scieee AI-readable full text Open interactive document viewer

CoreTrustSeal Requirements 2026-2028

CoreTrustSeal Standards and Certification Board

Abstract

The CoreTrustSeal Requirements describe the characteristics required to be a trustworthy repository for digital data and metadata. Each Requirement is accompanied by Guidance text describing the response statements and evidence that applicants must provide to enable an objective review. Applicants must respond to all of the Requirements. More information for applicants and reviewers can be found in the CoreTrustSeal extended guidance (see related work).

Full text

CoreTrustSeal Trustworthy Digital Repositories Requirements 2026-2028 V01.00 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 Table of Contents Introduction 3 CoreTrustSeal Resources 4 Background & General Guidance 5 Compliance Levels 5 Supporting Evidence Links and Missing Information/Evidence 5 Internal Information, Sensitive Information & Confidentiality 5 Use of English, and non-English Language Documentation 6 Certification Validity & Renewal 6 Application structure and length 6 Requirements 7 Background Information & Context (R.0) 7 Organisational Infrastructure 12 Mission & Scope (R01) 12 Rights Management (R02) 12 Continuity of Service (R03) 13 Legal & Ethical (R04) 14 Governance & Resources (R05) 15 Expertise & Guidance (R06) 16 Digital Object Management 17 Provenance and authenticity (R07) 17 Deposit, Appraisal & Accessibility (R08) 17 Preservation plan (R09) 18 Quality Assurance (R10) 19 Workflows (R11) 20 Discovery and Identification (R12) 21 Reuse (R13) 21 Information Technology & Security 23 Storage & Integrity (R14) 23 Technical Infrastructure (R15) 23 Security (R16) 24 Applicant Feedback 25 Page 2 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 Introduction The CoreTrustSeal Standards and Certification Board1, drawn from the CoreTrustSeal Community of Reviewers2 manages the periodic revision of the CoreTrustSeal Trustworthy Repository Requirements, the peer review process and the final approval of certifications. It also seeks to contribute to and align with other organisations, standards and practices across the data management lifecycle. An applicant for CoreTrustSeal must offer a long term preservation service. Some parts of the collection may have lower levels of care but this must be made clear in the text. Once assigned each reviewer will briefly check: ● The definition of the designated community to see whether it is clear enough. ● The preservation plan to ensure that active preservation is in place. ● The ingest & appraisal to confirm that digital objects receive active preservation. ● The reuse to confirm that the outcomes of curation are aligned with the needs of the designated community. If it is not clear that the applicant offers active preservation, or it is not clear what other levels of curation are offered, or it is not clear that the designated community as defined is well served by the information in Reuse, then the applicant is either not in scope, or has provided insufficient information for a review to take place. The FAQ “Who can apply to CoreTrustSeal” presented on the website offers more detail on which applicants are considered in scope3. In this case the review will be returned to the applicant with comments on the relevant items for revision. These changes may imply other changes to the application at the applicants’ discretion. Applications under review are confidential to CoreTrustSeal reviewers and the Board, but successful applications are made publicly available. Applicants should therefore keep all of these audiences in mind. Successful applicants can put staff members forward to become members of the community of reviewers. Members of this peer-review pool are eligible for Board membership. 3 https://www.coretrustseal.org/why-certification/frequently-asked-questions/ 2 https://www.coretrustseal.org/about/assembly-of-reviewers 1 https://www.coretrustseal.org/about/standards-and-certification-board/ Page 3 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 CoreTrustSeal Resources https://www.coretrustseal.org/apply/ https://www.coretrustseal.org/why-certification/frequently-asked-questions/ CoreTrustSeal Requirements v01.00 2026-2028 (https://doi.org/10.5281/zenodo.17660462) The full normative CoreTrustSeal Requirements and Guidance. Stable for the period 2026-2028. CoreTrustSeal Extended Guidance v01.00 2026-2028 (https://doi.org/10.5281/zenodo.17659852) The full CoreTrustSeal Requirements text with extended guidance including comments and discussion. May be periodically updated during the period 2026-2028. CoreTrustSeal Glossary v01.00 2023-2025 (https://doi.org/10.5281/zenodo.17660009) Definitions of key terms used in the CoreTrustSeal Requirements. CoreTrustSeal Curation & Preservation Levels v03.00 2024 (https://doi.org/10.5281/zenodo.6908018) The CoreTrustSeal Board-approved position paper describes the degree of care a digital object receives and which actors take responsibility for that care. Page 4 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 Background & General Guidance The CoreTrustSeal Requirements describe the characteristics required to be a trustworthy repository for digital data and metadata. Each Requirement is accompanied by Guidance text describing