EU Cybersecurity Act — ENISA certification mapped to your product roadmap.
The EU cybersecurity certification framework — for ICT products, services, and processes. EUCC, EUCS, and the CRA-driven CE-marking regime that lands on 11 December 2027.
Overview
A certification framework that becomes mandatory in pieces.
The EU Cybersecurity Act — Regulation (EU) 2019/881 — has two distinct parts. Part I (Articles 1–11) gives ENISA, the EU Agency for Cybersecurity, a permanent mandate, increased resources, and authority over EU cybersecurity policy and certification. Part II (Articles 46–68) establishes the EU cybersecurity certification framework: a structured system for certifying ICT products, services, and processes against common European standards.
Certification under the EU CSA is voluntary. What changes the calculation is the Cyber Resilience Act — a separate regulation, (EU) 2024/2847 — which from 11 December 2027 makes cybersecurity a condition of CE marking for products with digital elements. A European certification scheme at assurance level at least substantial is one of the routes to demonstrating that conformity, and the only route for some product classes. A voluntary framework is quietly becoming the compliance path of least resistance.
Who the EU CSA applies to
Anyone building or selling ICT products, services, or processes in the EU — and increasingly anyone supplying NIS2-covered customers.
ICT vendors and manufacturers
Hardware security modules, network equipment, smart cards, OS, embedded systems. Once the CRA product regime applies (11 December 2027), CE marking is conditional on cybersecurity conformity.
Cloud service providers
IaaS, PaaS, SaaS — the upcoming EUCS scheme covers availability, confidentiality, integrity, and portability across all three assurance levels.
Software companies and SaaS
Increasingly required as a procurement signal, particularly for public-sector buyers and NIS2-covered enterprise customers.
Critical infrastructure suppliers
5G network components and other critical-infrastructure technology — EU5G scheme in development.
Suppliers to NIS2-covered entities
NIS2-covered organisations assessing their ICT supply chain are increasingly requiring supplier certification under EU schemes as evidence of appropriate security.
Three assurance levels
How rigorous the assessment is.
- 01Basic
Documentation review and self-assessment
No third-party evaluation required. Typical for consumer IoT, standard software, low-criticality IT services.
- 02Substantial
Independent CAB testing against attack scenarios
Testing by an independent Conformity Assessment Body (CAB). Typical for professional software, cloud services, business network equipment.
- 03High
National authority or accredited body, stringent methodology
Most rigorous evaluation. Typical for critical infrastructure, government systems, high-security network equipment.
- 04EUCC
EU Common Criteria scheme — LIVE since Jan 2024
Replaces national Common Criteria schemes (including French CSPN). Substantial and high assurance levels for ICT products. Based on ISO/IEC 15408.
- 05EUCS
EU Cloud Services scheme — IN DEVELOPMENT
For IaaS, PaaS, SaaS. Will cover availability, confidentiality, integrity, and portability at all three assurance levels.
- 06EU5G
EU 5G certification — IN DEVELOPMENT
Certification scheme for 5G network components and technology. Critical-infrastructure focus.
Consequences (commercial)
No statutory fines. Market access is the lever.
The Cybersecurity Act itself does not specify direct fines for non-certification — but the consequences of not having certification compound through three mechanisms.
First, public procurement: EU institutions and member-state governments are increasingly requiring EUCC or EUCS certification in tenders. Second, NIS2 supply chain requirements: NIS2-covered entities push certification down their supply chain as evidence of supplier security. Third, the Cyber Resilience Act: from 11 December 2027, CE marking for products with digital elements is conditional on cybersecurity conformity, and its own fines reach €15M or 2.5% of worldwide turnover. No conformity, no CE mark, no EU market access.
CRA CE marking
11 Dec 2027
cybersecurity conformity becomes a condition of CE marking for products with digital elements.
Public procurement
Trending
EU and national tenders increasingly require EUCC or EUCS certification.
Lost market access
EU-wide
no certification, no eligibility for affected procurement and CRA-scope products.
Our approach
Scheme selection, gap analysis, certification roadmap.
What we deliver
- Scheme applicability assessment — EUCC vs EUCS vs EU5G, and at what assurance level
- CRA readiness assessment — what changes for your products, and when, under Regulation (EU) 2024/2847
- Gap analysis identifying evidence, documentation, and technical controls needed
- ISO 27001 leverage — most schemes accept ISMS evidence; we design implementations with certification readiness in mind
- Documentation pack for CAB submission (substantial level) or national authority (high level)
- CAB / authority selection guidance
- Pre-assessment readiness review
- Ongoing maintenance for certified products — surveillance, recertification, evidence updates
Typical timeline
Depends on scheme, assurance level, and product maturity.
Weeks
Basic assurance — well-documented product
Self-assessment plus documentation pack. Fastest path; suitable for consumer-grade and low-criticality products.
6–12 months
Substantial assurance (EUCC) — CAB-led
For products already aligned with Common Criteria and ISO 27001. CAB testing against defined attack scenarios.
12–24 months
High assurance — national authority or accredited body
Most stringent path — for critical infrastructure and high-security products.
FAQ