CoreTrustSeal certification is the entry-level, most widely held tier of the three-level
trustworthy-repository trust framework (core, extended, formal) used across the research-data
world. CASRAI’s CoreTrustSeal dictionary term and
the certification section of How to
Choose an Open Data Repository already cover what the seal is and why it matters when
selecting a repository. This guide goes one level deeper for anyone actually weighing whether
to pursue certification for a repository they run: the full list of the 16 requirements
assessed, exactly how the self-assessment-plus-peer-review process runs end to end, what it
costs, real examples of certified institutional repositories, and the practical trade-offs of
pursuing it versus depositing with an already-certified generalist repository instead.
What CoreTrustSeal certifies, briefly
CoreTrustSeal is a community-based, non-profit certification scheme for trustworthy digital
repositories, operated by the CoreTrustSeal Foundation. It sits at the “core” level of the
field’s three-tier trust framework: core (CoreTrustSeal, a peer-reviewed self-assessment)
sits below extended level (the German nestor Seal / DIN 31644, a plausibility-checked
self-assessment against 34 criteria — see CASRAI’s Extended level
certification term) and formal level (ISO 16363, a full external audit). CoreTrustSeal
itself traces to a 2017 merger of the Data Seal of Approval and the ICSU World Data System
certification scheme, and functions today as the field’s de facto entry-level baseline —
recognized by an increasing number of funders and by EU infrastructure programmes including
EOSC and OpenAIRE-Nexus.
The 16 requirements, in full
Applicants are assessed against 16 numbered requirements (R01–R16), organized into three
groups, plus a non-scored background/context statement (R0). This is the full list — CASRAI’s
existing repository-selection guide names the count but not the individual requirements:
Organisational infrastructure (R01–R06)
- R01 — Mission & Scope: the repository has an explicit mission
committing it to providing access to and preserving data within a defined designated
community and subject scope. - R02 — Rights Management: the repository manages legal and contractual
rights appropriately, including the rights it needs to preserve and provide access to
deposited data. - R03 — Continuity of Service: the repository has a plan for organisational
and financial sustainability, and for what happens to holdings if it ceases operating. - R04 — Legal & Ethical Compliance: the repository operates within
relevant legal and ethical norms (data protection, confidentiality, IP, consent). - R05 — Governance & Resources: the repository has adequate governance
and sufficient, appropriately qualified staff and resources for its function. - R06 — Expertise & Guidance: the repository provides guidance and
support to depositors and users on relevant standards and good practice.
Digital object management (R07–R13)
- R07 — Provenance and Authenticity: the repository guarantees the
integrity and authenticity of deposited data, tracking provenance from acquisition or
ingest onward. - R08 — Deposit & Appraisal: the repository applies documented
criteria for accepting or rejecting deposits, and communicates them to depositors. - R09 — Preservation Plan: the repository has an explicit plan covering
what preservation levels it applies to different object types over time. - R10 — Quality Assurance: the repository has documented processes for
ensuring data and metadata quality. - R11 — Workflows: repository workflows for ingest, management, and
access are documented and functionally sound. - R12 — Discovery and Identification: deposited objects are described
with adequate metadata and assigned persistent identifiers to support discovery and citation. - R13 — Reuse: the repository enables reuse over time by documenting
context, format, and any licence/access conditions attached to the data.
Technology (R14–R16)
- R14 — Storage & Integrity: the repository has documented processes
for storage and for verifying the integrity of stored data and metadata over time (this is
the requirement most directly satisfied by routine checksum/fixity verification — see
CASRAI’s Checksum
Verification and Fixity Checking guide for the practical mechanics). - R15 — Technical Infrastructure: the repository’s technical
infrastructure (hardware, software, network) is adequate, documented, and appropriately
maintained. - R16 — Security: the repository’s technical infrastructure provides for
the security of the facility and the data it holds, including disaster recovery.
All 16 are mandatory, equally weighted, standalone items — there is no partial credit or
weighted average across requirements. CoreTrustSeal revises the Requirements document
periodically (a 2023–2025 version and a 2026–2028 version have both been published); exact
requirement wording can shift slightly between versions, so an applicant should always work
from the current Requirements and Extended Guidance documents published on
coretrustseal.org rather than a summary such as this one.
The certification process, end to end
Based on CoreTrustSeal’s own published FAQ, the process runs roughly as follows:
- Registration and self-assessment: an applicant repository registers and
has up to three months to submit its initial self-assessment — documented evidence against
each of the 16 requirements. - Peer review: two reviewers, drawn from staff at other certified
repositories, independently review the submission, typically within a two-month window. - Board assessment: the CoreTrustSeal Board considers the reviewers’
findings and returns feedback, typically within about two weeks. - Revision cycles: applicants can submit up to five revised versions of
their self-assessment in response to reviewer/Board feedback, each re-reviewed within about
two months. - Decision: on approval, the Board issues a final certification decision,
typically within a month of the successful review.
The whole cycle — from initial submission to a final Board decision, approval or
declination — is capped at a maximum of two years from the submission date.
Cost
CoreTrustSeal charges an administrative fee, set at €3,000 as of a February 2024 fee
change. Discounts are available: umbrella organisations certifying ten or more repositories
together can receive a 25% bulk discount, and institutions that provide a minimum of six
peer reviews during their certification period can receive a 33% reviewer discount. Fee
waivers are available at the Board’s discretion for repositories based in low- and
middle-income countries. Fees are subject to change — confirm the current figure directly on
coretrustseal.org before budgeting for an application.
