Skip to main content
v2026.11,772 entries · CC-BY 4.0

CoreTrustSeal Certification: Requirements, Process, and Whether It’s Worth Pursuing

The full 16 CoreTrustSeal requirements, the self-assessment and peer-review process end to end, real certified-repository examples, and practical guidance for deciding whether your institution should pursue certification.

Written and maintained by CASRAI Editorial Board

Last updated

CoreTrustSeal certification is the entry-level, most widely held tier of the three-level
trustworthy-repository trust framework (core, extended, formal) used across the research-data
world. CASRAI’s CoreTrustSeal dictionary term and
the certification section of How to
Choose an Open Data Repository
already cover what the seal is and why it matters when
selecting a repository. This guide goes one level deeper for anyone actually weighing whether
to pursue certification for a repository they run: the full list of the 16 requirements
assessed, exactly how the self-assessment-plus-peer-review process runs end to end, what it
costs, real examples of certified institutional repositories, and the practical trade-offs of
pursuing it versus depositing with an already-certified generalist repository instead.

What CoreTrustSeal certifies, briefly

CoreTrustSeal is a community-based, non-profit certification scheme for trustworthy digital
repositories, operated by the CoreTrustSeal Foundation. It sits at the “core” level of the
field’s three-tier trust framework: core (CoreTrustSeal, a peer-reviewed self-assessment)
sits below extended level (the German nestor Seal / DIN 31644, a plausibility-checked
self-assessment against 34 criteria — see CASRAI’s Extended level
certification
term) and formal level (ISO 16363, a full external audit). CoreTrustSeal
itself traces to a 2017 merger of the Data Seal of Approval and the ICSU World Data System
certification scheme, and functions today as the field’s de facto entry-level baseline —
recognized by an increasing number of funders and by EU infrastructure programmes including
EOSC and OpenAIRE-Nexus.

The 16 requirements, in full

Applicants are assessed against 16 numbered requirements (R01–R16), organized into three
groups, plus a non-scored background/context statement (R0). This is the full list — CASRAI’s
existing repository-selection guide names the count but not the individual requirements:

For more detail, see HEPData — HEPData is the discipline-specific repository for scattering and kinematic data underlying particle-physics publications, hosted at Durham University and tightly linked to arXiv and INSPIRE-HEP.

Organisational infrastructure (R01–R06)

  • R01 — Mission & Scope: the repository has an explicit mission
    committing it to providing access to and preserving data within a defined designated
    community and subject scope.
  • R02 — Rights Management: the repository manages legal and contractual
    rights appropriately, including the rights it needs to preserve and provide access to
    deposited data.
  • R03 — Continuity of Service: the repository has a plan for organisational
    and financial sustainability, and for what happens to holdings if it ceases operating.
  • R04 — Legal & Ethical Compliance: the repository operates within
    relevant legal and ethical norms (data protection, confidentiality, IP, consent).
  • R05 — Governance & Resources: the repository has adequate governance
    and sufficient, appropriately qualified staff and resources for its function.
  • R06 — Expertise & Guidance: the repository provides guidance and
    support to depositors and users on relevant standards and good practice.

Digital object management (R07–R13)

  • R07 — Provenance and Authenticity: the repository guarantees the
    integrity and authenticity of deposited data, tracking provenance from acquisition or
    ingest onward.
  • R08 — Deposit & Appraisal: the repository applies documented
    criteria for accepting or rejecting deposits, and communicates them to depositors.
  • R09 — Preservation Plan: the repository has an explicit plan covering
    what preservation levels it applies to different object types over time.
  • R10 — Quality Assurance: the repository has documented processes for
    ensuring data and metadata quality.
  • R11 — Workflows: repository workflows for ingest, management, and
    access are documented and functionally sound.
  • R12 — Discovery and Identification: deposited objects are described
    with adequate metadata and assigned persistent identifiers to support discovery and citation.
  • R13 — Reuse: the repository enables reuse over time by documenting
    context, format, and any licence/access conditions attached to the data.

