CEN/CLC/TS 18331:2026
(Main)Maturity assessment of Common European Data Spaces
General Information
- Abstract
This document provides a multi-dimensional assessment framework of data spaces maturity, considering the different needs of data spaces, their participants, domain, or scope.
Specifically, it defines a maturity model concept, structure, methodology and measurable criteria, with related requirements and guidance for the assessment of data space maturity.
This document applies to all types of organizations, regardless of their type or size.
- Status
- Published
- Publication Date
- 30-Jun-2026
- Technical Committee
- JTC 25 - Data management, Dataspaces, Cloud and Edge
- Drafting Committee
- WG 2 - Dataspaces
- Current Stage
- 6060 - Definitive text made available (DAV) - Publishing
- Start Date
- 01-Jul-2026
- Due Date
- 05-Apr-2027
- Completion Date
- 01-Jul-2026
Overview
CEN/CLC/TS 18331:2026 – Maturity Assessment of Common European Data Spaces provides a comprehensive framework to evaluate the maturity of data spaces in Europe. Developed by the European Committee for Standardization (CEN), this technical specification offers a structured maturity model tailored for all organizations, regardless of size or type, involved in establishing or managing data spaces. The document supports the European data strategy by promoting fair access, regulatory compliance, and the sustainable scaling of data sharing ecosystems across sectors and domains.
Key Topics
The standard introduces a multi-dimensional assessment approach based on defined maturity phases, critical domains, and quantitative as well as qualitative indicators. Key elements include:
- Maturity Model Phases: Ranging from Exploratory to Scaling, covering the entire lifecycle of data space development and operation.
- Assessment Dimensions:
- Governance: Transparent decision-making, security, legal entity formation, and robust participation management.
- Business: Strategic planning, financial sustainability, and value creation for participants.
- Legal: Regulatory compliance, contract management, and rights/responsibilities structure.
- Interoperability: Focused on semantic and technical interoperability, data traceability, and data models governance.
- Control & Trust: Identity and credential management, access and usage policy enforcement, and trust frameworks.
- Value Creation: Mechanisms for provisioning, cataloguing, and measuring the impact of data space services and adoption.
- Maturity Indicators (DSMIs): Specific, measurable indicators are defined per dimension for granular assessment.
- Self-Assessment Guidance: Includes templates, methodology, scoring systems, and visualization tools such as spider charts for tracking progress.
- Reporting Structure: Requirements for additional documentation around policies, lawfulness, international participation, and societal or environmental value generated.
Applications
CEN/CLC/TS 18331:2026 serves a broad set of stakeholders engaged in the European data ecosystem:
- Data Space Initiators and Operators: Provides a roadmap to evaluate their stage of evolution, identify gaps, and plan improvement actions to move toward higher maturity.
- Potential Participants: Assists organizations in assessing the readiness and capability of data spaces before joining, supporting informed decision-making.
- Policymakers and Authorities: Offers an objective basis for monitoring and benchmarking the landscape of European data spaces, helping to shape supportive policies and best practices.
- Certification Bodies: Lays the foundation for developing certification schemes based on established maturity indicators and phases.
By applying this standard, organizations can enhance interoperability, strengthen governance, demonstrate compliance, and foster greater trust and value creation in data sharing initiatives. The model is adaptable for regular or ad hoc assessments, making it valuable for continuous improvement and strategic reporting.
Related Standards
CEN/CLC/TS 18331:2026 aligns with and references several related standards and frameworks, ensuring consistency and harmonization within the broader data and cloud computing ecosystem:
- EN 18235-1: Trusted Data Transactions - Concepts and Mechanisms
- ISO/IEC TS 27560: Privacy Technologies - Consent Record Information Structure
- ISO/IEC/DIS 20151: Dataspaces in Cloud Computing and Distributed Platforms
These standards provide foundational terminology, interoperability guidelines, and regulatory compliance mechanisms integral to implementing a robust maturity assessment for European data spaces.
Keywords: Data Spaces, Maturity Assessment, European Standard, Data Sharing, Governance, Interoperability, Data Trust, Data Ecosystem, CEN/CLC/TS 18331:2026, Data Space Maturity Model, Self-Assessment, Cloud Computing Standards.
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

NYCE
Mexican standards and certification body.
Sponsored listings
Frequently Asked Questions
CEN/CLC/TS 18331:2026 is a technical specification published by the European Committee for Standardization (CEN). Its full title is "Maturity assessment of Common European Data Spaces". This standard covers: This document provides a multi-dimensional assessment framework of data spaces maturity, considering the different needs of data spaces, their participants, domain, or scope. Specifically, it defines a maturity model concept, structure, methodology and measurable criteria, with related requirements and guidance for the assessment of data space maturity. This document applies to all types of organizations, regardless of their type or size.
This document provides a multi-dimensional assessment framework of data spaces maturity, considering the different needs of data spaces, their participants, domain, or scope. Specifically, it defines a maturity model concept, structure, methodology and measurable criteria, with related requirements and guidance for the assessment of data space maturity. This document applies to all types of organizations, regardless of their type or size.
CEN/CLC/TS 18331:2026 is classified under the following ICS (International Classification for Standards) categories: 35.210 - Cloud computing. The ICS classification helps identify the subject area and facilitates finding related standards.
CEN/CLC/TS 18331:2026 is associated with the following European legislation: EU Directives/Regulations: 2023/2854; Standardization Mandates: M/614. When a standard is cited in the Official Journal of the European Union, products manufactured in conformity with it benefit from a presumption of conformity with the essential requirements of the corresponding EU directive or regulation.
CEN/CLC/TS 18331:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-september-2026
Ocena zrelosti skupnih evropskih podatkovnih prostorov
Maturity assessment of Common European Data Spaces
Reifegradbewertung der gemeinsamen europäischen Datenräume
Ta slovenski standard je istoveten z: CEN/CLC/TS 18331:2026
ICS:
35.210 Računalništvo v oblaku Cloud computing
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
TECHNICAL SPECIFICATION CEN/CLC/TS 18331
SPÉCIFICATION TECHNIQUE
TECHNISCHE SPEZIFIKATION
July 2026
ICS 35.210
English version
Maturity assessment of Common European Data Spaces
Reifegradbewertung der gemeinsamen europäischen
Datenräume
This Technical Specification (CEN/TS) was approved by CEN on 10 May 2026 for provisional application.
The period of validity of this CEN/TS is limited initially to three years. After two years the members of CEN and CENELEC will be
requested to submit their comments, particularly on the question whether the CEN/TS can be converted into a European
Standard.
CEN and CENELEC members are required to announce the existence of this CEN/TS in the same way as for an EN and to make the
CEN/TS available promptly at national level in an appropriate form. It is permissible to keep conflicting national standards in
force (in parallel to the CEN/TS) until the final decision about the possible conversion of the CEN/TS into an EN is reached.
CEN and CENELEC members are the national standards bodies and national electrotechnical committees of Austria, Belgium,
Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy,
Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of North Macedonia, Romania, Serbia,
Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and United Kingdom.
CEN-CENELEC Management Centre:
Rue de la Science 23, B-1040 Brussels
© 2026 CEN/CENELEC All rights of exploitation in any form and by any means
Ref. No. CEN/CLC/TS 18331:2026 E
reserved worldwide for CEN national Members and for
CENELEC Members.
Contents Page
European foreword . 3
Introduction . 4
1 Scope . 4
2 Normative references . 4
3 Terms and definitions . 5
4 Data spaces maturity model concept . 5
4.1 Overview . 5
4.2 Data spaces maturity model purpose . 5
4.3 Data spaces maturity model structure . 6
4.4 Data spaces maturity phases . 6
4.5 Data spaces maturity dimensions . 7
4.6 Data space maturity indicators (DSMIs) . 7
4.7 Reporting structure . 8
5 Assessment methodology and guidance . 8
5.1 General. 8
5.2 DSMIs per dimension . 9
5.2.1 General. 9
5.2.2 Governance dimension . 9
5.2.3 Business dimension . 10
5.2.4 Legal dimension . 12
5.2.5 Interoperability dimension . 14
5.2.6 Control over data and Trust dimension . 15
5.2.7 Value Creation dimension . 17
5.3 Visualization of the assessment . 20
5.4 Evolution criteria . 21
Annex A (informative) Template for Data Spaces Maturity self-assessment . 26
Bibliography . 42
European foreword
This document (CEN/CLC/TS 18331:2026) has been prepared by Technical Committee CEN/CLC JTC 25
“Data Management, Dataspaces, Cloud and Edge”, the secretariat of which is held by UNI.
Attention is drawn to the possibility that some of the elements of this document may be the subject of
patent rights. CEN shall not be held responsible for identifying any or all such patent rights.
Any feedback and questions on this document should be directed to the users’ national standards body.
A complete listing of these bodies can be found on the CEN website.
According to the CEN/CENELEC Internal Regulations, the national standards organisations of the
following countries are bound to announce this Technical Specification: Austria, Belgium, Bulgaria,
Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland,
Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Republic of
North Macedonia, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye and the
United Kingdom.
Introduction
The Common European Data Spaces (CEDSs) are a key enabler for the implementation of the European
strategy on data.
The Data Act promotes the fair access and use of data in a harmonized legal framework. In support of
st
Article 33 of that regulation, the European Commission adopted on 1 July 2025 the European Trusted
Data Framework standardization request.
The CEN/CENELEC JTC5 has the mandate to draft various deliverables of this standardization request.
This document addresses one of these deliverables regarding “Technical Specification(s) on a maturity
model for Common European Data Spaces”.
The DSSC Maturity Model [1], created by the Data Spaces Support Centre (DSSC), has been taken as a
baseline document for producing this technical specification. Data spaces and similar data-sharing
initiatives evolve as the number of participants increases and as diverse use cases emerge. These factors
shape the priorities for their development.
At the same time, potential participants need insight into the capabilities of these data spaces.
This document introduces a maturity model designed for self-assessment of any data space and data
sharing initiative, offering guidance and transparency for data spaces and their stakeholders.
1 Scope
This document provides a multi-dimensional assessment framework of data spaces maturity, considering
the different needs of data spaces, their participants, domain, or scope.
Specifically, it defines a maturity model concept, structure, methodology and measurable criteria, with
related requirements and guidance for the assessment of data space maturity.
This document applies to all types of organizations, regardless of their type or size.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content
constitutes requirements of this document. For dated references, only the edition cited applies. For
undated references, the latest edition of the referenced document (including any amendments) applies.
ISO/IEC TS 27560, Privacy technologies — Consent record information structure
EN 18235-1, Trusted data transactions - Part 1: Terminology, concepts and mechanisms
ISO/IEC/DIS 20151, Cloud computing and distributed platforms — Dataspaces
Sectoral/domain-specific data spaces established in the European single market with a clear EU-wide scope that
adheres to European rules and values (DSSC Glossary).
3 Terms and definitions
For the purposes of this document, the terms and definitions given in EN 18235-1 and ISO/IEC DIS 20151
and the following apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https://www.iso.org/obp/
— IEC Electropedia: available at https://www.electropedia.org/
3.1
data spaces maturity model
means of and scale for evaluating and assessing the current state of maturity of a data space
[SOURCE: EN 13054:2012, definition 2.5, modified – «data spaces» added to the term]
3.2
data space maturity dimension
logical grouping of data space maturity indicators
3.3
data space maturity phase
defined phase in evolution of a data space, representing a specific level of development and capability
3.4
data space maturity indicator
DSMI
quantitative or qualitative metric applied to monitor, measure, and evaluate the maturity level of a data
space
4 Data spaces maturity model concept
4.1 Overview
This Technical Specification provides:
• The maturity model purpose and structure. The rationale, purpose and conception of the model,
the required structure and the method to be applied and measured.
• The maturity indicators to measure the maturity. They are measurable values to demonstrate the
fulfilment of a goal.
• The reporting structure to be produced by the data spaces. Set of reports which provides
additional information on the data space that is not captured through the Data Space Maturity
Indicators (DSMIs) or in supporting them.
• A self-assessment guidance and templates for conducting it. Other types of assessment, such as
third-party certifications, are feasible and proposed.
4.2 Data spaces maturity model purpose
The purpose of the data spaces maturity model is to enable any of the following:
• Assessing the evolution of a data space.
• Supporting the self-assessment of each data space.
• Benchmarking a data space in the overall landscape of data spaces.
• Enabling data spaces to identify their strengths and areas for improvement.
• Providing data spaces with a common reporting structure to collect information about their structure
and operations in alignment with European objectives and best practices.
• Evaluating the interoperability of a data space, both within the data space and across data spaces.
The data spaces maturity model can be used by:
1) Data space governance authorities or data space participants, during the assessment of their
current evolution stage, to identify the requirements needed to reach the next maturity level. This
process enables the determination of the necessary actions to implement in order to progress from
their current maturity phase to the target phase.
2) Data space candidate participants, for the assessment of the capabilities of the data space at any
time. This assessment enables them to decide their level of engagement in the data space based on
its self-assessment.
3) Policy makers, to gain an overview of the capabilities and evolution of the data spaces landscape.
This overview enables them to derive practical insights and conclusions from the self-assessments
conducted by the data spaces.
4) Certification providers, to develop their own certification programs based on these technical
specifications.
The maturity model relies on fundamental concepts in data spaces, namely interoperability, governance,
control over data, trust, regulatory compliance and value creation out of data products. These concepts
are aligned with the proposed dimensions described in clause 4.5.
