What you need to know
Profile M standardizes analytics metadata and events between products. It does not certify analytic accuracy, lawful use, model quality, or every conditional feature.
Potentially affected
Organizations evaluating or operating cameras, analytics services, VMS platforms, NVRs, cloud services, MQTT integrations, or access workflows that exchange analytics metadata.
DSE recommendation
Specify the exact metadata and events required, verify both producer and consumer conformance, and test interoperability separately from analytic performance and privacy.
What Profile M standardizes
Source fact: ONVIF Profile M addresses metadata and events for analytics applications. Its defined interfaces include analytics configuration and information queries, metadata configuration and streaming, filtering, generic object classification, and specified metadata for geolocation, vehicles, license plates, human faces, and human bodies.
The profile also includes event interfaces for object counting, face recognition, and license-plate recognition. ONVIF explains that these interfaces apply when a conformant product natively supports the corresponding feature. Events can travel through a metadata stream, the ONVIF event service, or MQTT when MQTT is supported. Rule configuration and images in metadata are also subject to the product’s supported capabilities.
A Profile M producer can be an edge device such as an IP camera or a server- or cloud-based analytics service. A client can be a VMS, NVR, analytics application, or server/cloud service that consumes or controls metadata. Profile M can be combined with video and access-control profiles, but each claimed profile and exact software version must be verified independently.
What conformance does not measure
Profile M defines interfaces and data structures. It does not certify detection accuracy, false-alarm rate, demographic performance, training data, model security, image suitability, evidentiary value, or compliance with privacy law. It also does not mean every possible object, event, MQTT function, or rule is present; the distinction between mandatory and conditional features still applies.
Two conformant products can exchange metadata and still produce different operator experiences, search results, event timing, or analytic outcomes. Accuracy and suitability must therefore be evaluated with representative scenes and a documented purpose, separate from the protocol test.
DSE evaluation checklist
DSE recommendation: The following is DSE operational synthesis, not an ONVIF accuracy or privacy standard.
- Write the security or operational use case before selecting object classes or events.
- List required fields, event transports, images, rules, timestamps, identifiers, and downstream actions.
- Verify the exact Profile M record and feature documents for every producer and consumer.
- Bench-test configuration, filtering, event delivery, metadata preservation, time alignment, reconnect behavior, and search.
- Measure false positives and false negatives with representative site conditions; do not infer accuracy from conformance.
- Complete a privacy assessment covering purpose, notice, access, retention, sharing, and any biometric or identifying data.
- Require human review and a safe failure path before metadata triggers a consequential physical or business action.
- Retest after model, camera, VMS, rule, or firmware changes.
Official references
- Profile M — current feature, producer, client, event, and conditional-capability scope.
- ONVIF announces the release of Profile M — the June 30, 2021 release and interoperability use cases.
- Conformant Products — authoritative model and version verification.
Review the official source
ONVIF — Profile M · Verified July 19, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE