO 22400 ISO 22400-1, ISO 22400-2:2014ISO 22400-1, ISO 22400-2:2014 ISO 22400 defines standard key performance indicators for manufacturing operations, such as availability, effectiveness and OEE, with their exact formulas and data elements. AASAAS Emerging IDTA-01001 to IDTA-01005; IEC 63278IDTA-01001 to IDTA-01005; IEC 63278 The Asset Administration Shell is the Industry 4.0 standard for a machine-readable digital twin of an asset, built from standard submodels such as the digital nameplate and technical data. DEXPIDEXPI Emerging DEXPI Specification 2.0.1 (ISO 15926-based)DEXPI Specification 2.0.1 (ISO 15926-based) DEXPI is the open, vendor-neutral standard for exchanging intelligent P&IDs between engineering tools, so the plant's equipment, piping and instrumentation can move as data rather than drawings. ISO 10628ISO 10628 ISO 10628-1, ISO 10628-2:2012ISO 10628-1, ISO 10628-2:2012 ISO 10628 defines how process flow diagrams and P&IDs are drawn in the chemical and petrochemical industry, including the graphical symbols for equipment such as columns, pumps and heat exchangers.
control TS 8200TS 8200 Emerging ISO/IEC TS 8200:2024ISO/IEC TS 8200:2024 ISO/IEC TS 8200 gives principles for keeping an automated AI system controllable — its state observable, and control transferable to a human or another system safely when needed. MTPMTP Emerging VDI/VDE/NAMUR 2658VDI/VDE/NAMUR 2658 MTP is a vendor-neutral description of a process module's automation interface — its displays, services and data — so that a package unit can be plugged into any orchestrating control system with little engineering. ISA-106ISA-106 ANSI/ISA-106.00.01-2023; ISA-TR106.00.01-2013; ISA-TR106.00.02-2017ANSI/ISA-106.00.01-2023; ISA-TR106.00.01-2013; ISA-TR106.00.02-2017 ISA-106 is the standard for automating operating procedures — start-ups, shutdowns, grade changes and abnormal-situation responses — in continuous process plants. IEC 61131-3IEC 61131-3 IEC 61131-3:2025IEC 61131-3:2025 IEC 61131-3 is the international standard for PLC and controller programming languages — Structured Text, Ladder Diagram, Function Block Diagram and Sequential Function Chart.
reliability ISO 20000-1ISO 20000-1 ISO/IEC 20000-1:2018 (with Amd 1:2024)ISO/IEC 20000-1:2018 (with Amd 1:2024) ISO/IEC 20000-1 specifies the requirements for a service management system that plans, delivers and improves IT services, such as a hosted platform or a support contract. ISO 22301ISO 22301 ISO 22301:2019ISO 22301:2019 ISO 22301 specifies a management system that prepares an organisation to keep delivering its critical services through and after a disruption. ISO 13374ISO 13374 ISO 13374-1:2003 to ISO 13374-4:2015ISO 13374-1:2003 to ISO 13374-4:2015 ISO 13374 defines an open architecture for condition-monitoring software, so that data acquisition, analysis, health assessment and advice from different products can work together. ISO 17359ISO 17359 ISO 17359:2018ISO 17359:2018 ISO 17359 describes the general procedure for setting up a condition-monitoring programme for any machine and points to the standards for each technique. NE 107NE 107 NAMUR NE 107NAMUR NE 107 NAMUR NE 107 reduces the many diagnostic messages of field devices to four standard status signals — failure, function check, out of specification and maintenance required — so operators and maintenance see the same meaning across vendors. ISO 14224ISO 14224 ISO 14224:2016ISO 14224:2016 ISO 14224 is the oil, gas and petrochemical standard for collecting and exchanging equipment reliability and maintenance data, with a common equipment taxonomy and failure codes. ISO 55000ISO 55000 ISO 55000, ISO 55001, ISO 55002ISO 55000, ISO 55001, ISO 55002 The ISO 55000 series defines how an organisation manages its physical assets over their whole life to balance cost, risk and performance, through a certifiable asset-management system.
energy ISO 50006ISO 50006 ISO 50006:2023ISO 50006:2023 ISO 50006 gives guidance on defining, using and maintaining energy performance indicators (EnPIs) and energy baselines, so that energy improvement can be demonstrated under an ISO 50001 energy management system. ISO 14064ISO 14064 ISO 14064-1:2018 (parts 2 and 3 for projects and verification)ISO 14064-1:2018 (parts 2 and 3 for projects and verification) ISO 14064-1 specifies how an organisation quantifies and reports its greenhouse-gas emissions and removals in an inventory that can be verified. ISO 14404ISO 14404 ISO 14404-1, -2, -3:2024ISO 14404-1, -2, -3:2024 ISO 14404 gives the calculation method for annual CO₂ emissions and CO₂ intensity of a steel plant, with a part dedicated to plants with direct-reduction (DRI) and electric arc furnace routes. ISO 50001ISO 50001 ISO 50001:2018ISO 50001:2018 ISO 50001 is the international standard for an energy management system that requires an organisation to measure and continually improve its energy performance.
alarm EEMUA 191EEMUA 191 EEMUA Publication 191, edition 4 (2024)EEMUA Publication 191, edition 4 (2024) EEMUA Publication 191 is the users' association guide to designing, managing and procuring alarm systems, the practical companion to ISA-18.2 and IEC 62682. OPC A&EOPC A&E Legacy OPC Alarms and Events 1.10 (OPC Classic)OPC Alarms and Events 1.10 (OPC Classic) OPC A&E is the legacy COM/DCOM interface through which a control system sends alarms and events, with their states and acknowledgements, to other software. ISA-18.2ISA-18.2 ANSI/ISA-18.2-2016; IEC 62682ANSI/ISA-18.2-2016; IEC 62682 ISA-18.2 (internationally IEC 62682) is the standard for managing alarm systems over their whole life, so that every alarm is meaningful, prioritised and calls for an operator action.
ot-integration OPC UAOPC UA Niche IEC 62541 (OPC 10000 series)IEC 62541 (OPC 10000 series) OPC UA is the vendor-neutral standard that lets software browse, read and write plant data together with its meaning, securely, on any operating system from the controller up to the cloud. UA PubSubUA PubSub Emerging IEC 62541-14 (OPC 10000-14)IEC 62541-14 (OPC 10000-14) OPC UA PubSub is the publish–subscribe form of OPC UA, in which a publisher sends data sets to many subscribers over UDP multicast or through a broker such as MQTT, without one session per client. OPC DAOPC DA Legacy Common OPC Data Access 1.0a / 2.05a / 3.0 (OPC Classic)OPC Data Access 1.0a / 2.05a / 3.0 (OPC Classic) OPC DA is the original Windows COM/DCOM interface for reading and writing current values with quality and timestamp; it is still installed in many plants but is legacy technology. OPC HDAOPC HDA Legacy OPC Historical Data Access 1.20 (OPC Classic)OPC Historical Data Access 1.20 (OPC Classic) OPC HDA is the legacy COM/DCOM interface for reading stored history — raw values and aggregates such as averages and interpolated values — from a historian.
industrial-ethernet Modbus TCPModbus TCP Niche Modbus Application Protocol v1.1b3; Modbus Messaging on TCP/IP v1.0bModbus Application Protocol v1.1b3; Modbus Messaging on TCP/IP v1.0b Modbus TCP is the simplest and most widespread industrial protocol on Ethernet, in which a client polls numbered registers in a device; it carries numbers only, with no names, units or security. EtherNet/IPEtherNet/IP Niche IEC 61158 / IEC 61784 (CIP over Ethernet)IEC 61158 / IEC 61784 (CIP over Ethernet) EtherNet/IP is the industrial Ethernet protocol of the ODVA family, carrying the Common Industrial Protocol (CIP) between controllers, I/O, drives and devices; it is native to Rockwell Automation controllers. PROFINETPROFINET Common IEC 61158 / IEC 61784IEC 61158 / IEC 61784 PROFINET is the industrial Ethernet standard of PROFIBUS & PROFINET International (PI) for real-time I/O between controllers and field devices; it is native to Siemens controllers and widespread in metals plants. EtherCATEtherCAT Niche IEC 61158 / IEC 61784IEC 61158 / IEC 61784 EtherCAT is an industrial Ethernet for very fast, tightly synchronised I/O and motion, in which every device reads and writes its data as the frame passes through it; in metals it links high-speed sensors and drives to technology controllers. Ethernet-APLEthernet-APL Emerging IEEE 802.3cg (10BASE-T1L); IEC TS 60079-47 (2-WISE)IEEE 802.3cg (10BASE-T1L); IEC TS 60079-47 (2-WISE) Ethernet-APL is a two-wire, loop-powered Ethernet physical layer that brings Ethernet all the way to process field instruments, including in hazardous areas; protocols such as PROFINET, EtherNet/IP, HART-IP and OPC UA run on top of it. S7commS7comm Common Proprietary; ISO-on-TCP (RFC 1006), TCP port 102Proprietary; ISO-on-TCP (RFC 1006), TCP port 102 S7comm is Siemens' proprietary protocol for programming SIMATIC S7 PLCs and reading and writing their memory; third-party drivers use it to read Siemens PLCs that offer no OPC UA.
