Catena-X Participation Readiness for Suppliers (2026)

catena-x-participation-readiness-compliance-guide

Most readiness conversations about Catena-X collapse three separate things into one word. Participation has an identity layer, a connectivity layer and a use case layer, and each is independently necessary — you can complete registration, receive your business partner number and be a verified participant while remaining unable to exchange a single record, because a verified identity with no connector is a name with no channel. The connector itself is also widely misunderstood: it negotiates access and usage policies between endpoints, and no data is processed or reviewed inside it. Your data does not go into Catena-X. It stays where it is, and the connector governs who may reach it. Understanding that distinction changes both the internal conversation and the honest answer to how ready you actually are. Talk to a solutions engineer about which layer is your real constraint.

Data Ecosystems · Participation Readiness

Catena-X Participation Readiness for Suppliers

The three layers you need before anything moves, what a connector actually does and does not do, the release timetable that sets your deadline, and a readiness assessment that names the constraint honestly.

Layer 1IdentityBusiness partner number and credentials — you exist in the data space
Layer 2ConnectivityAt least one connector per legal entity — mandatory, and you now have a channel
Layer 3Use caseAn application and the underlying data — you can finally exchange something

Three Layers, All Required

Sorting them out first prevents the most common failure in these programmes: declaring completion at layer one.

Swipe to see all columns
Layer What it consists of What it requires from you What you still cannot do
Identity Registration, company information validated, then a business partner number issued as your digital identity. Three credentials complete it — membership, business partner number and framework agreement Company data, a decision on which roles you want in the data space, and a certificate of conformity from an assessment body where the role requires one Exchange any data at all. You are verified and inert
Connectivity A dataspace connector — your technical access point for publishing, discovering and managing data offerings Deployment and operation of at least one connector per legal entity. This is mandatory rather than recommended Do anything useful with it, because the connector moves data it has no application to source
Use case An application for the specific exchange you need, plus the underlying data at the granularity that application expects Either an app integrating with your existing systems, or a standalone one. Many marketplace offerings bundle the connector with the application Nothing — at this point you are actually participating
Two identity details worth noting early because they surface as questions later. Legal entities are identified separately, so a group with several registered companies has an identity question before it has a technical one. And you will be asked whether you want your own wallet instance or one provided for you — a decision easier to make deliberately at registration than to revisit afterwards.

What the Connector Actually Does

The single most useful thing to be able to explain internally, because it dissolves the objection that usually stalls these programmes.

The common assumption Our data goes into a shared platform The mental model most people arrive with — a central repository where participants deposit information, governed by somebody else's rules and visible to parties you did not choose.
What is actually happening Peer-to-peer exchange, with your data where it already is There is no central cloud storing the data and no central authority routing it. The connector negotiates usage between endpoints by synchronising access and usage policies between provider and consumer — and no data is processed or reviewed inside the connector itself. Data usage happens at the endpoints, not in transit.
There is a practical consequence for groups worth acting on. Because the requirement is one connector per legal entity, published guidance recommends that a parent company provides a connector its subsidiaries can also use, specifically to minimise effort and cost. For a group with several registered companies that is a materially different budget from one connector each.
Quick readiness check Which legal entities need identities? Own wallet, or provided? One connector, or one per entity? Does the data exist per part?
The fourth question is the one that decides your timeline
The first three have known answers and defined costs. The fourth is where readiness programmes actually stall, because no amount of connector work compensates for material or carbon data held at plant level when the use case asks about a part number. Bring one product line to a 30-minute session and we'll establish which of the four is your real constraint.

The Release Timetable Is Your Deadline

Version lifecycles are published with end dates, which turns a vague intention into a dated plan.

Swipe to see all columns
Release Went live Maintained until What it means for you
Jupiter October 2024 Q4 2026 Applications had roughly a year to certify against the following release. If you are being offered something built to this version, ask about its certification path
Saturn November 2025 Through 2027 The current target for new deployments, with a support horizon long enough to justify implementation now rather than waiting
Use those dates in two ways. When evaluating any marketplace application, ask which release it is certified against and when that release stops being maintained — a solution certified only to an expiring version is a migration project you have not budgeted for. And when building an internal case, an end-of-maintenance date is considerably more persuasive than an argument about ecosystem momentum.

The Path, Step by Step

Six stages. The first two are administrative, the third is technical, and the rest determine whether any of it produces value.

1Register and provide company informationA short registration, then an invitation to set credentials and supply additional company detail. Straightforward, and the point at which the role and wallet questions arise.
2Validation, then your business partner numberOnce information is validated, the identifier is issued and you are notified. At that point you are a verified participant — which is a milestone rather than a capability.
3Identify the use case before choosing anythingWhich exchange actually serves a business need — traceability, carbon reporting, quality, demand and capacity, business partner data. This decision governs which application you need and what data you must assemble, so making it after procuring a connector is doing the work backwards.
4Deploy a connector, and an applicationOne connector per legal entity is mandatory. Many marketplace offerings combine connector and use case application in a single package, which is usually the shorter route for a first deployment.
5Test, then move to productionOnboarding services typically cover secure exchange on both test and production environments. Treat the test phase as where you discover what your data cannot yet answer, because that is what it is for.
6Invite partners and scale graduallyExtend across additional suppliers, customers and production sites, and add use cases once the first is stable. The recommended sequence is deliberately incremental rather than comprehensive.

Two Integration Routes

The choice is genuinely open, and the right answer depends on what you already run rather than on which is more sophisticated.

Integrate with existing systems
Select applications that fit into the infrastructure you already have. Longer to stand up, and the right choice where the data feeding the use case already lives in an enterprise system that will remain the source of truth.
Standalone or turnkey
Independent applications giving direct access, in a modular arrangement. Faster to demonstrate value, and frequently the sensible first move — establish that the exchange works and produces something useful before committing to deep integration.
Or an onboarding service provider
Certified providers offer packaged onboarding covering readiness assessment, connector setup, compliance validation and production deployment. Worth considering where internal capacity rather than internal capability is the constraint.

The Readiness Checklist Nobody Sends You

Drawn from published pre-onboarding practice. Four of these are organisational rather than technical, which is why technically capable companies still stall.

Data processing agreements in placeNamed explicitly as a pre-onboarding task. Legal review has its own lead time and runs in parallel with nothing, so starting it late delays everything behind it.
Internal team allocatedNamed people with time assigned, not a project sponsor and good intentions. The technical work is modest; the coordination across IT, quality, procurement and legal is not.
Technical pre-checks completedInfrastructure, connectivity and hosting decisions settled before the connector conversation starts, so that discussion is about configuration rather than about whether you have somewhere to run it.
Roles decidedWhich roles you want in the data space, since some require a certificate of conformity from an assessment body — an external dependency with its own timeline.
Data granularity honestly assessedThe item that is not on anyone's standard checklist and determines everything. If the use case asks for information per part number and you hold it per plant, connectivity readiness is irrelevant — you have a data problem wearing a technology costume.
Connectivity is a project. Data granularity is a programme.
The connector, the identity and the application are all bounded pieces of work with known shapes and available help. Assembling material, carbon or traceability data at the level a use case requires is the part that touches every plant and every part number — and it is the only one that cannot be outsourced to an onboarding provider. Establishing which of those you are facing is the first honest step.
Identity · weeks Connector · weeks Data at the right granularity · months

Frequently Asked Questions

What do we actually need to participate?

Three things, all required. An identity — registration, validation and a business partner number serving as your digital identity, completed by membership, business partner number and framework agreement credentials. Connectivity — at least one dataspace connector per legal entity, which is mandatory rather than optional. And a use case application with the underlying data behind it. Completing the first without the other two makes you a verified participant who cannot exchange anything.

Does our data get uploaded somewhere?

No, and this is the point worth explaining internally. There is no central cloud storing data and no central authority routing it — exchange is peer-to-peer through each participant's own connector. The connector negotiates usage between endpoints by synchronising access and usage policies, and no data is processed or reviewed inside it. Data usage happens at the endpoints of the provider and consumer, not in transit.

How many connectors does a group need?

At least one per legal entity is the mandatory baseline, since legal entities carry their own identifiers. But published guidance specifically recommends that a parent company provides a connector its subsidiaries can also use, to minimise effort and cost. For a group with several registered companies, clarifying that early materially changes the budget and the deployment plan.

Which release should we target?

Saturn went live in November 2025 and is maintained through 2027, which makes it the sensible target for new deployments. Jupiter launched in October 2024 and is maintained until the fourth quarter of 2026. When evaluating any application, ask which release it is certified against and when that release stops being maintained — a solution certified only to an expiring version is an unbudgeted migration.

Should we integrate or start standalone?

Both routes are supported. Applications that integrate into existing infrastructure suit cases where the data already lives in a system that will stay the source of truth. Standalone or turnkey applications give faster direct access and are frequently the better first move, since they establish that the exchange works before you commit to deep integration. Many marketplace offerings bundle the connector with the use case application, which shortens a first deployment considerably.

What should we do before contacting anyone?

Five things: get data processing agreements moving since legal review has its own lead time, allocate named internal people rather than a sponsor, complete technical pre-checks on infrastructure and hosting, decide which roles you want since some require a certificate of conformity from an assessment body, and assess your data granularity honestly. The first four appear on standard pre-onboarding checklists. The fifth does not, and it is the one that decides your timeline.

What usually causes the delay?

Not the technology. Identity and connectivity are bounded pieces of work with known shapes, published guidance and certified providers offering packaged onboarding. The constraint is almost always whether your material, carbon or traceability data exists at the granularity the use case requires — held per part number rather than per plant. That work touches every site and every part, cannot be outsourced, and is measured in months rather than weeks. Start free with three assets and get the granularity right first.

Get the Identity Right, Then Ask the Honest Question
Sort out which legal entities need identifiers and whether one connector can serve the group, choose the use case before procuring anything, target the release with the longer maintenance horizon, and then assess whether your data sits at the level the use case will ask for — because everything else on this page is a project with a known shape, and that last one is the programme.
Membership credential Business partner number credential Framework agreement credential
Standards, release dates, roles and onboarding steps reflect published documentation at the time of writing and continue to develop. Confirm current requirements with the operating company or a certified onboarding provider before scoping any implementation.
September 10, 2026 By Alex Rowan
All Articles

Share This Story, Choose Your Platform!

Latest Articles

Scroll