Start where you are; grow when you are ready. Your institute’s IT director gets the question every national body eventually asks: can we run this ourselves, and how small can we start? The honest answer is a matrix, not a sales call: one codebase boots in four postures, decided by a declared deployment profile, and a laboratory can join with the smallest one and grow. Two member instances are running in the pilot today, captured below as they serve.
The demo is the CS-operated posture: every role on one deployment, the cast assumed as personas through the identity service. The instance resets nightly.

The four postures, rendered plain
The matrix’s facts were verified against the deployment documentation (the deployment runbook that ships with the member repository: the two topologies, the profile system, the operations section) on 2026-08-31.
| Posture | What it runs | Who signs in | What federates where |
|---|---|---|---|
| CS-operated platform (the hub) | The whole scheme: the applicant portal, the authority consoles, the laboratory workbenches, the BIML register. Topology A of the runbook: one durable store, one provisioning seed. | Everyone: applicants, IA officers, TL operators, the scheme’s own roles. | Nothing to federate inward; member instances submit to it. Live as the hosted platform and as the demo. |
| IA-only instance | The authority’s own deployment: the intake, the evaluation projects, the certificates desk. Topology B of the runbook. | The authority’s officers, its applicants, its associated laboratories. | Completed evaluation chains travel to the CS platform as signed submission packages; the register validates and imports them, idempotently (a repeat submission returns the same registration reference). An export-download fallback covers the case where no submission URL is set. No public pilot instance today; the profile is the same one the pilots boot. |
| TL-only instance | The laboratory’s own deployment: the test-request inbox, the model-driven test runs, the report authoring. A disabled module’s routes simply do not exist (no applicant portal to run). | The laboratory’s operators and managers. | Receives dispatched test work from the authority’s instance and returns the report as data. Live in the pilot at tl.oimlsmart.org. |
| IA+TL instance | An authority and its laboratory under one roof: the national metrology institute’s classical shape, both role sets enabled. | The institute’s officers and operators, its applicants. | The same signed-chain submission to the CS platform’s register. Live in the pilot at nmi.oimlsmart.org. |
The pilot instances, captured as they serve


How it works
One codebase, and a declared profile decides the shape: the instance’s identity (which organization this deployment IS), its role set (hub, IA, TL, or IA+TL), the module toggles, the federation peers, and the per-profile seed. The navigation, the console switcher, and the route table follow the enabled modules; a disabled module’s routes answer 404 honestly rather than pretending. The federation is the scheme’s own: an authority-operated instance submits its completed evaluation chains to the CS platform as signed packages, and the register verifies the signature chain on import, so the validity reference stays single.
What this changes, and what it does not
Today the choice is framed as all-or-nothing: join a central system and cede the keyboard, or stay out and keep the filing cabinet. The postures dissolve that: the hosted platform needs no operations from you at all, and the self-hosted postures are one service-class deployment each, not a new kind of infrastructure. What does not change: whose acts are whose. The authority decides and signs on its own instance exactly as on the hosted one; the scheme’s register remains the single validity reference either way.
Today (SMART) and the vision (SMART+)
Today · SMART
- The hub posture: the hosted OIML-CS SMART Platform, with the demo as its public rehearsal. the demo ↗
- The IA+TL and TL-only pilot instances serving today, captured above. nmi ↗
- The signed-chain submission: completed evaluations travel to the register as signed packages, verified on import. the trust machinery ↗
Who may run what
The self-host entitlement attaches to the Member State; an authority or laboratory operates its instance under its proposing Member State’s entitlement. Quoted from the program’s single entitlement source, with the path spelled out:
| Service | Member State |
|---|---|
| OIML SMART account (the identity service) | ✅ |
| Identity service software | ✅ 🏠 🔄 |
| OIML-CS SMART Platform (cloud) | ✅ |
| SMART Platform software (self-host) | 🏠 🔄 |
| The demo instance | ✅ |
| The Studio viewer | ✅ |
| The Vocabulary | ✅ |
| The status service | ✅ |
| Ommisa, the AI service | ✅ member tier |
| SMART Recommendations content | ✅ |
| The trust registry (organization keys) | ✅ registers |
| The SMI Simulation | ✅ 🏠proposed |
| The SMART Twin (SMART+) | roadmap |
- Use — hosted, on the official services
- Self-host — on-prem/cloud, under the category’s own entitlement
- Streaming updates — the rolling channel the deployment runbook names
- The upsell note — see the narratives below the matrix
Quoted from the program's single entitlement source; the full matrix, all member categories by all services, lives atWho can run what.
A body asks: can we self-host?
The honest answer: the entitlement is your Member State’s. An Issuing Authority or Test Laboratory operates its own instance under its proposing Member State’s entitlement — the Member State is the entitled party; the body operates. The IA-only, TL-only, and IA+TL postures exist exactly for this, and the platform’s federation means your instance talks to the OIML-CS platform either way.
The honest questions
Must we self-host to stay sovereign?
No. The hosted platform serves every member category, and using it never requires running anything. Self-hosting is the Member State entitlement for those who want their own data residency; the federation means the register story is identical either way. The matrix above quotes the determination from the single source.
What does running our own instance actually cost?
The postures are deliberately minimal-ops: one service, one durable store (a SQLite volume or a DynamoDB table), the rolling update channel. The runbook’s operations section is the honest headline: backups are a file snapshot, upgrades are rolling and forward-compatible, health is two endpoints. It is operations a national metrology institute’s IT already runs.
Can a laboratory really start alone?
Yes, that is what the TL-only posture is for. The laboratory’s instance receives dispatched work from the authority’s platform and returns reports as data; when the authority later stands up its own instance, or joins the hosted one, the laboratory’s posture does not change. The pilot at tl.oimlsmart.org is this shape, serving today.
If everyone can run their own, whose register is true?
The scheme’s. Member instances submit their completed chains to the CS platform; the register validates the signature chain on import and publishes the single validity reference. A repeat submission is idempotent: it returns the same registration reference and never double-registers. Federation multiplies the keyboards, never the truths.
Where to go next
The demo is the hub; nmi.oimlsmart.org is the IA+TL pilot; tl.oimlsmart.org is the TL-only pilot. Same software, three profiles.
Every member category by every service, from the program's single source.
info@oimlsmart.org: which posture fits your organization, and what the first deployment looks like.


