8. Criteria assessment methods¶
8.1 Assessment of Declaration¶
A declaration is evaluated by verifying the presence of information fulfilling the criterion.
The information must be one of the following options:
- a self declaration using the Gaia-X Ontology v2511
- a certification as explained in the next section.
- a copy or resolvable URI of a certificate attesting compliance with an accepted Permissible Standard - .pdf, .doc, … - along with the digest of the document.
Permissible standards
The list of accepted permissible standards is specified by criterion
Linked Data design principle
For convenience, the declarant, ie the issuer, may decide to create reusable declarations in the form of Verifiable Credential and provide resolvable URI to VC containing the required information.
To be noted that linked-Data and RDF semantic is out of scope of this document. Please refer to RDF 1.1 for details.
Info
The resource exposed via those resolvable URI can be secured with access control measures.
Warning
The content of the document and the URI are not verified by the GXDCH. It’s the responsibility of the declarant to provide a declaration in accordance with the criteria.
8.1.1 Declaration of Conformity¶
This part aims to ease self-declaration of criteria by specifying the mandatory information to be provided for declaration of conformity. The same document could be used to cover several criteria.
Based on the ISO/IEC 17050-1:2004 “Supplier’s declaration of conformity”, a declarant can collectively declare ( “bulk” ) adherance to several criteria at once.
To help the understanding of Gaia-X Ontology, the mapping between the ISO/IEC “Supplier’s declaration of conformity” and Gaia-X Ontology is as follow:
| ISO/IEC “Supplier’s declaration of conformity” | Gaia-X Ontology with W3C VC |
|---|---|
| Declaration No. | @id of the gx:ServiceOffering‘VC |
| Issuer’s name | Service provider gx:LegalPerson |
| Issuer’s address | Service provider gx:LegalPerson |
| Object of the declaration | The credentialSubject of gx:ServiceOffering |
| The object of the declaration described above is in conformity with the requirements of the following documents | List of gx:TermsAndConditions |
| Additional information | optional permissible standards, T&C, … as W3C VC’s evidence or an Eclipse CAP related to ISO credential |
| Signed for and on behalf of | optional gx:LegalPerson |
| Place and date of issue | VC’s validFrom |
| Name, function - Signature or equivalent authorized by the issuer | VC Issuer’s gx:LegalPerson* |
*: Check the Gaia-X Identity document and DID Services specification on how to link a DID with a gx:LegalPerson credential.
8.2 Assessment of Certification¶
A certification is evaluated by verifying the presence of a resolvable URI, referred to as link below.
This link must resolve to a Verifiable Credential issued by an approved Gaia-X Notary.
The process to become an approved Gaia-X Notary is described in How to become a GXDCH.
Gaia-X Notary and CAB
A permissible standard CAB issuing itself a Gaia-X compliant VC is de facto a Gaia-X accepted Notary and must be recognized as Gaia-X Notary.
Minimum number of Gaia-X Notaries
As long as there are only two or less approved Gaia-X Notaries in addition to CAB, the use of Gaia-X Notaries is optional. If there are only two or less approved Gaia-X Notaries in addition to CAB, self declaration of your proof of compliance (i.e., evidence or permissible standard certificate) is accepted.
Permissible standards
The list of accepted permissible standards is specified for each criterion
Warning
It is the responsibility of the declarant, i.e. the issuer, to ensure that the permissible standards submitted to the Gaia-X Notary are consistent with the fulfillment of the criteria.
8.3 Assessment via Inheritance¶
As inheritance is accepted as proof of Gaia-X compliance for a criterion - or group of criteria - then Gaia-X Compliance can be fulfiled by demonstrating that the composing service offerings described in the criterion P1.1.4 are Gaia-X compliant.
Service offerings built on top of other compliant composed services will only partially inherit compliance. Criteria covering the newly created service offering scope still have to be demonstrated and assessed through declaration or certification.
Depending of its service composition, the service provider is in charge of defining which criteria are not inherited and which ones are, and performing its assessment accordingly.
Smallest Common Demoninator principle
The overall compliance level of a service shall not exceed the lowest compliance level assigned to any of its composing services.
For Gaia-X Label and Standard Compliance, the levels are ordered as follows, from highest to lowest:
- Gaia-X Label level 3
- Gaia-X Label level 2
- Gaia-X Label level 1
- Gaia-X Standard Compliance
8.4 Signature and Trust Anchors¶
In order to create legally relevant proofs, Gaia-X mandates the declarant, i.e., the issuer, to sign its declarations, i.e., the VCs, with one or more of the accepted cryptographic means listed in the Gaia-X Registry. Example: eIDAS, KTNET, EV-SSL, …