4.3 Data spaces maturity model structure
The structure of the data spaces maturity model defines the phases of a data space evolution, the
dimensions under which ones the data space is going to be evaluated, the data space maturity indicators
and the reporting structure for additional information provided by the data space.
4.4 Data spaces maturity phases
The data space maturity phases are:
a) Exploratory phase: The stage at which a data space initiative begins. Typically, at this stage, a group
of participants starts exploring the interest, potential, and feasibility of a data space. Exploratory
activities can include, among others: identifying and engaging stakeholders, gathering requirements,
discussing use cases and business goals, and reviewing existing regulations or standards.
b) Preparatory phase: This stage begins when a data space initiative has reached a critical mass of
committed partners and there is an agreement to move forward with the initiative and proceed
toward the creation of a data space. At this stage, it is common for these partners to collaboratively
develop use cases and prepare for the implementation of the data space.
c) Implementation phase: This stage begins when a data space initiative has a sufficiently detailed
project plan, milestones, and resources (financial and otherwise) to develop its governance
framework and infrastructure in the context of a data space pilot. At this stage, it is typical to clearly
identify the parties involved in the pilot and the value created for each one.
d) Operational phase: This stage begins when a data space initiative has a tested infrastructure
implementation and governance framework, and the first use cases become operational (data flows
between data providers and data users, and the use cases deliver the intended value). At this stage,
adjustments are typically made to both the governance framework and the technical implementation
of the data space in order to adapt to day-to-day operations.
e) Scaling phase: This stage begins when a data space initiative has demonstrated the ability to
consistently and organically attract new participants and adopt new use cases. At this stage, it can be
realistically expected that the data space is financially and operationally sustainable, responsive to
market changes, and capable of growing over time.
4.5 Data spaces maturity dimensions
The data space maturity dimensions are:
1) Governance dimension: includes aspects on transparent decision-making process, data-sharing
agreements establishment, making data transactions secure and legally sound, robust organisational
form and governance authority establishment and participation management.
2) Business dimension: includes aspects on data space strategic planning, financial sustainability to
guarantee operational continuity, balance participation of participants and generation of value for
all of them from the data sharing.
3) Legal dimension: includes aspects on the rights and responsibilities of participants, structure of
contracts and data-sharing rules establishment in accordance with relevant applicable legal
frameworks throughout data space lifecycle.
4) Interoperability dimension: includes aspects on semantic and technical interoperability as well as
provenance and traceability.
5) Control over data and trust dimension: includes aspects on participants and assets identification
and verification, establishment of trust and definition of enforcement policies for access and usage
control.
6) Value creation dimension: includes aspects on value-creation enablement through the
provisioning of value-creation services, cataloguing mechanisms, proper description of data and
services, and means to assess the adoption level of the data space.
4.6 Data space maturity indicators (DSMIs)
The DSMIs can provide the quantitative or qualitative assessment of the data space.
Every DSMI is measuring a set of metrics and capabilities of the data space.
Every DSMI has:
a. a description of the aspect which is going to be measured (i.e Participation Management);
b. the metrics which are used to measure the indicator (i.e. Onboarding process in place). Every metric
includes a set of capabilities which require to be fulfilled (i.e. Accession agreement signed);
c. the measure values which are the possible values that every metric can take (i.e. Undefined, Drafted,
Established, Continuously running, Size-adapted);
d. a weight of relevance per metric since not all the metrics are equally relevant for the overall indicator
maturity (i.e. 30% of the total);
e. a scoring per phase which provides the corresponding score obtained by the data space in each
metric depending on the measured value replied in the questionnaire (i.e Exploratory 10 points,
Preparatory 20 points, Implementation 50 points, Operation 80 points, Scaling 100 points).
4.7 Reporting structure
The reporting structure provides some additional information for the assessment of the data space.
The data space should report on at least the following capabilities:
a. Set of policies, standards, and protocols defined in the data space rulebook describing the
interoperability capabilities based on the structure of the European Interoperability Framework
(EIF).
b. Assessment report on lawfulness, including European rules and values, in particular personal data
protection, consumer protection legislation, and competition law.
c. Preconditions for participation, if not open to all organizations/individuals.
d. Assessment report providing insight into the different types of value (including societal and
environmental) generated through data being shared in the data space.
e. Assessment report on implementing the key characteristics of data spaces which are not measurable
through DSMIs.
f. Providing levels of international and cross-border interactions, considering the international
dimension (national, Union, non-Union) of data space participants and data flows.
5 Assessment methodology and guidance
5.1 General
The assessment method is of a hybrid nature, combining quantitative and qualitative measurement based
on data space maturity indicators (DSMIs) and additional information from the reporting structure.