the response statements and evidence that applicants must provide to enable an objective review. Applicants must respond to all of the Requirements. Compliance Levels The applicant must indicate a compliance level for each of the Requirements: ● In Progress: the repository is in the implementation phase. ● Implemented: the requirement has been fully implemented by the repository. ● Compliance levels are an indicator of the applicant's self-assessed progress, but reviewers judge compliance against response statements and supporting evidence. A reviewer may reduce a compliance level to ‘in progress’ and provide an explanation to the applicant in feedback. All requirements assessed as ‘in progress' must be supported by a statement from the applicant about the actions and timescales planned to reach ‘implemented’. A reviewer will not increase a self-assessed ‘in progress’ compliance level to ‘implemented’. Certification may be granted if some requirements are ‘in progress’. When CoreTrustSeal is renewed, reviewers will expect to see a move from 'in progress' to 'implemented' or clear explanations as to when this is foreseen or why this is not possible. Supporting Evidence Links and Missing Information/Evidence Response statements provided by applicants must be supported by links to public evidence online. Final versions of successful applications are public documents. This level of transparency is important, as the certification process does not include a site visit by an auditor. Links should be verified immediately before submitting applications. Those reading applications (Reviewers, and eventually the public) should be able to understand the response statements without detailed reading of linked evidence. When longer documents are presented as evidence, or the same evidence is used to support more than one Requirement, the applicant must refer specifically to which sections are relevant and quote/summarise the information in their response. Internal Information, Sensitive Information & Confidentiality No sensitive information disclosure is required to acquire CoreTrustSeal. If evidence cannot be made public it is possible to share this confidentially during the certification process. CoreTrustSeal certification does not require supporting evidence to be made public that is confidential, commercially sensitive, or poses a security risk. Applicants may have internal business information that contains both sensitive information and relevant evidence for the Page 5 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 CoreTrustSeal. Such evidence can be submitted confidentially to the reviewers4 and the documents named and described in the application. Over time, applicants should separate relevant evidence from confidential materials, and assure a public version is made available for the next review. If documentation does not yet exist, is in progress, or is currently for internal use only, then a date of public availability should be stated in the application. Certification may be approved based on these assurances. Applicants are expected to provide the public documentation when they renew their certification. Use of English, and non-English Language Documentation All responses must be in English. If links to non-English evidence are provided, then an English summary must be included in the response statement. This summary can be brief for certain types of documents (e.g. a reference to a list of preferred formats), but should be longer for others (e.g. a Preservation Policy document). Full English translations of linked evidence are not required. Certification Validity & Renewal CoreTrustSeal certification is valid for three years from the date of certification. An organisation with well-managed business processes and records should be able to reapply with minimal revisions. More significant revisions may be required if: ● The organisation, its data collection, technical infrastructure or Designated Community changes significantly ● The CoreTrustSeal Requirements are updated in ways that impact the applicant The CoreTrustSeal Requirements are subject to review and revision every three years. This does not affect a successful applicant until they seek renewal. Application structure and length It is not possible to cover every possible repository scenario in the Guidance or Extended Guidance and some guidance or questions may not be locally applicable. Applicant responses should refer to the issues raised in the Guidance text and provide responses based on their local context. Final evaluation of a Requirement depends on the completeness and quality of the response. Reviewers are looking for clear, open statements of evidence specific to the applicant. It is understood that the length of response statements will vary, but the overall application should provide a focussed narrative describing the supporting evidence. 4 Contact the CoreTrustSeal Secretariat via [email protected] Page 6 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 Requirements Background Information & Context (R.0) This section provides the information necessary for reviewers to fully assess the applicants response statements. It is important to the entire application that the correct options are selected and that sufficiently detailed responses are provided. (1) Re3data Identifier5. Response (2) Repository type. Select a repository type: - Generalist repository - Specialist repository - Specialist repositories are asked to provide their domain(s) and/or discipline(s). Response (3) Overview. Provide a short overview of key characteristics of the repository, reflecting the repository type selected. This should include information about the scope and size of data collections, data types and formats. Further contextual information may also be added. Response (4) Designated Community. A clear definition of the Designated Community demonstrates that the applicant understands the scope, knowledge base, and methodologies—including preferred software/formats—of the group(s) of users at whom the curation and preservation measures are primarily targeted. The definition should be specific so that reviewers can assess whether that community is being served in the responses to other requirements. Response (5) Levels of Curation and Preservation. Select all relevant types from: Z. Level Zero. Content distributed as deposited. Unattended deposit-storage-access. D. Deposit Compliance C. Initial Curation A. Active preservation Response 5 https://www.re3data.org/ Page 7 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 Guidance A repository must demonstrate that it assures long-term accessibility and understandability of data as the needs of the Designated Community change. Applying the appropriate levels of care to digital objects maximises the return on investment in data assets over time. Successful curation and long-term preservation activities depend on a repository having the rights and taking the responsibility to provide an effective organisational infrastructure, digital object management and technical/security environment If curation can be understood as the actions that deliver an immediate benefit to digital objects, then preservation includes these, and other steps to ensure data and metadata remain accessible, usable and understandable into the future. Preservation takes account of ongoing changes to the landscape, e.g. the knowledge base of the user community, the surrounding technical context, and the ethical and legal environment. Long-term does not have to mean ‘forever’. Objects may be reappraised over time and their level of curation or preservation may change. Long-term preservation means that organizational measures, infrastructure, and policies are in place to actively preserve digital assets for as long as necessary. Minimum periods of retention are important and should be clear, but these do not equate to active preservation. Z. Level Zero. Content distributed as deposited. Unattended deposit-storage-access. Data content and supporting metadata are stored for a given time period, or indefinitely. This may include multiple copies and monitoring of bitstreams for integrity. Data content and supporting metadata are distributed to users exactly as they are provided by depositors. Beyond these measures, there are no checks of deposit compliance, no initial curation or active long-term preservation. D. Deposit Compliance Data content and supporting metadata deposited are checked for compliance with defined criteria, e.g. data formats, metadata elements, and compliance with legal and ethical norms. Digital objects that do not meet these criteria may be rejected, or moved forwards to initial curation if provided by the repository. C. Initial Curation The digital objects are curated by the repository to meet defined criteria, which may exceed those defined for Deposit Compliance. This initial curation for access and use may include, e.g., the correction or enhancement of metadata and/or data content, or the creation of dissemination formats. A. Active preservation In addition to D and/or C above the repository takes long-term responsibility for ensuring that the data and metadata can be understood and rendered as required by the designated community for reuse. The preservation actions can be aimed at logical-technical, semantic, or quality aspects of the (meta)data, for example, in response to the threat of technological Page 8 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 obsolescence, to accommodate changing needs of the Designated Community, or in response to other considerations such as security or legal concerns. Logical-technical measures include updating hardand software environments, archival and dissemination formats of digital objects, and metadata. Semantic measures include updating the content of metadata elements and other semantic artefacts such as controlled vocabularies and ontologies if necessary. It may include responsibility for editing the structure and content of deposited data. It is recognised that a repository may offer different levels of curation to different digital objects. It is important that this is clear to depositors, users, and to CoreTrustSeal Reviewers. The levels may be cumulative as they progress from Deposit Compliance (D), through Initial Curation (C), to Active Preservation (A). A repository may offer different levels of curation and preservation for different digital objects depending on the type of data and curation and preservation terms agreed with the depositor. For each level selected add some concise information on how the respective levels are reached e.g. automatic checks