EU Cybersecurity Act

Certification

EU Cybersecurity Act — ENISA certification mapped to your product roadmap.

The EU cybersecurity certification framework — for ICT products, services, and processes. EUCC, EUCS, and the CRA-driven CE-marking regime that lands on 11 December 2027.

Overview

A certification framework that becomes mandatory in pieces.

The EU Cybersecurity Act — Regulation (EU) 2019/881 — has two distinct parts. Part I (Articles 1–11) gives ENISA, the EU Agency for Cybersecurity, a permanent mandate, increased resources, and authority over EU cybersecurity policy and certification. Part II (Articles 46–68) establishes the EU cybersecurity certification framework: a structured system for certifying ICT products, services, and processes against common European standards.

Certification under the EU CSA is voluntary. What changes the calculation is the Cyber Resilience Act — a separate regulation, (EU) 2024/2847 — which from 11 December 2027 makes cybersecurity a condition of CE marking for products with digital elements. A European certification scheme at assurance level at least substantial is one of the routes to demonstrating that conformity, and the only route for some product classes. A voluntary framework is quietly becoming the compliance path of least resistance.

Who the EU CSA applies to

Anyone building or selling ICT products, services, or processes in the EU — and increasingly anyone supplying NIS2-covered customers.

  • ICT vendors and manufacturers

    Hardware security modules, network equipment, smart cards, OS, embedded systems. Once the CRA product regime applies (11 December 2027), CE marking is conditional on cybersecurity conformity.

  • Cloud service providers

    IaaS, PaaS, SaaS — the upcoming EUCS scheme covers availability, confidentiality, integrity, and portability across all three assurance levels.

  • Software companies and SaaS

    Increasingly required as a procurement signal, particularly for public-sector buyers and NIS2-covered enterprise customers.

  • Critical infrastructure suppliers

    5G network components and other critical-infrastructure technology — EU5G scheme in development.

  • Suppliers to NIS2-covered entities

    NIS2-covered organisations assessing their ICT supply chain are increasingly requiring supplier certification under EU schemes as evidence of appropriate security.

Three assurance levels

How rigorous the assessment is.

  1. 01Basic

    Documentation review and self-assessment

    No third-party evaluation required. Typical for consumer IoT, standard software, low-criticality IT services.

  2. 02Substantial

    Independent CAB testing against attack scenarios

    Testing by an independent Conformity Assessment Body (CAB). Typical for professional software, cloud services, business network equipment.

  3. 03High

    National authority or accredited body, stringent methodology

    Most rigorous evaluation. Typical for critical infrastructure, government systems, high-security network equipment.

  4. 04EUCC

    EU Common Criteria scheme — LIVE since Jan 2024

    Replaces national Common Criteria schemes (including French CSPN). Substantial and high assurance levels for ICT products. Based on ISO/IEC 15408.

  5. 05EUCS

    EU Cloud Services scheme — IN DEVELOPMENT

    For IaaS, PaaS, SaaS. Will cover availability, confidentiality, integrity, and portability at all three assurance levels.

  6. 06EU5G

    EU 5G certification — IN DEVELOPMENT

    Certification scheme for 5G network components and technology. Critical-infrastructure focus.

Consequences (commercial)

No statutory fines. Market access is the lever.

The Cybersecurity Act itself does not specify direct fines for non-certification — but the consequences of not having certification compound through three mechanisms.

First, public procurement: EU institutions and member-state governments are increasingly requiring EUCC or EUCS certification in tenders. Second, NIS2 supply chain requirements: NIS2-covered entities push certification down their supply chain as evidence of supplier security. Third, the Cyber Resilience Act: from 11 December 2027, CE marking for products with digital elements is conditional on cybersecurity conformity, and its own fines reach €15M or 2.5% of worldwide turnover. No conformity, no CE mark, no EU market access.

  • CRA CE marking

    11 Dec 2027

    cybersecurity conformity becomes a condition of CE marking for products with digital elements.

  • Public procurement

    Trending

    EU and national tenders increasingly require EUCC or EUCS certification.