Technology (R14–R16)

  • R14 — Storage & Integrity: the repository has documented processes
    for storage and for verifying the integrity of stored data and metadata over time (this is
    the requirement most directly satisfied by routine checksum/fixity verification — see
    CASRAI’s Checksum
    Verification and Fixity Checking
    guide for the practical mechanics).
  • R15 — Technical Infrastructure: the repository’s technical
    infrastructure (hardware, software, network) is adequate, documented, and appropriately
    maintained.
  • R16 — Security: the repository’s technical infrastructure provides for
    the security of the facility and the data it holds, including disaster recovery.

All 16 are mandatory, equally weighted, standalone items — there is no partial credit or
weighted average across requirements. CoreTrustSeal revises the Requirements document
periodically (a 2023–2025 version and a 2026–2028 version have both been published); exact
requirement wording can shift slightly between versions, so an applicant should always work
from the current Requirements and Extended Guidance documents published on
coretrustseal.org rather than a summary such as this one.

For more detail, see aladin sky atlas — CDS Strasbourg operates SIMBAD, VizieR, and Aladin — the astronomical object database, catalogue service, and interactive sky atlas that much of professional astronomy relies on for FAIR-compliant data discovery, citation, and reuse.

The certification process, end to end

Based on CoreTrustSeal’s own published FAQ, the process runs roughly as follows:

  1. Registration and self-assessment: an applicant repository registers and
    has up to three months to submit its initial self-assessment — documented evidence against
    each of the 16 requirements.
  2. Peer review: two reviewers, drawn from staff at other certified
    repositories, independently review the submission, typically within a two-month window.
  3. Board assessment: the CoreTrustSeal Board considers the reviewers’
    findings and returns feedback, typically within about two weeks.
  4. Revision cycles: applicants can submit up to five revised versions of
    their self-assessment in response to reviewer/Board feedback, each re-reviewed within about
    two months.
  5. Decision: on approval, the Board issues a final certification decision,
    typically within a month of the successful review.

The whole cycle — from initial submission to a final Board decision, approval or
declination — is capped at a maximum of two years from the submission date.

Cost

CoreTrustSeal charges an administrative fee, set at €3,000 as of a February 2024 fee
change. Discounts are available: umbrella organisations certifying ten or more repositories
together can receive a 25% bulk discount, and institutions that provide a minimum of six
peer reviews during their certification period can receive a 33% reviewer discount. Fee
waivers are available at the Board’s discretion for repositories based in low- and
middle-income countries. Fees are subject to change — confirm the current figure directly on
coretrustseal.org before budgeting for an application.

Renewal

Certification runs on a three-year term. CoreTrustSeal sends renewal reminders six months
before expiry, and a certification remains listed for up to six months after expiry — giving
a repository roughly a year in total to complete recertification without a certification gap.
The renewal self-assessment is reviewed in essentially the same way as an initial application,
but typically over three review rounds rather than five, since the repository already has an
established baseline.

Repositories actually certified

Beyond the community-wide repositories already named on CASRAI’s CoreTrustSeal dictionary
term (DANS and 4TU.ResearchData), a range of institutional and disciplinary repositories hold
current CoreTrustSeal certification, illustrating that this is not only a national-archive-scale
undertaking:

  • ICPSR (Inter-university Consortium for Political and Social Research,
    University of Michigan) — a long-standing core-certified social science data archive, with
    periodic recertification.
  • Apollo, the University of Cambridge’s institutional research repository —
    certified in 2023, an example of a university-level (not national-archive-level) repository
    achieving certification.
  • Edinburgh DataShare, the University of Edinburgh’s research data
    repository.
  • TU Wien Research Data Repository — the first Austrian institutional
    research data repository to be certified.
  • Merritt (California Digital Library) and Dryad‘s
    underlying technical platform — both certified, illustrating certification at the
    shared-infrastructure/generalist-repository level.

