Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

CoreTrustSeal Certification: Requirements, Process, and Whether It’s Worth Pursuing

The full 16 CoreTrustSeal requirements, the self-assessment and peer-review process end to end, real certified-repository examples, and practical guidance for deciding whether your institution should pursue certification.

CoreTrustSeal certification is the entry-level, most widely held tier of the three-level
trustworthy-repository trust framework (core, extended, formal) used across the research-data
world. CASRAI’s CoreTrustSeal dictionary term and
the certification section of How to
Choose an Open Data Repository
already cover what the seal is and why it matters when
selecting a repository. This guide goes one level deeper for anyone actually weighing whether
to pursue certification for a repository they run: the full list of the 16 requirements
assessed, exactly how the self-assessment-plus-peer-review process runs end to end, what it
costs, real examples of certified institutional repositories, and the practical trade-offs of
pursuing it versus depositing with an already-certified generalist repository instead.

What CoreTrustSeal certifies, briefly

CoreTrustSeal is a community-based, non-profit certification scheme for trustworthy digital
repositories, operated by the CoreTrustSeal Foundation. It sits at the “core” level of the
field’s three-tier trust framework: core (CoreTrustSeal, a peer-reviewed self-assessment)
sits below extended level (the German nestor Seal / DIN 31644, a plausibility-checked
self-assessment against 34 criteria — see CASRAI’s Extended level
certification
term) and formal level (ISO 16363, a full external audit). CoreTrustSeal
itself traces to a 2017 merger of the Data Seal of Approval and the ICSU World Data System
certification scheme, and functions today as the field’s de facto entry-level baseline —
recognized by an increasing number of funders and by EU infrastructure programmes including
EOSC and OpenAIRE-Nexus.

The 16 requirements, in full

Applicants are assessed against 16 numbered requirements (R01–R16), organized into three
groups, plus a non-scored background/context statement (R0). This is the full list — CASRAI’s
existing repository-selection guide names the count but not the individual requirements:

Organisational infrastructure (R01–R06)

  • R01 — Mission & Scope: the repository has an explicit mission
    committing it to providing access to and preserving data within a defined designated
    community and subject scope.
  • R02 — Rights Management: the repository manages legal and contractual
    rights appropriately, including the rights it needs to preserve and provide access to
    deposited data.
  • R03 — Continuity of Service: the repository has a plan for organisational
    and financial sustainability, and for what happens to holdings if it ceases operating.
  • R04 — Legal & Ethical Compliance: the repository operates within
    relevant legal and ethical norms (data protection, confidentiality, IP, consent).
  • R05 — Governance & Resources: the repository has adequate governance
    and sufficient, appropriately qualified staff and resources for its function.
  • R06 — Expertise & Guidance: the repository provides guidance and
    support to depositors and users on relevant standards and good practice.

Digital object management (R07–R13)

  • R07 — Provenance and Authenticity: the repository guarantees the
    integrity and authenticity of deposited data, tracking provenance from acquisition or
    ingest onward.
  • R08 — Deposit & Appraisal: the repository applies documented
    criteria for accepting or rejecting deposits, and communicates them to depositors.
  • R09 — Preservation Plan: the repository has an explicit plan covering
    what preservation levels it applies to different object types over time.
  • R10 — Quality Assurance: the repository has documented processes for
    ensuring data and metadata quality.
  • R11 — Workflows: repository workflows for ingest, management, and
    access are documented and functionally sound.
  • R12 — Discovery and Identification: deposited objects are described
    with adequate metadata and assigned persistent identifiers to support discovery and citation.
  • R13 — Reuse: the repository enables reuse over time by documenting
    context, format, and any licence/access conditions attached to the data.

Technology (R14–R16)

  • R14 — Storage & Integrity: the repository has documented processes
    for storage and for verifying the integrity of stored data and metadata over time (this is
    the requirement most directly satisfied by routine checksum/fixity verification — see
    CASRAI’s Checksum
    Verification and Fixity Checking
    guide for the practical mechanics).
  • R15 — Technical Infrastructure: the repository’s technical
    infrastructure (hardware, software, network) is adequate, documented, and appropriately
    maintained.
  • R16 — Security: the repository’s technical infrastructure provides for
    the security of the facility and the data it holds, including disaster recovery.

All 16 are mandatory, equally weighted, standalone items — there is no partial credit or
weighted average across requirements. CoreTrustSeal revises the Requirements document
periodically (a 2023–2025 version and a 2026–2028 version have both been published); exact
requirement wording can shift slightly between versions, so an applicant should always work
from the current Requirements and Extended Guidance documents published on
coretrustseal.org rather than a summary such as this one.

The certification process, end to end

Based on CoreTrustSeal’s own published FAQ, the process runs roughly as follows:

  1. Registration and self-assessment: an applicant repository registers and
    has up to three months to submit its initial self-assessment — documented evidence against
    each of the 16 requirements.
  2. Peer review: two reviewers, drawn from staff at other certified
    repositories, independently review the submission, typically within a two-month window.
  3. Board assessment: the CoreTrustSeal Board considers the reviewers’
    findings and returns feedback, typically within about two weeks.
  4. Revision cycles: applicants can submit up to five revised versions of
    their self-assessment in response to reviewer/Board feedback, each re-reviewed within about
    two months.
  5. Decision: on approval, the Board issues a final certification decision,
    typically within a month of the successful review.

The whole cycle — from initial submission to a final Board decision, approval or
declination — is capped at a maximum of two years from the submission date.

