The Unified Standard: Topological BIM & Hierarchical BOM.
A single computable graph schema reconciling physical process engineering topology (ISO 15926-4 / DEXPI 2.0) with full-spectrum supply chain multi-BOM transparency (OWASP CycloneDX 1.6+). Breaking proprietary CAD monopolies through sovereign applied complexity science.
DEXPI 2.0 & ISO 15926-4
Reconciling physical P&ID equipment models, piping specs, and instrument tags into an open vendor-neutral schema, breaking proprietary CAD lock-in.
CycloneDX 1.6+ Multi-BOM
Unifying Hardware, Software, Firmware, and ML BOMs with cryptographically verifiable VEX attestations to satisfy strict NIS2 and CRA compliance.
Schema G_CPDT Digital Twin
A single computable multigraph coupling physical fluid/thermal process dynamics with cyber attack surface models for air-gapped deterministic simulation.
Liberating Industrial Engineering from Proprietary Walled Gardens
For decades, proprietary CAE and BIM vendors have locked critical piping, instrumentation, and thermodynamic details inside closed binary schemas. When engineering metadata is trapped in proprietary geometry blobs, automated multi-physics co-simulation and supply chain vulnerability verification become impossible.
DEXPI 2.0 provides an open, vendor-neutral information model grounded in ISO 15926-4, serializing the plant as a machine-readable directed graph. OWASP CycloneDX 1.6+ provides full-spectrum transparency across hardware, software, runtime configurations, and cryptographic assets. By binding DEXPI equipment tags directly to CycloneDX component references, Eigenia delivers the complete cyber-physical state machine.

Why Open Interoperability Inevitably Triumphs
Evaluating the unified standard through long-term economic moats, radical design clarity, and first-principles thermodynamics.
Chief Investment Officer
Sector: Catastrophe Reinsurance“Buying a closed proprietary system does not transfer your liability. Proprietary CAD vendors protect their license margins, not your plant. When a physical catastrophe halts operations, the asset owner absorbs every dollar of loss. Open, inspectable data standards build the only real economic moat: capital compounds without vendor lock-in, and risk rests on empirical physics.”
Chief Design Officer
Sector: Human-Machine Interfaces (HMI)“Simplicity comes from removing artificial boundaries. For decades, plants forced mechanical engineers to work in isolated piping diagrams while software teams looked at code elsewhere. That division makes no sense. When you place physical piping and digital components on the same computable canvas, the interface gets out of the way, and operators can finally see how the whole machine behaves.”
Chief Engineer
Sector: Autonomous Physical Systems“Start from first principles. If cooling stops, 140 kilowatts of rack heat will destroy silicon packaging in twelve seconds. A cybersecurity compliance checklist that ignores fluid dynamics protects nothing. Build the digital twin around physical ground truth: mass flow, pump curves, pressure limits, and silicon temperatures.”
The Voices of Industrial Operations
Real-world operational perspectives from mechanical piping, operational technology, cyber-physical modeling, plant operations, and catastrophe underwriting.
“Proprietary CAD files trap engineering intent inside closed geometry. When we engineer a 140 kW liquid cooling loop, our P&IDs hold critical data: pipe schedules, glycol mixtures (PG25), valve flow coefficients, and pump head curves. In traditional CAD tools, that hydraulic data is locked away. DEXPI 2.0 serializes the piping schematic into an open directed graph. Mapping DEXPI equipment tags straight to the digital twin lets us test flow failures and valve trips without paying CAD seat licenses.”
“SPDX was created for open source software licenses, not physical plants. Under IEC 62443 and the EU Cyber Resilience Act, security requires tracking five distinct layers: hardware roots of trust (HBOM), operating firmware (SBOM), network register setpoints (OBOM), cryptographic keys (CBOM), and cloud telemetry endpoints (SaaSBOM). CycloneDX 1.6+ supports every layer and evaluates VEX exploitability offline, so air-gapped control rooms can check vulnerabilities without external network connections.”
