Skip to content
DRAFT⚠OIML SMART pilot programme · internal use only · all documents and specifications are drafts and may change without notice

The CIML tour

The Digital OIML, live

OIML SMART as a guided tour: every claim one click from a running proof, every demo moment playable live or read from a dated capture.

  • Nineteen slides, two cuts: the 5-minute committee slot and the 20-minute working visit. The presenter notes carry both, with the recorded rehearsal timings.
  • Navigate with the arrow keys, the on-screen buttons, or a clicker. Every slide has a stable address: /tour#s07 goes straight to the seventh slide.
  • The honesty rules: everything on the demo instance is simulated (a fictional cast, a nightly reset), and every future is labeled SMART+.

The problem, said kindly

Certification runs on documents, and it works

Today's chain is careful people re-keying careful documents at every hand-off. The medium is lossy; the people are not the problem.

  • The Recommendation is a PDF. Every tool that touches it, the application form, the test bench, the report template, re-encodes it by hand, and every re-encoding drifts a little from the text.
  • The application is a scanned form and an email; the test report is a PDF re-typed at the authority; the certificate is a signed PDF, verified by a phone call to the issuer.
  • None of this is broken. It is the best the portable document could do. The cost is paid quietly: in transcription, in drift, in waiting, and in evidence nobody can query.

The services, one picture

The service map

One model at the center, everything else derived: the page you read, the form you fill, the verdict computed, the certificate signed, the register that answers.

The OIML SMART service map: the Recommendation models at the center, the platform deriving every surface, the services beside, the member instances federating in, the public surfaces answering without an accountOne source, every surface derivedThe Recommendations as modelsR 60 · R 91 · R 129 · R 144, authored in Primmelprovenance down to the clause; the text stays the gateThe SMART platformapplications · evaluation projects · dispatchmodel-driven tests · verdicts · CNML certificatesthe demo runs this boxThe servicesidentity · vocabularies · AI · statusstudio viewer · trust registryaccounts per organizationMember instancesIA-only · TL-only · IA+TLone codebase, four posturestl. and nmi. pilots live todayThe public surfacesthe certificate register · the verificationno account, no phone callderivesaccountssigned chainspublisheseverything else on this tour is one of these boxes, opened
The services at a glance: the Recommendation models are the single source; the platform derives the workflow, the verdicts, and the certificates from them; member instances run the same codebase in their own postures; the register and the verification answer without an account.

Flow 01 · the applicationSMART

The form is the Recommendation

The manufacturer applies in a wizard whose instrument form the R 60 model itself authors. Change the Recommendation and the form changes.

  • The first pick is the Recommendation, explicitly, with its edition; everything downstream derives from it.
  • The instrument step renders the declaration R 60-3 §4.5 asks for, with the model's own guidance on every field.
  • The authority is picked from scoped cards; only authorities that can take R 60 are shown.

Open the live step ↗

Sign in as the Applicant, open the new-application wizard, pick R 60, and watch the instrument step render from the model.

The whole flow, narrated: Walkthrough 01 · the application, six steps narrated.

The wizard's instrument step: the LC-500 family picked and a model placed in scope, on the form the R 60 model authors.
The wizard's instrument step: the LC-500 family picked and a model placed in scope, on the form the R 60 model authors. Live surface · captured 2026-09-01 by the scripted apparatus.

The no-network room: this dated capture carries the moment.

Flow 02 · the authority's intakeSMART

The honest reject-or-accept

The application lands in the authority's review queue, oldest first. The accept opens the evaluation project: the shared dataspace the three parties work in.

  • The review queue shows every waiting application with its age on the row; nothing waits silently.
  • The reject is honest: a reason, recorded, returned to the applicant. The accept opens the evaluation project.
  • Samples, custody, and the dispatch to the laboratory ride the same project; the laboratory sees exactly what the authority sent.

Open the live step ↗

Sign in as the Issuing Authority and open the review queue; the waiting application is flow 01's submit, seen from the other side.

The whole flow, narrated: Walkthrough 02 · the intake, eight steps narrated.

The IA console's review queue holding the waiting application, oldest first, with its Recommendation, applicant, and age.
The IA console's review queue holding the waiting application, oldest first, with its Recommendation, applicant, and age. Live surface · captured 2026-09-01 by the scripted apparatus.

The no-network room: this dated capture carries the moment.

