CoreTrustSeal Trustworthy Digital Repositories Requirements 2026-2028 Extended Guidance
Abstract
The CoreTrustSeal Requirements describe the characteristics required to be a trustworthy repository for digital data and metadata. Each Requirement is accompanied by Guidance text describing the response statements and evidence that applicants must provide to enable an objective review. Applicants must respond to all of the Requirements. In addition to the full CoreTrustSeal Requirements text, which remains stable for the period 2026-2028, this document provides the Extended Guidance for CoreTrustSeal reviewers and applicants. Extended Guidance text is presented within a border and in blue within the document. This text may be updated during the 2026-2028 period.
Full text
CoreTrustSeal Trustworthy Digital Repositories Requirements 2026-2028 Extended Guidance V01.00
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 Table of Contents Introduction 3 CoreTrustSeal Resources 4 Background & General Guidance 5 Compliance Levels 5 Supporting Evidence Links and Missing Information/Evidence 5 Internal Information, Sensitive Information & Confidentiality 6 Use of English, and non-English Language Documentation 6 Certification Validity & Renewal 7 Application structure and length 7 Requirements 8 R0. Background Information & Context 8 Organisational Infrastructure 14 Mission & Scope (R01) 14 Rights Management (R02) 14 Continuity of Service (R03) 16 Legal & Ethical (R04) 17 Governance & Resources (R05) 18 Expertise & Guidance (R06) 19 Digital Object Management 21 Provenance and authenticity (R07) 21 Deposit, Appraisal & Accessibility (R08) 22 Preservation plan (R09) 23 Quality Assurance (R10) 24 Workflows (R11) 25 Discovery and Identification (R12) 26 Reuse (R13) 27 Information Technology & Security 29 Storage & Integrity (R14) 29 Technical Infrastructure (R15) 30 Security (R16) 31 Applicant Feedback 32 Page 2 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 Introduction The CoreTrustSeal Standards and Certification Board1, drawn from the CoreTrustSeal Community of Reviewers2 manages the periodic revision of the CoreTrustSeal Trustworthy Repository Requirements, the peer review process and the final approval of certifications. It also seeks to contribute to and align with other organisations, standards and practices across the data management lifecycle. An applicant for CoreTrustSeal must offer a long term preservation service. Some parts of the collection may have lower levels of care but this must be made clear in the text. Once assigned each reviewer will briefly check: ● The definition of the designated community to see whether it is clear enough. ● The preservation plan to ensure that active preservation is in place. ● The ingest & appraisal to confirm that digital objects receive active preservation. ● The reuse to confirm that the outcomes of curation are aligned with the needs of the designated community. If it is not clear that the applicant offers active preservation, or it is not clear what other levels of curation are offered, or it is not clear that the designated community as defined is well served by the information in Reuse, then the applicant is either not in scope, or has provided insufficient information for a review to take place. The FAQ “Who can apply to CoreTrustSeal” presented on the website offers more detail on which applicants are considered in scope3. In this case the review will be returned to the applicant with comments on the relevant items for revision. These changes may imply other changes to the application at the applicants’ discretion. Applications under review are confidential to CoreTrustSeal reviewers and the Board, but successful applications are made publicly available. Applicants should therefore keep all of these audiences in mind. Successful applicants can put staff members forward to become members of the community of reviewers. Members of this peer-review pool are eligible for Board membership. In addition to the full CoreTrustSeal Requirements text, which remains stable for the period 2026-2028, this document provides the Extended Guidance for CoreTrustSeal reviewers and applicants. Extended Guidance text is presented within a border and in blue. This text may be updated during the 2026-2028 period. 3 https://www.coretrustseal.org/why-certification/frequently-asked-questions/ 2 https://www.coretrustseal.org/about/assembly-of-reviewers 1 https://www.coretrustseal.org/about/standards-and-certification-board/ Page 3 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 CoreTrustSeal Resources https://www.coretrustseal.org/apply/ https://www.coretrustseal.org/why-certification/frequently-asked-questions/ CoreTrustSeal Requirements v01.00 2026-2028 (https://doi.org/10.5281/zenodo.17660462) The full normative CoreTrustSeal Requirements and Guidance. Stable for the period 2026-2028. CoreTrustSeal Extended Guidance v01.00 2026-2028 (https://doi.org/10.5281/zenodo.17659852) The full CoreTrustSeal Requirements text with extended guidance including comments and discussion. May be periodically updated during the period 2026-2028. CoreTrustSeal Glossary v01.00 2023-2025 (https://doi.org/10.5281/zenodo.17660009) Definitions of key terms used in the CoreTrustSeal Requirements. CoreTrustSeal Curation & Preservation Levels v03.00 2024 (https://doi.org/10.5281/zenodo.6908018) The