Standards and profile status
This is a dated record of standards and profile status. Confirm the current edition and lifecycle information with the original publisher before using it.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Inherited check dated 13 September 2026. Supporting evidence for this inherited check has not been independently confirmed.
Recorded scope: Selected current publisher status was rechecked for ONVIF, OSDP, BACnet, OPC UA, Matter and Zigbee Suzi. Other entries retain their stated source date and must be checked at decision time.
Original standards snapshot from 25 August 2026 with inherited September checks and a scoped Matter catalogue correction on 29 September 2026; licensed text, amendments, errata, regional adoption, certification listings, and exact product/firmware support must be checked at decision time.
On this page
Overview#
Most entries retain the 25 August 2026 source baseline and inherited September review records. The Matter catalogue listing was corrected on 29 September 2026; see the source correction record. Other entries require a current source check before use.
This register is navigation and review evidence, not normative text or a product support matrix. Obtain the official edition, applicable amendments/errata, certification record, and product declaration before implementation or procurement.
Status vocabulary#
| Label | Meaning in this register |
|---|---|
| Current base | Published edition used as the maintained reference on the verification date |
| Current alongside older deployment | Published and usable, but older editions remain materially deployed or interoperable |
| Release candidate | Public pre final profile/specification; do not claim final conformance |
| Living/mutable | Publisher maintains an evolving web specification or support document; pin retrieval date |
| Legacy | Still encountered but should not be selected as a modern baseline without an explicit migration constraint |
| Deprecated | Publisher has announced withdrawal/deprecation or ended conformance submissions |
| Superseded | Replaced by a later normative edition; retain only for exact legacy compatibility |
| Edition conflict | Publisher facing indexes disagree; obtain and identify the purchased normative copy |
The status of a standard, a profile, a certification program, a product, and a deployed feature are five different facts. See interoperability, conformance, and profiles.
Video and media#
| Family | Snapshot status | Engineering consequence | Canonical page |
|---|---|---|---|
| ONVIF Network Interface Specifications | 26.06, June 2026 release, current snapshot | Record every service namespace/version and test specification release; “ONVIF” alone is incomplete | ONVIF |
| ONVIF Profiles A, C, D, G, M, S, T | Published profiles listed by ONVIF; individual lifecycle differs | Match exact product/firmware/role and conditional features in the registered products database | ONVIF |
| ONVIF Profile S | Published but deprecation in progress; ONVIF says new product conformance submissions end 31 March 2027 | Plan Profile T migration; existing conformant products do not become non conformant merely from the submission cutoff | ONVIF |
| ONVIF Profile Q | Deprecated 1 April 2022 | Do not use as a new procurement/security baseline | ONVIF |
| ONVIF Profile V and Profile V Security Add on | Release candidate, Profile V page dated 9 July 2026 | Track final text and test tools; never represent RC implementation as final conformance | ONVIF |
| ONVIF TLS Configuration Add on | Version 2.0 Release Candidate published 9 September 2026; ONVIF expects the final specification at the end of 2026. Version 1.0 conformance submissions end 31 March 2027 | Pin addon version and transition dates; do not treat the Release Candidate as final conformance | ONVIF |