Flow 03 · the laboratory's workSMART

Evidence captured at the bench

The laboratory accepts the assignment, joins the project dataspace, and runs the tests the model declares: the procedure walked step by step, the report generated, never transcribed.

  • The dispatched request lands in the laboratory's inbox; accepting it joins the evaluation project.
  • The test-run wizard walks the declared procedure; every step's purpose and clause read from the model.
  • The report composer knows completeness: what is missing is named, never silently absent.

Open the live step ↗

Sign in as the Test Laboratory, open the accepted request, and step the model-driven test run at the bench.

The whole flow, narrated: Walkthrough 03 · the laboratory's work, six steps narrated.

The model-driven test run: the step wizard walks the declared procedure, the header tooltip reads the test's purpose and clause from the model.
The model-driven test run: the step wizard walks the declared procedure, the header tooltip reads the test's purpose and clause from the model. Live surface · captured 2026-09-01 by the scripted apparatus.

The no-network room: this dated capture carries the moment.

Flow 04 · the evaluation and the certificateSMART

The verdict computed, the certificate signed

The authority validates the reports against the model, runs the review period, issues the signed certificate, and the BIML registers it: the register anyone can read.

  • The evaluation reads the test reports as data; the verdict chain computes from the model, and the decision stays the authority's.
  • The certificate issues as signed, time-stamped, schema-validated data (CNML), and registers with the BIML.
  • The public register is the validity reference: the registered copy is what verification answers from.

Open the live step ↗

Open the public register (no sign-in): the BIML-registered certificates, browsable by anyone.

The whole flow, narrated: Walkthrough 04 · the evaluation and the certificate, eight steps narrated.

The public Certificate Register: the ACTIVE worked-example certificate readable by anyone, no sign-in.
The public Certificate Register: the ACTIVE worked-example certificate readable by anyone, no sign-in. Live surface · captured 2026-09-01 by the scripted apparatus.

The no-network room: this dated capture carries the moment.

Flow 05 · the applicant's journeySMART

Anyone can verify, in seconds

The manufacturer follows every stage, downloads the certificate, and anyone (a customer, a market inspector, another authority) verifies it against the public register. No account, no phone call.

  • The applicant is notified at every stage; the application's page is the journey's spine.
  • Verification reads the BIML-registered copy plus the live revocation and suspension lists.
  • Try it: R60/2021-A-EX1-26.01 answers ACTIVE on the demo today.

Open the live step ↗

Open the verify page (no sign-in) and enter R60/2021-A-EX1-26.01: the verdict, the registration, the revocation and suspension checks.

The whole flow, narrated: Walkthrough 05 · the applicant's journey, five steps narrated.

The public verify page: the certificate number checked against the BIML-registered copy, ACTIVE, not revoked, not suspended.
The public verify page: the certificate number checked against the BIML-registered copy, ACTIVE, not revoked, not suspended. Live surface · captured 2026-09-01 by the scripted apparatus.

The no-network room: this dated capture carries the moment.

The technologies · 1 of 7SMART

SMART Recommendations and Primmel

The Recommendation as a structured, executable model, authored in an open modelling language: one source for the page, the form, the tests, the verdicts, with provenance down to the clause.

  • R 60 today: 180 requirements in 14 classes, 62 test procedures, the report forms, all counted from the model, never hand-typed.
  • Primmel is the open language the models are authored in: subjects, requirements, processes, packages, developed by Ribose and adopted by OIML SMART as its reference user.
  • Four Recommendations ride the pilot: R 60, R 91, R 129, R 144.

The technologies · 2 of 7SMART+

The SMART Twin

The vision: the Recommendation model as the running instrument's digital twin, the standard declaring the served interface, the compliance engine judging the served evidence continuously.

  • Labeled honestly: this is the SMART+ vision, anchored to the roadmap, not a shipped surface.
  • The twin serves the instrument's governed aspects; compliance becomes monitorable between assessments, not only at them.
  • The SMI Simulation below is how the program rehearses that future today.

The technologies · 3 of 7SMART

The SMI Simulation

Simulated SMART Measuring Instrument Twins (SSTs) with realistic physics behind the governed twin interface: the full certification workflow rehearsed and taught without hardware.