CoreTrustSeal Board-approved position paper describing the degree of care a digital object receives and which actors take responsibility for that care. A number of the concepts and terms used in CoreTrustSeal are informed by the OAIS Reference Model4. Applicants are encouraged to familiarise themselves with this standard. This version of the requirements has been deemed compatible with the version 3 of OAIS. 4Consultative Committee for Space Data Systems (December 2024). Reference Model for an Open Archival Information System (OAIS). Recommended Practice, issue 2, CCSDS 650.0-M-3. NASA. https://ccsds.org/publications/magentabooks/entry/3054/ Page 4 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 Background & General Guidance The CoreTrustSeal Requirements describe the characteristics required to be a trustworthy repository for digital data and metadata. Each Requirement is accompanied by Guidance text describing the response statements and evidence that applicants must provide to enable an objective review. Applicants must respond to all of the Requirements. Compliance Levels The applicant must indicate a compliance level for each of the Requirements: ● In Progress: the repository is in the implementation phase. ● Implemented: the requirement has been fully implemented by the repository. Compliance levels are an indicator of the applicant's self-assessed progress, but reviewers judge compliance against response statements and supporting evidence. A reviewer may reduce a compliance level to ‘in progress’ and provide an explanation to the applicant in feedback. All requirements assessed as ‘in progress' must be supported by a statement from the applicant about the actions and timescales planned to reach ‘implemented’. A reviewer will not increase a self-assessed ‘in progress’ compliance level to ‘implemented’. Certification may be granted if some requirements are ‘in progress’. When CoreTrustSeal is renewed, reviewers will expect to see a move from 'in progress' to 'implemented' or clear explanations as to when this is foreseen or why this is not possible. During a renewal process an applicant may reduce a self-assessed compliance level from ‘implemented’ to ‘in progress’, e.g. if a significant upgrade is in place that has a temporary impact on the service. This level of transparency is highly desirable and, with sufficient explanation, should not be a barrier to renewing certification. There is no formally applied maximum number of ‘in progress’ compliance levels that would stop an application from being successful. This will depend on the individual repository and the timescales and planning information provided for implementation. Reviewers will pay particular attention if a repository approach to continuity of service (R03) or active preservation planning (R09) is ‘in progress’. Supporting Evidence Links and Missing Information/Evidence Response statements provided by applicants must be supported by links to public evidence online. Final versions of successful applications are public documents. This level of transparency is important, as the certification process does not include a site visit by an auditor. Links should be verified immediately before submitting applications. Those reading applications (Reviewers, and eventually the public) should be able to understand the response statements without detailed reading of linked evidence. When longer documents are presented as evidence, or the same evidence is used to support more than one Requirement, the applicant must refer specifically to which sections are relevant and quote/summarise the information in their response. Page 5 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 The CoreTrustSeal certification process depends on applicant responses supported by clear evidence. The quality of public supporting evidence is expected to increase over time. Applications cannot be assessed if information is missing, insufficient, or unclear. Prior knowledge of a repository by the reviewer must not play a role when assessing the applications. The final, public evidence statement must also be clear for peer repositories to understand. A reviewer is not expected to search through the applicant’s website for evidence. Applicants must provide specific references, including quotes/summaries of the cited information. The application will be returned with an explanation if the information provided is insufficient for the reviewer to reach a decision and assign a compliance level. For evidence provided by a party other than the applicant, the relationship with that party should be described, see Cooperation and outsourcing to third parties, partners and host organisations. Internal Information, Sensitive Information & Confidentiality No sensitive information disclosure is required to acquire CoreTrustSeal. If evidence cannot be made public it is possible to share this confidentially during the certification process. CoreTrustSeal certification does not require supporting evidence to be made public that is confidential, commercially sensitive, or poses a security risk. Applicants may have internal business information that contains both sensitive information and relevant evidence for the CoreTrustSeal. Such evidence can be submitted confidentially to the reviewers5 and the documents named and described in the application. Over time, applicants should