Resources · Framework
The Orion Five Readiness Model
Five dimensions decide whether an integration survives contact with a working site. Any one of them, left fatal, is enough to sink a project that is excellent on the other four — and that combination is not the unlucky case, it is the characteristic shape of the ones that fail. This is the model written out: what each dimension measures, how it fails, and what it costs to fix.

The premise
UNIT 01Integration projects are rarely killed by the thing they were about. The controller can be read, the model is accurate, the dashboard is correct — and the project fails anyway, because nobody could agree which of three identifiers referred to the same pump, or because the engineering laptop that programs the line also reads email, or because eighteen months after go-live the person who understood it moved on and no budget existed to replace them.
Each of those is a different dimension of readiness, and they are genuinely independent. A site can be exemplary on four and fatal on the fifth. That is why this model refuses to average.
Why no dimension is weighted
Weighting would imply we know the exchange rate between a flat network and an absent process owner. We do not, and neither does anybody claiming to. Every dimension carries three questions and scores from 0 to 9, and the model runs to 45.
Why the binding constraint sets the band
What the model does instead of weighting is refuse to let a strong total carry a fatal dimension. A single dimension at or below a third of its scale caps the verdict at pilot-ready no matter how high the total; two of them cap it at not-ready. The total then decides where within the band you sit, and nothing more.
This is not a scoring convenience. Four strong dimensions and one fatal one is the exact profile of a project that gets funded, delivered competently, and quietly abandoned — and a model that averaged it into a respectable 80% would be describing that project as ready.
Equipment accessibility
UNIT 02Whether the physical asset can be read and commanded, by someone other than the company that installed it.
How it fails
The project is specified against the newest asset on the floor and then priced against the oldest. Discovery finds a machine whose controller is out of support, whose protocol needs a licence, or whose vendor will not grant access at all — and by then the scope is signed. Equipment accessibility is the dimension most likely to be assumed rather than checked, because checking it means opening a panel.
What it costs to fix
A survey. Two to five days for a typical SME site, ending in an inventory of what each asset speaks, who holds the credentials, and what the OEM's position is. It costs a small fraction of a build and it is the only thing that turns an estimate into a quote. Where access is refused, the answer is non-invasive retrofit sensing, which is more expensive per asset and entirely independent of the vendor.
What a full score looks like
Every asset in scope has a known interface, a documented address map, and credentials the company holds. Nobody outside the business has to agree to anything.
The tell
"It should have Modbus, I think."
Data foundation
UNIT 03Whether there is anything trustworthy to integrate, and whether a thing on the floor can be matched to a row in a system.
How it fails
The integration works and nobody believes it. Two systems disagree about how many units were made, because they count different things and neither was ever reconciled; or the same physical asset carries three identifiers and the join between them is a spreadsheet somebody maintains. The system is then quietly bypassed, which looks like resistance to change and is actually a correct response to unreliable data.
What it costs to fix
Identity first, history second. Settling on one identifier scheme and reconciling the existing ones is unglamorous operations work, usually a few weeks, and it does not need a vendor. History cannot be bought at all — if nothing has been retained, collection starts now and anything that learns from patterns waits a year.
What a full score looks like
One identifier scheme, applied consistently, resolving to exactly one record. A year or more of retrievable timestamped history. When the system and the floor disagree, people investigate the floor.
The tell
"You'd have to ask Sarah, she keeps the master list."