“Neither model works in isolation. A piping schematic shows that closing valve FCV-201 starves supply manifold A, but says nothing about the microcontroller controlling the actuator. An SBOM flags a vulnerability in that actuator's TCP stack, but cannot tell you that exploiting it drives GPU junction temperature above 105°C within 12 seconds. Binding DEXPI equipment tags directly to CycloneDX component references connects the vulnerability to the physical consequence.”
“In an alarm state, operators need actionable physical insight, not a list of software packages. The digital twin must respect Purdue Model boundaries. Facility staff need to see their familiar piping schematics, while security teams track vulnerability blast radius. Most importantly, the model must maintain an unbreachable safety boundary: software agents can observe and run simulations, but hardwired safety instrumented systems retain sole control over physical trips.”
“Self-attestation spreadsheets cannot underwrite a billion-dollar facility. Under Lloyd's Market Association Y5381 requirements, syndicates demand measurable proof of risk accumulation. Joining BIM piping topology with BOM component catalogs lets us run Monte Carlo simulations to calculate Single Loss Expectancy and Annualised Loss Expectancy based on actual physical damage. Insurers get defensible exposure numbers, and facility owners can price captive retention layers accurately.”
“Proprietary CAD files trap engineering intent inside closed geometry. When we engineer a 140 kW liquid cooling loop, our P&IDs hold critical data: pipe schedules, glycol mixtures (PG25), valve flow coefficients, and pump head curves. In traditional CAD tools, that hydraulic data is locked away. DEXPI 2.0 serializes the piping schematic into an open directed graph. Mapping DEXPI equipment tags straight to the digital twin lets us test flow failures and valve trips without paying CAD seat licenses.”
“SPDX was created for open source software licenses, not physical plants. Under IEC 62443 and the EU Cyber Resilience Act, security requires tracking five distinct layers: hardware roots of trust (HBOM), operating firmware (SBOM), network register setpoints (OBOM), cryptographic keys (CBOM), and cloud telemetry endpoints (SaaSBOM). CycloneDX 1.6+ supports every layer and evaluates VEX exploitability offline, so air-gapped control rooms can check vulnerabilities without external network connections.”
“Neither model works in isolation. A piping schematic shows that closing valve FCV-201 starves supply manifold A, but says nothing about the microcontroller controlling the actuator. An SBOM flags a vulnerability in that actuator's TCP stack, but cannot tell you that exploiting it drives GPU junction temperature above 105°C within 12 seconds. Binding DEXPI equipment tags directly to CycloneDX component references connects the vulnerability to the physical consequence.”
“In an alarm state, operators need actionable physical insight, not a list of software packages. The digital twin must respect Purdue Model boundaries. Facility staff need to see their familiar piping schematics, while security teams track vulnerability blast radius. Most importantly, the model must maintain an unbreachable safety boundary: software agents can observe and run simulations, but hardwired safety instrumented systems retain sole control over physical trips.”
“Self-attestation spreadsheets cannot underwrite a billion-dollar facility. Under Lloyd's Market Association Y5381 requirements, syndicates demand measurable proof of risk accumulation. Joining BIM piping topology with BOM component catalogs lets us run Monte Carlo simulations to calculate Single Loss Expectancy and Annualised Loss Expectancy based on actual physical damage. Insurers get defensible exposure numbers, and facility owners can price captive retention layers accurately.”
The Three-Tier Equipment Catalog
Decoupling engineering intent from procurement and operations, enabling automated simulation before procurement and continuous verification in production.
The Reference Requirements Specification
Process modelers specify operating limits, nominal flow rates, design pressures, and required Safety Integrity Levels (IEC 61508) without vendor coupling. This enables complete hydraulic simulation prior to commercial equipment bidding.