separate relevant evidence from confidential materials, and assure a public version is made available for the next review. If documentation does not yet exist, is in progress, or is currently for internal use only, then a date of public availability should be stated in the application. Certification may be approved based on these assurances. Applicants are expected to provide the public documentation when they renew their certification. Use of English, and non-English Language Documentation All responses must be in English. If links to non-English evidence are provided, then an English summary must be included in the response statement. This summary can be brief for certain types of documents (e.g. a reference to a list of preferred formats), but should be longer for others (e.g. a Preservation Policy document). Full English translations of linked evidence are not required. 5 Contact the CoreTrustSeal Secretariat via [email protected] Page 6 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 Certification Validity & Renewal CoreTrustSeal certification is valid for three years from the date of certification. An organisation with well-managed business processes and records should be able to reapply with minimal revisions. More significant revisions may be required if: ● The organisation, its data collection, technical infrastructure or Designated Community changes significantly ● The CoreTrustSeal Requirements are updated in ways that impact the applicant The CoreTrustSeal Requirements are subject to review and revision every three years. This does not affect a successful applicant until they seek renewal. Application structure and length It is not possible to cover every possible repository scenario in the Guidance or Extended Guidance and some guidance or questions may not be locally applicable. Applicant responses should refer to the issues raised in the Guidance text and provide responses based on their local context. Final evaluation of a Requirement depends on the completeness and quality of the response. Reviewers are looking for clear, open statements of evidence specific to the applicant. It is understood that the length of response statements will vary, but the overall application should provide a focussed narrative describing the supporting evidence. Applications should not respond to each item of guidance in a question-and-answer format. Applications should include prose responses to each Requirement, incorporating relevant elements of the Guidance and Extended Guidance provided. Reviewers understand that applicants’ organizational structures, missions, size and digital object collections vary widely. Even the Extended Guidance cannot cover every topic and evidence type that could be relevant to the application. Some additional text may be needed to explain the relevance of evidence provided; especially, if not available in English. No minimum or maximum lengths for responses are defined, but even the most complex evidence statements are usually at the lower end of the 500–800 word range. Evidence statements should be supported by public links to the documentation the applicant uses to manage their organization and digital objects. It is this public evidence that offers the most assurance of compliance with the Requirements. The CoreTrustSeal Requirements seek to minimise repetition and overlap, but some applicants may submit the same evidence for more than one requirement. Applicants should not need to repeat long portions of text in different Requirement responses. In cases where evidence is applicable to more than one Requirement, a short summary statement of the relevant information can be provided with a reference to the Requirement that contains further details. Page 7 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 Requirements R0. Background Information & Context This section provides the information necessary for reviewers to fully assess the applicants response statements. It is important to the entire application that the correct options are selected and that sufficiently detailed responses are provided. (1) Re3data Identifier6. Response (2) Repository type. Select a repository type: - Generalist repository - Specialist repository - Specialist repositories are asked to provide their domain(s) and/or discipline(s). Response As stated in the glossary (ref), a specialist repository is a domain or subject-based repository which specializes in a specific (research) field or data type, and supports that defined designated community. A generalist repository does not specialise in a domain, discipline, specific (research) field or data type and supports a defined designated community. (3) Overview. Provide a short overview of key characteristics of the repository, reflecting the repository type selected. This should include information about the scope and size of data collections, data types and formats. Further contextual information may also be added. The overview should include contextual information that is not covered elsewhere in the Requirements. Response (4) Designated Community. A clear definition of the Designated Community demonstrates that the applicant understands the scope, knowledge base, and methodologies—including preferred software/formats—of the group(s) of users at whom the curation and preservation measures are primarily targeted. The definition should