Examples
Worked examples
- Is an instance
A national space-agency or national-scale scientific data archive commissioning an accredited external audit to formally demonstrate trustworthy long-term preservation.
- Is an instance
A CoreTrustSeal-certified repository pursuing ISO 16363 as a higher, externally audited tier of assurance requested by a funder or government mandate.
Counter-examples
Looks similar, but isn't
- Not an instance
A repository that runs the ISO 16363 metrics as an internal self-review, without an accredited external auditor formally certifying the result, is not ISO 16363 certified.
- Not an instance
Holding CoreTrustSeal or the nestor Seal alone does not constitute ISO 16363 certification — they are separate, lower-rigor tiers of the same framework.
Editorial commentary
ISO 16363 (full title: Space data and information transfer systems — Audit and certification of trustworthy digital repositories) is the Formal level of the three-tier trustworthy-repository certification framework used across research data management: CoreTrustSeal is the Core/Basic level (peer-reviewed self-assessment), the nestor Seal is the Extended level (plausibility-checked self-assessment against DIN 31644), and ISO 16363 is the Formal level: a full external audit conducted by accredited auditors against an evidence-based checklist of over 100 metrics, rather than a self-assessment reviewed by peers.
What makes something an ISO 16363 (Formal-level) certification
A repository is ISO 16363-certified only when an independent, accredited auditing body has conducted an on-site or fully independent audit against the standard’s metrics and formally attested the result — not when a repository merely uses the ISO 16363 checklist internally for self-review, and not when it holds a lower-tier self-assessed certification such as CoreTrustSeal or the nestor Seal instead. The audit body most commonly cited for this work is the Primary Trustworthy Digital Repository Authorisation Body (PTAB), which was itself accredited to conduct ISO 16363 audits under ISO 17021 (as extended by ISO 16919, the companion standard specifying requirements for bodies that audit and certify candidate trustworthy digital repositories).
Origins: CCSDS, the OAIS model, and the TRAC checklist
ISO 16363 did not appear from nothing. It was developed from 2007 onward by the Repository Audit and Certification Working Group within the Consultative Committee for Space Data Systems (CCSDS) — the same body responsible for the OAIS Reference Model (ISO 14721), which supplies ISO 16363’s underlying conceptual vocabulary for what a repository must do to preserve digital information over the long term. Its direct predecessor document is TRAC (Trustworthy Repositories Audit & Certification: Criteria and Checklist), published in 2007 by RLG (the Research Libraries Group, later merged into OCLC) together with the U.S. National Archives and Records Administration (NARA). TRAC established the checklist structure and audit criteria that ISO 16363 formalised into an international standard. ISO 16363 was first published in 2012 (test-audited at six repositories, three in Europe and three in the U.S., before publication) and has since been revised, with a current edition on the ISO catalogue; TRAC itself is now considered superseded by ISO 16363 rather than used as a standalone certification pathway. “ISO 16363 / TRAC” is still frequently used as a combined shorthand in the literature for this reason, even though TRAC is the historical checklist and ISO 16363 the current standard built on it.
What the audit covers
Consistent with its TRAC lineage, ISO 16363’s evidence-based metrics are organised around the same three broad areas used across the trustworthy-repository framework generally:
- Organizational infrastructure — governance, staffing, financial sustainability, succession planning, and the repository’s documented commitment to long-term preservation.
- Digital object management — how the repository ingests, represents, stores, and preserves the integrity and usability of the digital objects it holds over time.
- Infrastructure and security risk management — technical infrastructure, systems security, and risk management appropriate to the scale and sensitivity of the holdings.
Because the audit is evidence-based rather than a checklist a repository completes about itself, a Formal-level review typically requires substantially more auditor time, documentation, and cost than pursuing CoreTrustSeal or the nestor Seal — which is why most repositories that hold ISO 16363 certification already have significant scale, a regulatory or funder mandate for audited assurance, or both.
Worked examples
- A national space-agency or national-scale scientific data archive — the domain ISO 16363 originated in — commissioning an accredited external audit to formally demonstrate trustworthy long-term preservation, rather than relying on a self-assessed certification.
- A repository that already holds CoreTrustSeal certification being asked by a funder, government mandate, or international partner to demonstrate a higher, externally audited tier of assurance, and pursuing ISO 16363 as the next step up rather than switching schemes entirely.
Counter-example
A repository that runs the ISO 16363 metrics as an internal self-review — without an accredited external auditor formally conducting and certifying the audit — is not ISO 16363 certified, even if it can truthfully say it “meets the ISO 16363 criteria” by its own assessment. That distinction is the entire point of the Formal level: certification requires an independent auditor’s attestation, not self-conformance. Similarly, holding CoreTrustSeal or the nestor Seal alone does not constitute ISO 16363 certification — they are separate, lower-rigor tiers of the same overall framework, not lesser versions of the same certificate.
How it relates to CoreTrustSeal and the nestor Seal
These three certifications are not competing standards a repository picks between arbitrarily — they are commonly understood as increasing tiers of the same trust framework, and a repository can hold more than one, or move upward over time. See CASRAI’s CoreTrustSeal certification guide for the Core-level requirements, process, and cost in detail, and the Extended level (nestor Seal) entry for the middle tier. All three ultimately build on the same OAIS Reference Model vocabulary for what “trustworthy” preservation means, and relate to the broader concept of a trusted digital repository.
Also known as
TRAC · ISO 16363:2012 · Trustworthy Repositories Audit & Certification · Formal level certification
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="ISO 16363 (Formal-Level Certification)"
vocab-term-identifier="https://casrai.org/dictionary/term/iso-16363-formal-level-certification" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/iso-16363-formal-level-certification",
"name": "ISO 16363 (Formal-Level Certification)",
"identifier": "https://casrai.org/dictionary/term/iso-16363-formal-level-certification",
"description": "The Formal level of the three-tier trustworthy-repository certification framework: a repository is ISO 16363-certified only when an accredited external auditor (typically PTAB, accredited under ISO 17021/16919) has conducted a full audit against ISO 16363's evidence-based metrics and formally certified the result — distinct from CoreTrustSeal's and the nestor Seal's self-assessment models. Full title: Space data and information transfer systems — Audit and certification of trustworthy digital repositories. Descends from the 2007 TRAC (Trustworthy Repositories Audit & Certification) checklist published by RLG/NARA, formalised by CCSDS as ISO 16363:2012 and subsequently revised.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/data-infrastructure#set",
"url": "https://casrai.org/dictionary/term/iso-16363-formal-level-certification",
"sameAs": [
"TRAC",
"ISO 16363:2012",
"Trustworthy Repositories Audit & Certification",
"Formal level certification"
],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-18T06:30:51",
"inLanguage": "en"
}






