From 50a54c02bc30d67cfefbd1cd95d4264d44c08ae3 Mon Sep 17 00:00:00 2001 From: Sharang Parnerkar <30073382+mighty840@users.noreply.github.com> Date: Thu, 16 Jul 2026 23:59:44 +0200 Subject: [PATCH] docs(plc): add PLC Runtime Landscape reference + support watch-list MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Documents the soft-PLC runtime ecosystem as a support watch-list: we support the CODESYS family today (incl. the many rebranded-CODESYS OEMs — Schneider, WAGO, ABB, Bosch, Eaton, KEBA), and everything else (ProConOS/ISaGRAF/straton, Siemens TIA, Rockwell, Beckhoff TwinCAT, B&R, Mitsubishi, Omron, PLCnext) is watch-list — we add a project-format parser when a customer needs it. The dynamic OT probe is vendor-agnostic. Also lists the open-source test-bench substrates (OpenPLC, Beremiz+MatIEC, 4diac). New Reference sidebar entry. Co-Authored-By: Claude Opus 4.8 --- docs/.vitepress/config.mts | 1 + docs/reference/plc-runtimes.md | 97 ++++++++++++++++++++++++++++++++++ 2 files changed, 98 insertions(+) create mode 100644 docs/reference/plc-runtimes.md diff --git a/docs/.vitepress/config.mts b/docs/.vitepress/config.mts index 73dad79..5b14b47 100644 --- a/docs/.vitepress/config.mts +++ b/docs/.vitepress/config.mts @@ -44,6 +44,7 @@ export default withMermaid(defineConfig({ items: [ { text: 'Glossary', link: '/reference/glossary' }, { text: 'Tools & Scanners', link: '/reference/tools' }, + { text: 'PLC Runtime Landscape', link: '/reference/plc-runtimes' }, ], }, ], diff --git a/docs/reference/plc-runtimes.md b/docs/reference/plc-runtimes.md new file mode 100644 index 0000000..f0cfc08 --- /dev/null +++ b/docs/reference/plc-runtimes.md @@ -0,0 +1,97 @@ +# PLC Runtime Landscape & Support + +A soft PLC is a **SoC + Linux + a software runtime + an IEC 61131-3 control app** +(see [PLC / SPS Projects](/guide/plc)). +The **runtime** is what defines the device — it provides the IEC engine, the +Modbus / OPC UA / EtherNet/IP servers, and the WebVisu. This page tracks the +runtime ecosystems Certifai may encounter. + +We do **not** aim to support every runtime up front. Certifai supports the +**CODESYS family** today; everything else is a **watch-list** — when a customer +shows up using one, we add the parser/support for it then. The dynamic OT probe +(Modbus / OPC UA / EtherNet/IP) is **vendor-agnostic** and works regardless of +the runtime. + +## Support status + +| Status | Meaning | +| --- | --- | +| ✅ **Supported** | Static analysis works today (control-logic SAST + library/runtime SBOM + CVE). | +| 🟡 **Covered via CODESYS** | A rebranded CODESYS runtime — our CODESYS parsing applies (may need minor per-vendor tweaks). | +| 🔭 **Watch-list** | Own project format — we add a format parser when a customer needs it. The dynamic OT probe already applies. | +| 🧪 **Test-bench** | A free runtime we use to *reconstruct and dynamically test* a device (see epic: provision-and-test). | + +## 1. CODESYS and rebranded CODESYS (the largest slice) + +Much of the market licenses the CODESYS runtime and rebrands the IDE. If a +customer "doesn't use CODESYS", they often do — under another name. + +| Product / vendor | Based on | Status | +| --- | --- | --- | +| **CODESYS** (3S-Smart Software Solutions) | CODESYS | ✅ Supported | +| Schneider **EcoStruxure Machine Expert** (ex-SoMachine) | CODESYS | 🟡 Covered via CODESYS | +| **WAGO** e!COCKPIT / PFC controllers | CODESYS | 🟡 Covered via CODESYS | +| **ABB** AC500 / Automation Builder | CODESYS | 🟡 Covered via CODESYS | +| **Bosch Rexroth** ctrlX / IndraLogic | CODESYS | 🟡 Covered via CODESYS | +| **Eaton** XSoft-CODESYS, **KEBA** KeStudio, Berghof, Kontron, Festo (CPX-E), IFM, Turck, … | CODESYS | 🟡 Covered via CODESYS | + +## 2. Other embeddable IEC 61131-3 runtime toolkits + +Same model as CODESYS (an OEM licenses a runtime + IDE and bakes it into a +device), but with **different project formats and libraries**. + +| Toolkit | Vendor | Status | +| --- | --- | --- | +| **ProConOS / MULTIPROG** | Phoenix Contact / KW-Software | 🔭 Watch-list | +| **ISaGRAF** (also does IEC 61499) | Rockwell | 🔭 Watch-list | +| **straton** | COPA-DATA | 🔭 Watch-list | +| **logi.CAD** | logi.cals | 🔭 Watch-list | + +## 3. Fully proprietary ecosystems (own runtime + IDE + protocols) + +Static analysis here needs a **per-vendor project parser**; the **dynamic OT +probe still works** (they speak Modbus / OPC UA / EtherNet/IP, plus vendor +protocols like S7comm / CIP). + +| Ecosystem | Vendor | Notes | Status | +| --- | --- | --- | --- | +| **TIA Portal / STEP 7** (S7-1200/1500), S7-1500 **Software Controller**, **Virtual PLC** | Siemens | Largest install base; the soft/virtual variants are Linux/container | 🔭 Watch-list | +| **Studio 5000** (ControlLogix / CompactLogix) | Rockwell / Allen-Bradley | Strong in North America | 🔭 Watch-list | +| **TwinCAT 3** | Beckhoff | Genuine PC-based control on Windows / TwinCAT-BSD; IEC 61131-3 **+ C++ + Simulink** | 🔭 Watch-list | +| **Automation Studio** | B&R (ABB) | Own Automation Runtime | 🔭 Watch-list | +| **GX Works** (MELSEC) | Mitsubishi | | 🔭 Watch-list | +| **Sysmac Studio** (NX / NJ) | Omron | | 🔭 Watch-list | +| **Proficy Machine Edition** (PACSystems) | Emerson / GE | | 🔭 Watch-list | + +## 4. Linux-native / containerized soft-PLC (the direction of travel) + +| Product | Vendor | Notes | Status | +| --- | --- | --- | --- | +| **PLCnext** | Phoenix Contact | Open, Linux-based; native runtime is eCLR (not CODESYS), but can also run CODESYS as an app | 🔭 Watch-list | +| **ctrlX** | Bosch Rexroth | Ubuntu-core, app-store model (CODESYS runtime inside) | 🟡 Covered via CODESYS | +| **Virtual PLC** / **CODESYS Virtual Control** | Siemens / CODESYS | Containerized PLCs (Docker / K8s) | 🟡 / 🔭 | + +## 5. Open-source runtimes (free — our test-bench substrates) + +Used to **reconstruct and dynamically test** a customer device without touching +their network (provision-and-test). + +| Runtime | Standard | Notes | Status | +| --- | --- | --- | --- | +| **OpenPLC** | IEC 61131-3 | Modbus-centric, education/small automation; uses MatIEC | 🧪 Test-bench (current) | +| **Beremiz + MatIEC** | IEC 61131-3 | Fuller open-source IDE; compiles ST/IL → C. Natural fidelity step-up from OpenPLC | 🧪 Test-bench (candidate) | +| **Eclipse 4diac (FORTE)** | IEC **61499** | Distributed, event-driven — a *different paradigm* from 61131-3's scan cycle | 🔭 Watch-list | +| **ProView** | — | Open-source process control + SCADA | 🔭 Watch-list | + +## How we add support for a new runtime + +- **Static (SAST / SBOM):** needs a parser for that runtime's **project format** + (and its library/package convention). This is the per-vendor work. +- **Dynamic (ICS probe / DAST):** already **vendor-agnostic** — it targets the + device's OT ports and WebVisu, not the runtime's file format. So a brand-new + ecosystem still gets dynamic coverage on day one. + +::: tip Rule of thumb +Confirm whether a "non-CODESYS" controller is actually a **rebranded CODESYS** +runtime (Section 1) before assuming new work — most of the long tail is. +::: -- 2.54.0