Gaia-X Compliance
The current Gaia-X Compliance Document defines requirements and assessment methods for participating in federated Gaia-X ecosystems and data spaces. It covers machine-readable descriptions of participants, service offerings, and resources; trust anchors; conformity evidence; data protection; cybersecurity; portability; and data exchange.
The Compliance Document supersedes the older Gaia-X Trust Framework and Policy Rules and Labelling Document. A Legra assessment should therefore target the current compliance scheme rather than claim conformance to an obsolete release.
Buyer question
“Can Legra participate in a sovereign, federated data space where identities, services, resources, rules, and conformity evidence are machine-readable and independently verifiable?”
Legra fit
| Assessment area | Legra fit | Status |
|---|---|---|
| Federated and sovereign operation | Peer nodes, encrypted workspaces, independent operators, replication policy, and decentralized discovery support federation without making one platform the data authority. | Native fit |
| Machine-readable descriptions | Legra can represent participants, services, resources, Data Products, policies, and evidence as Linked Data. Exact Gaia-X schemas and required attributes still need a maintained profile. | Partial fit |
| Signed claims and trust anchors | Legra has signed identities, commits, and provenance, but Gaia-X conformity requires its own accepted credential issuers, trust anchors, and verification rules. | Partial fit |
| Data Product and service discovery | Workspace catalogs, DCAT/DPROD metadata, service descriptions, and federated queries provide the substrate for data-space discovery. Gaia-X-specific publication and exchange workflows remain to be productized. | Partial fit |
| Automated conformity evidence | SHACL, versioned rules, validation reports, signed history, and queryable provenance can produce machine-readable evidence. Gaia-X assessment methods and declarations must still be implemented exactly. | Partial fit |
| Contractual and regulatory criteria | Legra can store contracts, policies, attestations, and supporting evidence, but legal declarations, certification, and conformity-body decisions belong to the participating organizations. | External responsibility |
What Legra can say
Gaia-X is a close architectural match for Legra because both treat trust and data-space participation as machine-readable information rather than a private platform database:
- A participant, service, resource, policy, or conformity result can have a stable identity and a governed graph representation.
- Workspace encryption separates data custody from authority to read the data.
- Signed commits and provenance preserve the history behind published claims.
- SHACL and merge gates can validate descriptions before they are published.
- Catalogs and peer discovery can expose independently operated Data Products and services without moving their authority into one central marketplace.
Assessment boundary
Architectural similarity is not Gaia-X compliance. A conforming deployment must implement the applicable Gaia-X vocabulary, credential profiles, trust-anchor rules, evidence requirements, assessment methods, and current compliance criteria. The participating legal entities remain responsible for declarations, contracts, certifications, and regulatory obligations.
Legra can provide the governed Linked Data, validation, identity, distribution, and evidence substrate on which that implementation operates.