  • Lost market access

    EU-wide

    no certification, no eligibility for affected procurement and CRA-scope products.

Our approach

Scheme selection, gap analysis, certification roadmap.

What we deliver

  • Scheme applicability assessment — EUCC vs EUCS vs EU5G, and at what assurance level
  • CRA readiness assessment — what changes for your products, and when, under Regulation (EU) 2024/2847
  • Gap analysis identifying evidence, documentation, and technical controls needed
  • ISO 27001 leverage — most schemes accept ISMS evidence; we design implementations with certification readiness in mind
  • Documentation pack for CAB submission (substantial level) or national authority (high level)
  • CAB / authority selection guidance
  • Pre-assessment readiness review
  • Ongoing maintenance for certified products — surveillance, recertification, evidence updates

Typical timeline

Depends on scheme, assurance level, and product maturity.

  1. Weeks

    Basic assurance — well-documented product

    Self-assessment plus documentation pack. Fastest path; suitable for consumer-grade and low-criticality products.

  2. 6–12 months

    Substantial assurance (EUCC) — CAB-led

    For products already aligned with Common Criteria and ISO 27001. CAB testing against defined attack scenarios.

  3. 12–24 months

    High assurance — national authority or accredited body

    Most stringent path — for critical infrastructure and high-security products.

FAQ

Common questions.

Does the EU Cybersecurity Act apply to software companies and SaaS providers?
Increasingly, yes — through three pathways. (1) Public procurement bidding where EU/national tenders require certification. (2) NIS2 supply chain pressure from covered customers. (3) From 11 December 2027, CRA-driven CE marking for software products that fall in scope — with the CRA reporting obligation already live since 11 September 2026. Even today, the EUCS scheme (in development) targets cloud and SaaS specifically.
What is EUCC and does it replace national certifications?
EUCC is the EU Common Criteria scheme, adopted January 2024 — based on ISO/IEC 15408. It covers hardware security modules, operating systems, network equipment, smart cards, and similar at substantial and high assurance levels. EUCC replaces the previous national Common Criteria schemes across EU member states, including the French CSPN scheme, the German BSI scheme, the Italian OCSI scheme, and the Dutch NSCIB scheme. Holders of national CC certifications transition to EUCC under defined arrangements.
What is the Cyber Resilience Act and how does it relate?
The Cyber Resilience Act — Regulation (EU) 2024/2847 — is a separate regulation, not an amendment to the EU CSA, but the two are designed to interlock. It sets essential cybersecurity requirements for products with digital elements and, from 11 December 2027, makes CE marking conditional on a cybersecurity conformity assessment; its Article 14 reporting obligation has applied since 11 September 2026. A European cybersecurity certification scheme adopted under the EU CSA at assurance level at least substantial is one of the accepted conformity routes — and for Annex III class II and Annex IV critical products, the alternative is a notified body. CRA does not replace the EU CSA; it turns CSA certification into a market-access instrument for a much wider product set.
How does EU cybersecurity certification help with NIS2 compliance?
NIS2 covered entities are required to assess and manage ICT supply chain risk under Article 21(2)(d). They use EU CSA certification as evidence of appropriate security. If your customers are NIS2-covered, expect increasing pressure to hold an applicable certification — even before procurement makes it formal.
How long does certification take and what does it cost?
Time and cost depend heavily on the scheme (EUCC vs EUCS), the assurance level (basic/substantial/high), and the current security maturity of the product or service. Basic-assurance certifications can complete in weeks for a well-documented product. Substantial-assurance EUCC typically runs 6–12 months through a CAB. High-assurance certification can run 12–24 months. Pricing is shared in the proposal after the scoping call.
Does existing ISO 27001 help with Cybersecurity Act certification?
Yes — significantly. EUCC products must align with Common Criteria and ISO 27001. EUCS expects ISO 27001 (and preferably ISO 27701) as the baseline governance foundation. Organisations with existing ISO 27001 certification have already done much of the documentation, risk assessment, and policy work that the EU schemes require — often reducing certification effort by 40–50%.