Founder & Lead Engineer, RAITHub
SCORM is a set of standards that lets e-learning content, packaged as a zip file with an imsmanifest.xml, run inside any compliant learning management system (LMS) and report progress and scores back to it. SCORM 1.2, released in October 2001, is still the version every content vendor supports. You need SCORM when you buy or sell off-the-shelf training content; for courses authored inside your own product, you usually do not.
If you would rather have SCORM, xAPI or cmi5 support built into your platform, see how RAITHub would build this below.
This guide is for product leads, L&D (learning and development) teams and EdTech founders deciding whether their LMS needs SCORM, and what it takes to support it. Facts come from the SCORM and xAPI reference pages published by Rustici Software, the Moodle documentation and vendor pricing pages, checked on 2 October 2026. The wider build-or-buy picture is in custom LMS vs Moodle.
What is SCORM, in plain terms?
SCORM (Sharable Content Object Reference Model) is a bundle of specifications from ADL, the US Department of Defense's Advanced Distributed Learning initiative. It answers two questions: how a course is packaged so any LMS can import it, and how the running course talks to the LMS so progress is saved.
- Packaging. A SCORM course is a zip file. At its root "there must be an XML file called 'imsmanifest.xml'" describing the content and its structure (SCORM 1.2 overview for developers).
- Run-time. The course runs in the browser, finds a JavaScript object the LMS has placed in a parent window, and calls functions on it to read and write tracking data.
- Data model. A fixed list of fields, all prefixed cmi, such as the lesson status, the score and a bookmark for resuming.
The unit of content that talks to the LMS is called a SCO (Sharable Content Object). A package can hold one SCO or many.
What is the difference between SCORM 1.2 and SCORM 2004?
SCORM 2004 added sequencing; SCORM 1.2 is what everyone supports. According to scorm.com's version history, SCORM 1.2 "lacked a sequencing and navigation specification", and SCORM 2004 added it, so an author can, for example, stop a learner taking the final test before finishing the course. The same page says SCORM 1.2 "is still the industry workhorse" and that, of the 2004 editions, "the 3rd edition is the most widely used".
| Feature | SCORM 1.2 | SCORM 2004 (4th edition) |
|---|---|---|
| Released | October 2001 | March 2009 (1st edition January 2004) |
| API object name | API | API_1484_11 |
| Function names | LMSInitialize, LMSGetValue, LMSSetValue, LMSCommit, LMSFinish | Initialize, GetValue, SetValue, Commit, Terminate |
| Status | One field: cmi.core.lesson_status | Two fields: cmi.completion_status and cmi.success_status |
| Score | cmi.core.score.raw, with min and max | Adds cmi.score.scaled, from -1 to 1 |
| Suspend data limit | 4,096 characters | 64,000 characters (4,000 in 2nd and 3rd editions) |
| Sequencing and navigation | None | Yes, defined by the author |
| Support among LMSs and authoring tools | Near universal | Wide, but less consistent |
Sources: SCORM versions, SCORM run-time and the run-time reference. The suspend data limit matters more than it looks: it is where a course saves its internal state, and long courses built for 2004 can overflow a 1.2 LMS.
Support is not universal even among well-known platforms. Moodle's documentation says SCORM 1.2 is supported and passes ADL's 1.2 conformance tests, but "SCORM 2004 is not supported in Moodle", and points to a commercial plugin for it (Moodle SCORM FAQ).
How does an LMS actually run a SCORM package?
In four steps, and only the last two are hard.
- Import. The LMS unzips the package, reads imsmanifest.xml, and stores the files where the browser can load them, ideally on the same origin as the LMS page, because the course must reach into a parent window.
- Launch. The LMS opens the SCO's launch page in a frame or a new window.
- Talk. Before launching, the LMS puts an API adapter object in the parent window. "The API object should be located in a window that is a parent of the SCO or a parent of the opener window of the SCO" (SCORM run-time). The course finds it, calls LMSInitialize, reads and writes cmi values, and calls LMSCommit and LMSFinish.
- Persist. The adapter is plain JavaScript in the browser, so the LMS must send the data to its server on commit and on exit, store it per learner, course and attempt, and hand it back next launch so the learner resumes where they left off.
Here is the course side of a minimal SCORM 1.2 session. The LMS side is the object these calls land on.