Network and security posture
UNIT 04What gets exposed the moment the operational side and the business side are joined.
How it fails
Not through an attack on the plant. Through the business network: an ordinary ransomware event reaches production because the two halves share identity, share switching, or are joined by a laptop that goes between them. The integration project is what made the plant reachable, and it is what gets blamed, usually fairly.
What it costs to fix
Segmentation and a brokered path for outside access. On an SME site this is frequently one hardened host and a firewall rule set rather than a data centre — the cost is in deciding and owning it, not in the hardware. It has to be scoped into the integration from the start; done afterwards it is a change request, and not done at all it is an incident.
What a full score looks like
Plant and business are separated with a controlled crossing point, vendor access is brokered and recorded, and one named person's remit explicitly covers the operational side.
The tell
"It's all behind the firewall."
Process stability
UNIT 05Whether the process being automated is settled enough to be worth encoding.
How it fails
Automation freezes an argument. The process varies by shift or by person, everyone believes their version is the standard, and encoding one of them makes that disagreement permanent and expensive to change. Or the exception rate was never measured, turns out to be a quarter of cases, and most of the promised saving is still being done by hand after go-live.
What it costs to fix
Settle the process before encoding it, and count the exceptions before pricing the build. Both are operations work rather than engineering, both are cheap, and both are far cheaper than a change request against a signed scope. Two weeks of somebody counting is the single highest-return activity available before an automation project.
What a full score looks like
Documented, practised as documented, under 5% exceptions, and the exceptions have names. Two people doing it produce the same result.
The tell
"Everyone does it slightly differently, but it works."

Operating capacity
UNIT 06Who runs the thing on the Monday after handover, and what happens when it breaks.
How it fails
After go-live, and quietly. The system works, the project closes, the integrator's support period ends, and eighteen months later it has been worked around because the person who understood it changed roles and nobody was funded to take it on. Every element of the technical work was sound. This is the most common failure in this model and it is the one nobody scopes for.
What it costs to fix
A named owner whose manager agrees, and an operating budget separate from the capital one. Neither costs much and neither can be bought from a vendor — this is the one dimension where the remedy is entirely internal, which is exactly why it gets deferred.
What a full score looks like
A named individual owns it, their job description says so, there is recurring budget for licences, support and their time, and the organisation has taken on a system before and it stuck.
The tell
"We'll work out who owns it once it's live."
Using it
UNIT 07Score it before you go to market, not after
Three of the five dimensions can be materially improved by work you do yourself, without a vendor: identity and history, process stability, and ownership. All three are cheaper as operations work than as change requests against a signed scope, and all three raise the quality of the quotes you receive, because a vendor pricing a settled process prices a smaller contingency.
Scope the pilot at the weakest dimension
The instinct is to pilot the part most likely to succeed. That produces a demonstration rather than evidence. A pilot is worth running where the model says you are weakest, because that is the only place the answer is genuinely unknown — and a pilot that fails there has told you something a successful demonstration never could.
Re-score after go-live
Readiness decays. New equipment arrives with closed controllers, new crossings appear on the network, the person who owned the last system takes on two more. Running this annually costs an hour and catches the drift while it is still cheap.
The model is implemented as a scored assessment at the Integration Readiness Assessment — fifteen questions, six minutes, and it applies the binding- constraint rule described above.
Technical references
UNIT 08What the reasoning on this page is drawn from. Where a standard costs money to read it is marked, and where a free document covers the same ground better it is listed first.
- NIST SP 800-82 Rev. 3NISTGuide to Operational Technology Security. Free, several hundred pages, and the most useful single document in this field. The segmentation logic in our planner follows its zone and conduit reasoning.
- ISA-95Paid standardISAThe enterprise-control integration standard the Purdue level model comes from. Levels 0 to 4 as they are actually defined.
- SAE JA1011Paid standardSAE InternationalThe evaluation criteria for reliability-centred maintenance. The discipline behind asking which failure mode before buying any sensor.
Links open in a new tab so anything you have entered above survives. Every one was checked at build time; if one has rotted since, tell us and it comes out rather than getting patched from memory.
Every one of these tools is a compressed version of a conversation. If yours turned up something you would rather talk through than read about, that is what the scoping call is for — bring your result with you.
Have your weakest dimension looked at properlyAlso on the shelf
- Framework
Spec template
The sections an integration brief needs before it goes out to vendors, so that three quotes come back describing the same job.
- Framework
Pilot to production
The gates a working pilot has to clear before it is allowed to run the business, and the specific ones most SME automation dies at.
- Framework
Vendor scorecard
How to compare integration vendors on what will actually determine the outcome, weighted and scored — including the questions we would rather you asked us.