be specific so that reviewers can assess whether that community is being served in the responses to other requirements. As stated in the definition (see Glossary), it is possible for a repository to have a Designated Community composed of different ‘sub-communities’; for example, for different collections. If this is the case, the applicant should provide a definition and sufficiently detailed description of each of these sub-communities. It is important to note that the Designated Community may be smaller than the overall group of consumers of the repository data, metadata and services. The digital collections of a natural history museum may be appealing to a wide group 6 https://www.re3data.org/ Page 8 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 of interested users, including the general public. Nevertheless, the museum may define its Designated Community as narrower than this (e.g., biologists and anthropologists researching topics from the field of natural history). A repository must have an understanding of the Designated Community’s composition, skills, knowledge base, and needs, and how these may transform over time. This includes an understanding of typical re-use scenarios and purposes, whether they are as general as “Read online publications on a computer to learn more about the history of X” or as specific as “Run statistical analyses using SPSS”. Throughout the application, evidence should demonstrate an understanding of what the curation and preservation actions (additional context, preferred formats, etc.) will best serve the Designated Community (including respective sub-communities, if applicable). It should also be clear how the applicant monitors and responds to changes in the needs of the Designated Community. A repository with a highly specific, narrow Designated Community might easily state the expected knowledge base (e.g., the degree of understanding of genetics, or the level of expertise in using statistical software). In contrast, a broad Designated Community (i.e. composed of multiple user communities) means that the repository should have a sufficient understanding of all their knowledge bases and offer a wide range of contextual documentation to ensure its data can be understood by everyone within the Designated Community. With regard to defining the Designated Community’s knowledge base, applicants should explicitly state any tacit assumptions, such as (foreign) language skills, ability to access specific Operating Systems or Internet browsers, use certain software, and so on. Response (5) Levels of Curation and Preservation. Select all relevant types from: Z. Level Zero. Content distributed as deposited. Unattended deposit-storage-access. D. Deposit Compliance C. Initial Curation A. Active preservation Response Guidance A repository must demonstrate that it assures long-term accessibility and understandability of data as the needs of the Designated Community change. Applying the appropriate levels of care to digital objects maximises the return on investment in data assets over time. Successful curation and long-term preservation activities depend on a repository having the rights and taking the responsibility to provide an effective organisational infrastructure, digital object Page 9 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 Continuity of Service (R03) R03. The Repository has a plan to ensure ongoing access to and preservation of its data and metadata. Self-Assessed Compliance Level: Response Guidance The repository must have measures in place to address the risks inherent in changing circumstances, including in mission and/or scope. This Requirement covers the stable management of repository services over time (business continuity) and the response when services have problems (disaster recovery). It also includes preparations for handover of digital objects and services to another repository (succession planning). The deposit, storage, preservation, and access services offered by the repository to depositors and users are all in scope. The response statement and evidence should include references to the following items: ● The functions and services offered by the repository to depositors and users. ● The approach to rapid changes of circumstance and long-term planning. ● The options for relocation or transition of the activity to another repository. For example, the case of cessation of funding due to an unexpected withdrawal of funding, or a shift of host institution interests. Such options should also include the levels of service that will be continued at relocation or transition (e.g. data retention only, or including other services). ● The repository approach to managing policies, procedures and other business information over time. Even though succession agreements may be hard to achieve it is important to acknowledge the possibility that a repository will cease to function or exist. Applications can be certified and recertified with compliance level “In Progress: the repository is in the implementation phase”. If there is no formal, written agreement between the repository and a successor then the compliance level cannot be higher than “In Progress: the repository is in the implementation phase”. Such an agreement can be with another repository to take over holdings, but is not limited to this and may also concern a software or services