Certification schemes

Currently, various cybersecurity certification frameworks are being developed in the European Union under the CSA for the certification of ICT services and products. ENISA develops and maintains the CSA certification frameworks, with the support of two advisory groups: ECCG (European Cybersecurity Certification Group) and SCCG (Stakeholders Cybersecurity Certification Group) who provide their input on the matter.

Once ENISA delivers the draft of each developed certification framework, the European Commission turns it into an official European framework by publishing it as an Implementing Regulation. Once the frameworks are published, they are managed by ENISA in cooperation with the member states.

Status of cybersecurity certification frameworks

EUCC

European Cybersecurity Certification Scheme on Common Criteria

This framework, which focuses on ICT products such as hardware and software, was the first to be launched. On January 31, 2024, the European Commission published the Implementing Act that initiated the framework, and ENISA is publishing the state-of-the-art documents and guidelines that support certification in this framework.

EUCS

European Certification Scheme for Cloud Services

The framework for cloud services was drafted with the support of a working group and the Member States. Currently, the text is in the process of receiving feedback from the European Cybersecurity Certification Group (ECCG).

EU5G

European Cybersecurity Certification Scheme for 5G

This framework is being developed in two phases. The first phase, which ended in the fall of 2022, involved analyzing existing industrial assessments. A first draft of the framework will be available for public consultation, with the date still under discussion.

EUDI Wallet

The certification framework for the European Digital Identity Wallet (EUDI Wallet) is under development. This framework will focus on the security of digital wallet applications that enable the identification and authentication of EU citizens.

Artificial Intelligence

ENISA is assessing how artificial intelligence could be subject to cybersecurity certification, in light of the adoption of the draft EU Regulation on AI. This work is preparatory, as a formal request from the European Commission to develop a certification framework has not yet been received.

Managed Security Services

Mentioned in the NIS2 Directive as a critical sector, managed security services are at the core of preventing and responding to cybersecurity threats and incidents. ENISA has initiated preparatory work in this area, and future amendments to the Cybersecurity Act are expected to include the possibility of certifying these services.