of metadata, intellectual checks and editing of documentation, file format identification, transformation to preservation file formats, etc. To qualify for the CoreTrustSeal a repository must deliver Active Preservation to at least some of their holdings. Common approaches to active preservation can include transformations to new data formats and metadata schemas, and updates to (meta)data content so that digital objects remain understandable and technically usable by the community. When a repository performs care at more than one level, further information should be added on the proportion of the data in the collection handled according to the respective levels. In this case, applicants should take care that responses to the Requirements state any relevant differences in workflows or employed measures for each selected curation level of curation and preservation. The designated community’s needs and preferences must be considered when determining the curation and preservation actions to be applied. This depends on monitoring the knowledge base and technology needs of the community, and an understanding of wider technical risks as well as technical, ethical, legal and other developments that may impact how digital objects can be used. For digital objects with specialist characteristics and users (e.g. disciplinary) the active preservation of (meta)data can be more challenging and require additional expertise. A more generalist approach may not preserve those characteristics or meet those specialist needs. All levels of curation and preservation assume (1) initial deposits are retained unchanged and that edits are only made on copies of those originals, (2) metadata that enables the Designated Community to understand and use the data independently (i.e., without having to consult the original creator) is present at deposit or added by the repository, and (3) ongoing measures for active preservation are in place for the greater part of the collection(s). Annotations/edits must fall within the terms of the license agreed with the data depositor and be Page 9 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 Expertise & Guidance (R06) R06. The repository adopts mechanisms to secure ongoing expertise, guidance and feedback-either in-house, or external. Self-Assessed Compliance Level: Response Guidance A repository must identify the skills necessary to deliver the services it offers, and source and maintain those skills either as internal resources or through external engagement. An effective repository strives to accommodate evolutions in data types, data volumes, and data rates, as well as to adopt the most effective new technologies in order to remain valuable to its Designated Community. The response statement and evidence should include references to the following items: ● That guidance and expertise reflects the scientific scope of the repository, if relevant. ● The repository aligns internal recruitment and external engagement with the services it offers. ● The repository ensures that its staff have access to ongoing training and professional development. ● The range and depth of expertise of both the organisation and its staff, including any relevant affiliations (e.g. national or international bodies), is appropriate to the mission. ● In-house advisers, or external advisory committees that include technical, curation, data science, data security, and disciplinary experts. ● How the repository communicates with experts for advice. Page 16 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 Digital Object Management Provenance and authenticity (R07) R07. The repository guarantees the authenticity of the digital objects and provides provenance information. Self-Assessed Compliance Level: Response Guidance The repository should provide evidence to show that it operates a data and metadata management system that maintains provenance information to ensure authenticity from deposit, and through curation and preservation to the point of access. Any intentional changes to data and metadata should be documented, including the rationale and originator of the change. Authenticity covers reliability and provenance, including the relationship between the deposited digital objects and those provided at the point of access. The response statement and evidence should include references to the following items: ● The repository approach to changing and versioning data and metadata. How the approach and records of changes are communicated to data depositors and users. ● The provenance information and audit trails recorded for data and metadata processing and versioning. ● How the repository compares the essential properties of different versions of the same file. ● Identification checks for depositors. Deposit, Appraisal & Accessibility (R08) R08. The repository accepts data and metadata based on defined criteria to ensure relevance and accessibility for users. Self-Assessed Compliance Level: Response Guidance The appraisal function during deposit is critical to evaluate whether digital objects meet all criteria for selection and to ensure appropriate management for their preservation. Appraisal ensures that deposited digital objects are relevant and are, or can become, accessible to the Designated Community. Accessible means that users should easily be able to