Requirements analysis and architecture design
Months 1–13Captures technical and non-technical requirements for the decentralised architecture, defines the roles and obligations of all actors (NMIs, accredited labs, accreditation bodies, verifiers), and designs the EBSI-based architecture aligned with FAIR, Digital SI, ISO/IEC 17025, ILAC, eIDAS, and GDPR.
Activities (6)
Non-technical requirements & BPMN
Deadline: M8Defines preliminary non-technical requirements and business-logic workflows (BPMN or equivalent) for issuing and using DCCs as Verifiable Credentials — specifying roles, legal/procedural preconditions, and validity criteria.
Technical & compliance requirements
Deadline: M9Defines technical requirements for the blockchain solution (DCC content, FAIR, Digital SI alignment) and compliance requirements based on eIDAS, ISO 27001, and GDPR — embedding trust and privacy by design.
Identity & credential lifecycle
Deadline: M9Defines procedures for onboarding labs/NMIs (DID issuance, accreditation linkage), credential revocation (e.g. accreditation expiry), and off-boarding — consistent with EBSI capabilities.
Decentralised architecture design
Deadline: M10Designs the overall decentralised architecture leveraging EBSI — defining how wallets, Verifiable Credentials, and ledger components interact within the temperature calibration workflows.
GDPR & privacy verification
Deadline: M11Verifies the architecture against GDPR and privacy requirements — keeping personal data off-chain or properly consented — and feeds the outputs into the Data Management Plan (A6.3.2).
Trust architecture aligned with eIDAS
Deadline: M11Defines the trust architecture in line with eIDAS and metrology needs — specifying how trust anchors (e.g. national accreditation bodies) issue and sign accreditation credentials anchored on the blockchain.