Cost

CoreTrustSeal charges an administrative fee, set at €3,000 as of a February 2024 fee
change. Discounts are available: umbrella organisations certifying ten or more repositories
together can receive a 25% bulk discount, and institutions that provide a minimum of six
peer reviews during their certification period can receive a 33% reviewer discount. Fee
waivers are available at the Board’s discretion for repositories based in low- and
middle-income countries. Fees are subject to change — confirm the current figure directly on
coretrustseal.org before budgeting for an application.

Renewal

Certification runs on a three-year term. CoreTrustSeal sends renewal reminders six months
before expiry, and a certification remains listed for up to six months after expiry — giving
a repository roughly a year in total to complete recertification without a certification gap.
The renewal self-assessment is reviewed in essentially the same way as an initial application,
but typically over three review rounds rather than five, since the repository already has an
established baseline.

Repositories actually certified

Beyond the community-wide repositories already named on CASRAI’s CoreTrustSeal dictionary
term (DANS and 4TU.ResearchData), a range of institutional and disciplinary repositories hold
current CoreTrustSeal certification, illustrating that this is not only a national-archive-scale
undertaking:

  • ICPSR (Inter-university Consortium for Political and Social Research,
    University of Michigan) — a long-standing core-certified social science data archive, with
    periodic recertification.
  • Apollo, the University of Cambridge’s institutional research repository —
    certified in 2023, an example of a university-level (not national-archive-level) repository
    achieving certification.
  • Edinburgh DataShare, the University of Edinburgh’s research data
    repository.
  • TU Wien Research Data Repository — the first Austrian institutional
    research data repository to be certified.
  • Merritt (California Digital Library) and Dryad‘s
    underlying technical platform — both certified, illustrating certification at the
    shared-infrastructure/generalist-repository level.

CoreTrustSeal maintains the authoritative, current list of certified repositories at its
own certificate database (amt.coretrustseal.org/certificates) — check there directly rather
than relying on any secondary list, including this one, since certifications lapse and renew
on a rolling three-year cycle.

Why this matters for research administrators specifically

Certification status increasingly shows up as a real, checkable condition rather than a
soft preference:

  • EU infrastructure programmes — the European Open Science Cloud (EOSC) and
    OpenAIRE-Nexus — require or strongly prefer deposit into a CoreTrustSeal-certified (or
    equivalent) repository.
  • An increasing number of individual funders reference certified-repository status,
    directly or via FAIR-repository guidance, when assessing a grantee’s proposed data
    management plan or evaluating repository choice — see CASRAI’s DMP review criteria guide for
    how repository trustworthiness fits into that broader review lens.
  • For an institution weighing whether to build and run its own repository versus pointing
    researchers at an existing certified one (a domain repository, Zenodo, Dryad, or a
    certified generalist platform), certification status is a legitimate, verifiable due-diligence
    check either way — see CASRAI’s repository-selection guide for the
    fuller decision framework.

Should your institution pursue certification?

Certification is a real undertaking, not a checkbox. Before starting the process, it is
worth weighing:

  • Resourcing: compiling evidence against all 16 requirements, in practice,
    touches governance documentation, legal/rights agreements, technical infrastructure
    documentation, and preservation/quality-assurance policy — work that usually spans more than
    one institutional unit (research office, IT, library/archives, legal). Budget staff time
    across the up-to-two-year process, not just the €3,000 fee.
  • Whether self-hosting is the right call at all: if the institution’s
    researchers can reasonably deposit with an existing certified disciplinary or generalist
    repository, pursuing certification for a smaller institutional repository may not be the best
    use of resources — the trust benefit already exists via the external repository’s own
    certification. Certification is most clearly worth pursuing for a repository an institution is
    committed to operating long-term as core infrastructure.
  • Peer-review reciprocity: the process runs on community peer review —
    institutions considering certification should expect to also contribute reviewer time to
    other applicants (and can offset part of the fee by doing so).
  • Sequencing with related work: much of the evidence a self-assessment
    needs — fixity/checksum verification practice, a documented preservation plan, persistent
    identifier assignment, metadata quality — overlaps with good repository operations generally.
    Institutions already doing this work well are typically closer to certification-ready than
    the requirement count alone suggests.

Frequently asked questions

Is CoreTrustSeal certification mandatory for a research data repository?

No single global mandate applies universally, but it is increasingly a named or implied
expectation in specific contexts — most concretely for repositories used within EOSC or
OpenAIRE-Nexus, and as a factor some funders weigh when assessing a data management plan’s
proposed repository. Whether it is effectively required depends on the specific funder,
programme, and repository — check the applicable funder’s own data policy directly.

How is CoreTrustSeal different from FAIR data certification?

They assess different things. FAIR (Findable, Accessible, Interoperable, Reusable)
describes properties of data and metadata themselves — see CASRAI’s FAIR data checklist
guide. CoreTrustSeal assesses the repository as an organisation and system — its governance,
processes, and infrastructure. A repository can host FAIR data without itself being
CoreTrustSeal-certified, and certification does not by itself guarantee every dataset it
holds is FAIR; the two are complementary, not substitutes.

What happens if a repository fails to complete certification?

An application can be declined by the Board if requirements are not adequately
demonstrated even after the permitted revision cycles. A declined or withdrawn applicant is
not barred from reapplying later once gaps are addressed; CoreTrustSeal does not publish a
“failed” list, and a repository not shown in the certified-repositories database simply is
not (or is no longer) certified.

Does CoreTrustSeal certification expire?

Yes — certification runs for three years, with a renewal window that begins six months
before expiry and a roughly one-year total grace period to complete recertification before a
listing lapses.

Related CASRAI resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →