Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 23257

Blockchain and DLT - Reference Architecture

Technology & Innovation Published: 2022

ISO 23257:2022 at a glance

Current edition
ISO 23257:2022 - Blockchain and distributed ledger technologies — Reference architecture
Published
2022
Status
Published
Type of standard
Guidance
Certifiable
No — used for reference and implementation, not certification
Official ISO page
View ISO 23257:2022 on iso.org
Last verified

Overview

Reference architecture for blockchain and distributed ledger technology systems, defining concepts, roles, functional components and architectural views

ISO 23257:2022 specifies a reference architecture for distributed ledger technology (DLT) systems, including blockchain systems. It was published in February 2022 by ISO/TC 307 as a full International Standard. It is an architectural reference rather than a requirements standard, so organizations and products are not certified against it.

The document addresses concepts, cross-cutting aspects, architectural considerations and architecture views, describing functional components, roles, activities and their relationships for blockchain and DLT systems. Its purpose is to give architects, procurers and regulators a common structure for describing and comparing systems that are otherwise described in vendor-specific terms.

Roles are a central organising device, building on the vocabulary of ISO 22739: DLT users, DLT node operators, DLT service providers, application providers, and supporting roles such as auditors and regulators. Defining who performs which activity is what makes governance, liability and assurance questions tractable in systems that are deliberately decentralised.

The functional view covers the components that recur across DLT platforms: ledger and ledger record management, consensus and transaction ordering, node and network management, identity and key management, smart contract execution, APIs and integration interfaces, and operations, monitoring and administration functions.

Cross-cutting aspects cover the concerns that cannot be isolated in a single component — security, privacy and personally identifiable information protection, governance, interoperability, performance and scalability, and auditability. These sections are often the most useful part of the standard in practice, because they name the trade-offs (for example between immutability and data protection rights, or between decentralisation and throughput) that DLT projects must resolve explicitly.

Typical uses include structuring solution architecture documentation, writing platform-neutral procurement requirements, comparing candidate platforms on consistent criteria, defining audit and assurance scope, and supporting regulatory dialogue about how a proposed system actually works.

Related documents from ISO/TC 307 include ISO 22739 (vocabulary), ISO/TS 23635 (guidelines for governance), ISO/TR 23455 (smart contracts overview), ISO/TR 23244 (privacy and PII protection) and ISO/TR 23578 (discovery issues related to interoperability). For general architecture description practice, ISO/IEC/IEEE 42010 provides the underlying conventions.

Purpose

To provide a platform-neutral reference architecture — concepts, roles, functional components, views and cross-cutting concerns — for describing, designing, comparing and assessing blockchain and distributed ledger technology systems.

Key Benefits

  • Gives a vendor-neutral structure for describing and comparing DLT platforms
  • Defines roles and responsibilities in decentralised systems, clarifying governance and accountability
  • Identifies the functional components common to blockchain and DLT systems
  • Names cross-cutting concerns such as security, privacy, interoperability and auditability explicitly
  • Supports platform-neutral procurement requirements and evaluation criteria
  • Provides a common basis for audit, assurance and regulatory discussion
  • Builds directly on the ISO 22739 vocabulary, keeping terminology consistent
  • Helps teams surface trade-offs such as immutability versus data protection rights
  • Useful for architecture documentation aligned with ISO/IEC/IEEE 42010 practice
  • Applicable to permissioned and permissionless, public and private systems alike

Key Requirements

  • Note: ISO 23257 is a reference architecture — it is applied as design and description guidance, not certified against
  • Use the defined roles — DLT user, DLT node operator, DLT service provider and related roles — when describing a system
  • Describe the system using the architecture views set out in the standard
  • Identify the functional components present, including ledger management, consensus and node management
  • Address identity, credential and cryptographic key management within the architecture
  • Describe smart contract execution capability where present, including deployment and lifecycle
  • Define APIs and integration interfaces with external systems
  • Address the cross-cutting aspect of security across components and interfaces
  • Address privacy and protection of personally identifiable information, including data minimisation on-ledger
  • Address governance arrangements for the DLT system and its participants
  • Address interoperability with other DLT and conventional systems
  • Address performance, scalability, availability and auditability considerations
  • Use the vocabulary of ISO 22739 consistently throughout architectural documentation

Who Needs This Standard?

Solution and enterprise architects designing DLT systems, procurement teams evaluating blockchain platforms, auditors and assurance providers scoping DLT engagements, regulators and policy teams assessing proposed systems, and consortium participants defining shared governance.

Where to get ISO 23257

The full text of ISO 23257 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 23257 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Our AI Risk Assessment Workbook is a set of blank, printable templates for running an AI risk process: an AI system inventory, a risk register with worked example rows, a likelihood and impact scoring matrix, a treatment plan and a monitoring log. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Related Standards