The assessment is conducted by:
1) Gathering the values provided by the data space using a human-oriented questionnaire which
includes one question per metric for all DSMIs (see Annex A for template example).
2) Applying the corresponding weight to each metric, obtaining the pondered value.
3) Assessing the measured value with the scoring per phase.
4) Summing up the score per metric to calculate the total score per DSMI.
5) Summing up the score per indicator to calculate the total score per dimension.
6) Visualizing the results of the assessment by using a spider graph with the percentages of fulfilment
per dimension. The data space evolution can be illustrated with a bar graph of dimensions over the
time (i.e. years). See clause 5.3.
7) Assessing the current maturity phase per dimension by looking at the criteria per phase in table
provided in clause 5.4. It also allows to identify the requirements for evolving to the next phase.
This process can be repeated on a fixed timeframe (e.g. annually) or at any point when the data space
needs to assess its maturity status.
5.2 DSMIs per dimension
5.2.1 General
The Following DSMIs shall be measured by the data space. The tables in the following sub-clauses show
the specific metrics to measure in each DSMI, the capabilities that are required to assess for each metric
and the measure values per metric.
Annex A provides a template of the questionnaire with the corresponding questions per DSMI and metric
to facilitate the assessment process.
5.2.2 Governance dimension
Table 1
DSMI METRICS CAPABILITIES MEASURE VALUES
Governance Organizational Decision on permanent/temporary Undefined
Framework form set up form, type of legal entity and
Drafted
Establishment jurisdiction of the legal entity;
Established
Include participant types, privileges
Enforced
and duties;
Long term sustainable
Identify the role of members in the data
space operation;
Keeping long term structure
sustainability.
Data Space Governance framework creation; Undefined
Governance
Governance model definition; Drafted
Authority
Ensure transparent decision making Established - under
established
process; validation
Internal regulations in place; Operational
Scalable
Rulebook Book of data space rules tailored to Not existing
existence data space needs;
Exists with basic tailoring
Covering contract frameworks and
Comprehensive, tailored,
data licensing requirements;
and covers all key topics
Bylaws, internal rules, procedures,
Applied in daily operation
contract templates, technical
at least in human-readable
requirements and standards;
format
In human and machine readable
Fully operational, digital
formats.
integrated, and available in
a machine-readable format
Governance Processes for governance execution, No formal processes in
processes in including mechanisms for monitoring, place
place review, and continuous improvement;
Draft processes
DSMI METRICS CAPABILITIES MEASURE VALUES
Dispute resolution procedures; Defined and communicated
processes
Change management procedures;
Enforced and regularly
Management of data space agreements
updated
processes;
Size-adapted processes
Adaptation to the scale;
Participation lifecycle management
process.
Participation Roles and Keep updated the matrix of roles and Undefined
Management responsibilities responsibilities and scale it up when
Drafted
management needed;
Established
Management of participants;
Continuous operation
Transactions monitoring.
Size-adapted
Onboarding Signature of participation agreement, Undefined
processes in include accepting the data spaces rules;
Drafted
place
Participants verification, including
Established
identity verification and compliance
Continuous operation
with data space rules for participation;
Size-adapted
Technical requirements verification;
Access policies;
Contract policies.
Offboarding Termination of the participation Undefined
processes in agreement;
Drafted
place
Closing ongoing contracts;
Established
Assurance of operation continuity;
Continuous operation
Remove granted access;
Size-adapted
Data Contract Management.
Support Identify the support needs of data Undefined
mechanisms to space participants;
Drafted
participants
Provision of continuous support
Established
service to all participants in all the data
Continuous operation
space services (onboarding,
Size-adapted
offboarding, contracts…);
Having a help-desk system for
managing the supporting actions and
track the process.
5.2.3 Business dimension
Table 2
DSMI METRICS CAPABILITIES MEASURE VALUES
Business Model Business goals Define the purpose, principles and scope Discussed
Development and profits of the data space (possible use of Data
Defined
defined Space Canvas);
Adopted
DSMI METRICS CAPABILITIES MEASURE VALUES
Define the ultimate goal of the data Continuous business
space and potential benefits for all operation
participants;
Size-adapted and
Consider the multi-party approach of validated by the
the business model definition; market
Support a collaborative business model
approach;
Evidence of market validation.
Clear revenue Identify the feasible mechanisms to Undefined
and funding ensure the sustainability of the data
Defined
mechanisms space;
Adopted
Collect and apply the possible funding
Continuously running
sources;
Size-adapted
Ensure a clear revenue in investment for
all participant roles;
Guarantee the coverage of data space
maintenance costs.