provider. Any technical aspects of business continuity, and disaster and succession planning should be covered in R15 (Technical infrastructure). Repositories must ensure continuity of their collections and assume responsibility in the case of a temporary or permanent break in service. Responses and evidence should demonstrate the level of responsibility taken for digital objects, the level of risk for the repository , and the level of succession planning for the future of the data collection. Page 16 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 Possible evidence for this Requirement could include an exit plan, continuity plan, escrow agreement, or Service Level Agreement with a software or service provider. Relevant information could include whether the applicant is the primary or only custodian, whether the depositor shares some responsibility for the future of the digital objects and any service level guarantees or minimum guaranteed time periods (e.g. for retention or preservation) in place. If sustainability partially depends on a host or parent organisation, or another organisation has guaranteed that it will take over the responsibility in the case of a service discontinuity, this should be clearly indicated. Identifying and entering a formal agreement with a successor organisation that can undertake to deliver the same levels of care and service is acknowledged as a challenge for many repositories. For this reason a continued status of ‘in progress’ may be accepted as sufficient during renewal of certification if clearly explained. Legal & Ethical (R04) R04. The repository ensures to the extent possible that data and metadata are created, curated, preserved, accessed and used in compliance with legal and ethical norms. Self-Assessed Compliance Level: Response Guidance This requirement relates to repository awareness and processes around legal and ethical issues, including privacy and confidentiality, that impact the creation, curation, and use of digital objects. To maintain the trust of those who agree to have their digital objects held by the repository, evidence should demonstrate practices that reflect the legal status and sensitivity of digital objects, including guidance for depositors and users. The response statement and evidence should include references to the following items: ● How the repository identifies and manages relevant legal and ethical standards that impact operations. ● Compliance with specific legal and/or ethical discipline or domain standards. ● Information requested from depositors to confirm that data collection or creation was carried out in accordance with legal and ethical criteria in the relevant geographical location or discipline (e.g. Ethical Review Committee/Institutional Review Board or Data Protection legislation). ● Any data or metadata with disclosure risk e.g. depositor/user information, personal, cultural, or environmental information For applicants that hold data or metadata with disclosure risk include references to the following items: ● Special procedures applied to manage disclosure risk Page 17 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 ● Conditions of distribution, access protection and use ● Processes to review disclosure risk and to take the necessary steps to either anonymize files or to provide access in a secure way ● Staff training in the management of digital objects with disclosure risk. ● Guidance provided on the responsible deposit, download, and use of disclosive or potentially disclosive data and metadata. The management of related rights and compliance checks should be covered under Rights (R02). Measures to protect digital objects should be addressed under Security (R16). All organizations responsible for data have an ethical duty to manage them to the level expected by the Designated Community. In addition to national and international expectations of scientific practice, repositories holding data about individuals, organizations, indigenous peoples or protected areas and species, there are additional legal and ethical expectations. Disclosure of these data could also present a risk of personal harm, a breach of commercial confidentiality, or the release of critical information e.g. the identification of a person who participated in a survey or the location of endangered species or an archaeological site. If there is any risk that identifiable data are deposited the repository must take appropriate measures to ensure they are dealt with in accordance with legal regulations. For applicants that hold data or metadata with a disclosure risk, the target compliance level should be “Implemented: the requirement has been fully implemented by the repository”. Evidence should demonstrate that the applicant understands their legal environment and the relevant ethical practices, and that they have documented procedures in place to ensure conformity. This requirement includes the appropriate handling of data and metadata about the users of repository services. Governance & Resources (R05) R05. The repository has adequate funding and sufficient numbers of staff managed through a clear system of governance to effectively carry out the mission. Self-Assessed Compliance Level: Response Guidance This Requirement reflects a need for transparency of financing, governance, responsibilities, and decision making. Evidence should