| ONVIF Media Signing Add on | Version 1.0 is a Release Candidate announced 26 August 2026; current scope is H.264 and H.265 video signing. ONVIF expects final specification at the end of 2026 | Verify device, client, profile and trust chain support; audio is not in the current Release Candidate | Video evidence export and integrity |
| RTSP 2.0 | RFC 7826, current standards track reference | Treat RTSP 2.0 as a separate capability from 1.0 | RTSP, RTP, RTCP, and SDP |
| RTSP 1.0 | RFC 2326 is obsoleted by RFC 7826 but remains materially deployed | Preserve for declared legacy/product interoperability only; do not mix version state machines | RTSP, RTP, RTCP, and SDP |
| RTP / RTCP | RFC 3550 / STD 64 with updates and profiles | Record the payload, feedback, security, multiplexing and clock rules | RTSP, RTP, RTCP, and SDP |
| SDP | RFC 8866 is the current base and obsoletes RFC 4566 | Preserve offered version/profile; validate all address and format fields | RTSP, RTP, RTCP, and SDP |
| WebRTC browser API | W3C Recommendation dated 13 March 2025; browser behaviour remains versioned/mutable | Pin target browsers and IETF media/security suite; owner compatibility testing remains required | WebRTC |
| SIP / SRTP | SIP RFC 3261 and SRTP RFC 3711 remain bases with many updates/extensions | Declare extension, identity, Digest, offer/answer, key management, and SRTP profile set | SIP and SRTP |
| HLS | RFC 8216 is published; second edition work was an Internet Draft on the snapshot date | Label draft behaviour as work in progress and pin player/server expectations | Codecs and streaming |
| MPEG DASH | ISO/IEC 23009-1:2026 Edition 6 is the current reviewed base | Pin profiles, codecs, manifests, segment addressing, DRM/entitlement, origin/cache, and player support | Codecs and streaming |
| GB/T 28181 | GB/T 28181-2022 current; 2016 edition abolished; related GB 35114-2017 and GB/T 43026-2023 have separate roles | Pin national/regional requirement, domain/role, security edition, and test evidence | GB/T 28181 |
| SRT | Active project protocol; reviewed library release 1.5.6; the IETF Internet Draft expired and is not an IETF standard | Pin implementation/library/interop profile; track security advisories and never call SRT an RFC | SRT and RIST |
| RIST | VSF Simple Profile 2020; Main and Advanced Profile publications reviewed at 2024 status | Pin exact VSF Technical Recommendation/profile and implementation subset | SRT and RIST |
Web, messaging, and serialisation#
| Family | Snapshot status | Engineering consequence | Canonical page |
|---|---|---|---|
| HTTP semantics/cache/1.1/2/3 | RFCs 9110 to 9114 are the current coordinated base set; RFC 9931 (March 2026) updates HTTP/1.1 transition security | Pin supported HTTP versions and intermediaries; apply current update/errata state | HTTP and REST |
| REST | Architectural style, not a versioned wire standard or conformance label | Specify the API's media types, resources, errors, auth, versioning, and semantics | HTTP and REST |
| SOAP | SOAP 1.2 Second Edition is a W3C Recommendation; SOAP 1.1 persists in deployed profiles | Pin envelope/binding/WSDL/profile; do not treat 1.1 and 1.2 as interchangeable | SOAP and XML |
| WebSocket | RFC 6455 base remains current with extension/subprotocol registries and updates | Pin HTTP opening context, extensions, subprotocol, auth renewal, and bounds | WebSocket, SSE, and webhooks |
| Server Sent Events | WHATWG HTML Living Standard feature | Pin browser/client behaviour and event contract retrieval date | WebSocket, SSE, and webhooks |
| Webhooks | No single universal webhook standard | Treat each vendor/API contract, signature, replay, retry, and callback registration profile separately | WebSocket, SSE, and webhooks |
| MQTT 5.0 | OASIS Standard, 2019, current published major version | Declare protocol version and feature subset; v3.1.1 behaviour differs | MQTT |
| MQTT 3.1.1 | OASIS Standard 2014 / ISO/IEC 20922:2016; still current for compatibility but older than v5 | Do not send v5 properties or assume v5 reason/session semantics | MQTT |