Monitoring and Establish processes to monitor and Undefined
evolution of adapt the business model over the time;
Defined
business model
Keep the business model documented in
Implemented
in place
the rulebook;
Continuously running
Governance authority is responsible to
Size-adapted
keep the business model in operation
and attractive to engage new
participants;
Define a scaling up strategy to make the
data space growing over the time.
Value Identify the value of data sharing for Discussed
proposition for each type of participant;
Defined
each
Define the different business model for
Implemented
participant
type of role;
Continuously running
defined
Ensure the participants are rolling out
Size-adapted
the business models;
Align participants per role to agree on
required incentives.
Use Case Collection of Identify potential use cases at a high Identified
Development use cases level (purpose, value, roles), and justify
Designed
identified the need for a data space;
Implemented
Define in detail the most promising or
Continuously running
prioritized ones (data products,
Size-adapted
services, business case, regulation);
Implement the selected use cases to
validate the viability of the data space;
Use cases increase, are scalable and
create demand in the data space
ecosystem to keep data space alive.
DSMI METRICS CAPABILITIES MEASURE VALUES
Data products For each use case, identify the data Undefined
identified for products that will be shared;
Identified
sharing
Ensure the data products are being
In sharing
shared in the related use cases;
Continuously shared
Assess the data products are shared
Massively shared
over the time in the corresponding use
case;
Promote new data products are shared
over the time.
Participants For each use case, identify the Undefined
involved in use participants will be involved;
Identified
cases
Ensure the participants are engaged in
Engaged
the use cases where involved;
Continuously engaged
Assess the participants are engaged
Expanding
over the time in the corresponding use
engagement
case;
Promote new participants are engaged
over the time.
Data For each use case, monitor the data Undefined
transactions transactions that are being executed
Not executed
executed over the time and at different stages of
Executed in validation
the use case.
Continuously executed
Large-scale execution
Added value For each use case, monitor the added Undefined
services value services that are being generated
Defined
generated over the time and at different stages of
Implemented
the use case.
Continuously running
Size-adapted
5.2.4 Legal dimension
Table 3
DSMI METRICS CAPABILITIES MEASURE VALUES
Regulatory Regulatory Identify general, local and sector-specific Identified
Compliance framework regulations (regulatory compliance
Requirements
identified flowcharts);
defined
Get familiarized with the requirements
Requirements
imposed by each of the regulations;
implemented
Define the required implementations to
Continuously
be compliant with the regulation;
updated
Implement the corresponding
Scope-adapted
components to achieve the requirements.
DSMI METRICS CAPABILITIES MEASURE VALUES
Regulatory Identity the type of triggers which applies Identified
compliance to the data space (data type, type of
Requirements
triggers participants, type of use cases);
defined
identified
Identify the requirements that emerge
Requirements
from the triggers;
implemented
Define the required implementations to
Continuously
address the regulation due to the triggers;
updated
Support the implementation the
Scope-adapted
corresponding components to achieve the
requirements.
Compliance Having mechanisms and tools to ensure Undefined
ensuring the compliance with identified
Designed
mechanisms regulations at all levels;
Implemented
Establish continuous monitoring of
Continuously
compliance at highest automated way;
running
Generation of alerts when the compliance
Automated
is broken;
Processes for recovering the compliance
breaches at highest automated way;
management of legal claims.
Contractual Institutional Define general terms and conditions for Undefined
Framework agreements in participation in the data space;
In definition
place
Include management of potential legal
Available
incidents;
Continuously
Provide legal basis for operations.
provided
Scope-adapted
Sharing Govern data transactions among Undefined
agreements in participants;
In definition
place
Include data license, scope of data use,
Available
geographical coverage, ownership
Continuously
conditions, sensitive data included, data
provided
sovereignty, delivery method…
Scope-adapted
Service Regulate the provision of data space Undefined
agreements in services, either related to data (i.e. data
In definition
place intermediation) and enabling services
Available
(i.e. participant agent, federation services,
Continuously
etc).
provided
Scope-adapted
5.2.5 Interoperability dimension
Table 4
DSMI METRICS CAPABILITIES MEASURE VALUES
Shared Data models Reuse or develop the data models to be Undefined
semantics adopted adopted by the data space participants;
Defined
Ensure the proper use of ontologies,
Adopted
vocabularies, schemas and profiles;
Continuously used
Use of the data models by the data products
Cross data space use
in the use cases;
Support cross data space interoperability.
Use of open Having data models based on standards for Undefined
standards for semantic interoperability;
Defined
semantic
Machine-readable interoperability;
Adopted
interoperability
Use of open standards for expressing data
Continuously used
models and datasets (like DCAT).
Cross data space use
Use of Refer the data models to one or more Undefined
reference reference datasets (such as ISO country code
Defined
datasets list);
Adopted
Ensure consistency and alignment in data
Continuously used
representation.
Cross data space use
Data models Define the processes and tools to maintain, Undefined
governance evolve and govern the data models of the
Defined
data space over the time;
Adopted
Having the data models perfectly
Continuously used
documented;
Cross data space use
Provide support to participants in their use.
Interoperable Data exchange Support the participants in having a data Undefined
exchange protocol exchange protocol defined and
Defined
implemented, covering both control and data
Adopted
plane;
Continuously used
Cross data space use
Use of Provide a common and standard API for Undefined
standardized allowing participants to query, create,
Defined
API update and delete data among them, once the
Adopted
data transaction is agreed.
Continuously used
Cross data space use
Provenance, Data Cope with the legal requirements related to Undefined
Observability provenance provenance;
Designed
and monitoring
Design the approach to track the provenance
Implemented
Traceability
of the data by following the defined data
Continuously running
models in the data space;
Automatically
extended
DSMI METRICS CAPABILITIES MEASURE VALUES
Define processes and tools to track the
provenance of data;
Reuse the existing standards and guidelines
for traceability (i.e. PROV-O, PIDs,
ISO/IEC 27560).
Data sharing Cope with the legal and contractual Undefined
contracts requirements related to observability;
Designed
observation
Design the approach to track the
Implemented
observability of the data by following the
Continuously running
defined data models in the data space;
Automatically
Define mechanisms and tools to monitor the
extended
data sharing contracts (observability);
Reuse the existing standards and guidelines
for observability (i.e. Data Space Protocol).
Data Cope with the legal requirements related to Undefined
traceability traceability;
Designed
tracking
Design the approach to track the traceability
Implemented
of the data by following the defined data
Continuously running
models in the data space;
Automatically
Define processes and tools to track the
extended
sharing and use of actual data;
Reuse the existing standards and guidelines
for traceability (i.e. PROV-O, PIDs, ISO/IEC
27560).
5.2.6 Control over data and Trust dimension
Table 5
DSMI METRICS CAPABILITIES MEASURE VALUES
Identity Mng Use of Having standardized method for verify Not in place
and Attestation verifiable the digital identity of participants;
Designed
digital identity
Supports secure onboarding, trusted
Implemented
and
exchanges between participants, and
Continuously running
attestations
federation with other data spaces
Automatically extended
through reliable identity and
attestation mechanisms;
Adoption of recognized standards to
ensure consistency and
interoperability (i.e. W3C Verifiable
Credentials for tamper-evident and
cryptographically verifiable digital
attestations).
Use of Having a secure credential exchange Not in place
credential and communication with wallets;
Designed
exchange
Adoption of recognized standards for
Implemented
protocols
credential exchange protocols to
Continuously running
ensure consistency and
DSMI METRICS CAPABILITIES MEASURE VALUES
interoperability (i.e. Decentralized Automatically extended
Claim Protocol (DCP) and OID4VC,
enabling participants to share
verifiable credentials securely while
maintaining data sovereignty).
Systematic Having a machine-readable rulebook; Not in place
compliance
Establish the mechanism to make that Designed
with the
every participant and service within the
Implemented
rulebook
data space can be systematically
Continuously running
verified against the data space
Automatically extended
rulebook’s requirements, ensuring
adherence to governance standards.
Trust Technical Having a trust framework defined and Not in place
framework enforcement implemented to support the
Designed
of the data enforcement of the data space
Implemented
space governance, which includes the rules,
Continuously running
semantic models, processes for
governance
compliance verification and technical Automatically extended
standards for interoperability.
Trust anchors Implement clear guidelines for Not in place
establishment establishing trust anchors and other
Designed
entities (e.g., trust service providers,
Implemented
conformity assessment bodies) that are
Continuously running
recognised to issue attestations on
Automatically extended
identities or other attributes.
Data Space Existence and operation of a registry Not in place
Registry for participants credentials, list of
Designed
integration accredited trust anchors, schemas to
Implemented
assess the compliance and data space
Continuously running
rulebook; include all the mechanism to
Automatically extended
manage the operations over the
registry (store, delete, update, report.).
