Immersive training generates far more data than a course completion, and most organisations throw nearly all of it away because the pipe they send it down was designed in 2001. SCORM can tell your LMS that someone passed. xAPI can tell you that they checked the patient’s airway before calling for help, forty seconds in, on the second attempt. Choosing between them is the single decision that determines whether your analytics are useful or decorative.
Key takeaway: Use SCORM if the only question is who completed. Use xAPI, launched through cmi5, if you want to know what people did. And decide early what you are going to do with gaze and motion data, because it is more identifying than it looks.
SCORM: what it can and cannot carry
SCORM came from ADL, the US Advanced Distributed Learning initiative, with 1.2 landing in October 2001 and the 2004 editions running to a fourth in March 2009 (Rustici).
It reports back a small, fixed vocabulary. SCORM 1.2 gives you cmi.core.lesson_status, which accepts passed, completed, failed, incomplete, browsed or not attempted. SCORM 2004 usefully separates completion from success, so a learner can finish a scenario and still fail it. Both carry a score and a session time, and both support an interactions array with question ids, learner responses, results and latency (Rustici run-time reference).
The limit people hit is cmi.suspend_data, the field that stores where a learner got to. The numbers are not what most people assume:
| Version | suspend_data limit |
|---|---|
| SCORM 1.2 | 4,096 characters |
| SCORM 2004 2nd Edition | 4,000 characters |
| SCORM 2004 3rd and 4th Editions | 64,000 characters |
Note that 2004 2nd Edition is slightly smaller than 1.2, which catches people out. Worse, exceeding the limit does not throw an error. The learner simply resumes at an earlier point than they left off, so it gets diagnosed as a bug rather than a ceiling.
For a branching scenario with dozens of decision points, four thousand characters disappears quickly.
xAPI: statements instead of status codes
xAPI records what happened as a sentence. An actor, a verb, an object, plus context and a timestamp: “Chloe answered the escalation question incorrectly, in scene three, at 14:02”. ADL describes the model as data about “the actor (e.g., learner), verb (e.g., watched, passed), and object (e.g., video, quiz) as well as contextual information such as the timestamp and issuing authority” (ADL). Those statements go to a Learning Record Store rather than to a course.
The thing to know in 2026, because most published comparisons predate it: xAPI is no longer just a specification. It is IEEE 9274.1.1-2023, board approved on 30 March 2023, published on 6 October 2023, and listed as an Active Standard (IEEE SA). What the industry calls xAPI 2.0 and what IEEE calls 9274.1.1-2023 are the same thing, not two releases. Rustici, which wrote the original specification under contract, now states plainly that “IEEE is the steward of the standard” (xapi.com).
One oddity worth knowing if you are checking sources: ADL’s own xAPI page still describes the IEEE work in the future tense, three years after it published. Cite the IEEE page.
cmi5: the piece that makes xAPI work with an LMS
xAPI on its own does not tell an LMS how to launch a course, how to pass credentials, or how a course is structured. cmi5 fills that gap. It is an xAPI profile that defines the launch mechanism, authorisation, reporting rules and a course structure of Assignable Units grouped into Blocks (xapi.com, cmi5 specification).
AICC began it in 2010, redesigned it around xAPI in 2012, and transferred it to ADL when AICC dissolved in 2014. The current release is Quartz, 1st Edition, from June 2016. There has been no published release since, and there will never be a cmi6: updates ship as named editions.
If your LMS supports cmi5, that is the route to take. If it does not, you are looking at a SCORM wrapper for launch and completion with xAPI statements going to a separate LRS alongside, which works but means two places to look.
Is SCORM dead?
No, and anyone who tells you otherwise is selling something. ADL’s position is careful: SCORM solutions “are still in wide use and retain a great deal of interoperability”, while “the ADL Initiative recommends xAPI and cmi5 solutions for new acquisitions and implementations” (ADL). The conformance test suites are still maintained.
Rustici, reporting from its own launch telemetry around 2023 and 2024, put it more bluntly: nearly three in four course launches were still SCORM 1.2 or SCORM 2004. That is vendor-reported and a couple of years old now, but the direction is right. Legacy and actively discouraged is not the same as deprecated.
The gap nobody advertises: there is no VR profile
This one is worth getting right, because it is regularly overstated in vendor material.
