PSIA specification family
PSIA publishes several interoperability specifications. Identify the relevant specification, product version and supported role before selecting an interface.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
PSIA publishes specifications rather than accredited standards; exact downloadable documents, schemas, product declarations, and errata are required for implementation.
On this page
Overview#
The Physical Security Interoperability Alliance (PSIA) publishes complementary system and domain specifications for exchanging security data. PSIA itself distinguishes its specifications from standards formally accredited by ANSI, IEC, ISO, or similar bodies.1 Use “implements PSIA specification/version/profile” rather than an unsupported generic “PSIA standard compliant” claim.
Family and status#
| Layer/specification | PSIA listed edition | Role/status |
|---|---|---|
| Common Security Model (CSEC) | v2.0 R1, posted 18 April 2015 | Network/session security, key/certificate and permission model shared by PSIA nodes |
| Service Model | v3.0 | Shared service framework/reference work |
| Common Metadata & Event Model (CMEM) | v3.1 Rev 0.4, posted 12 May 2016 | Shared metadata and event vocabulary/reference work |
| Area Control including PLAI | v3.1, released 7 August 2019 | Access/intrusion integration and PLAI profile |
| IP Media Device | 1.1 package / older 1.0 registrations | Legacy, no active development |
| Recording and Content Management | 1.1a (r0.6b) | Legacy video recording/search/content integration |
| Video Analytics | v1.0 | Legacy analytics discovery and output |
The editions and legacy labels above are taken from PSIA's current overview, FAQ, and legacy download page.23 PSIA says present organizational focus is access control and credential management, through PLAI and secure credential work.4
Integration method#
- Select the exact functional specification and all referenced system specifications.
- Obtain the official documents, XML schemas/examples, errata, and conformance materials.
- Build a product capability matrix: version, services, resources/events, optional fields, authentication, transport, limits, extensions, and declared conformance.
- Validate XML with hardened parsers: prohibit external entities and network resolution; bound document size, depth, lists, strings, and decompression.
- Preserve namespace/version and unknown extensions. Don't erase a value simply because an older peer can't represent it.
- Model delivery, application acceptance, persistence, rule processing, and physical action as separate results.
CMEM supplies common vocabulary but doesn't make two vendors' operational meanings identical. Map identity, device/location hierarchy, event type, severity, state transition, timestamps, acknowledgement, clear/restore, media references, and extension fields explicitly.
Security and conformance#
CSEC remains part of the family but its posted edition predates current TLS guidance. Apply its required PSIA semantics together with the exact product profile and current TLS/PKI baseline; don't silently rewrite the specification or claim conformance to a newer transport profile that the product lacks.
PSIA's PLAI listing states that PSIA doesn't itself test products: members conduct the conformance test and submit a self declaration and results.5 Record the declaring vendor, exact product/version, profile/version, declaration/certificate date, and test evidence. A listing is useful evidence, not proof of project specific interoperability or security.
Safety boundary#
PSIA events can trigger cross system rules, credential revocation, barrier movement, recording, or alarm workflows. Prevent loops with origin/correlation and idempotency, constrain automation by authoritative event quality, require human approval for high impact actions, and keep safe egress/life safety logic in its approved path. Validate endpoint, schema, retry, duplicate, and authorisation behaviour against the selected implementation.