Access and Access control Having policies in machine-readable Not in place
usage policies policies formats and implemented using policy
Designed
enforcement engines to ensure who can access the
Implemented
data and how the data is granted and
Continuously running
controlled;
Automatically extended
Defining conditions for access based on
roles and attributes;
Define policy-based frameworks to
determine who access what, under
which conditions and how
authorizations are enforced;
Having mechanisms to monitor and log
data transactions to verify the
compliance with access policies and
provide enforcement evidences;
DSMI METRICS CAPABILITIES MEASURE VALUES
Use of standard policy languages (i.e.
ODRL)
Usage control Having policies in machine-readable Not in place
policies formats and implemented using policy
Designed
engines to ensure which actions can be
Implemented
(or not be) performed on data;
Continuously running
Specify the permitted operations
Automatically extended
(update, delete, share…);
Set up the rule to enforce the
boundaries of allowed actions in
compliance with the policy;
Having mechanisms to monitor and log
data transactions to verify the
compliance with usage policies and
provide enforcement evidences;
Use of standard policy languages (i.e.
ODRL).
Consent Having policies in machine-readable Not in place
Management formats and implemented using policy
Designed
policies engines to manage consent and
Implemented
permission for data usage;
Continuously running
Verifies authorize consent;
Automatically extended
Establish explicit consent processes
(opt-in, opt-out);
Verification and revocation workflows;
Having mechanisms to monitor and log
data transactions to verify the
compliance with consent policies and
provide enforcement evidences;
Use of standard policy languages (i.e.
ODRL).
5.2.7 Value Creation dimension
Table 6
DSMI METRICS CAPABILITIES MEASURE VALUES
Data, Services Complete Clear, structured description of data Undefined
and Offerings description of products and services, including
Standardized
descriptions data products metadata, license terms, usage
description
and services conditions, and access mechanisms;
Machine-readable
machine-readable metadata; use of
standardized
standard vocabularies and policy
description
frameworks.
Continuously
updated descriptions
Automated extension
of descriptions
DSMI METRICS CAPABILITIES MEASURE VALUES
Publication and Catalogue Participants can publish, update, and Not available
Discovery availability for remove data and service offerings
Designed
publishing through a catalogue system; the
Implemented
catalogue supports access control
Continuously
mechanisms to manage visibility of
updated
offerings.
Massively used
automatically
Catalogue Participants can search, filter, and Not available
availability for discover offerings based on metadata,
Designed
discovery terms, and conditions; the catalogue
Implemented
supports access control mechanisms to
Continuously
manage visibility of offerings.
updated
Massively used
automatically
Value Creation Catalogue of A taxonomy of value creation services is Not available
services services is in in place, distinguishing between core
Designed
place services, data handling services, value-
Implemented
added services, infrastructure
Continuously
integration services, application
updated
integration services, and business
Massively used
enablement services.
automatically
Service A service management system is Not available
Management implemented that supports the
Designed
system provisioning, delivery, use, trusted
Implemented
implemented execution, monitoring, scalability, and
Continuously used
maintenance of value creation services.
Massively used
automatically
Cross-data space The data space allows the data sharing Not planned
interoperability with other data spaces in a federated
Planned (at least with
(federation environment.
1 DS)
service)
Adopted (at least with
1 DS)
Continuously running
(at least with 1 DS)
Expanded to
additional data
spaces
Adoption level Participation Measure the total number of Core founding
level participants engaged in the data space stakeholders
(onboarded) over time;
Core founding + use
The measure can help to activate actions cases participants
to attract new participants.
DSMI METRICS CAPABILITIES MEASURE VALUES
Core founding + use
cases participants +
early community
Core founding + use
cases participants +
mature community
Extensive
participation
Data reusability Calculate the percentage of data Not sharing
level products which have been shared with
Data identified for
more than one participant;
sharing
The measure can help to assess the
Data is shared one to
amount of data which is shared on
one in the use cases
frequently basis with multiple
Data is shared one to
participants (avoid one data one user
one on a regular basis
effect).
Data is shared one to
many at scale
High availability Measure the total number of data No data available
of data products described in the data space
Data products from
catalogue;
use cases
The more data the more value of data documented in the
space for AI; data space
The measure can help to assess the Data products from
activity level of sharing and interest of use cases described in
participants in publishing data. the catalogue
Catalogue
continuously
populated with data
products from data
providers
Massive catalogue
population
Participants Define the processes and tools to gather No assessment
satisfaction the level of satisfaction perceived by the
Defined gathering
data space participants according to
process
their experience and obtained value
Collected from use
within the data space (surveys,
cases participants
interviews,…);
Collected from data
Conduct gathering actions of
space community on
satisfaction level; apply measures to
regular basis
improve the satisfaction.
Automated to all
participants
New services and Track the number of new business No services
offerings services and commercial offerings that
Identified by the use
have been ge
...



