ONVIF Profile M: what analytics metadata interoperability does—and does not—prove

Profile M standardizes analytics metadata and events between products. It does not certify analytic accuracy, lawful use, model quality, or every conditional feature.

Executive summary

What you need to know

Profile M standardizes analytics metadata and events between products. It does not certify analytic accuracy, lawful use, model quality, or every conditional feature.

Potentially affected

Organizations evaluating or operating cameras, analytics services, VMS platforms, NVRs, cloud services, MQTT integrations, or access workflows that exchange analytics metadata.

DSE recommendation

Specify the exact metadata and events required, verify both producer and consumer conformance, and test interoperability separately from analytic performance and privacy.

What Profile M standardizes

Source fact: ONVIF Profile M addresses metadata and events for analytics applications. Its defined interfaces include analytics configuration and information queries, metadata configuration and streaming, filtering, generic object classification, and specified metadata for geolocation, vehicles, license plates, human faces, and human bodies.

The profile also includes event interfaces for object counting, face recognition, and license-plate recognition. ONVIF explains that these interfaces apply when a conformant product natively supports the corresponding feature. Events can travel through a metadata stream, the ONVIF event service, or MQTT when MQTT is supported. Rule configuration and images in metadata are also subject to the product’s supported capabilities.

A Profile M producer can be an edge device such as an IP camera or a server- or cloud-based analytics service. A client can be a VMS, NVR, analytics application, or server/cloud service that consumes or controls metadata. Profile M can be combined with video and access-control profiles, but each claimed profile and exact software version must be verified independently.

What conformance does not measure

Profile M defines interfaces and data structures. It does not certify detection accuracy, false-alarm rate, demographic performance, training data, model security, image suitability, evidentiary value, or compliance with privacy law. It also does not mean every possible object, event, MQTT function, or rule is present; the distinction between mandatory and conditional features still applies.

Two conformant products can exchange metadata and still produce different operator experiences, search results, event timing, or analytic outcomes. Accuracy and suitability must therefore be evaluated with representative scenes and a documented purpose, separate from the protocol test.

DSE evaluation checklist

DSE recommendation: The following is DSE operational synthesis, not an ONVIF accuracy or privacy standard.

  1. Write the security or operational use case before selecting object classes or events.
  2. List required fields, event transports, images, rules, timestamps, identifiers, and downstream actions.
  3. Verify the exact Profile M record and feature documents for every producer and consumer.
  4. Bench-test configuration, filtering, event delivery, metadata preservation, time alignment, reconnect behavior, and search.
  5. Measure false positives and false negatives with representative site conditions; do not infer accuracy from conformance.
  6. Complete a privacy assessment covering purpose, notice, access, retention, sharing, and any biometric or identifying data.
  7. Require human review and a safe failure path before metadata triggers a consequential physical or business action.
  8. Retest after model, camera, VMS, rule, or firmware changes.

Official references

Primary reference

Review the official source

ONVIF — Profile M · Verified July 19, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE