Certification · Last verified

European Common Criteria-based Cybersecurity Certification Scheme

EUCC is the EU's first Cybersecurity Act certification scheme for ICT products, based on Common Criteria and applied from 27 February 2025. Certification bodies must be accredited to ISO/IEC 17065 by a national accreditation body; the scheme itself is voluntary, with no public-procurement mandate confirmed.

Class
Certification
Owner
European Commission, under Regulation (EU) 2019/881 (the Cybersecurity Act); the scheme was prepared by the European Union Agency for Cybersecurity (ENISA)
Who asks for it
Voluntary
Last verified

What it is

EUCC ("European Common Criteria-based Cybersecurity Certification Scheme") was adopted by COMMISSION IMPLEMENTING REGULATION (EU) 2024/482 of 31 January 2024, "laying down rules for the application of Regulation (EU) 2019/881 ... as regards the adoption of the European Common Criteria-based cybersecurity certification scheme (EUCC)", under legal basis "Article 49(7)" of Regulation (EU) 2019/881 (the Cybersecurity Act) — ENISA describes it as the EU's first cybersecurity certification scheme, adopted 31 January 2024.

The scheme rests on an existing, internationally used evaluation framework, not a new one: ENISA's own description states it "is based on the time-proven SOG-IS Common Criteria evaluation framework already used across 17 EU Member States". The regulation defines its terms directly: "'Common Criteria' mean the Common Criteria for Information Technology Security Evaluation, as set out in ISO standard ISO/IEC 15408; 'Common Evaluation Methodology' means ... ISO/IEC 18045".

It applies to ICT products — hardware, software and components — evaluated at assurance level Substantial or High. Certification bodies are accredited, not self-declared: "A certification body should be accredited in accordance with standard ISO/IEC 17065 by the national accreditation body for assurance level 'substantial' and 'high'" (Recital 18).

The regulation "shall enter into force on the twentieth day following that of its publication ... It shall apply from 27 February 2025. Chapter IV and Annex V shall apply from the date of entry into force of this Regulation" (art. 50). A later ENISA library page also names two amending regulations, (EU) 2024/3144 and (EU) 2025/2462, whose content was not separately opened for this record.

ENISA describes the scheme's basis plainly: "Voluntary-based, the new EUCC scheme allows ICT suppliers who wish to showcase proof of assurance to go through an EU commonly understood assessment process." No source opened for this record described a public-procurement or other legal mandate to hold an EUCC certificate.

Who owns it

The European Commission adopted the scheme by implementing regulation under the Cybersecurity Act; the underlying scheme candidate was prepared by the European Union Agency for Cybersecurity (ENISA), which also runs the public certification library referenced above.

Who assesses it

Certification bodies carry out EUCC evaluations, and they must themselves be accredited: "A certification body should be accredited in accordance with standard ISO/IEC 17065 by the national accreditation body for assurance level 'substantial' and 'high'" (Recital 18). Which national accreditation bodies have accredited which certification bodies, and under what published register, was not verified in the sources opened for this record.

Assurance levels

  • Substantial
  • High

Who asks for it

ENISA frames the audience as ICT suppliers themselves: "Voluntary-based, the new EUCC scheme allows ICT suppliers who wish to showcase proof of assurance to go through an EU commonly understood assessment process." No public-procurement mandate for EUCC was found in the sources opened for this record; whether other EU instruments create such a mandate was not researched for EUCC specifically and is not stated here.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"European Common Criteria-based Cybersecurity Certification Scheme." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/eucc

All frameworks & audits →