EDIH, EEN, Interreg: the platform for European programmes.Find out more

Blockchain applications maturity

Your blockchain use cases placed on a maturity scale, and the roadmap that takes them into production.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Blockchain applications maturity

Strategy and use case qualificationN1 → N5
Architecture and network choicesN1 → N5
Smart contracts and code lifecycleN1 → N5
Network and consortium governanceN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Strategy and use case qualification6484
Architecture and network choices5379
Smart contracts and code lifecycle6182
Network and consortium governance3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • ANITI
  • CNRS
  • LIRMM
  • CNES
  • Docaposte
  • KPMG

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Datamensio framework for blockchain and distributed ledger applications maturity assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism (one level, the level above, and the action linking the two) that turns an observation into a trajectory.

Are smart contracts subject to an independent security review before deployment?

  1. N1

    No review separate from development. Code is deployed after functional testing carried out by the team that wrote it.

  2. N2

    A read-through is done by a developer from the team, without a control checklist or record of the points examined.

  3. N3

    A security review draws on a checklist of known vulnerabilities, carried out by someone outside the development team, with minutes kept on file.

  4. N4

    The review is systematic before every deployment, supplemented by automated tests and an external audit for contracts handling assets. Fixes are tracked through to closure.

  5. N5

    The process is revised in line with published vulnerabilities and sector incidents. Findings feed into design rules and are presented to the network’s technical committee.

Action to move from level 2 to level 3

Formalise a review checklist covering common smart contract vulnerabilities, appoint a reviewer from outside the development team, and make sign-off on this review a condition for approval at the production go-live committee.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurement

What this framework covers

This framework assesses an organisation’s maturity in the use of distributed ledgers: selection and qualification of use cases, choice of network type (public, permissioned, hybrid), design and verification of smart contracts, key and identity management, governance between participants, integration with the information system, operations and value tracking. It does not cover crypto-assets as an investment class but the application of the technology to business processes: traceability, asset tokenisation, document certification, business-to-business exchanges.

In practice, the difficulty is rarely technical. It lies in governance and trajectory. Who decides on a data schema change when the network brings together five competing companies? What happens if a major participant leaves the consortium? Are your deployed smart contracts subject to an independent code review before going live, or only to functional testing? And the question that comes up in every steering committee: does the use case justify a distributed ledger, or would a shared database with well-defined access rights be enough?

The context has shifted on two points. First, the maturity of permissioned platforms, which has moved the topic from prototype to operations: node supervision, coordinated version upgrades, data reversibility. Second, European regulation, with the MiCA regulation on crypto-assets and the pilot regime for market infrastructures based on this technology. One common misconception is worth clearing up: blockchain does not make data accurate, it makes its history hard to alter. Data quality on entry remains entirely your responsibility.

An audit answers compliant or non-compliant. The maturity assessment answers differently: what level of control each theme has reached, and what concrete action moves it up a level. A consortium may be strong on smart contract design and absent on network governance. The score by theme makes this gap visible, the target you set quantifies it, and the difference between the two becomes an ordered action plan.

The framework is ready to use in Datamensio and remains yours. AI adjusts the themes, rephrases the questions in your sector’s vocabulary and refines the levels according to the CMMI method. It can also build a variant from your existing documents: consortium charter, architecture file, technical committee minutes.

Reference standard: Datamensio framework for blockchain and distributed ledger applications maturity

The themes assessed

  • Strategy and use case qualification

    Selection criteria, justification for using a distributed ledger over alternatives, alignment with the transformation programme, use case portfolio and trade-offs.

  • Architecture and network choices

    Ledger type (public, permissioned, hybrid), consensus mechanism, sizing, platform choices, reversibility and exit strategy.

  • Smart contracts and code lifecycle

    Design, testing, independent code review, security audit before deployment, version management, update and deprecation process.

  • Network and consortium governance

    Legal status, membership and exit rules, decision-making process on changes, cost allocation, dispute management between participants.

  • Identities, keys and access rights

    Key lifecycle management, escrow and recovery, participant identities, allocation and revocation of network rights.

  • Data and interoperability

    Quality and provenance of data fed in, articulation between on-ledger and off-ledger data, shared schemas, exchange standards, interoperability with other networks.

  • Legal and regulatory framework

    Qualification of assets and tokens, evidential value of ledger entries, personal data protection in light of immutability, applicable sector obligations.

  • Integration with the information system

    Connection to business applications and management software, application programming interfaces, flow management, consistency with the company’s data framework.

  • Operations and supervision

    Node maintenance, supervision, incident management, version upgrades coordinated between participants, continuity plan, tracking of operating costs.

  • Skills, adoption and value measurement

    In-house skills and dependency on providers, training for business teams, value indicators, periodic review of use cases in production.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this assessment lead to a certification?

No. There is no body that certifies blockchain applications maturity. The assessment measures your practices, places each theme on a progressive scale and produces an action plan. It is meant to inform decisions and steer progress, not to secure a label.

How does it differ from a technical smart contract audit?

A code audit examines a given contract and concludes on its vulnerabilities. The assessment covers the organisation that produces and operates these contracts: governance, code lifecycle, operations, value. The two complement each other, and the assessment often indicates when to trigger a code audit.

How long does the assessment take?

The short version takes about thirty minutes to complete by someone who knows the use case portfolio. The full version involves several contributors and runs over one to two weeks, most of the time spent gathering input from technical teams and network partners.

Do respondents need technical expertise?

The questions cover design, governance and operating practices, not configuration detail. Some require input from an architect or developer: the collaborative mode lets you assign those questions to the right person and keeps a record of the answers.

Can the framework be adapted to our context?

Yes. You can edit the questions, levels and themes, or start from a blank base. AI refines the wording for your sector and can build a variant from your documents, consortium charter or architecture file. The framework remains your property.

Does the assessment work for a consortium bringing together several companies?

Yes. Each participant can be assessed separately, then results compared through the benchmark between entities. A cross-cutting roadmap consolidates actions common to the network and separates out those specific to each member.

How does this framework relate to data and AI governance?

Blockchain guarantees the integrity of a history, not the accuracy of the data recorded. A data governance assessment therefore sheds light on the quality of what goes into the ledger. Cross-cutting roadmaps allow the two topics to be combined without duplicating actions.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.

Take your first measurement