Skip to content
DRAFT⚠OIML SMART pilot programme · internal use only · all documents and specifications are drafts and may change without notice

The SMART Twin

The Recommendation model as the running instrument’s digital twin: the standard declares the served interface, and the compliance engine judges the served evidence continuously.

A SMART twin is the running instrument’s digital counterpart, shaped by the standard itself: the Recommendation declares which values the twin serves and how fresh they must be, and the platform’s compliance engine judges the served evidence continuously. The certificate stops being a point-in-time snapshot and becomes a live, re-computed state.

Watch the monitor run in the demo →

The demo's twin console: the real monitor and gateway runtimes judging the simulated twin feed against the modelled R 60 requirement
The demo's twin console: the real monitor and gateway runtimes judging the simulated twin feed against the modelled R 60 requirement Live surface · captured 2026-08-29 by the scripted apparatus.

This page is a SMART+ page: the twin is the vision tier, and the split below is honest about which parts run today (against the simulated fleet, in the demo) and which are roadmap (physical instruments, signed serves, member deployments).

What it does today

  • Judges a live twin in the demo. The twin console wires the real monitor and gateway runtimes against the simulated feed, judging the modelled R 60 requirement measuring-range-min on every poll; assume the Admin persona through the identity service’s account chooser and provision the demo twin (the capture above).
  • Degrades honestly. A stale served value degrades the requirement’s verdict to indeterminate rather than failing or passing silently; the freshness gate reads the twin’s own timestamps.
  • Introspects instead of assuming. The twin lab connects to a served interface and reads its declared registers and operations, never a hard-coded shape.
  • Keeps the evidence. Facts, verdicts, and escalations accrue in append-only, version-pinned evidence streams; a stored window can be re-judged under new limits without querying the twin again (in the demo the store is in-memory and resets with the page, as the console itself states).
  • Reads as an AAS submodel. To an Asset Administration Shell consumer, served registers map to properties and commands to operations; the asymmetry is governance, documented on the interoperability page.

How it works

Two distinctions carry the design. The first separates the abstract reference from the live twin: the manufacturer’s product reference model declares what the instrument type promises and serves; the live twin is one running instrument’s governed projection, pinned to that reference and answering for itself. The second separates the twin’s own declaration from its judgment: the Recommendation’s twin declaration fixes the interface (which registers, through which operations, with which freshness windows), and the platform’s monitor computes verdicts per requirement per twin against it. The declarations are authored in Primmel, the open modelling language the program adopts, so the interface a twin serves is derived from the standard, never hand-designed per instrument.

The Recommendation declares the twin interface; the instrument serves governed registers; the monitor computes verdicts per requirement; evidence accrues in append-only streamsFrom point-in-time certificate to live compliance stateThe Recommendation declareswhich registers the twin serves,through which operations, with whichfreshness windows (fresh_within)the interface is derived, never hand-designedThe live twinone running instrument's governedprojection, pinned to the productreference, answering for itselfserves value + unit + servedAtThe monitorthe scheduler runs the declaredmonitoring program; a stale valuedegrades the verdict to indeterminatenever a silent pass, never a silent failservesjudgedThe evidence stream (append-only, version-pinned)facts · verdicts · escalations accrue; a stored window re-judges under new limitswithout querying the twin againre-judgedThe probe channel keeps physics primarya reference instrument, an observer attestation, or simulator ground truth catches a lying twin
The continuous-compliance loop: the standard declares the interface; the twin serves it; the monitor judges; the evidence stream remembers. A stored window re-judges without asking the instrument again.

Physical evidence stays primary: the twin-certification program pairs served values with a probe channel (a reference instrument, an observer attestation, or simulator ground truth), so a lying twin is caught by physics rather than by signature checks.

Today (SMART) and the vision (SMART+)

Today · SMART

  • The monitor and gateway runtimes run today in the platform and the demo, against the simulated fleet; no OIML Recommendation ships a twin binding yet (the machinery is opt-in). the console ↗
  • The twin lab introspects any served interface from the browser. open ↗
  • The SMI adoption programme documents what providing a SMART twin means for a manufacturer. read ↗

The vision · SMART+

  • The deployable client/server compliance engine and cryptographically signed serves are roadmap items, the deployment and provenance legs of the platform’s future wave. roadmap ↗
  • Twin certification under the TW-1 governing document, with suspension and withdrawal semantics, at member deployments. roadmap ↗
  • Continuous compliance as the surveillance default: the certificate as a live, re-computed state rather than a snapshot. roadmap ↗

Why it exists

Type evaluation today ends at issuance. The instrument then enters service, drifts, is recalibrated or repaired, and its conformity is re-established episodically, from paper records, at re-verification. Between those episodes the authority’s record says nothing about the instrument’s actual state. A twin that serves its governed registers turns surveillance into a continuous computation over evidence instead of a periodic excavation of files.

Who may use it, and who may run it

The SMART Twin is the SMART+ tier, and the program’s determination for it is roadmap across every member category, quoted here from the single entitlement source. The pilot surfaces above are open today; the member deployments follow the roadmap.

Member StateCorresponding MemberIssuing Authority / Test Laboratory (of a Member State)Utilizer / AssociateApplicant / public
roadmaproadmaproadmaproadmaproadmap

The SMART Twin (SMART+), quoted from the program's single entitlement source; the full matrix, all services by all member categories, lives atWho can run what.

The honest questions

Is this live for physical instruments today? No, and the page says so wherever it matters. Today the monitor and gateway runtimes run in the demo against the simulated fleet, judging a real modelled requirement. Physical-instrument bindings, the deployable compliance engine, and cryptographically signed serves are roadmap items, labeled roadmap above with their anchors.

How is a SMART twin different from the manufacturer’s own dashboard? A dashboard serves whatever the vendor chose to expose. A SMART twin serves the governed projection the Recommendation declares: identical across conforming instruments, with freshness semantics, standing behind a certification verdict.

What stops a twin from lying? The probe channel. Served values are paired with physical evidence (a reference instrument, an observer attestation, simulator ground truth in rehearsal), so a twin that misreports is caught by physics, not by trusting its signature.

What happens when a twin goes silent? The verdict degrades to indeterminate. The freshness gate reads the twin’s own timestamps; the platform never upgrades silence into a pass, and never reports an outage as a failure it cannot distinguish.

Try it, read it, talk to us

Try the demo

Assume the Admin persona through the identity service, open the twin console, and provision the demo twin: the monitor judges the simulated feed within seconds. The instance resets nightly.

→
Read the docs

The platform volume: the twin runtime, the twin lab, the projection machinery, and the composite twin.

→
Talk to us

info@oimlsmart.org, the programme's front-door address. The SMI documentation carries the adoption programme for legal-metrology authorities.

→