CoreTrustSeal maintains the authoritative, current list of certified repositories at its
own certificate database (amt.coretrustseal.org/certificates) — check there directly rather
than relying on any secondary list, including this one, since certifications lapse and renew
on a rolling three-year cycle.

Why this matters for research administrators specifically

Certification status increasingly shows up as a real, checkable condition rather than a
soft preference:

  • EU infrastructure programmes — the European Open Science Cloud (EOSC) and
    OpenAIRE-Nexus — require or strongly prefer deposit into a CoreTrustSeal-certified (or
    equivalent) repository.
  • An increasing number of individual funders reference certified-repository status,
    directly or via FAIR-repository guidance, when assessing a grantee’s proposed data
    management plan or evaluating repository choice — see CASRAI’s DMP review criteria guide for
    how repository trustworthiness fits into that broader review lens.
  • For an institution weighing whether to build and run its own repository versus pointing
    researchers at an existing certified one (a domain repository, Zenodo, Dryad, or a
    certified generalist platform), certification status is a legitimate, verifiable due-diligence
    check either way — see CASRAI’s repository-selection guide for the
    fuller decision framework.

Should your institution pursue certification?

Certification is a real undertaking, not a checkbox. Before starting the process, it is
worth weighing:

  • Resourcing: compiling evidence against all 16 requirements, in practice,
    touches governance documentation, legal/rights agreements, technical infrastructure
    documentation, and preservation/quality-assurance policy — work that usually spans more than
    one institutional unit (research office, IT, library/archives, legal). Budget staff time
    across the up-to-two-year process, not just the €3,000 fee.
  • Whether self-hosting is the right call at all: if the institution’s
    researchers can reasonably deposit with an existing certified disciplinary or generalist
    repository, pursuing certification for a smaller institutional repository may not be the best
    use of resources — the trust benefit already exists via the external repository’s own
    certification. Certification is most clearly worth pursuing for a repository an institution is
    committed to operating long-term as core infrastructure.
  • Peer-review reciprocity: the process runs on community peer review —
    institutions considering certification should expect to also contribute reviewer time to
    other applicants (and can offset part of the fee by doing so).
  • Sequencing with related work: much of the evidence a self-assessment
    needs — fixity/checksum verification practice, a documented preservation plan, persistent
    identifier assignment, metadata quality — overlaps with good repository operations generally.
    Institutions already doing this work well are typically closer to certification-ready than
    the requirement count alone suggests.

Frequently asked questions

Is CoreTrustSeal certification mandatory for a research data repository?

No single global mandate applies universally, but it is increasingly a named or implied
expectation in specific contexts — most concretely for repositories used within EOSC or
OpenAIRE-Nexus, and as a factor some funders weigh when assessing a data management plan’s
proposed repository. Whether it is effectively required depends on the specific funder,
programme, and repository — check the applicable funder’s own data policy directly.

How is CoreTrustSeal different from FAIR data certification?

They assess different things. FAIR (Findable, Accessible, Interoperable, Reusable)
describes properties of data and metadata themselves — see CASRAI’s FAIR data checklist
guide. CoreTrustSeal assesses the repository as an organisation and system — its governance,
processes, and infrastructure. A repository can host FAIR data without itself being
CoreTrustSeal-certified, and certification does not by itself guarantee every dataset it
holds is FAIR; the two are complementary, not substitutes.

What happens if a repository fails to complete certification?

An application can be declined by the Board if requirements are not adequately
demonstrated even after the permitted revision cycles. A declined or withdrawn applicant is
not barred from reapplying later once gaps are addressed; CoreTrustSeal does not publish a
“failed” list, and a repository not shown in the certified-repositories database simply is
not (or is no longer) certified.

Does CoreTrustSeal certification expire?

Yes — certification runs for three years, with a renewal window that begins six months
before expiry and a roughly one-year total grace period to complete recertification before a
listing lapses.

Related CASRAI resources

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · included with Regulatory Radar

Ask about CoreTrustSeal Certification: Requirements, Process, and Whether It’s Worth Pursuing

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.