About ANCC
The Secretary of State Director of the National Intelligence Center, as the director of the National Cryptological Center (CCN), has been appointed in Spain as the National Cybersecurity Certification Authority (ANCC) for the certification schemes developed under Regulation (EU) 2019/881 and the national implementation of that regulation.
According to Article 58 of this Regulation (EU) 2019/881 of the European Parliament and of the Council, of April 17, 2019, concerning ENISA, also known as the Cybersecurity Regulation, each member State must designate one or more national cybersecurity certification authorities. The CCN, as the support office for the ANCC, is responsible for overseeing and managing the implementation of cybersecurity certification frameworks in our country.
The main responsibilities of the ANCC at the national level are:
- Oversee the compliance of the certificates issued for ICT products, services, and processes with the cybersecurity certification frameworks established at the European level.
- Manage complaints related to the issued certificates and, if necessary, impose penalties for non-compliance. These responsibilities ensure the integrity and reliability of the cybersecurity certification process in the European Union.
- Act as a point of contact for stakeholders at the national level, ensuring the correct implementation of the Regulation and the European cybersecurity certification frameworks.
- Authorize Conformity Assessment Bodies (CABs - Conformity Assessment Body-) to ensure they meet the necessary requirements.
- Regularly supervise and audit CABs to ensure they maintain quality standards for the high level.
The ANCC Certification Body will be able to issue cybersecurity certificates for products, services, and processes that meet the requirements of the European high-level certification frameworks.
Collaboration with other national authorities and the European Union Agency for Cybersecurity (ENISA) to ensure consistency and quality of the certification frameworks.
Encourage the adoption of best cybersecurity practices and the use of certification frameworks among businesses and users.
Provide technical advice and support to national entities and stakeholders in implementing cybersecurity measures.
Apply penalties in cases of non-compliance with the requirements of Regulation (EU) 2019/881 by certifying entities or evaluators.
FAQ
A comprehensive set of provisions, technical requirements, standards, and procedures established at the Union level that apply to the certification or conformity assessment of specific ICT products, services, and processes;



