EDIH, EEN, Interreg: the platform for European programmes.Find out more

Open Data Adoption and API Management Maturity

Your data exposure and APIs, measured by theme and turned into a roadmap.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

Open Data Adoption and API Management Maturity

Opening strategy and use casesN1 → N5
Governance and ownershipN1 → N5
Quality, freshness and metadataN1 → N5
Formats, licences and reuse conditionsN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Opening strategy and use cases6484
Governance and ownership5379
Quality, freshness and metadata6182
Formats, licences and reuse conditions3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • ANITI
  • CNRS
  • LIRMM
  • CNES
  • Docaposte
  • KPMG

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Open data and API management maturity framework (non-certifying) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism, a level, the next level, and the action linking the two, that turns a finding into a trajectory.

How are API changes and retirements managed towards consumers?

  1. N1

    No versioning policy. Changes are deployed to production without prior notice to consumers.

  2. N2

    A versioning convention exists in the technical documentation, but its application depends on the team and announcements are informal.

  3. N3

    The versioning policy and deprecation window are documented and applied to most APIs. Consumers are notified ahead of any breaking change.

  4. N4

    Consumers are identified per API, notified automatically, and retirement only proceeds once migration has been confirmed.

  5. N5

    The policy is reviewed based on incidents and reuser feedback, with documented tracking of retired versions and supported migrations.

Action to move from L2 to L3

Set the deprecation window and announcement format in the API design guideline, publish the version calendar on the developer portal, and check compliance at the monthly architecture board.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurement

What this framework covers

This framework covers two sides of the same subject: data openness, both internal and external, and the lifecycle management of the APIs that make it usable. It assesses publication strategy, dataset quality and documentation, formats and licences, catalogue and discoverability, interface design, security and authentication, version management, consumption tracking and community engagement. Each theme is read through observable practices, not intentions.

In practice, governance often stumbles on simple questions. Who decides that a dataset or an API becomes a maintained product, with an owner and a service commitment? How many APIs actually exist across the IT estate, and how many are documented to the same standard? When a version changes, how are consumers notified, and within what deprecation window? Without a shared answer, the organisation accumulates interfaces without ever consolidating a reusable foundation.

The context has shifted. The EU Data Act and the Open Data Directive have established the notion of high-value datasets, accessible via application programming interfaces, with format and freshness requirements. At the same time, the rise of agents and AI use cases makes the API the primary entry point into systems. A common confusion worth clearing up: opening data is not the same as publishing files on a portal, and an API gateway is not an API strategy.

A compliance audit ends with a gap or a pass. This framework is not certifying and does not aim for that verdict. It answers a different question: what level of mastery has each practice reached, and what specific action moves it up a level. The score per theme, the gap to target and the comparison between business units produce a transformation trajectory rather than a binary finding.

The framework is ready to use and adapts. AI adjusts the themes, rephrases the questions and refines the levels using the CMMI method, or builds a variant from your own documents: data policy, API standards, publication charter. You remain the owner of the grid.

Reference standard: Open data and API management maturity framework (non-certifying)

The themes assessed

  • Opening strategy and use cases

    Existence of a publication strategy, dataset selection criteria, expected value, trade-off between internal, partner and public opening.

  • Governance and ownership

    Roles and responsibilities, an owner for each dataset and API, an arbitration body, alignment with existing data governance.

  • Quality, freshness and metadata

    Completeness, accuracy, update frequency, metadata standards, provenance traceability, anomaly reporting by users.

  • Formats, licences and reuse conditions

    Machine-readable formats, open standards, explicit licence, attribution requirements, pricing terms where they exist.

  • Catalogue and discoverability

    Inventory of datasets and APIs, developer portal, search functionality, functional description understandable to a non-specialist.

  • API design and standards

    Design guideline, naming conventions, OpenAPI specifications, data model consistency, test environment.

  • Security and access control

    Authentication and key management, fine-grained authorisation, rate limiting, personal data protection, inventory of exposed interfaces.

  • Lifecycle and version management

    Versioning policy, deprecation window, communication of breaking changes, retirement of obsolete interfaces.

  • Operations and service levels

    Monitoring, availability, service level commitments, incident management, consumption tracking and any related billing.

  • Ecosystem and value measurement

    Engagement with reusers, support and documentation, usage indicators, feedback fed back into the publication roadmap.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this framework lead to certification?

No. There is no body certifying data openness or API management. The assessment measures the maturity of the programme, sets a target and tracks progress over time.

What is the difference with an audit?

An audit checks for the presence of requirements and ends with a gap. The assessment places each practice on a progressive scale and produces the action that moves it up a level. The output is a roadmap, not a compliance report.

How long does the assessment take?

The short version can be completed in a single working session. In collaborative mode, with contributors from data, architecture and security, allow one to two weeks, with most of the time spent on data gathering.

Can the framework be adapted to our context?

Yes. You can amend the questions, levels and themes, or start from your own standards. AI generates a variant from your data policy and API design guideline, then refines the levels using the CMMI method.

Should the open data and API strands be assessed separately?

The two are best managed together, since data published without a usable interface remains under-used. You can nonetheless split the framework into two assessments and consolidate the results into a cross-organisational roadmap.

How can several business units be compared?

Each entity completes the same assessment, with a score per theme. The benchmark compares entities against each other and each one against its previous results. Recurring actions are grouped into shared workstreams.

Where is the data hosted?

In France, at OVH, with backup at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurement