How to Build a Skills Taxonomy for a Mid-Size Company (Without Consultants)
AI · SEPTEMBER 2026 · 13 MIN READ
By The Humavera Team
The method fits in four steps: adopt a public taxonomy, cut it down to your roles, add behavioural proficiency levels, and name an owner. It takes weeks rather than quarters, one person can carry most of it, and the source data is free. The O*NET 31.0 database, maintained by the U.S. Department of Labor and updated in August 2026, is published under a Creative Commons Attribution 4.0 licence — you can copy and adapt it commercially as long as you credit it, link to the licence and note your changes.
So the honest answer to how to build a skills taxonomy is that building is the wrong verb. Three credible taxonomies already exist in public. Every hour you spend inventing skill names reproduces work a public dataset did better, and that reinvention is exactly what turns this into a consultant-shaped project.
One warning before you start, and it matters more than anything else here. A taxonomy is not a deliverable, it is a dependency. It earns its cost only when something downstream reads from it. If nothing in your hiring, development or planning process is waiting for this list, stop now and come back when something is.
Answer this before you download anything.
Legitimate consumers: hiring criteria that reference skills instead of degree requirements, development plans that target named gaps, internal mobility matching, capacity and staffing decisions, succession planning. Each of those is a process that will break, visibly, if the skills data is missing or wrong. That breakage is what keeps a taxonomy alive.
“We want visibility into our skills” is not a consumer. Neither is “the board asked about our skills strategy.” Both produce a spreadsheet that is admired once and stale within a year.
When companies ask me for help with skills data, what usually arrives is a job architecture, some job descriptions of uneven vintage, and a competency framework somebody built in 2019 that nobody has opened since. The pattern is consistent enough to be a rule: the taxonomy is almost never the blocker. The blocker is that nothing downstream was ever waiting for it. Every one of those 2019 frameworks was fine. It just had no consumer, so it died.
If you only have one consumer, that is enough. Start there and build the list that serves it.
Here is your skills library setup, and it starts with a download rather than a workshop.
The licence is the differentiator. ONET 31.0 is distributed under Creative Commons Attribution 4.0 International, which means you may copy or adapt the information provided you credit the ONET database and the U.S. Department of Labor’s Employment and Training Administration as the original source, link to the licence, and indicate where you made changes. That is an unusually clean permission for a dataset of this quality, and not one page competing for this search leads with it.
What you get: 1,016 occupations under the O*NET-SOC taxonomy, with a content model of 3,006 elements spanning knowledge, abilities, skills, work activities, work styles and work context. It is occupation-anchored and research-grade, which cuts both ways. It is heavier on abilities and general work activities than on tool names, so it will tell you a role requires “critical thinking” but will not tell you it requires Snowflake.
The European Commission’s classification covers 3,039 occupations and 13,939 skills and competences, currently at version 1.2.1, last updated 10 December 2025. It is available through a free online portal, as a full download, and via an API.
The decisive feature for anyone operating across EU markets is that ESCO is translated into 28 languages — all official EU languages plus Icelandic, Norwegian Bokmål, Ukrainian and Arabic. If you employ people in five countries and want one skill to mean the same thing in each, that translation work has been done for you, and it is the single most expensive thing you would otherwise be paying someone to do. English-language content on this topic almost never mentions it.
One precision point, because it matters: the ESCO classification pages confirm free consultation and download, but do not state an explicit reuse licence. Describe it as free to download and use through the portal and API. Do not call it open-source or CC-licensed, and if you need a formal licence position for a commercial product, verify it at source before you rely on it.
More than 34,000 skills, organised in three levels — Category, then Sub-Category, then Skill — derived from hundreds of millions of job postings and professional profiles. Because it is built from postings, it moves with the market in a way the government datasets do not. When a new framework becomes a hiring requirement, it appears here first.
Be precise about what this is: a commercial vendor’s free tier, not an open dataset. The skills are browsable free on the web and there is a public changelog. API access is by request, and nonprofits registering to use it receive full access free of charge. No open licence is stated, so do not assume you may redistribute it inside a product.
US-only and you want to adapt freely: ONET. Operating across multiple EU countries, or you need one vocabulary in several languages: ESCO. You mostly need to name the technologies people actually list on their CVs: Lightcast. Mixing two is normal and I would expect most companies to end up doing it — an occupational spine from ONET or ESCO, with technology names layered in from Lightcast. Nobody will audit your sourcing. Pick the one that covers most of your roles and move.
This is the actual work, and it runs backwards from how people expect.
Start from your role list, not from the taxonomy. Take your live job architecture — every role you currently employ or plan to hire — and map each to its nearest occupation in your chosen source. Then pull the skills attached to those occupations, which will already have cut your working set by an order of magnitude.
Now delete. The test for keeping a skill is whether you would ever staff, train or hire against it. If you would not put it in a job posting, build a development plan around it, or use it to choose between two people for a project, it goes. Most of what remains after the occupational filter still fails this test.
Merge synonyms without mercy. “Data analysis”, “data analytics” and “analytical skills” are one entry, and the argument about which name wins should take ninety seconds. Keep a rejected tab listing what you cut and why, because otherwise you will re-litigate the same forty decisions every quarter for two years.
How granular? Granular enough that two managers would independently put the same person at the same level, coarse enough that you would actually staff or train against it. In practice, for a company of around 500 people, that lands at a few hundred skills, not thousands. I will say that number knowing it invites argument, because every vendor page refuses to say any number at all, and that refusal is precisely why those pages are useless to someone trying to start on a Monday.