| gRPC | Project protocol/docs are maintained and implementation support windows are mutable | Pin protocol mapping, runtime, generated code/compiler window, and transport profile | gRPC and serialisation |
| Protocol Buffers | Edition/language/runtime support is versioned; ordinary serialisation is explicitly non canonical | Pin schema syntax/edition and runtime support window; never reuse field numbers | gRPC and serialisation |
| JSON / CBOR | RFC 8259 and RFC 8949 / STD 94 are current bases | Add explicit duplicate, numeric, depth, tag, deterministic/canonical rules when needed | gRPC and serialisation |
| AMQP 1.0 | OASIS Standard, distinct from AMQP 0-9-1 | Pin role, link, settlement, SASL/TLS, transaction, and product extension support | AMQP 1.0 |
| CoAP / OSCORE | RFC 7252, RFC 8323, RFC 8613, and RFC 9175 are published IETF bases with distinct transports/security scopes | Pin UDP/TCP/WebSocket, OSCORE/group profile, observation, proxy, and application semantics | CoAP, OSCORE, and LwM2M |
| OMA LwM2M | 1.2.2 is the reviewed published release | Pin Core/Transport/Device Management documents, object model, bootstrap, and implementation support | CoAP, OSCORE, and LwM2M |
| CAP / EDXL DE | CAP 1.2 is an OASIS Standard and ITU T X.1303bis basis; EDXL DE 2.0 is Committee Specification 02 | Pin regional profile and issuer/feed contract; delivery is not activation | CAP and EDXL |
Access control and credentials#
| Family | Snapshot status | Engineering consequence | Canonical page |
|---|---|---|---|
| SIA OSDP | 2.2.2, released October 2024, current SIA baseline | Buy/use normative edition and exact conformance profile; verify Secure Channel and roles | OSDP |
| IEC OSDP adoption | IEC 60839-11-5:2020, edition 1.0 | Record whether project/procurement cites SIA or IEC edition and applicable regional adoption | OSDP |
| SIA 26 bit Wiegand | SIA AC-01-1996.10; legacy interface/format baseline |
Do not select as a modern secure reader link; retain only for migration evidence | Legacy reader interfaces |
| ISO/IEC 14443 | Parts have independent edition/amendment status; Parts 1/3/4 are 2018 bases and Part 2 is 2020 in this snapshot | Pin every required part and amendment; RF/interface conformance does not define credential security | Contactless and smart card standards |
| ISO/IEC 15693 | Parts 1:2018, 2:2019, and 3:2026 in this snapshot | Do not cite the family without individual parts/editions | Contactless and smart card standards |
| ISO/IEC 7816 | Multi part series with different editions; Part 4:2020 confirmed 2025 | Pin command/application/profile parts; ISO 7816 compatibility is not a credential assurance claim | Contactless and smart card standards |
| NFC Forum | Release 15 published June 2025; CR15/TR15.0 launched October 2025; Certification Release 15 authorised May 2026 | Pin technical set, test release, authorised certification release, and product feature record separately | NFC, BLE, and UWB |
| Bluetooth Core | 6.3 adopted May 2026 | Pin controller/host/profile/features; adoption does not imply product supports every feature | NFC, BLE, and UWB |
| IEEE UWB base | IEEE 802.15.4-2024 active; 802.15.4z 2020 superseded; P802.15.4ab active project on snapshot date | Treat 4ab as draft/project work; product FiRa/ranging claims require exact feature/certification evidence | NFC, BLE, and UWB |
| FiRa | Core 4.0 specifications/certification announced December 2025 | Pin exact device role and certified feature set; “UWB” alone is insufficient | NFC, BLE, and UWB |
| Aliro | 1.0 introduced 26 February 2026 | New current baseline; require exact product/role/certification evidence and track early revisions | Credential formats and mobile credentials |
| PKOC | Core/NFC/BLE 2.0.1 dated 13 August 2026; PKOC over OSDP 1.63 approved 22 March 2024 | Record each component/binding version; do not infer product support | Credential formats and mobile credentials |
| PIV | FIPS 201-3 current base; SP 800-73-5 Part 1 final 2024 | Select exact authentication mechanism and facility access risk profile | Credential formats and mobile credentials |