// Inside the SCO: find the API object the LMS placed in a parent window.
function findAPI(win) {
let tries = 0
while (!win.API && win.parent && win.parent !== win && tries < 10) {
win = win.parent
tries++
}
return win.API || null
}
const api = findAPI(window) || (window.opener ? findAPI(window.opener) : null)
// SCORM 1.2 functions take and return strings: 'true' means success.
if (api && api.LMSInitialize('') === 'true') {
if (api.LMSGetValue('cmi.core.lesson_status') === 'not attempted') {
api.LMSSetValue('cmi.core.lesson_status', 'incomplete')
}
// ...the learner works through the lesson and its quiz...
api.LMSSetValue('cmi.core.score.min', '0')
api.LMSSetValue('cmi.core.score.max', '100')
api.LMSSetValue('cmi.core.score.raw', '85')
api.LMSSetValue('cmi.core.lesson_status', 'passed')
api.LMSSetValue('cmi.core.session_time', '00:12:30')
api.LMSCommit('')
api.LMSFinish('')
} else if (api) {
console.error('SCORM error', api.LMSGetLastError())
}
The allowed lesson status values in 1.2 are passed, completed, failed, incomplete, browsed and not attempted (run-time reference). On the LMS side you rarely write the adapter from scratch: scorm-again is an MIT-licensed JavaScript runtime for SCORM 1.2 and 2004 that you attach as window.API, with an lmsCommitUrl setting for where the data is posted. Your server still owns storage, attempts, reporting and security.
What are xAPI and an LRS, and do they replace SCORM?
xAPI (the Experience API, once called Tin Can) records learning anywhere, not just inside an LMS window. It is now "an IEEE approved standard (IEEE 9274.1.1-2023)", and an application sends statements in the form "Noun, verb, object" to a Learning Record Store, or LRS, which "can exist on its own or inside an LMS" (xAPI overview).
A statement is JSON sent over HTTP to the LRS:
{
"actor": { "mbox": "mailto:learner@example.com", "name": "Sample Learner" },
"verb": { "id": "http://adlnet.gov/expapi/verbs/completed", "display": { "en-US": "completed" } },
"object": { "id": "https://learn.example.com/courses/fire-safety", "objectType": "Activity" },
"result": { "score": { "scaled": 0.85 }, "success": true }
}
That frees you from the browser-frame model: a mobile web app, a simulator or an offline workshop can all report. What xAPI alone does not define is how an LMS launches content, who is allowed to send statements, or when a course counts as complete. That gap is what cmi5 fills.
What is cmi5?
cmi5 is "an xAPI Profile that bridges the SCORM and xAPI divide by defining interoperability rules, including launch, authorization, reporting and course structure", released in 2016 (xapi.com: cmi5). Think of it as SCORM's job done with xAPI's plumbing: the LMS launches the content with credentials, the content sends xAPI statements to the LMS's LRS, and agreed rules decide completion. Content no longer has to live in a frame on the same origin as the LMS.
| Question | SCORM 1.2 / 2004 | xAPI | cmi5 |
|---|---|---|---|
| Where can learning happen? | In a browser window launched by the LMS | Anywhere that can send HTTP | Launched by the LMS, content can be hosted anywhere |
| Where is data stored? | The LMS's cmi data model | An LRS | The LMS's LRS |
| Defines launch and completion? | Yes | No | Yes |
| Data detail | Fixed fields: status, score, time, interactions | Any statement you design | xAPI statements with defined verbs |
| Content you can buy today | The large majority | Some | Growing |
| Build effort for an LMS | Low to medium with a runtime library | Medium: an LRS, or a hosted one | Medium to high: launch, auth and LRS |
When do you need SCORM, and when don't you?
Ask where the content comes from.
- You need SCORM 1.2 if you are a corporate L&D team buying compliance or skills courses from content vendors, a platform selling to such teams (their procurement checklist will ask), or a content studio whose customers each run a different LMS. Most authoring tools export SCORM 1.2, so it is the safe default.
- Add SCORM 2004 only when a customer brings packages that depend on sequencing. Test them; do not assume.
- Consider xAPI and cmi5 when you must track learning outside the LMS (simulations, field practice, mobile web), or a buyer specifies it.
- You do not need SCORM when every lesson is authored in your own product, as in most consumer EdTech, tutoring and cohort platforms. Your own events table will be richer than the cmi data model. Add SCORM import later, when a buyer actually asks.
A common mistake is building SCORM first because it sounds like a requirement, then discovering no customer uploads a package in the first year.
Buy, build or hire?
| Option | Example and cited price | Choose this when |
|---|---|---|
| Off-the-shelf LMS | TalentLMS: a free plan for 5 users, paid plans from $119 a month, with "SCORM 1.2/Tin Can/cmi5" listed on every plan | You run internal training and only need to upload and track packages |
| Open-source LMS | Moodle: no licence fee; SCORM 1.2 and AICC supported, SCORM 2004 not | You have someone to host and administer it, and your packages are 1.2 |
| Hosted SCORM engine added to your product | SCORM Cloud: free trial tier with 10 registrations; paid plans from $40 a month, $360 a month for 300 registrations | You have your own platform and want broad SCORM, xAPI and cmi5 support without building a player |
| Custom build | An open-source runtime such as scorm-again, plus your own storage, attempts and reporting | SCORM is one feature of a product you own, volumes make per-registration fees costly, or you need the data in your own database |
For a do-it-yourself build, an experienced developer can usually add a basic SCORM 1.2 player to an existing LMS in about 2–4 weeks using a runtime library; that is an engineering estimate, not a vendor figure. The main risk is real-world packages: authoring tools interpret the specification differently, so a player that passes your test course can still fail a customer's. Budget time for a library of real packages and regression tests against them.