fieldbus Modbus RTUModbus RTU Modbus over Serial Line Specification and Implementation Guide v1.02Modbus over Serial Line Specification and Implementation Guide v1.02 Modbus RTU is the serial (RS-485/RS-232) form of Modbus, in which one master polls up to 247 slave devices on a shared line; it is still common in analyzers, meters and package units. PROFIBUSPROFIBUS Common IEC 61158 / IEC 61784IEC 61158 / IEC 61784 PROFIBUS is the serial fieldbus of PI, with DP for fast remote I/O and drives on RS-485 and PA for bus-powered, intrinsically safe process instruments; it has a large installed base and PROFINET is its successor for new projects. HARTHART HART 7 (incl. HART-IP); IEC 61784-1 CPF 9HART 7 (incl. HART-IP); IEC 61784-1 CPF 9 HART superimposes a digital signal on the classic 4–20 mA loop, so a transmitter or valve can report extra variables, diagnostics and configuration over the same two wires; it is the most widely installed field protocol in process plants. WirelessHARTWirelessHART IEC 62591 (HART 7 WirelessHART)IEC 62591 (HART 7 WirelessHART) WirelessHART is the wireless mesh version of HART for battery-powered field instruments, used where running cables is too costly; data reaches the control system through a gateway. FFFF IEC 61158 Type 1 (H1) and Type 5 (HSE)IEC 61158 Type 1 (H1) and Type 5 (HSE) FOUNDATION Fieldbus is an all-digital process fieldbus in which instruments communicate as function blocks and can even execute control in the field; it was chosen for many large refinery and petrochemical projects. IO-LinkIO-Link IEC 61131-9 (SDCI)IEC 61131-9 (SDCI) IO-Link is a point-to-point digital link between one small sensor or actuator and an IO-Link master, carrying process data, parameters and diagnostics over a standard unshielded cable.
messaging MQTTMQTT Niche OASIS MQTT 5.0 (2019); MQTT 3.1.1 = ISO/IEC 20922:2016OASIS MQTT 5.0 (2019); MQTT 3.1.1 = ISO/IEC 20922:2016 MQTT is a lightweight publish–subscribe messaging protocol in which devices and applications exchange messages through a central broker by topic; it moves data efficiently but does not define what the data means. Sparkplug BSparkplug B Sparkplug 3.0.0 = ISO/IEC 20237:2023Sparkplug 3.0.0 = ISO/IEC 20237:2023 Sparkplug B is an open specification on top of MQTT that fixes the topic structure, the binary payload and the online/offline state of edge devices, so that industrial MQTT systems from different vendors work together. KafkaKafka Apache Kafka protocolApache Kafka protocol Apache Kafka is a distributed event-streaming platform that stores streams of records durably in partitioned topics, so many applications can consume the same plant data at their own pace. AMQPAMQP OASIS AMQP 1.0 = ISO/IEC 19464:2014OASIS AMQP 1.0 = ISO/IEC 19464:2014 AMQP is an open wire protocol for reliable business messaging between applications through queues and brokers; it is common in IT and cloud messaging services and is one transport of OPC UA PubSub.
power IEC 61850IEC 61850 Niche IEC 61850 seriesIEC 61850 series IEC 61850 is the international standard for communication inside electrical substations, combining a data model of protection and control devices with the MMS, GOOSE and Sampled Values protocols. DNP3DNP3 IEEE Std 1815IEEE Std 1815 DNP3 is a SCADA telemetry protocol from North American utilities that lets a master station collect time-stamped events from remote outstations over slow or unreliable links. IEC 104IEC 104 IEC 60870-5-104:2006IEC 60870-5-104:2006 IEC 60870-5-104 is the international telecontrol protocol that carries IEC 60870-5-101 messages over TCP/IP between a control centre and substations or remote stations; it is widely used in grid and electrical SCADA outside North America.
it-api RESTREST REST architectural style (Fielding, 2000) over HTTPREST architectural style (Fielding, 2000) over HTTP REST is the common style of web API in which applications read and change resources with standard HTTP requests, usually exchanging JSON; most modern historians, MES, LIMS, CMMS and cloud platforms offer one. gRPCgRPC gRPC over HTTP/2 with Protocol BuffersgRPC over HTTP/2 with Protocol Buffers gRPC is a high-performance remote-procedure-call framework in which services are defined in Protocol Buffers and called over HTTP/2, with built-in streaming; it is used between platform services and from edge to cloud. GraphQLGraphQL GraphQL Specification (October 2021 edition)GraphQL Specification (October 2021 edition) GraphQL is a typed query language for APIs in which the client asks for exactly the fields and relationships it needs in one request; it suits navigating contextualised asset and data models.
database SQL / ODBCSQL / ODBC Common ISO/IEC 9075 (SQL); ODBCISO/IEC 9075 (SQL); ODBC SQL access, through standard drivers such as ODBC or JDBC, is how many plant systems — LIMS, MES, historians' relational layers and ERP extracts — are read when they have no other open interface.
file File transferFile transfer Various (CSV, XML, JSON; FTP, SFTP, FTPS, SMB)Various (CSV, XML, JSON; FTP, SFTP, FTPS, SMB) File-based exchange — a system writes a CSV, XML, JSON or binary file to a folder or server and another system picks it up — is still a common, simple interface for lab instruments, high-speed recorders, reports and transfers across one-way gateways.
batch ISA-88ISA-88 ANSI/ISA-88 (Parts 1–4); IEC 61512ANSI/ISA-88 (Parts 1–4); IEC 61512 ISA-88 (IEC 61512) is the standard for batch control that separates recipes from equipment through common physical, procedural and recipe models.
hmi ISA-101ISA-101 ANSI/ISA-101.01-2015ANSI/ISA-101.01-2015 ISA-101 is the standard for designing and managing operator displays over their lifecycle, aimed at better situational awareness and fewer operator errors.