There is no published, governed xAPI profile for VR or simulation training. ADL’s repository of official profiles covers serious games, virtual patient, video, audio, SCORM, cmi5, open badges and others, but nothing for immersive or VR, and that repository was archived and made read-only in March 2026 (ADL profiles repository). At IEEE, the profile standard layer, 9274.2.1, was listed as not active.
Researchers building learning analytics for VR reached the same conclusion and built their own vocabulary because there was nothing to adopt, noting the research community still needs consensus (Görzen, Heinemann and Schroeder, LAK24 workshops).
So what happens in practice is that every platform defines its own verbs and activity types. That is legitimate under xAPI, but it means immersive data from two vendors will not line up without mapping work. Make it a procurement question: ask which verbs a platform emits and whether it will give you the list in writing.
What is actually worth measuring
Completion tells you almost nothing, and satisfaction tells you less than people believe. The Kirkpatrick® model, created by Donald Kirkpatrick in the 1950s and developed by Jim and Wendy Kirkpatrick, separates reaction, learning, behaviour and results, and its own guidance warns that “Level 1 is not sufficient to tell you if behavior transfer will occur” (Kirkpatrick Partners).
The evidence on satisfaction ratings is harsher. Will Thalheimer’s review of four meta-analyses covering more than two hundred studies puts the average correlation between learner ratings and actual learning at around .10, which is effectively nothing (Work-Learning Research). The clearest of those, Uttl, White and Wong Gonzalez, concluded institutions “may want to abandon SET ratings as a measure of faculty’s teaching effectiveness” (Studies in Educational Evaluation, 2017). That study is about university teaching rather than workplace training, so do not stretch it, but the smile sheet is not the instrument people hope it is.
From an immersive scenario, the things worth capturing are the ones a classroom cannot give you:
- Decision sequence. Not just what they chose, but in what order and after how long.
- Retries. A learner who got it right on the fourth attempt is a different learner from one who got it right immediately.
- Time to a specific action. Time to escalate, time to isolate the machine, time to check the airway.
- What they looked at. Where attention went before a mistake.
- Free text. What they would actually say, marked against a rubric rather than a multiple choice.
Node XR captures each choice, retry and free-text answer per learner per attempt, samples camera gaze at around one hertz through the scene, and supports marking attempts against a weighting scheme. It exports through SCORM and xAPI so the completion still lands in your LMS while the detail goes somewhere it can be analysed.
The privacy question to settle before you collect anything
Gaze and motion data is where immersive training gets legally interesting, and the answer is more nuanced than either “it is all biometric” or “it is just telemetry”.
The ICO’s position: biometric data becomes special category data only when used to identify someone. Its guidance states directly that “Not all biometric data is automatically special category biometric data. It only becomes this if you use it to uniquely identify someone” (ICO). The ICO does, however, explicitly name gaze-based recognition and gait recognition among behavioural biometric recognition methods (ICO).
So training telemetry collected to assess performance rather than to identify people is ordinary personal data in most designs. It still needs a lawful basis, transparency, minimisation and very probably a DPIA. It is not automatically Article 9 material.
The reason to be careful anyway is a piece of research that should be better known. Across a pool of 55,541 real VR users, researchers identified individuals “with 94.33% accuracy from 100 seconds of motion, and with 73.20% accuracy from just 10 seconds of motion”, using only head and hand movement (Nair et al., USENIX Security ‘23). Head and hand motion is functionally identifying whether you intend it to be or not, which makes casual claims about anonymised VR telemetry hard to sustain.
Two practical consequences. Write the retention and aggregation policy before you switch tracking on, not after. And note that the ICO’s biometric guidance, published in November 2024, is itself under review following the Data (Use and Access) Act 2025, so this is not settled ground.
The short answer
SCORM reports completion and a score, and its suspend data runs out fast on a branching scenario. xAPI, now an IEEE standard, records what learners actually did, and cmi5 is the piece that lets an LMS launch it properly. There is still no agreed xAPI profile for VR, so ask vendors which verbs they emit. Measure decisions, retries and timings rather than completions and smile sheets, and decide what you are doing with gaze and motion data before you start collecting it.
The LMS and integrations page covers how this connects to your existing stack, and the xAPI glossary entry has the short version for a specification document.