Cybersecurity Act
The Cybersecurity Act (EU 2019/881) gives ENISA a permanent mandate and sets up the EU framework for certifying ICT products, services and processes.
The Cybersecurity Act (Regulation (EU) 2019/881) is the EU regulation that gives the European Union Agency for Cybersecurity (ENISA) a permanent mandate and that establishes the European cybersecurity certification framework for ICT products, services and processes. It entered into force in 2019 and complements, but differs from, the later NIS2 directive, which sets baseline security and incident-reporting obligations for organisations rather than certifying products.
Under the framework, ENISA prepares candidate certification schemes that define security requirements and one of three assurance levels - basic, substantial or high - against which a product, service or process can be evaluated. Certification is carried out by accredited conformity assessment bodies and overseen by national cybersecurity certification authorities - in the Netherlands this role sits with the Rijksinspectie Digitale Infrastructuur (RDI) - though manufacturers may self-assess products at the basic assurance level. A certificate issued under an EU scheme is recognised across all member states and can replace overlapping national cybersecurity certification schemes.
The best-known scheme, EUCC, was adopted by the European Commission through Implementing Regulation (EU) 2024/482 and became applicable in early 2025. It is based on Common Criteria and is used to certify hardware such as smart cards and HSMs, including devices that can serve as a QSCD; qualified-signature-device certification under eIDAS article 30 today still largely relies on national and SOG-IS Common Criteria certification bodies, and the shift to EUCC is an ongoing transition. Further schemes, such as one for cloud services (EUCS) and one for 5G networks, are still in preparation and have not yet been adopted. Certification under the Act is voluntary unless another piece of EU or national law makes a specific scheme mandatory; mandatory product-security requirements for most hardware and software are instead introduced separately by the Cyber Resilience Act.