From DSSC research to a European standard: the Maturity Assessment of Common European Data Spaces
Data spaces are becoming a practical reality across Europe, as hospitals, manufacturers, energy operators and public bodies test new ways to share data safely. A question comes up in every initiative: how mature is this data space, and what should come next?
DSSC has worked on this question since the start of the programme. The result is the Maturity Assessment of Common European Data Spaces, a multi-dimensional assessment framework that helps any initiative measure its progress, now moved from DSSC guidance into a formal European Technical Specification.
From DSSC guidance to a formal standard
The Maturity Assessment started as a flagship DSSC deliverable. Through three iterations, DSSC worked with practitioners across sectors to define what maturity in a data space looks like, from first talks to full-scale operation [1].
That work gained wider significance once the European Commission initiated the European Trusted Data Framework standardisation request on 1 July 2025, supporting Article 33 of the Data Act. CEN-CLC/JTC 25 was mandated to turn this into formal deliverables, including a maturity model for Common European Data Spaces [2]. Thanks to DSSC's active liaison with JTC 25, this preparatory work carried over directly into the new specification, CEN/CLC/TS 18331 was officially published following its approval by CEN and CENELEC members in April 2026 [2].
Six dimensions that capture maturity
A data space is more than technology, it is an arrangement between organisations, rules and systems. The framework assesses maturity across six dimensions, each mapped against the five phases [2].
Governance covers how decisions get made: the organisational form, the governance authority and the rulebook that puts this into practice.
Business examines the economic ground the data space stands on: the business model, the value proposition for each participant and the funding mechanisms in place.
Legal focuses on regulatory compliance and the contractual backbone, including agreements for participation and data sharing.
Interoperability assesses whether participants can exchange data with shared understanding, through common data models and open standards.
Control over data and trust looks at how participants keep sovereignty over their data, covering identity, credential exchange and policy enforcement.
Value creation measures tangible outcomes: how well data products are described and discovered, and whether new offerings emerge from shared data.
A data space can be strong in one dimension and still have work to do in another. The framework shows exactly where that is.
Five phases that map the journey
The Maturity Assessment defines five phases describing how a data space typically evolves.
In the exploratory phase, stakeholders test feasibility, discuss use cases and review existing regulations [2].
The preparatory phase begins once committed partners agree to move forward and start designing the foundational rules and architecture [2].
In the implementation phase, governance and technical infrastructure take shape, and the first data-sharing capabilities go live [2].
The operational phase is where the data space runs day to day, with use cases delivering value [2].
In the scaling phase, the data space attracts new participants organically, becoming sustainable and able to grow further [2].
A data space need not sit at the same phase across every part of its operation. Governance can move ahead of the technical build, or the business model can mature faster than interoperability. What matters is steady progress over time.
Measuring maturity through data space maturity indicators
Behind each dimension sit Data Space Maturity Indicators (DSMIs), the actual measuring units of the data space. Each DSMI describes a specific capability, such as participation management or trust anchor establishment, and breaks it down into metrics with defined capabilities and measure values, from undefined through to size-adapted or automatically extended [2]. A weight is attached to each metric, since not every metric carries equal relevance, and a score is attributed per maturity phase. Self-assessment answers feed directly into these DSMIs, which are summed up per dimension to produce the percentage scores used for benchmarking [1] [2]. This gives data spaces a common, comparable language for maturity, rather than a subjective impression. Why this matters for the ecosystem
Data Space Governance Authorities: Functions as a practical self-assessment tool and a common benchmark for peer comparison.
Candidate Participants: Provides clear transparency regarding a data space's readiness before committing resources.
Policymakers: Delivers a comprehensive overview of overall progress across the European data space landscape.
Certification Providers: Serves as a foundational reference to build customized assessment programs [2].
A collaborative next step
This move from DSSC research to a European Technical Specification shows what happens when hands-on ecosystem work is carried into formal standardisation. Lessons from real initiatives become the backbone of a European standard. We invite data space initiatives, governance authorities, operators, and participants across Europe to actively apply this Technical Specification and share their findings, experiences, and lessons learned. Together with CEN/CLC JTC 25, DSSC will analyze these real-world results to derive practical, actionable guidance for building mature, value-creating data spaces that power Europe's digital future.
References
[1] DSSC, Maturity Model V2, DSSC ASSET, September 2025.
[2] CEN-CENELEC, Maturity assessment of Common European Data Spaces, CEN/CLC/TS 18331:2026, July 2026