06. Open and Closed CDEs: What the Difference Means for Your Data

An open CDE is a Common Data Environment (CDE) whose record can move. Files, version history, metadata and approval evidence can be read out of it by other systems, in a form another platform can use. A closed CDE keeps the record inside one vendor's environment, where the full context of a document exists only while the licence is current. 

Most organisations hold both positions at once. The corporate platform is closed, one delivery joint venture runs something else, and a handful of exports keep the two roughly aligned. The question is which position you have chosen deliberately and which one you have inherited. 

This article covers: 

  • What an open CDE and a closed CDE are 

  • What a closed CDE does well 

  • What an open posture provides 

  • The difference between platform selection and data custody 

  • Practical signals of CDE vendor lock-in 

  • Planning for renewal repricing 

  • Keeping your platform and adding a neutral connection layer 

What is an open CDE and what is a closed CDE?

The distinction is about what leaves the platform, not about how many application programming interfaces a vendor publishes. An open CDE exposes the whole record, including superseded revisions, custom metadata, workflow state and the audit trail, in a form another system can read and reassemble. A closed CDE exposes the files and leaves the rest inside the platform. 

Almost every platform can export documents. Fewer can export a project record. Where the difference lands is in the material an organisation would need years later to answer a claim, satisfy a regulator or hand an asset to an operator. 

Openness is also a spectrum rather than a label. A platform can be closed on approvals and open on files, or open on models and closed on transmittals, and the useful assessment is attribute by attribute. 

What a closed CDE gets right

A closed CDE gives an organisation one coherent security model. One identity provider, one permission structure, one set of audit logs, and one place where a security assessment lands. Reproducing that control environment across four platforms is real work, and much of it falls on people who are already fully committed to delivery. 

Support is simpler as well. When something fails the week before a stage gate submission, there is no dispute about which vendor caused it, and behaviour stays predictable because a single vendor controls the whole path from upload to approval. 

A regulated owner may reasonably choose a closed CDE for those reasons. An operator under a critical infrastructure regime such as the SOCI Act has to evidence its control environment to a regulator, and a single assessed platform is cheaper to evidence than an assembled one. That is a considered trade of flexibility for auditability. 

What an open posture provides

An open posture provides reach into the supply chain. Subcontractors, surveyors, specialist designers and asset teams run platforms of their own, and moving them onto yours means paying for licences, training, migration and the productivity dip that follows. Deloitte and Autodesk found in their 2025 State of Digital Adoption research that construction businesses across Asia Pacific use a median of 11 separate data environments, so a supply chain that arrives with its own tools is the normal case. 

Switching cost is the second benefit. Where the record can leave in a usable form, an organisation retains a real alternative at renewal, and the internal conversation about the platform stops being hypothetical. 

Exposure to a single roadmap falls too. When a vendor retires a module, changes a data model or shifts its development priorities, an organisation whose record also exists elsewhere absorbs the change without reorganising around it. The cost of the open position is genuine: more identity surfaces, more contracts, more places for a permission to be set wrongly, and a compliance story you assemble yourself. 

Platform selection, data custody and the ninety day test

This is usually run as a platform selection exercise, with a features matrix, a security questionnaire and a price comparison. The decision that actually persists is a data custody decision, because the platform will be replaced long before the record stops being needed. Why CDE Migration Matters: The Platform Is Temporary, The Record Isn't sets out how long that gap usually is. 

There is a practical test for it. If your organisation decided today to leave the platform, could it be fully operational elsewhere within ninety days, with the record intact, including version history, metadata, approval state and audit trail? Answer it against your largest estate, where the cost of leaving is real. 

A negative answer describes a lock-in position regardless of how open the platform is said to be. Write the answer down, put the gap on the risk register, and review it before each renewal comes up. 

Four practical signals of CDE vendor lock-in

  • Version history that does not export. Files come out at their latest revision and the superseded chain stays behind. Anything later needed for a dispute then sits in a platform the organisation no longer pays for. 

  • Metadata that exists only in the vendor's schema. Custom fields, suitability values and workflow attributes with no representation in any export format. Large public sector projects routinely require in excess of a hundred individual metadata fields per document, and a partial export of that is not a record. 

  • Approval state with no external representation. Who approved what, when, and against which revision. Where that lives only inside the platform's review module, it does not travel with the file. 

  • Pricing that escalates with estate size. Per project or per data volume models that are inexpensive at pilot scale and become a major line in the digital budget once the estate reaches programme scale. 

Planning for renewal repricing

Vendors reprice, and it is a normal commercial act. The CDE market is projected to grow from US$6.2 billion in 2023 to US$24.9 billion by 2032 on Asite and Construction Management figures, and a market growing at that rate attracts investment, consolidation and pricing discipline. 

Treat the platform as a single-supplier dependency and plan for it the way you would plan for any other. Know what the record looks like outside the platform, know approximately what an exit would cost in effort and elapsed time, and refresh both figures annually. Data residency and sovereignty obligations belong in the same review, and Data Sovereignty and Residency: Moving Your CDE Data Where Compliance Requires covers what those obligations require of a platform choice. 

Keeping your platform and adding a neutral connection layer

The choice is not restricted to two options. An organisation can keep the platform its teams know and its auditors have assessed, and add a connection layer beneath it so that the record also exists somewhere the organisation controls. Openness then belongs to the architecture rather than to a vendor's roadmap. 

CDE Sync™ works on that basis. It streams models, documents and metadata between platforms without storing project files, retaining only encrypted credentials and synchronisation logs, and it preserves version history and workflow state across the connection. Where a move becomes the right answer, CDE Migrate™ handles the one-time transfer with folder structure, version history, metadata and audit trail preserved. 

Closed, open and platform plus neutral layer compared

Dimension Closed CDE Open CDE posture Platform plus neutral layer
Security model One model, one audit surface Several models to reconcile The platform’s model, plus a connection with its own controls
Support Single vendor accountability Several vendors, shared responsibility Platform vendor plus connection vendor
Supply chain reach Partners adopt your platform Partners keep their own tools Partners keep their own tools
Switching cost High, and rises with estate size Low by design Falls as the record exists in more than one place
Pricing exposure Full exposure at renewal Spread across several vendors Reduced, because the estate can credibly move
Compliance story Inherited from the vendor Assembled by you Inherited, plus synchronisation logs

Is an open CDE less secure than a closed one?

Not inherently, though the security work is distributed across more parties. A closed platform hands you one control environment to assess. An open posture means assessing each platform and the connection between them, so look for a connection layer with its own certifications, encrypted credential storage and audit logging, evidenced in a security and trust portal

How do I tell whether we are locked into our CDE?

Ask your document control lead what a full export actually contains. If superseded revisions, custom metadata fields and approval history are missing from the answer, the organisation is locked in to the extent of what is missing. The ninety day test formalises it: fully operational elsewhere, with the record intact, inside a quarter. 

Can we stay on our current CDE and still be open?

Yes, and for most organisations that is the sensible answer. A neutral synchronisation layer keeps the record in a second location under your own control while day to day work continues in the platform your teams already know and your auditors have already assessed. 

Under ISO 19650 at BIM Stage 2, the level most projects operate at, multiple CDE solutions on one project are permitted, so a mixed estate is a compliant position. CDE Sync gives an organisation an open posture without asking it to leave a platform that works, and CDE Migrate handles the move when leaving is the right call. Get in touch for a view of what your record would look like outside your current CDE. 

Previous
Previous

07. CDE Backup: Holding an Independent Copy of Your Project Record 

Next
Next

05. CDE Connectors and Connected CDEs: What the Difference Means at Scale