demonstrate that the repository has a clear system of governance and sufficient human and financial resources to carry out its mission. The response statement and evidence should include references to the following items: ● Up-to-date organizational chart and description outlining the governance structure, key Page 18 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 bodies, and reporting lines; it is important to show the hierarchy, roles, and relationships between management, operational teams, etc. ● Timescales for provision and renewal of funding for operational costs and recruitment; it is understood that permanent, ongoing funding cannot be perfectly quantified or guaranteed. ● Evidence that the repository is, or is hosted by, a recognized institution (supporting long-term stability and sustainability) appropriate to its Designated Community. ● Demonstrate that the repository can meet its obligations, including sufficient funding, staff resources, IT resources, and a budget for external engagement when necessary. The availability of appropriate expertise is covered under Expertise (R06) below. Responses and evidence should demonstrate that the repository can meet its obligations, including sufficient funding, staff resources, IT resources, and a budget for external engagement when necessary. The organization’s governance/management decision-making processes and the entities involved should be clear e.g. through organizational diagrams. Evidence should include how often periodical renewal of funding occurs. It is acknowledged that repositories work under a range of different funding models, and often with limited resources, but demonstrating awareness of these issues is important to trustworthiness. It is acknowledged that past funding is not a guarantee of future funding, but it may be indicative to state the historical timescale of the repository. Other relevant information could include the balance of structural versus project funding, the total number of full time equivalent (FTE) employees, and the proportions of staff employed on a permanent or temporary basis. Expertise & Guidance (R06) R06. The repository adopts mechanisms to secure ongoing expertise, guidance and feedback-either in-house, or external. Self-Assessed Compliance Level: Response Guidance A repository must identify the skills necessary to deliver the services it offers, and source and maintain those skills either as internal resources or through external engagement. An effective repository strives to accommodate evolutions in data types, data volumes, and data rates, as well as to adopt the most effective new technologies in order to remain valuable to its Designated Community. The response statement and evidence should include references to the following items: ● That guidance and expertise reflects the scientific scope of the repository, if relevant. ● The repository aligns internal recruitment and external engagement with the services it Page 19 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 offers. ● The repository ensures that its staff have access to ongoing training and professional development. ● The range and depth of expertise of both the organisation and its staff, including any relevant affiliations (e.g. national or international bodies), is appropriate to the mission. ● In-house advisers, or external advisory committees that include technical, curation, data science, data security, and disciplinary experts. ● How the repository communicates with experts for advice. Responses and evidence should demonstrate that the repository has sufficient internal expertise and is linked to a wide network for advice and guidance. Evidence must account for the repository day-to-day activities and the monitoring of potential new challenges on the horizon (community and technology watch). Page 20 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 Digital Object Management Provenance and authenticity (R07) R07. The repository guarantees the authenticity of the digital objects and provides provenance information. Self-Assessed Compliance Level: Response Guidance The repository should provide evidence to show that it operates a data and metadata management system that maintains provenance information to ensure authenticity from deposit, and through curation and preservation to the point of access. Any intentional changes to data and metadata should be documented, including the rationale and originator of the change. Authenticity covers reliability and provenance, including the relationship between the deposited digital objects and those provided at the point of access. The response statement and evidence should include references to the following items: ● The repository approach to changing and versioning data and metadata. How the approach and records of changes are communicated to data depositors and users. ● The provenance information and audit trails recorded for data and metadata processing and versioning. ● How the repository compares the essential properties of different versions of the same file. ● Identification checks for depositors. Responses and evidence should provide a clear overview of the processes used to ensure data authenticity throughout the entire curation and preservation lifecycle—including the level of manual and automated practice. Audit trails, which are written records of the actions performed on the data, should be described in the evidence provided. An example of an informative statement could be ‘A relational database maintains a timestamped record of metadata changes, including which logged-in account made the change.’ Page 21 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 Deposit, Appraisal & Accessibility (R08) R08. The repository accepts data and metadata based on defined criteria to ensure relevance and accessibility for users. Self-Assessed Compliance Level: Response Guidance The appraisal function during deposit is critical to evaluate whether digital objects meet all criteria for selection and to ensure appropriate management for their preservation. Appraisal ensures that deposited digital objects are relevant and are, or can become, accessible to the Designated Community. Accessible means that users should easily be able to find, retrieve, and use the data and metadata. The response statement and evidence should include references to the following items: ● Any documented deposit process that includes steps to ensure that data and metadata are sufficient for long-term preservation. ● A collection development policy or procedures to guide the selection of digital objects. ● Criteria for prioritisation and any different curation-levels or preservation levels defined during appraisal. ● The approach to digital objects that do not fall within the mission/collection profile. ● Procedures to determine that the metadata required to interpret and use the digital objects are provided. ● Any automated assessment of metadata adherence to relevant schemas. ● The repository approach if metadata provided is insufficient for long-term preservation. ● A list of preferred formats. ● Checks in place to ensure that depositors adhere to the preferred formats. ● The approach towards digital objects that are deposited in non-preferred formats. ● The transfer of custody and responsibility during the handover from the depositor to the repository. This Requirement covers the selection criteria applied at the point of deposit. Data Quality (R11) should be used to address steps taken by the repository during the curation process. Responses and evidence should demonstrate that only data and metadata appropriate to the documented collection development policy or procedures are accepted. Repository staff should have all the necessary information, procedures, and expert knowledge to ensure long-term preservation and use as applicable to the Designated Community. For the collection to remain relevant to and usable by the Designated Community—particularly in light of changes in technology, culture, or legislation (e.g., data Page 22 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 protection or intellectual property rights)—selection criteria may have to be revised ; this may influence reappraisal (see Preservation PlanR09). Preservation plan (R09) R09. The repository assumes responsibility for long-term preservation and manages this function in a planned and documented way. Self-Assessed Compliance Level: Response Guidance The repository, depositors, and Designated Community need to understand the level of responsibility undertaken for the long-term preservation of data and metadata. This exceeds bit level integrity alone and covers plans to respond to potential future changes which may impact the understandability and reusability of data and metadata over time. Procedures must be documented and their completion assured. The response statement and evidence should include references to the following items: ● The documented approach to preservation, including whether this involves format migration, emulation, etc. Ensuring bit level integrity is vital but not sufficient for preservation. ● File formats and metadata schemas for long term preservation. ● How the level of responsibility for the preservation of each item is defined. ● Plans related to future migrations or similar measures to address the threat of obsolescence. ● Actions relevant to preservation specified in documentation, including custody transfer, submission information criteria, and preservation information metadata. ● Measures to ensure these actions are taken. ● Any minimum stated retention and/or preservation periods. ● How often the digital objects are re-appraised and the possible outcomes of reappraisal. ● The repository approach to deleting/removing data and metadata from collection/holdings including the impact on persistent identifiers as well as the availability and curation of tombstone records. The rights of the repository, including the right to preserve, are covered under Rights Management (R02). Bit level integrity is covered under Storage and Integrity (R14). Acceptable file formats at deposit should be covered under Deposit and Appraisal (R08). Measures to ensure that file formats, schemas and content are appropriate to the Designated Community should be covered under Reuse (R13). The term preservation plan refers to having a documented approach for defining and Page 23 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 implementing preservation actions. The Requirements do not define or differentiate between a preservation policy, plan, strategy, or action plan. Responses and evidence should demonstrate clear, managed documentation to ensure: (1) an organized approach to long-term preservation, (2) continued