DOME qualification process
The DOME platform will provide means to qualify products in the Marketplace with respect to their fulfillment against relevant reference standards.
Initial clarifications:
-
DOME won't certify services
-
DOME will verify that services that want to be endorsed to DOME are compliant to the selected relevant schemes, from the EU Cloud Rulebook. To do so, DOME will verify the validity of the certificates provided by the CSPs for each of the services.
-
DOME will assess the "continuous validity of the certificate" during the lifecycle of the cloud service in DOME.
The certification qualification process is composed of 4 sub-processes:
Certification initialisation: The DOME admin/Market place admin set ups the certification level for the services, selecting which certifications/frameworks need to be provided when a service is endorsed into the DOME/federated marketplace.
Certification accreditation: A CSP that wants to be part of DOME provides the certificates, uploading the corresponding evidence (pdf files or the links to the pdf).
Currently Supported standards (in green) :
STANDARDS |
Mandatory |
General |
|
ISO/IEC 22123-1:2021 |
No |
ISO/IEC 20000-1:2018 |
No |
ISO/IEC 20000-2:2019 |
No |
ISO/IEC 19944-1:2020 |
No |
ISO/IEC 17826:2022 |
No |
ISO/IEC 17788:2014 |
No |
Interoperability and portability standards |
|
ISO/IEC 19941:2017 |
No |
Information security standards |
|
ISO 22301:2019 |
No |
ISO/IEC 27000:2018 |
No |
ISO/IEC 27001:2022 |
No |
ISO/IEC 27002:2022 |
No |
ISO/IEC 27701:2019 |
No |
ISO/IEC 27017:2015 |
No |
Payment Card Industry Data Security Standard (PCI DSS) v4.0 |
No |
Data protection and privacy standards |
|
ISO/IEC 29100:2011 |
No |
ISO/IEC 29101:2018 |
No |
ISO/IEC 19086-4:2019 |
No |
ISO/IEC 27018:2019 |
No |
Service level agreement standards |
|
ISO/IEC 19086-1:201 |
No |
ISO/IEC 19086-2:2018 |
No |
ISO/IEC 19086-3:2017 |
No |
Certification assessment: DOME assesses the validity of the certificate and if valid generates the related Verified Credential for the CSP to be stored in the wallet. The certification assessment activity will be done in a continuous basis process.
Service qualification and onboarding: The service is qualified in the DOME marketplace based on the valid certificates and the information is updated in the catalog. Once the product receives the validation it will be visible in the marketplace pages including the Certification profile achieved through the validation.There are 3 compliance levels based on the types of evidence provided for the supported certifications. These are the different compliance levels a service can be qualified to:
- DOME Level 1 - No certifications provided/achieved
- DOME Level 2 - Some supported certifications have been verified
- DOME Level 3 - All the supported certifications have been verified by DOME