REQ-CDU-PUMP-01: Functional Role: Secondary Coolant Circulation Pump Fluid Medium: Propylene Glycol 25% (PG25) Nominal Flow: Q >= 35.0 m3/h | Design Pressure: 16.0 bar Safety Integrity: SIL-2 (IEC 61508) Security Target: SL-3 (IEC 62443-3-3) Fail-Safe State: Fail-Open to Maximum Flow
The Dual-View Cyber-Physical Bridge
The physical P&ID layout (DEXPI 2.0 / ISO 15926-4) defines hydraulic conductivity, pipe schedules, and fail-safe valve states. The multi-BOM hierarchy (OWASP CycloneDX 1.6+) defines firmware libraries, silicon roots of trust, and cryptographic readiness.

The Seven Foundational Treatises
Authored under clean direct-prose academic standards, establishing the mathematical, topological, and actuarial foundations of the sovereign digital twin.
Breaking the Proprietary CAD/BIM Monopoly
Why DEXPI 2.0 (ISO 15926 series) is the open foundation for industrial cyber-physical twins, liberating engineering models from closed Autodesk and AVEVA formats.
The Omnipresent Bill of Materials
Full-spectrum OWASP CycloneDX 1.6+ specification across HBOM, SBOM, OBOM, CBOM, and SaaSBOM for 100% offline air-gapped systems assurance.
Unified DEXPI & CycloneDX Schema
Formal specification of the single computable graph schema G_CPDT, joining physical P&ID multigraphs with digital component dependency DAGs.
Thermal Catastrophe in 140 kW AI Racks
Joint hydraulic P&ID and silicon root-of-trust blast radius modeling. Simulating the 12-second burnout horizon in high-density direct-to-chip liquid cooling.
Automated CyHAZOP & Monte Carlo Graphs
Coupling IEC 61882 hazard guide words with stochastic Monte Carlo attack walks across unified cyber-physical schemas to expose non-linear failure modes.
Physics-Grounded Cyber Underwriting
Deriving Single Loss Expectancy (SLE), Annualized Loss Expectancy (ALE), and Return on Security Investment (ROSI) from verified digital twin asset registers.
The Sovereign Cyber Digital Twin: An Open Architecture Standard for Critical Infrastructure Assurance
The synthesis whitepaper releasing the open-source Reference Facility Specification (RefFac-100MW-AI), defining the multi-agent governance charter, and establishing the global working group roadmap for hyperscalers, plant operators, and catastrophe reinsurance syndicates.
Joining DEXPI 2.0, CycloneDX 1.6, and IEC 61970 CIM
Three identity systems, one traversable graph. A specification, a CIM profile, a conformance suite, an open reference asset, and three applied cases across energy, manufacturing, and rail. The applied cases disagree with each other, and that disagreement is the result.
The Three-Identity Join
Thirty-five requirements binding DEXPI TagName, CycloneDX purl, and CIM mRID into one traversable graph.
A CIM Profile for Cyber-Physical Assets
The CPAI profile, completeness levels L0 to L4, and the rule that silence is not absence.
Conformance Suite and Reference Implementation
Thirty-two validation rules, and the suite that turns the specification from reasoned into observed.
RefBESS-250MW Reference Architecture
An open, citable 250 MW battery storage asset: fifteen sourced and thirty-five modeled parameters.
Energy: The Join at RefBESS-250MW
A CIM-rich asset at completeness level L4, where the three-schema traversal works as designed.
Manufacturing: The CIM-Thin Test
Where the third leg contributes nothing and the join collapses to a two-schema bridge.
Rail: A Split Domain at RefDepot-EMU-12
The component leg as the only bridge, and a join that crosses in one direction only.
Blast Radius Across Three Ontologies
Generalizing the two-schema multigraph metric, and the two conditions under which the third leg adds nothing.
Participate in the Sovereign Digital Twin Working Group.
Contribute domain expertise in DEXPI 2.0 piping topology, CycloneDX BOM schemas, or catastrophe underwriting to build open standards.
Join the Sovereign Knowledge Network
Access and contribute to Open Unified Standards (DEXPI 2.0, CycloneDX 1.6+), theorem workshops, and bilateral executive stress-testing simulations.
This Site Uses No Cookies
Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.