Renewal
Certification runs on a three-year term. CoreTrustSeal sends renewal reminders six months
before expiry, and a certification remains listed for up to six months after expiry — giving
a repository roughly a year in total to complete recertification without a certification gap.
The renewal self-assessment is reviewed in essentially the same way as an initial application,
but typically over three review rounds rather than five, since the repository already has an
established baseline.
Repositories actually certified
Beyond the community-wide repositories already named on CASRAI’s CoreTrustSeal dictionary
term (DANS and 4TU.ResearchData), a range of institutional and disciplinary repositories hold
current CoreTrustSeal certification, illustrating that this is not only a national-archive-scale
undertaking:
- ICPSR (Inter-university Consortium for Political and Social Research,
University of Michigan) — a long-standing core-certified social science data archive, with
periodic recertification. - Apollo, the University of Cambridge’s institutional research repository —
certified in 2023, an example of a university-level (not national-archive-level) repository
achieving certification. - Edinburgh DataShare, the University of Edinburgh’s research data
repository. - TU Wien Research Data Repository — the first Austrian institutional
research data repository to be certified. - Merritt (California Digital Library) and Dryad‘s
underlying technical platform — both certified, illustrating certification at the
shared-infrastructure/generalist-repository level.
CoreTrustSeal maintains the authoritative, current list of certified repositories at its
own certificate database (amt.coretrustseal.org/certificates) — check there directly rather
than relying on any secondary list, including this one, since certifications lapse and renew
on a rolling three-year cycle.
Why this matters for research administrators specifically
Certification status increasingly shows up as a real, checkable condition rather than a
soft preference:
- EU infrastructure programmes — the European Open Science Cloud (EOSC) and
OpenAIRE-Nexus — require or strongly prefer deposit into a CoreTrustSeal-certified (or
equivalent) repository. - An increasing number of individual funders reference certified-repository status,
directly or via FAIR-repository guidance, when assessing a grantee’s proposed data
management plan or evaluating repository choice — see CASRAI’s DMP review criteria guide for
how repository trustworthiness fits into that broader review lens. - For an institution weighing whether to build and run its own repository versus pointing
researchers at an existing certified one (a domain repository, Zenodo, Dryad, or a
certified generalist platform), certification status is a legitimate, verifiable due-diligence
check either way — see CASRAI’s repository-selection guide for the
fuller decision framework.
Should your institution pursue certification?
Certification is a real undertaking, not a checkbox. Before starting the process, it is
worth weighing:
- Resourcing: compiling evidence against all 16 requirements, in practice,
touches governance documentation, legal/rights agreements, technical infrastructure
documentation, and preservation/quality-assurance policy — work that usually spans more than
one institutional unit (research office, IT, library/archives, legal). Budget staff time
across the up-to-two-year process, not just the €3,000 fee. - Whether self-hosting is the right call at all: if the institution’s
researchers can reasonably deposit with an existing certified disciplinary or generalist
repository, pursuing certification for a smaller institutional repository may not be the best
use of resources — the trust benefit already exists via the external repository’s own
certification. Certification is most clearly worth pursuing for a repository an institution is
committed to operating long-term as core infrastructure. - Peer-review reciprocity: the process runs on community peer review —
institutions considering certification should expect to also contribute reviewer time to
other applicants (and can offset part of the fee by doing so). - Sequencing with related work: much of the evidence a self-assessment
needs — fixity/checksum verification practice, a documented preservation plan, persistent
identifier assignment, metadata quality — overlaps with good repository operations generally.
Institutions already doing this work well are typically closer to certification-ready than
the requirement count alone suggests.
Frequently asked questions
Is CoreTrustSeal certification mandatory for a research data repository?
No single global mandate applies universally, but it is increasingly a named or implied
expectation in specific contexts — most concretely for repositories used within EOSC or
OpenAIRE-Nexus, and as a factor some funders weigh when assessing a data management plan’s
proposed repository. Whether it is effectively required depends on the specific funder,
programme, and repository — check the applicable funder’s own data policy directly.
How is CoreTrustSeal different from FAIR data certification?
They assess different things. FAIR (Findable, Accessible, Interoperable, Reusable)
describes properties of data and metadata themselves — see CASRAI’s FAIR data checklist
guide. CoreTrustSeal assesses the repository as an organisation and system — its governance,
processes, and infrastructure. A repository can host FAIR data without itself being
CoreTrustSeal-certified, and certification does not by itself guarantee every dataset it
holds is FAIR; the two are complementary, not substitutes.
What happens if a repository fails to complete certification?
An application can be declined by the Board if requirements are not adequately
demonstrated even after the permitted revision cycles. A declined or withdrawn applicant is
not barred from reapplying later once gaps are addressed; CoreTrustSeal does not publish a
“failed” list, and a repository not shown in the certified-repositories database simply is
not (or is no longer) certified.
Does CoreTrustSeal certification expire?
Yes — certification runs for three years, with a renewal window that begins six months
before expiry and a roughly one-year total grace period to complete recertification before a
listing lapses.
Related CASRAI resources
- CoreTrustSeal (dictionary term) — the
operational definition, named examples, and counter-examples. - Extended
level certification (trustworthy repository) — the nestor Seal / DIN 31644 tier above
CoreTrustSeal. - Trusted digital repository.
- How to Choose an Open Data
Repository — where certification fits into the broader repository-selection decision. - Checksum
Verification and Fixity Checking — the practical mechanics behind R14. - DMP Review Criteria Used by
Funding Agencies — how repository trustworthiness factors into funder review.