find, retrieve, and use the data and metadata. The response statement and evidence should include references to the following items: Page 17 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 ● Any documented deposit process that includes steps to ensure that data and metadata are sufficient for long-term preservation. ● A collection development policy or procedures to guide the selection of digital objects. ● Criteria for prioritisation and any different curation-levels or preservation levels defined during appraisal. ● The approach to digital objects that do not fall within the mission/collection profile. ● Procedures to determine that the metadata required to interpret and use the digital objects are provided. ● Any automated assessment of metadata adherence to relevant schemas. ● The repository approach if metadata provided is insufficient for long-term preservation. ● A list of preferred formats. ● Checks in place to ensure that depositors adhere to the preferred formats. ● The approach towards digital objects that are deposited in non-preferred formats. ● The transfer of custody and responsibility during the handover from the depositor to the repository. This Requirement covers the selection criteria applied at the point of deposit. Data Quality (R11) should be used to address steps taken by the repository during the curation process. Preservation plan (R09) R09. The repository assumes responsibility for long-term preservation and manages this function in a planned and documented way. Self-Assessed Compliance Level: Response Guidance The repository, depositors, and Designated Community need to understand the level of responsibility undertaken for the long-term preservation of data and metadata. This exceeds bit level integrity alone and covers plans to respond to potential future changes which may impact the understandability and reusability of data and metadata over time. Procedures must be documented and their completion assured. The response statement and evidence should include references to the following items: ● The documented approach to preservation, including whether this involves format migration, emulation, etc. Ensuring bit level integrity is vital but not sufficient for preservation. ● File formats and metadata schemas for long term preservation. ● How the level of responsibility for the preservation of each item is defined. ● Plans related to future migrations or similar measures to address the threat of obsolescence. ● Actions relevant to preservation specified in documentation, including custody transfer, submission information criteria, and preservation information metadata. Page 18 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 ● Measures to ensure these actions are taken. ● Any minimum stated retention and/or preservation periods. ● How often the digital objects are re-appraised and the possible outcomes of reappraisal. ● The repository approach to deleting/removing data and metadata from collection/holdings including the impact on persistent identifiers as well as the availability and curation of tombstone records. The rights of the repository, including the right to preserve, are covered under Rights Management (R02). Bit level integrity is covered under Storage and Integrity (R14). Acceptable file formats at deposit should be covered under Deposit and Appraisal (R08). Measures to ensure that file formats, schemas and content are appropriate to the Designated Community should be covered under Reuse (R13). Quality Assurance (R10) R10. The repository addresses technical quality and standards compliance, and ensures that sufficient information is available for end users to make quality-related evaluations. Self-Assessed Compliance Level: Response Guidance Different repositories undertake different levels of curation on data, metadata and documentation depending on the needs and expectations of their depositors and Designated Community. Quality assurance by the repository ensures that digital objects comply with a range of standard criteria including acceptable formats, metadata schema, metadata content and links to other digital objects. This relates to ‘technical quality’ rather than the ‘scientific quality’ of the original digital objects creation or collection prior to deposit, though the repository must ensure there is sufficient information about the digital objects for the Designated Community to assess their fitness for use. Data, or associated metadata, may have quality issues relevant to their research value, but this does not preclude their use if a user can make a well-informed decision on their suitability through provided documentation. The response statement and evidence should include references to the following items: ● The approach to data and metadata quality taken by the repository including variations for different curation-levels. ● The standards that data, metadata and documentation must comply with to be acceptable for preservation and access. Whether these are general external standards, internally developed standards or specific to a community of practice. ● The quality control checks in place ensure the completeness and understandability of data and metadata. ● The approach to resolving issues e.g. whether the digital objects are returned to the Page 19 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 