| SAML / OpenID Connect | SAML 2.0 and OpenID Connect Core 1.0 remain published enterprise federation bases; OAuth security guidance continues through RFC updates | Pin metadata/issuer/audience/recipient, flow, token, client, and logout/session profile | Enterprise federation |
| SCIM | RFC 7643/7644 bases plus RFC 9865, RFC 9944, and RFC 9967 extensions reviewed | Pin schema/resource types, extension support, cursor model, async signalling, and reconciliation rules | SCIM provisioning |
| WebAuthn / CTAP | WebAuthn Level 2 final; Level 3 Candidate Recommendation; CTAP 2.3 Proposed Standard; CTAP 2.3.1 Working Draft | Do not present candidate/draft features as final; pin browser, platform, authenticator, and extension support | WebAuthn, FIDO, and passkeys |
Alarm monitoring#
| Family | Snapshot status | Engineering consequence | Canonical page |
|---|---|---|---|
| SIA DC09 | DC09 2026, current public listing; 2026 revision adds normative key rotation capability | Purchase/use exact edition and verify both endpoint security/key rotation modes | SIA DC09 |
| SIA DC03 | Public listing DC03 2017 | Exact licensed timing/framing/code behaviour required; treat as legacy security posture | SIA DC03 |
| Contact ID / SIA DC05 | Public listing DC05 2016; legacy DTMF format | No modern cryptographic security; validate carrier/gateway/receiver path | Contact ID |
| SIA DC07 | Public page says 2001.04 while store exposes a 2012 label: edition conflict | Identify the purchased normative copy; never guess frame/code rules | SIA DC07 |
| SIA AV01 | Public listing AV01 2014 | Treat audio/DTMF/relay capabilities as privacy and safety sensitive | SIA AV01 |
| IEC 60839-5 family | IEC 60839-5-1:2014, -5-2:2016, and -5-3:2016 are separate published parts; IEC TS 60839-7-8:2019 remains a Technical Specification | Obtain licensed parts and national adoption; do not treat the TS as a final International Standard | IEC 60839 alarm transmission |
Building, industrial, and infrastructure#
| Family | Snapshot status | Engineering consequence | Canonical page |
|---|---|---|---|
| BACnet | ANSI/ASHRAE 135-2024 current base used by committee updates; addenda/errata remain separately maintained | Obtain standard plus applicable addenda/errata and product PICS/certification | BACnet family |
| BACnet/SC | Current BACnet secure data link option within maintained BACnet work | Verify node/hub/failover and certificate lifecycle; legacy links remain separate | BACnet/SC |
| Modbus application protocol | V1.1b3 remains the current publisher listed application specification | Treat semantic/address model and transport mapping separately | Modbus family |
| Modbus serial | Serial Line Protocol and Implementation Guide V1.02 is publisher recommended for new serial implementations; an older 1996 document is labeled legacy only | Record exact serial guide, electrical profile, and product limits | Modbus RTU |
| Modbus Security | Publisher lists MB TCP Security v36, dated 30 July 2021 | Pin certificate/role profile and product support; port 802 alone proves nothing | Modbus Security |
| OPC UA | Multi part 1.05 line: Parts 1/2 and several others are 1.05.06; Parts 4/6/8/12/13/17/26 are 1.05.07 at this snapshot; other Parts differ | Pin every required Part/companion specification, profile, namespace/model version, and product certification | OPC UA |
| KNX | Public V3 set dated February 2025; member/certification 3.0.4 released 22 August 2025 and used for certification from end August | Identify whether evidence is the public set, member document, or certification record; pin media/profile/secure feature and ETS project | KNX |
| DNP3 | IEEE 1815-2012 remains last published but is administratively inactive; superseding P1815 is an Active PAR/draft | Do not present P1815 as published; pin installed subset/profile and secure authentication support | DNP3 |
| IEC 60870-5-101/-104 | Published telecontrol companion profiles; IEC TS 60870-5-7:2025 and IEC 62351-5:2023 provide separate security context | Pin every base/companion/security part and national/product profile | IEC 60870-5-101 and -104 |
| IEC 61850 | Maintained multi part utility automation family with independently versioned SCL, communication mappings, conformance, and IEC 62351 security parts | Pin every required part, edition/amendment, logical model, SCL profile, and product conformance evidence | IEC 61850 |
| Matter | CSA lists Matter 1.6.1 specifications on 29 September 2026; camera support began in 1.5 and was refined in 1.5.1 | Pin device type, cluster, fabric/controller, certification, and ecosystem support; never infer PACS/ONVIF/fire capability | Matter |
| RADIUS over TLS / RADIUS 1.1 | RFC 6614 and RFC 9765 are both Experimental; RFC 9765 requires TLS 1.3 and removes legacy MD5 packet mechanisms | Require explicit bilateral support and certificate/identity policy; do not treat RFC status as deployment approval | AAA and network access |
| TLS | TLS 1.3 RFC 8446 current base; TLS 1.2 remains deployed under current policy constraints | Use current algorithm/profile policy and product capability; never silently downgrade | TLS, PKI, and secure transport |
| NTP / NTS | NTPv4 RFC 5905; NTS RFC 8915 | NTS support must be explicit; security and clock accuracy are separate evidence | Time synchronisation |
| SNMP | SNMPv3 architecture/USM current standards family; v1/v2c remain legacy deployments | Prefer authenticated privacy mode where supported; pin MIB revisions | Monitoring and administration |
How to use this register#
For a design or compatibility record, copy none of the rows blindly. Instead record:
- publisher and exact title;
- edition/version/date and amendments/errata;
- normative role, profile, options, and required/conditional features;
- certification/conformance program and exact product/firmware listing;
- product declared capability plus configuration evidence;
- owner controlled interoperability, negative, failure, and recovery results;
- migration trigger, withdrawal date, and next review.
Update this page when a listed publisher changes a revision, lifecycle date, test program, or release candidate state. Don't update last_verified merely because prose was edited.
Sources#
- ONVIF HISTORY, ONVIF Specification History, including June 2026 release, accessed 25 August 2026.
- ONVIF PROFILES, ONVIF Profiles, Add ons and Specifications, lifecycle status checked 13 September 2026.
- ONVIF TLS RC, TLS Configuration Add on 2.0 Release Candidate, ONVIF, 9 September 2026.
- ONVIF MEDIA SIGNING RC, Media Signing Add on Release Candidate, ONVIF, 26 August 2026.
- IETF RFC, IETF Datatracker RFC index, individual RFC status pages accessed 25 August 2026.
- W3C WEBRTC, WebRTC: Real Time Communication in Browsers, W3C Recommendation, 13 March 2025.
- MQTT5, MQTT Version 5.0, OASIS Standard, 7 March 2019.
- SIA OSDP, Open Supervised Device Protocol, Security Industry Association, accessed 25 August 2026.
- SIA INDEX, At a Glance Guide to SIA Standards, Security Industry Association, accessed 25 August 2026.
- NFC SPECS, NFC Forum Specifications, accessed 25 August 2026.
- BT63, Bluetooth Core Specification 6.3, Bluetooth SIG, adopted May 2026.
- IEEE154, IEEE 802.15.4-2024, IEEE Standards Association.
- FIRA4, FiRa Core 4.0 specifications and certification announcement, FiRa Consortium, 3 December 2025.
- ALIRO, Introducing Aliro 1.0, Connectivity Standards Alliance, 26 February 2026.
- PKOC, Secure Credential Interoperability and PKOC, PSIA, status dated 13 August 2026.
- BACNET UPDATES, BACnet standard and addenda status, ASHRAE BACnet Committee, accessed 25 August 2026.
- MODBUS, Modbus specifications and implementation guides, Modbus Organization, accessed 25 August 2026.
- OPCUA, OPC UA Part 1 v1.05.06, OPC Foundation, published 22 October 2025.
- KNX304, KNX Standard Version 3.0.4, KNX Association, 22 August 2025.