Realistic time for a 500-person company: two to three weeks of part-time work for the filtering itself. The filtering is not the cost. The meetings are the cost, and every hour of disagreement about whether “stakeholder management” is one skill or three is an hour you should have capped at fifteen minutes and moved on from.
Spend more time here than on the list. A skills framework template with a good vocabulary and bad levels is unusable; the reverse is merely annoying.
Use three or four levels, defined behaviourally. Something close to: can do it with support, can do it alone, can teach it and set the standard. Notice these describe observable behaviour rather than attaching adjectives to it.
Adjectives are where these frameworks die. “Advanced” means nothing you can calibrate — it means whatever the rater felt at the time, which correlates with how much they like the person. “Can do it unsupervised” means something specific, and two people watching the same work will usually agree about it.
The test is straightforward and you should run it before rolling anything out. Take one job family, have two managers independently rate the same five people, and compare. If they disagree, your level definitions are wrong. Not the managers — the definitions. Rewrite them and run it again. This is a competency framework without consultants, and this calibration hour is the thing a consulting engagement would actually have been useful for.
I will be fair about that, because it makes the case stronger rather than weaker: what a good consultant genuinely sells you here is facilitation and political cover for the pruning arguments. They are not selling you the vocabulary, which is free. If your organisation cannot resolve a granularity argument without an outside referee, hire one for that and only that. Do not pay anyone to write a skills list.
Three options and none is clean. Self-assessment is fast and biased upward. Manager assessment is slower and biased in more interesting directions. Inference from actual work is the most accurate and by far the most expensive to set up.
For most mid-market companies the practical answer is self-assessment plus manager confirmation on the subset that matters — the skills tied to your consumer. If you built this for internal mobility, confirm the skills that actually appear in role requirements and let the rest sit as self-reported.
What to skip: do not try to score every person against every skill. A 500-person company with 300 skills is 150,000 judgements, which is how a skills project turns into a year of work that produces a matrix nobody trusts. Score people on the skills their role touches, and leave the grid deliberately sparse.
One named owner. Not a committee, one person, with it written into their objectives.
A quarterly review tied to something real — a hiring round, a planning cycle, promotion decisions. A review with no forcing event gets skipped in month seven.
A rule for adding: a skill enters when two different roles need it. A rule for removing: if nothing has referenced it in a year, it goes. And a warning sign worth watching for — if nobody has argued about the taxonomy in six months, it is not settled, it is dead. Live frameworks generate disagreement because people are using them for decisions that matter.
The spreadsheet stops scaling somewhere around the point where several systems each hold part of the picture and they start to disagree. That is where skills intelligence tooling earns its place, ours included — keeping one definition current across the HRIS, the ATS and whatever else holds skills data, so that last year’s ratings still mean what they meant. That is a year-two problem. Everything above is free and you should do it first.
A taxonomy does not tell you who is good at their job. It tells you what shape the work is, not how well it is done.
It does not fix a bad org design. If the problem is that three teams own the same outcome, naming skills more precisely will not help.
It does not predict performance. And it will not survive a reorganisation without real work, because your role list is the spine and a reorg rewrites the spine.
Hiring practice, incidentally, is the consumer most people build this for, and getting the criteria and the interview scoring right is a separate discipline that a taxonomy enables but does not deliver [pending: T-02].
For an HR function of three to eight people.
Week 1 — Pick the consumer and the source. Name the process that will read from this, and choose O*NET, ESCO or Lightcast by the decision rule above. Map your role list to occupations. Half a day of real work, plus one meeting to agree the consumer.
Week 2 — The cut. Pull the skills for your mapped occupations, apply the staff-train-hire test, merge synonyms, keep the rejected tab. End the week with a list of a few hundred.
Week 3 — Proficiency levels and calibration. Write three or four behavioural levels. Test them on one job family with two managers and five people. Rewrite whatever failed.
Week 4 — Populate one department and check whether the consumer actually used it. That last clause is the point of the whole month. If the process you named in week one did not touch the data, you have learned something more valuable than a finished taxonomy: you have learned this was not the constraint.
Do you need a skills taxonomy before skills-based hiring? No. You need agreed criteria for the roles you are hiring now, which is a much smaller job. A taxonomy helps once you want consistency across many roles, comparison between candidates over time, or ratings that still mean something next year. Starting with a full taxonomy is the most common way skills-based hiring projects stall before they hire anyone.
How many skills should a mid-size company’s taxonomy contain? For a company of around 500 people, a few hundred — not thousands. The test is whether two managers would place the same person at the same level, and whether you would ever staff, train or hire against the skill. Lists that run into the thousands are almost always copied wholesale from a source dataset without the pruning step, and nobody uses them.
Can you use a free public skills taxonomy commercially? It depends which one, and the differences matter. O*NET is Creative Commons Attribution 4.0 — adapt it commercially with credit, a link to the licence and a note of your changes. ESCO is free to download and use through its portal and API, but states no explicit licence on its classification pages. Lightcast Open Skills is a vendor free tier: browsable free, API access on request, no redistribution rights implied.
How many proficiency levels should a skills framework have? Three or four, defined by behaviour rather than adjectives. “Can do it with support”, “can do it alone”, “can teach it” beats a five-point scale nobody calibrates. More levels create more disagreement without adding information, because the boundaries between them stop being observable. If two managers cannot independently agree on a rating, the definitions need rewriting.
How long does it take to build a skills taxonomy? Four weeks part-time for a mid-size company, if you adopt a public dataset instead of writing one. The filtering work is two to three weeks; the rest is proficiency levels and calibration. Projects that run six months are almost always inventing vocabulary from scratch or trying to score every employee against every skill, and both are avoidable.