What has to be built for SCORM support in a custom LMS?
- Upload and validation: unzip safely (reject path traversal and oversized archives), parse imsmanifest.xml, detect the version.
- Hosting: serve content from a path the API can reach, usually the same origin or a proxied one.
- Runtime and persistence: attach the adapter, post commits to your API, and store cmi values per learner, package and attempt.
- Attempts and resume: honour cmi.core.exit set to suspend, restore suspend data and the bookmark on relaunch.
- Reporting: completion, scores and time per learner and group, exportable for audits.
Cost ranges for a full custom LMS are in LMS development cost, and the module-by-module plan is in how to build an LMS from scratch.
Why RAITHub for this
RAITHub built PadhAI, an AI tutoring platform: 11 services (9 Node/TypeScript, 2 Python), a Socratic tutor with math verification and retrieval-augmented generation, a 70/20/10 LLM router, delivery across a PWA, WhatsApp and Telegram, and 9 payment gateways. That is learning-product engineering with tracking, attempts and payments at its core. RAITHub's published work does not include a SCORM, xAPI or cmi5 implementation, so on your project it would be scoped and tested as new work, against a set of your real packages. The QA-first habit is the part that matters here: package compatibility is a testing problem more than a coding one.
When you don't need us
- You only need to run SCORM courses for your staff. Buy an LMS that lists SCORM 1.2 on its pricing page.
- Your platform needs broad standards support quickly. A hosted engine such as SCORM Cloud is faster than any custom player.
- You need SCORM courses authored. That is instructional design and an authoring tool, not platform engineering.
- You need a certified or SOC 2 audited vendor. RAITHub is not certified.
How RAITHub would build this
- Scope: SCORM 1.2 import and playback in your LMS, with optional SCORM 2004 support if your packages need it.
- A runtime adapter, a commit API and per-attempt storage in PostgreSQL, with resume and suspend data.
- Optional xAPI statement capture to a hosted or self-run LRS, or cmi5 launch where a buyer requires it.
- Completion and score reports per learner and group, with CSV export.
- A regression suite run against a library of real packages from your content vendors.
Timeline: added to an existing platform, this is backend and API work, typically 6–12 weeks; as part of a new LMS MVP with a fixed scope, 4–6 weeks for the first version, with SCORM 1.2 only.
You receive: automated tests and CI, handover docs and runbooks, and full IP under an NDA. RAITHub signs NDAs and DPAs and works inside your controls; production learner data stays in your own cloud account, and development uses synthetic data. Builds run under SaaS development as fixed scope or a dedicated team.
Next step: book the free 15-minute technical audit, bring two or three packages your customers use, and you will get a written fixed quote. More context is on the EdTech page and in the EdTech software development guide; for a quick range, try the MVP cost estimator.
scorm.com, xapi.com, Moodle, TalentLMS and SCORM Cloud sources checked on 2 October 2026.
Frequently asked questions
What does SCORM stand for?
Sharable Content Object Reference Model. It is a set of specifications from ADL that defines how e-learning content is packaged and how it reports progress and scores to an LMS.
Should I support SCORM 1.2 or SCORM 2004?
Start with SCORM 1.2: scorm.com calls it the industry workhorse that every vendor should support. Add SCORM 2004 when customers bring packages that need its sequencing rules, and test those packages first.
Is xAPI replacing SCORM?
Not yet in practice. xAPI is an IEEE standard and tracks learning beyond the LMS, but most purchasable content still ships as SCORM. Many platforms support both, and cmi5 adds the launch and completion rules xAPI lacks.
What is the difference between an LMS and an LRS?
An LMS manages courses, enrolments and learners. A Learning Record Store only stores xAPI statements. An LRS can run on its own or inside an LMS.
Does Moodle support SCORM?
Moodle supports SCORM 1.2 and AICC. Its documentation says SCORM 2004 is not supported and points to a commercial plugin for it.
How long does it take to add SCORM to a custom LMS?
A basic SCORM 1.2 player built on a runtime library takes an experienced developer about 2–4 weeks. Reporting, SCORM 2004 and testing against real packages take longer.
Has RAITHub built SCORM support before?
No. RAITHub built PadhAI, an AI tutoring platform, and would scope SCORM, xAPI or cmi5 support as new work, tested against your real packages.
Related posts
Ready to discuss your project?
Book a free 15-minute technical audit with our engineering team.