  • The classroom runs on it: certify a simulated load cell end to end before touching a real instrument.
  • The demo's instrument itself is simulated; the software around it is the production codebase.
  • Its production role (twins serving live evidence into certification) rides the SMART+ roadmap.

The technologies · 4 of 7SMART

CNML: the certificate as signed data

The Certificat Numérique de Métrologie Légale: signed, time-stamped, schema-validated, verifiable by anyone, account-free, offline, built on CalConnect's Signatif framework.

  • The certificate keeps its paper meaning; as data it carries its own proof.
  • Verification never has to phone home: the trust registry resolves who may sign what.
  • The same certificate serves neighboring ecosystems: a W3C Verifiable Credential, an SD-JWT, a DPP conformity attestation, an AAS submodel.

The technologies · 5 of 7SMART

The identity federation

One account across the services: a single OpenID Provider, every platform instance a relying party, and members may run their own provider from the same software.

  • Accounts issue per organization, approved by the organization's own administrator; the join flow knows the real OIML member directory.
  • Federation is the sovereignty answer: a member state's own identity provider, same software, its own custody.

The technologies · 6 of 7SMART

The trust registry

The public registry of who may sign what: each organization's signing keys and its standing, resolvable in one anonymous request.

  • A verifier never has to trust a deployment; it resolves the signer against the registry.
  • The registry proves the negative honestly: an unregistered organization is refused with a named error, and the 404 is the answer being demonstrated.

The technologies · 7 of 7SMART

Dataspace and interop: the standards map

The program speaks the neighboring standards rather than replacing them. Every interop artifact is a projection outward from the authoritative model, never a competing source.

  • The federation planes map onto the dataspace vocabulary: the Dataspace Protocol (ISO/IEC 20151), ODRL 2.2, the IDS Reference Architecture Model.
  • The models export, generated never authored: ReqIF requirement rows (the DIN DKE SPEC 99200 profile), RDF/OWL with SHACL shapes (the IEC-ISO Core Ontology projection), OpenCDD back-references.
  • The certificate serves the neighboring ecosystems today: W3C Verifiable Credential, SD-JWT, DPP conformity attestation, AAS submodel.

DeploymentSMART

One codebase, four postures

The CS-operated hub, an IA-only instance, a TL-only instance, the combined IA+TL instance: the deployment profile decides, and a member starts at the size that fits.

  • The demo is the hub posture: every role on one deployment.
  • Two member instances run in the pilot today: tl.oimlsmart.org (TL-only, the start-small posture) and nmi.oimlsmart.org (IA+TL, the institute shape).
  • Member instances submit signed evaluation chains to the CS platform; the register validates and imports them, idempotently.
  • Start small, grow: the same codebase grows from a laboratory's instance to a member state's.

Governance

The committee decides; the text stays

The adopted text is the source. The model derives from it with clause-level provenance, computes verdicts, and records who decided what. The legal acts stay exactly where the law puts them.

  • The Recommendation's text remains the gate: new editions join the modelled set through the authoring programme, under the committee's adoption.
  • The platform never decides: designation, acceptance, issuance, withdrawal remain the authorities' acts, with better evidence.
  • Nothing dies: PDFs keep their meaning, the register coexists with today's, and records mode lets paper-based work enter the record honestly marked.
  • The liability surface is the existing one; the platform widens nothing.

The adoption pathSMART

Start where you are; grow when ready

Reading costs nothing, participating costs an account, self-hosting is one deployment under your category's entitlement. Nothing is retired until your regime is satisfied.

  • Read: the audience pages, the use cases, the walkthroughs; the public surfaces need no account.
  • Reproduce: the demo's guided tour walks the whole chain in 22 steps; the instance resets nightly.
  • Pilot: one Recommendation, one authority, one laboratory, the TL-only posture running in the pilot today.
  • Self-host: the entitlement matrix quotes who may use what and who may run what, per member category.

The ask

Two asks of the committee

Pilot members, and honest feedback. Everything you saw is running today; the doors are open.

  • Pilot members: one Recommendation, one issuing authority, one laboratory. The pilot postures are running; the onboarding starts with a conversation.
  • Feedback: info@oimlsmart.org. Guided walkthroughs for committees and working visits are the commonest request.
  • The leave-behind: seven per-audience one-pagers, one printable page each, for the members who were not in the room.
  • The demo stays up: demo.oimlsmart.org, the cast assumed as personas through the identity service, the guided demo built in.