access for data types despite format changes, and (3) there is sufficient documentation to support usability by the Designated Community. The response should address whether the repository has defined preservation levels and, if so, how these are applied. The preservation plan should be managed to ensure that changes to data, metadata, technology and user requirements are handled in a stable and timely manner. If preservation levels differ between classes or collections of items, the differences in preservation approach, and the criteria applied to determine the preservation level should be explained. This may be relevant if, for example, the file size of an object or the sensitivity of the data it contains determines the number of redundant copies made; or, only items deposited in preferred formats are converted to standard preservation formats and will be migrated in the future. Policies and documented procedures for reappraisal should be in place to manage changes to the curation or preservation levels of digital objects, or their deletion or removal from the repository. Applications that do not link to a documented preservation approach can be only at a maximum Compliance Level of ‘In Progress’. There must be a link to a documented plan by the time of renewal. Quality Assurance (R10) R10. The repository addresses technical quality and standards compliance, and ensures that sufficient information is available for end users to make quality-related evaluations. Self-Assessed Compliance Level: Response Guidance Different repositories undertake different levels of curation on data, metadata and documentation depending on the needs and expectations of their depositors and Designated Community. Quality assurance by the repository ensures that digital objects comply with a range of standard criteria including acceptable formats, metadata schema, metadata content and links to other digital objects. This relates to ‘technical quality’ rather than the ‘scientific quality’ of the original digital objects creation or collection prior to deposit, though the repository must ensure there is sufficient information about the digital objects for the Designated Community to assess their fitness for use. Data, or associated metadata, may have quality issues relevant to their research value, but this does not preclude their use if a Page 24 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 user can make a well-informed decision on their suitability through provided documentation. The response statement and evidence should include references to the following items: ● The approach to data and metadata quality taken by the repository including variations for different curation-levels. ● The standards that data, metadata and documentation must comply with to be acceptable for preservation and access. Whether these are general external standards, internally developed standards or specific to a community of practice. ● The quality control checks in place ensure the completeness and understandability of data and metadata. ● The approach to resolving issues e.g. whether the digital objects are returned to the depositor for rectification, fixed by the repository, noted by quality flags, and/or included in the accompanying metadata. ● The approach to managing changes to expected standards (e.g. new or updated data formats of metadata schemas) in response to changes in the technical environment or to changes in the needs of the Designated Community. ● Any links provided to other digital objects’ data and metadata e.g. related digital objects, publications, or the use of controlled vocabularies and ontologies. This Requirement refers to data and metadata quality standards and assurance during curation. Selection criteria are covered during Deposit and Appraisal (R08). Measures to ensure that digital objects remain fit for purpose over time are covered under Preservation Plan (R09). Responses and evidence should demonstrate an understanding of the quality levels that can be reasonably expected from depositors. Evidence should describe how quality will be assured during curation, and the quality expectations of the Designated Community. Both the repository and its depositors are expected to document any areas in which data or metadata quality falls below the expected standard. Quality assessment becomes increasingly relevant when the Designated Community is multidisciplinary, where users may not have the personal experience to make an evaluation of quality from the data alone. Workflows (R11) R11. Digital object management takes place according to defined workflows from deposit to access. Self-Assessed Compliance Level: Response Guidance For Quality Assurance (R10) to be achieved, it is necessary to avoid ad hoc actions and to Page 25 of 32
CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17659852 Evidence should include which security policies are in place to govern the security of all systems, including network security, intrusion checks, physical facility security, and passwords. If the response to Legal and Ethical (R04) includes references to holding sensitive digital objects then the response here should be explicit about the additional measures taken to protect this data and metadata. Applicant Feedback We welcome feedback on the CoreTrustSeal Requirements and the Certification procedure. Response Page 32 of 32