depositor for rectification, fixed by the repository, noted by quality flags, and/or included in the accompanying metadata. ● The approach to managing changes to expected standards (e.g. new or updated data formats of metadata schemas) in response to changes in the technical environment or to changes in the needs of the Designated Community. ● Any links provided to other digital objects’ data and metadata e.g. related digital objects, publications, or the use of controlled vocabularies and ontologies. This Requirement refers to data and metadata quality standards and assurance during curation. Selection criteria are covered during Deposit and Appraisal (R08). Measures to ensure that digital objects remain fit for purpose over time are covered under Preservation Plan (R09). Workflows (R11) R11. Digital object management takes place according to defined workflows from deposit to access. Self-Assessed Compliance Level: Response Guidance For Quality Assurance (R10) to be achieved, it is necessary to avoid ad hoc actions and to deliver consistency of practice for all digital objects and across repository functions. This requires that workflows be defined, documented, and change-managed. Workflows may be specified in a mixture of standard operating procedures, business process descriptions and diagrams that guide normal practice and provide mechanisms for handling exceptions. The response statement and evidence should include references to the following items: ● Workflows/business process descriptions covering the curation levels performed. ● How workflows are adjusted for different types of data and metadata. ● Decision handling within the workflows. ● Change management of workflows. ● Ability to track workflow execution, with mechanisms to handle exceptions. This Requirement confirms that all workflows are documented. A diagram can be included to illustrate this. It should be noted if there are different workflows for different levels of security mentioned in the Legal and Ethical (R04) response statement. Workflows may include qualitative and quantitative checking of outputs, but any detail on checks and compliance should be addressed under Quality Assurance (R10). Page 20 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 Discovery and Identification (R12) R12. The repository enables users to discover the digital objects and refer to them in a persistent way through proper citation. Self-Assessed Compliance Level: Response Guidance Effective data and metadata sharing discovery is key to resource discovery. Once discovered, digital objects should be referenceable through full citations, including persistent identifiers (PIDs) to help ensure that they can be retrieved into the future. The response statement and evidence should include references to the following items: ● The search facilities offered by the repository. ● The standards that a searchable metadata catalogue complies with. ● The approach to ensuring that identifiers are unique and persistent. ● Machine harvesting of the metadata. ● Repository, or repository data and metadata, inclusion in disciplinary or generic registries of resources. ● Recommended data citations. Applicants should describe their use of a third party persistent identifier system, or document their own approach to ensuring that identifiers remain globally unique and persistent. The use of a third party to support PID creation and resolution is not sufficient; applicants should describe how they ensure that identifiers continue to resolve to the correct data or metadata over time, including the version rules that guide when a new identifier is created for a digital object. Applicants that do not have a persistent identifier solution cannot achieve “Implemented: the requirement has been fully implemented by the repository” for this requirement. Reuse (R13) R13. The repository enables reuse of the digital objects over time, ensuring that appropriate information is available to support understanding and use. Self-Assessed Compliance Level: Response Guidance Repositories must ensure that data and metadata continue to be understood and used effectively into the future despite changes in technology and the Designated Community’s knowledge base. This Requirement evaluates the measures taken to ensure that data and metadata are reusable. Page 21 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 The response statement and evidence should include references to the following items: ● The ways in which the repository engages with their Designated Community of users to identify their needs. ● The data formats, metadata schemas, controlled vocabularies and ontologies used to support reuse, and how these meet the community needs. ● The metadata and documentation provided at the point of access to support understandability and reuse appropriate to the Designated Community. This may include information specific to data type, e.g. manuals, calibration records, photos, protocols. ● Measures to ensure that data and metadata remain understandable. ● Management of changes to data, metadata, documentation or other information that supports reuse. Responses to this Requirement should focus on engagement with the Designated Community, identification of their needs and specifying how their needs are met. Page 22 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 Information Technology & Security Storage & Integrity (R14) R14. The repository applies documented processes to ensure data and metadata storage and integrity. Self-Assessed Compliance Level: Response Guidance In addition to maintaining ‘archival’ copies of digital objects, repositories need to store data and metadata from the point of deposit, for curation and preservation, and for access by users. For each storage location, measures should be in place to ensure that unintentional or unauthorised changes can be detected and correct versions of data and metadata recovered. The response statement and evidence should include references to the following items: ● Processes and documents to ensure that the repository staff have a clear understanding of all storage locations and how they are managed. ● The repository’s strategy for multiple copies. ● The risk management techniques used to inform the strategy. ● Procedures for handling and monitoring deterioration of storage media. ● Procedures to ensure that data and metadata are only deleted as part of an approved and documented process. ● Any checks (i.e. fixity checks) used to verify that a digital object has not been altered or corrupted from deposit to use. Storage and integrity measures should be covered here (R14) and not as part of Technical Infrastructure (R15) or Security (R16) responses. Details of how intentional changes to the data and metadata are logged should be covered under Provenance & Authenticity (R07). Technical Infrastructure (R15) R15. The repository is managed on well-supported operating systems and other core infrastructural software and hardware appropriate to the services it provides to its Designated Community. Self-Assessed Compliance Level: Response Guidance Repositories must operate on reliable and stable core infrastructure that maximises service Page 23 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 availability. The details of technical infrastructure will vary widely across repositories. Responses and evidence should focus on demonstrating that the repository solution, including hardware and software is well managed and appropriate to the needs of the repository functions and the Designated Community of users. The response statement and evidence should include references to the following items: ● The repository software used for deposit, curation, preservation and access management. Whether it is community supported, open source, or locally developed. ● Any IT service management approach followed and the functions this approach specifies (e.g. systems documentation, software inventories, code repositories, infrastructure development planning). ● Any international, community or other technical infrastructure standards in place and how compliance is monitored. ● The version control systems used for repository generated software. ● Measures taken to ensure that availability, bandwidth, and connectivity are sufficient to meet the needs of the Designated Community. ● Processes in place to monitor and manage the need for technical change, including in response to the changing needs of Preservation (R10), and Reuse (R13) by the Designated Community. Technical aspects of business continuity, disaster recovery and succession planning are relevant here, but their management should be covered under Continuity of Service (R03). This requirement excludes Security (R16) measures and Storage & Integrity (R14). File formats and metadata schema information should be referenced under Deposit & Appraisal (R08) and Reuse (R13). Standards that are not technical or security focussed should be referenced under Quality Assurance (R10). Security (R16) R16. The repository protects the facility and its data, metadata, products, services, and users. Self-Assessed Compliance Level: Response Guidance The repository should analyze potential threats, assess risks, and create a consistent security system. It should consider damage scenarios based on malicious actions, human error, or technical failure that pose a threat to the repository and its data, metadata, products, services, and users. It should measure the likelihood and impact of such scenarios, decide which risk levels are acceptable, and determine which measures should be taken to counter the threats to the repository and its Designated Community. This should be an ongoing process. Page 24 of 25 CoreTrustSeal-Requirements-2026-2028_v01.00 https://doi.org/10.5281/zenodo.17660462 The response statement and evidence should include references to the following items: ● The levels of security required for different data and metadata and environments, and how these are supported. ● The IT security system, employees with roles related to security (e.g. security officers), and any risk analysis approach in use. ● Measures in place to protect the facility. How the premises where digital objects are held are secured. ● Any security-specific standards the repository references or complies with. ● Any authentication and authorization procedures employed to securely manage access to systems in use. Responses should not cover Storage and Integrity (R14) measures or the wider Technical Infrastructure (R15). Applicant Feedback We welcome feedback on the CoreTrustSeal Requirements and the Certification procedure. Response Page 25 of 25